Courseiva
easyMultiple Choice

CRISC Practice Question: A mid-sized retail company processes over 1…

A mid-sized retail company processes over 1 million credit card transactions daily. It uses an automated monitoring system with static thresholds to flag potential fraud. Recently, the fraud detection team has been overwhelmed by a 40% increase in false positive alerts, causing legitimate transactions to be delayed and customer service complaints to rise. The risk manager is tasked with improving the situation. After reviewing the alert logs, it is clear that the thresholds have not been updated in 18 months, and transaction patterns have shifted due to seasonal promotions and new payment methods. The team has limited resources and cannot handle the current alert volume. What should the risk manager recommend as the most effective course of action?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Perform a root cause analysis on the false positives to refine the detection rules and thresholds.

Performing a root cause analysis to refine detection rules and thresholds (Option A) directly addresses the outdated thresholds that caused the increase in false positives. This approach is systematic and can be tailored to the current transaction patterns without requiring additional resources or tools. Option B (deploying a machine learning tool) introduces new complexity and costs without fixing the underlying threshold issue, and the team's limited resources may hinder implementation. Option C (hiring an external consultant) is costly and slow, and may not be sustainable. Option D (increasing thresholds immediately) could reduce alert volume but risks missing true positives, making it a temporary fix rather than a long-term solution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Perform a root cause analysis on the false positives to refine the detection rules and thresholds.

    Why this is correct

    Static thresholds left unchanged for 18 months no longer reflect shifted transaction patterns, so the alerts themselves are mis-calibrated. Root cause analysis identifies which rules and thresholds generate the false positives, letting the team recalibrate detection precisely rather than adding headcount it does not have.

  • ✗

    Deploy an additional monitoring tool with machine learning capabilities.

    Why it's wrong here

    A new machine learning tool adds cost and integration effort while leaving the stale static thresholds untouched, so the false-positive driver persists. Machine learning suits environments lacking labelled historical data; here the thresholds simply need recalibrating against current transaction patterns.

  • ✗

    Engage an external fraud detection consultant to review the system.

    Why it's wrong here

    An external consultant reviews and advises but does not itself recalibrate the static thresholds that generate the false positives, and consumes limited budget. Consultants are warranted when internal expertise is absent; here the logs already identify stale thresholds as the cause.

  • ✗

    Immediately increase the alert thresholds to reduce the volume of alerts.

    Why it's wrong here

    Raising static thresholds suppresses alerts indiscriminately, letting genuine fraud through while the underlying pattern shift from promotions and new payment methods remains unaddressed. It is tempting because it immediately cuts volume, and it would be correct only if the thresholds were demonstrably too tight rather than stale.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.