CRISC Risk Response and Reporting Practice Question
A healthcare provider has experienced repeated phishing incidents that led to credential compromise. The risk committee has approved a new email security control that will quarantine suspicious messages and enforce multifactor authentication. Which TWO activities are essential to validate that the control is operating effectively after implementation? (Choose two.)
⚠ Common exam trap
The trap here is treating vendor certifications and policy attestations as evidence of control effectiveness, when only direct testing and performance monitoring demonstrate operating effectiveness.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct periodic control testing by simulating phishing campaigns and reviewing whether messages are quarantined and MFA is enforced.
Validation of a control requires evidence that it operates as intended in the production environment. Simulated phishing tests combined with MFA enforcement checks directly exercise the control against realistic threats, while performance metrics and exception reporting provide continuous, quantifiable evidence of effectiveness. Vendor documentation, policy acknowledgment, and project delivery metrics may support the program but do not demonstrate that the control is actually working.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Review the vendor's marketing materials and SOC 2 report to confirm the product supports quarantine and MFA features.
Why it's wrong here
Vendor documentation and SOC 2 reports describe the product's capabilities and the vendor's own control environment, but they do not demonstrate that the healthcare provider's specific configuration blocks real phishing attempts. Relying on vendor assertions alone is a common assurance gap. These artifacts support due diligence during selection, not post-implementation validation of operating effectiveness in this environment.
- ✓
Conduct periodic control testing by simulating phishing campaigns and reviewing whether messages are quarantined and MFA is enforced.
Why this is correct
Simulated phishing campaigns and verification of MFA enforcement directly test whether the new control performs as designed against realistic attack patterns. This produces evidence about control effectiveness rather than assuming implementation equals effectiveness. Periodic testing also reveals configuration drift and user bypass behaviors, allowing the risk committee to confirm that the approved risk response is actually reducing the phishing exposure.
- ✗
Confirm that the project to implement the control was completed within the approved budget and schedule.
Why it's wrong here
Budget and schedule adherence is project management performance, not control effectiveness. A control can be delivered on time and on budget yet be misconfigured, bypassed, or ineffective against actual threats. While project metrics matter for delivery governance, they provide no assurance that phishing messages are quarantined or that MFA is enforced, so they cannot validate the risk response.
- ✗
Ask employees to sign an acknowledgment that they have read the updated acceptable use policy.
Why it's wrong here
Policy acknowledgment confirms awareness and intent to comply, but it does not test whether the email security control actually quarantines malicious messages or enforces multifactor authentication. Training and attestation are preventive and cultural measures, not validation of technical control operation. Treating a signed acknowledgment as evidence of control effectiveness would mislead the risk committee about the true residual phishing exposure.
- ✓
Collect and analyze control performance metrics, such as the percentage of suspicious emails quarantined and MFA challenge success rates, and report exceptions.
Why this is correct
Performance metrics and exception reporting provide ongoing, quantifiable evidence that the quarantine and MFA functions are working at the expected level. Reviewing metrics such as quarantine rates and MFA challenge success identifies degradation or misconfiguration before incidents occur. This continuous validation aligns with monitoring expectations and gives the risk committee objective data to confirm the control remains effective over time.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.