Courseiva
IT Risk Assessment →mediumMultiple Choice

CRISC IT Risk Assessment Practice Question

A risk assessment identifies a critical vulnerability in a web application. Which control type would be most effective in preventing exploitation of this vulnerability?

⚠ Common exam trap

CRISC often tests the distinction between control types; candidates must recognize that 'prevent' questions require a preventive control, not a detective or corrective one, even if those are also valuable.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Preventive control such as patching the vulnerability

A preventive control stops an incident before it occurs, and patching the vulnerability removes the exploitable condition entirely, which is the most effective way to prevent exploitation. Since the vulnerability is identified as critical, remediation via patching directly addresses the root cause rather than merely detecting or recovering from an exploit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Compensating control such as additional monitoring

    Why it's wrong here

    Additional monitoring is compensating, providing an alternative safeguard when the primary control cannot be applied; it observes rather than blocks. Compensating controls suit situations where patching is impossible and residual risk must be managed another way.

  • ✓

    Preventive control such as patching the vulnerability

    Why this is correct

    Patching removes the vulnerable code path entirely, stopping exploitation before it can occur, which is the defining mechanism of a preventive control. This directly satisfies the stem's requirement for the control type most effective at preventing exploitation of the identified web application vulnerability.

  • ✗

    Corrective control such as backup restoration

    Why it's wrong here

    Backup restoration is corrective: it recovers data after exploitation has already succeeded, so it cannot stop the attack. Corrective controls are the right answer when the question asks how to restore operations following an incident, not how to block it.

  • ✗

    Detective control such as log monitoring

    Why it's wrong here

    Log monitoring is detective: it identifies exploitation after it occurs, generating alerts rather than stopping the attack. Detective controls are the correct answer when the requirement is to discover and respond to incidents, not to prevent them.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.