CRISC Risk Response and Reporting Practice Question
A Key Control Indicator (KCI) for a firewall rule review process shows an exception rate of 15% for the past quarter, exceeding the acceptable threshold of 10%. What is the most appropriate immediate action for the control owner?
⚠ Common exam trap
ISACA often tests the misconception that exceeding a KCI threshold automatically requires escalation or control replacement, when in fact the immediate step is always root cause analysis to determine if the threshold breach is a temporary anomaly or a systemic issue.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Investigate the root cause of the high exception rate
A KCI exception rate exceeding the threshold indicates a process failure, not necessarily a control failure. The control owner must first perform root cause analysis to determine whether the exceptions are due to misconfigured rules, policy violations, or environmental changes before taking corrective action. This aligns with the CRISC principle that control owners are responsible for monitoring and improving control effectiveness through investigation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Investigate the root cause of the high exception rate
Why this is correct
A 15% exception rate signals the control is failing beyond tolerance, so the control owner must first determine why exceptions occur before remediating. Root-cause investigation identifies whether the issue is rule design, process adherence or tooling, informing corrective action.
- ✗
Increase the acceptable threshold to 20%
Why it's wrong here
Raising the threshold to 20% conceals the control failure rather than correcting it, weakening the KCI's ability to signal risk. Thresholds are adjusted through formal risk appetite review when the original limit proves unrealistic, not to accommodate an adverse result.
- ✗
Replace the control with a different one
Why it's wrong here
Replacing the control discards a functioning firewall rule review process over a single quarter's threshold breach, without first diagnosing why exceptions rose. Control redesign is warranted when testing shows the control is fundamentally ineffective or misaligned to the risk, not merely underperforming.
- ✗
Escalate to the board immediately
Why it's wrong here
Escalating to the board bypasses the control owner's own remediation duties and the risk committee's review path; a 15% exception rate is an operational control failure, not a governance-level crisis. Board escalation is reserved for material risk exposures that exceed management's authority or appetite.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.