Courseiva
easyMultiple Choice

CRISC Practice Question: A financial institution monitors the number of…

A financial institution monitors the number of unauthorized access attempts to its core banking system. The risk owner recommends increasing the monitoring frequency from daily to hourly because a recent attack exploited a delayed detection. Which of the following is the PRIMARY benefit of this change?

⚠ Common exam trap

Watch out — candidates often confuse 'increased monitoring frequency' with 'improved system performance' or 'reduced false positives,' when in reality the primary benefit is always faster detection of anomalies, not cost savings or performance gains.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Faster detection of anomalies

Increasing monitoring frequency from daily to hourly reduces the time between an unauthorized access attempt and its detection. This faster detection enables the security team to respond more quickly to anomalies, minimizing the potential impact of an attack that exploits delayed detection, such as a brute-force or credential-stuffing campaign.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Faster detection of anomalies

    Why this is correct

    Hourly polling shortens the interval between an intrusion attempt occurring and its appearance in monitoring output, directly addressing the delayed-detection weakness the attack exploited. Detection speed, not prevention or impact reduction, is the constraint the risk owner is targeting.

  • ✗

    Lower cost of monitoring

    Why it's wrong here

    Hourly polling multiplies collection, storage and analyst effort, so monitoring cost rises, not falls. Cost reduction is tempting because batching checks less often genuinely lowers overhead, and that would be the benefit if the driver were budget pressure rather than delayed attack detection.

  • ✗

    Increased system performance

    Why it's wrong here

    Frequent polling adds query and processing load on the core banking system, so performance does not improve. It is tempting because faster detection sounds like a system health gain, and reduced load would be the benefit if the change were fewer checks or lighter collection.

  • ✗

    Reduced false positive rate

    Why it's wrong here

    Polling more often does not change detection logic, so the proportion of alerts that are false positives stays the same. It is tempting because tuning thresholds does cut false positives, and that would be the benefit if analysts were overwhelmed by noisy alerts rather than by slow detection.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.