Courseiva
Risk Response and Reporting →mediumMultiple Choice

CRISC Risk Response and Reporting Practice Question

A risk manager is evaluating a control that addresses a high-risk finding from an internal audit. Which of the following is the MOST important factor in determining whether the control is effective?

⚠ Common exam trap

Watch out — candidates often confuse 'alignment with best practices' (Option D) with proof of effectiveness, but CRISC requires evidence of actual control performance, not just theoretical compliance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Key control indicators (KCIs) such as control deficiency rate and test results

B is correct because the effectiveness of a control is determined by its ability to reduce risk to an acceptable level, which is directly measured by key control indicators (KCIs) such as the control deficiency rate and test results. These metrics provide empirical evidence of whether the control is operating as intended and mitigating the identified high-risk finding. Without such performance data, any assessment of effectiveness is speculative.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The vendor's reputation for providing reliable security solutions

    Why it's wrong here

    Vendor reputation is a procurement consideration, not evidence that the deployed control mitigates the specific audit finding. Reputation matters when shortlisting suppliers during selection; effectiveness is judged by testing whether the control actually reduces the identified risk to within tolerance.

  • ✓

    Key control indicators (KCIs) such as control deficiency rate and test results

    Why this is correct

    KCIs provide measurable evidence of how reliably the control performs in practise, directly satisfying the audit finding's requirement to prove effectiveness. Deficiency rate and test results reveal whether the control operates consistently, which is the decisive factor when a high-risk finding demands demonstrable, ongoing assurance rather than design intent alone.

  • ✗

    The cost of the control relative to the asset value

    Why it's wrong here

    Cost relative to asset value is a budgetary justification, not evidence that the control mitigates the audit finding. Effectiveness depends on whether the control actually reduces the identified risk to within tolerance. Cost-benefit analysis is tempting because it supports control selection and funding decisions, but it cannot demonstrate that a deployed control operates as intended.

  • ✗

    The control's alignment with industry best practices

    Why it's wrong here

    Alignment with best practice indicates sound design but does not demonstrate that the control operates as intended against this finding. Best-practice alignment is useful when designing or benchmarking controls; effectiveness requires evidence, such as testing results, that the control actually mitigates the audited risk.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.