Courseiva

CRISC Risk Response and Mitigation Practice Question

A financial services firm is deploying a new trading platform. The risk committee has approved a risk treatment plan that includes a requirement to implement a circuit breaker that halts trading if losses exceed a predefined threshold. The project manager asks the risk practitioner to verify that the control is designed effectively before go-live. Which activity BEST validates the design of this risk mitigation control?

⚠ Common exam trap

A common mix-up: candidates confuse design effectiveness with operating effectiveness, and selecting live monitoring as the validation method.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Review the control's technical specification and conduct a tabletop walkthrough with the trading and technology teams.

Design effectiveness testing confirms that a control, as planned, will mitigate the identified risk before it is relied upon. Reviewing specifications and walking through scenarios with stakeholders validates the logic, thresholds, and responsibilities. Live monitoring tests operating effectiveness, internal audit provides later assurance, and vendor documentation only confirms feature availability. The pre-go-live design validation is the most direct and timely way to confirm the circuit breaker will work as intended.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Monitor trading losses for the first month after go-live and confirm that the circuit breaker activates when the threshold is breached.

    Why it's wrong here

    Monitoring live losses tests operating effectiveness, not design effectiveness. The question asks for validation before go-live, and waiting for a real breach could cause financial harm. While operational testing is valuable later, it does not confirm that the control was designed correctly to meet the risk treatment requirement. Design validation must occur before the control is relied upon in production.

  • ✗

    Confirm that the vendor's product documentation states the circuit breaker feature is included in the licensed version.

    Why it's wrong here

    Vendor documentation confirms feature availability but not that the control is configured or designed to meet the firm's specific risk threshold. A licensed feature can be misconfigured or not integrated with the trading platform's loss calculation. This option addresses procurement, not design effectiveness. The risk practitioner must verify the actual implementation logic and operational procedures, not just the product's marketing or technical specification.

  • ✗

    Ask the internal audit team to add the circuit breaker to the annual audit plan and review it during the next audit cycle.

    Why it's wrong here

    Internal audit provides independent assurance after the control has been implemented and operating. Scheduling a future audit does not validate the design before go-live, and audit cycles may occur months later. The risk practitioner needs timely design validation to support the go-live decision. Relying on a future audit leaves the project exposed to a poorly designed control during initial trading.

  • ✓

    Review the control's technical specification and conduct a tabletop walkthrough with the trading and technology teams.

    Why this is correct

    Design effectiveness is evaluated before the control operates in production. Reviewing the technical specification confirms that the circuit breaker logic matches the risk treatment requirement, and a tabletop walkthrough reveals whether the teams understand how the threshold triggers and who is responsible for halting trading. This combination validates the design without waiting for a live trading loss event.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.