Courseiva
mediumMultiple Choice

CRISC Practice Question: A healthcare organization operates a legacy…

A healthcare organization operates a legacy electronic health record (EHR) system that is manually monitored for access anomalies by a small IT team. The organization is planning to migrate to a new cloud-based EHR with integrated logging and monitoring. However, due to budget constraints, the migration will take two years. In the interim, the risk manager wants to improve monitoring for unauthorized access to patient data. The current manual process involves weekly log reviews, but recent audits have identified instances of delayed detection (up to two weeks) and missed incidents. The IT team can dedicate only 10 additional hours per week for monitoring. What is the best approach to enhance monitoring during the transition period?

⚠ Common exam trap

CRISC often tests the tendency to choose the most comprehensive or outsourced solution — candidates overlook that risk-based prioritization is preferred when resources are constrained, even if it is not the 'perfect' long-term fix.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a phased risk-based approach, prioritizing monitoring of high-risk areas such as privileged accounts and sensitive patient data.

Given budget and staffing constraints, a phased risk-based approach that prioritizes high-risk areas (privileged accounts, sensitive patient data) is the most practical way to improve monitoring during the two-year transition. It focuses limited resources where risk is highest and can be implemented incrementally without a large upfront investment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Outsource the monitoring to a third-party managed security service provider.

    Why it's wrong here

    Outsourcing transfers log review to a provider lacking the clinical context and legacy EHR access needed to triage access anomalies, and onboarding exceeds the interim window. It is tempting where in-house monitoring capacity is genuinely absent; here the team has 10 weekly hours available for targeted improvement.

  • ✗

    Implement a full automation suite for access monitoring immediately.

    Why it's wrong here

    A full automation suite cannot be deployed within the interim window: procurement, integration and tuning typically exceed the two-year migration timeline, and the team's 10 weekly hours cannot sustain it. It is tempting because automation is the eventual target state once the cloud EHR's integrated logging is live.

  • ✓

    Use a phased risk-based approach, prioritizing monitoring of high-risk areas such as privileged accounts and sensitive patient data.

    Why this is correct

    A phased risk-based approach directs the team's limited ten hours weekly toward privileged accounts and sensitive patient data, where unauthorised access carries the greatest impact. This targets the constraint of scarce analyst capacity while reducing the delayed detection and missed incidents that audits identified, without awaiting the two-year cloud migration.

  • ✗

    Accept the current monitoring state as adequate given the upcoming migration.

    Why it's wrong here

    Accepting the current state leaves the two-week detection delay and missed incidents unaddressed, breaching the risk manager's requirement to improve monitoring now. It is tempting when a migration is imminent, but acceptance is only defensible where residual risk already sits within the organisation's stated tolerance.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.