Courseiva
Risk Response and ReportingmediumMultiple SelectObjective-mapped

CRISC Risk Response and Reporting Practice Question

A financial services company is implementing a new control to mitigate the risk of unauthorized access to customer data. Which TWO of the following are key factors to consider during the control design phase?

⚠ Common exam trap

CRISC often tests the distinction between design-phase activities (like selecting control type and cost-benefit analysis) versus implementation or operational activities (like assigning ownership or training), leading candidates to confuse 'what to design' with 'how to run' the control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Conducting a cost-benefit analysis comparing annual control cost to ALE reduction

A cost-benefit analysis comparing the annualized cost of the control to the reduction in Annualized Loss Expectancy (ALE) is a key factor during control design because it ensures the control is economically justified. This aligns with the risk response principle that the cost of mitigation should not exceed the risk reduction benefit, a core tenet of quantitative risk analysis in CRISC.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Assigning control ownership to a specific individual or team

    Why it's wrong here

    Control ownership is established during implementation, not design.

  • Conducting a cost-benefit analysis comparing annual control cost to ALE reduction

    Why this is correct

    Cost-benefit analysis ensures the control is economically justified.

  • Performing user training on the new control

    Why it's wrong here

    Training is a post-implementation activity.

  • Developing a detailed control implementation plan

    Why it's wrong here

    Implementation plan is part of the later implementation phase.

  • Selecting the control type (preventive, detective, or corrective)

    Why this is correct

    Choosing the right control type is fundamental to addressing the specific risk.

About these practice questions

One of 983 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.