Courseiva
easyMultiple ChoiceObjective-mapped

CRISC Practice Question: A mid-sized retail company processes over 1…

A mid-sized retail company processes over 1 million credit card transactions daily. It uses an automated monitoring system with static thresholds to flag potential fraud. Recently, the fraud detection team has been overwhelmed by a 40% increase in false positive alerts, causing legitimate transactions to be delayed and customer service complaints to rise. The risk manager is tasked with improving the situation. After reviewing the alert logs, it is clear that the thresholds have not been updated in 18 months, and transaction patterns have shifted due to seasonal promotions and new payment methods. The team has limited resources and cannot handle the current alert volume. What should the risk manager recommend as the most effective course of action?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Perform a root cause analysis on the false positives to refine the detection rules and thresholds.

Performing a root cause analysis to refine detection rules and thresholds (Option A) directly addresses the outdated thresholds that caused the increase in false positives. This approach is systematic and can be tailored to the current transaction patterns without requiring additional resources or tools. Option B (deploying a machine learning tool) introduces new complexity and costs without fixing the underlying threshold issue, and the team's limited resources may hinder implementation. Option C (hiring an external consultant) is costly and slow, and may not be sustainable. Option D (increasing thresholds immediately) could reduce alert volume but risks missing true positives, making it a temporary fix rather than a long-term solution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Perform a root cause analysis on the false positives to refine the detection rules and thresholds.

    Why this is correct

    This directly addresses why false positives are high and enables data-driven adjustments.

  • Deploy an additional monitoring tool with machine learning capabilities.

    Why it's wrong here

    Adding another tool without tuning existing ones can double the workload and complexity.

  • Engage an external fraud detection consultant to review the system.

    Why it's wrong here

    External consultants may provide expertise but are not a quick fix; root cause must be addressed internally first.

  • Immediately increase the alert thresholds to reduce the volume of alerts.

    Why it's wrong here

    Blindly increasing thresholds risks missing actual fraud events.

About these practice questions

Courseiva writes every CRISC question from scratch — 983 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.