mediumMultiple ChoiceObjective-mapped
CRISC Practice Question: A healthcare organization is subject to strict…
A healthcare organization is subject to strict regulatory requirements regarding patient data privacy. The organization has a control that requires all access to patient records to be logged and reviewed weekly by the compliance team. The review is currently performed manually by sampling 10% of the logs. The compliance team reports that the review takes 20 hours per week and they are often unable to complete it on time. As a result, some suspicious access patterns are detected weeks after they occur. The risk manager needs to propose an improvement to the monitoring process. The organization's risk appetite for undetected unauthorized access is very low. Which of the following is the MOST effective recommendation?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy user behavior analytics (UBA) tools for automated anomaly detection.
The most effective recommendation because deploying user behavior analytics (UBA) tools automates the detection of anomalous access patterns, enabling real-time or near-real-time monitoring. This reduces manual effort, improves detection speed, and aligns with the organization's low risk appetite for undetected unauthorized access. Option A is wrong because reducing review frequency to bi-weekly would further delay detection, increasing risk. Option B is wrong because hiring additional staff only addresses the workload issue temporarily and does not improve detection timeliness or scalability. Option D is wrong because increasing the sample size to 50% would increase manual effort and still result in delayed detection due to the manual review bottleneck.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reduce the review frequency to bi-weekly to free up time.
Why it's wrong here
Less frequent reviews increase the window for undetected access.
- ✗
Hire additional staff to perform the manual reviews.
Why it's wrong here
Hiring increases cost and still relies on manual sampling.
- ✓
Deploy user behavior analytics (UBA) tools for automated anomaly detection.
Why this is correct
UBA provides continuous, automated monitoring and immediate alerts.
- ✗
Increase the sample size to 50% of logs for better coverage.
Why it's wrong here
More manual checks will increase workload and delays.
Go deeper
Related to this question
About these practice questions
One of 983 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.