Courseiva
Risk Response and ReportinghardMultiple ChoiceObjective-mapped

CRISC Risk Response and Reporting Practice Question

A risk manager is evaluating the effectiveness of a control that requires dual authorization for high-value transactions. The Key Control Indicator (KCI) for this control is the rate of transactions processed without dual authorization (i.e., exception rate). If the acceptable exception rate is less than 1% and the observed rate is 2.5%, what is the most appropriate immediate action?

⚠ Common exam trap

A common mix-up: candidates assume a 2.5% exception rate is still 'low' and choose to accept the risk (Option C), but CRISC emphasizes that any deviation from the acceptable threshold requires investigation and remediation, not automatic acceptance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Investigate the root cause of the exceptions

The observed exception rate of 2.5% exceeds the acceptable threshold of 1%, indicating a control deficiency. The most appropriate immediate action is to investigate the root cause of the exceptions to determine whether the control is failing due to process gaps, user behavior, or system issues. Root cause analysis (RCA) is a foundational step before any remediation, as it prevents premature redesign or unjustified risk acceptance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Investigate the root cause of the exceptions

    Why this is correct

    Root cause analysis is needed to determine why the control is failing.

  • Redesign the control immediately

    Why it's wrong here

    Redesign should come after understanding the root cause.

  • Accept the risk since the rate is still low

    Why it's wrong here

    The rate exceeds the acceptable threshold and requires action.

  • Increase the acceptable exception rate to 2.5%

    Why it's wrong here

    Changing the threshold without addressing the control deficiency is inappropriate.

About these practice questions

Courseiva writes every CRISC question from scratch — 983 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.