CRISC Risk Response and Reporting Practice Question
A company is implementing a new access control system. During the project, the IT team updates the system configuration without notifying the risk team. This leads to a temporary misconfiguration that exposes sensitive data. Which process should have been followed to prevent this issue?
⚠ Common exam trap
CRISC often tests the distinction between preventive controls (change management) and detective controls (continuous monitoring) — candidates frequently select continuous monitoring because it sounds proactive, but the question asks what should have been followed to prevent the issue, not detect it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Change management process
The change management process is the correct answer because it is the formal ITIL/COBIT-aligned control that ensures all configuration changes to production systems are requested, assessed for risk impact, approved by relevant stakeholders (including the risk team), tested, and documented before implementation. In this scenario, the IT team bypassed this process by updating the access control system configuration without notifying the risk team, which is precisely the failure mode change management is designed to prevent. A properly executed change management workflow would have triggered a risk assessment and impact analysis, flagging the sensitive data exposure before the misconfiguration reached production.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Control design approval
Why it's wrong here
Design approval happens before implementation, not during changes.
- ✗
Continuous monitoring
Why it's wrong here
Continuous monitoring would detect the issue but not prevent it.
- ✓
Change management process
Why this is correct
Change management requires configuration changes to be requested, risk-assessed, approved and tested before implementation. The unannounced update bypassed that control, causing the misconfiguration that exposed sensitive data, so this process directly addresses the stem's root cause.
- ✗
Vendor risk assessment
Why it's wrong here
The issue is internal, not vendor-related.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.