Courseiva

CRISC Risk Response and Reporting Practice Question

A company is implementing a new access control system. During the project, the IT team updates the system configuration without notifying the risk team. This leads to a temporary misconfiguration that exposes sensitive data. Which process should have been followed to prevent this issue?

⚠ Common exam trap

CRISC often tests the distinction between preventive controls (change management) and detective controls (continuous monitoring) — candidates frequently select continuous monitoring because it sounds proactive, but the question asks what should have been followed to prevent the issue, not detect it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Change management process

The change management process is the correct answer because it is the formal ITIL/COBIT-aligned control that ensures all configuration changes to production systems are requested, assessed for risk impact, approved by relevant stakeholders (including the risk team), tested, and documented before implementation. In this scenario, the IT team bypassed this process by updating the access control system configuration without notifying the risk team, which is precisely the failure mode change management is designed to prevent. A properly executed change management workflow would have triggered a risk assessment and impact analysis, flagging the sensitive data exposure before the misconfiguration reached production.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Control design approval

    Why it's wrong here

    Design approval happens before implementation, not during changes.

  • ✗

    Continuous monitoring

    Why it's wrong here

    Continuous monitoring would detect the issue but not prevent it.

  • ✓

    Change management process

    Why this is correct

    Change management requires configuration changes to be requested, risk-assessed, approved and tested before implementation. The unannounced update bypassed that control, causing the misconfiguration that exposed sensitive data, so this process directly addresses the stem's root cause.

  • ✗

    Vendor risk assessment

    Why it's wrong here

    The issue is internal, not vendor-related.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.