CRISC Risk Response and Mitigation Practice Question
A risk manager is reviewing the risk treatment plan for a new mobile banking application. The plan includes implementing multi-factor authentication (MFA) and conducting regular vulnerability scans. The risk manager wants to ensure that the controls are operating effectively. Which of the following should be performed to verify the effectiveness of the controls?
⚠ Common exam trap
Test-takers frequently confuse control testing with risk assessment; risk assessment identifies risks, but control testing verifies that controls mitigate those risks effectively.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Control testing
To verify that controls are operating effectively, the risk manager should perform control testing. This involves examining and testing the controls to ensure they are implemented correctly and functioning as intended. Risk assessment, gap analysis, and BIA serve different purposes and do not provide assurance on control effectiveness.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Gap analysis
Why it's wrong here
Gap analysis compares current state to a desired state, often to identify missing controls. It is useful during planning, but it does not verify the operational effectiveness of implemented controls. The controls are already in place; the risk manager needs to test them, not just identify gaps.
- ✗
Business impact analysis (BIA)
Why it's wrong here
A BIA is used to determine critical business functions and the impact of disruptions. It is part of business continuity planning and does not verify the effectiveness of security controls like MFA or vulnerability scans. Therefore, it is not the appropriate activity here.
- ✓
Control testing
Why this is correct
Control testing involves evaluating whether controls are designed and operating effectively. It can include walkthroughs, inspections, and re-performance. For MFA and vulnerability scans, testing might involve attempting to bypass MFA or reviewing scan reports to ensure they are complete and timely. This provides assurance that the controls are functioning as intended and mitigating the risk.
- ✗
Risk assessment
Why it's wrong here
A risk assessment identifies and evaluates risks, but it does not verify the effectiveness of existing controls. It may consider controls as part of the analysis, but it is not a verification activity. The risk manager already has a treatment plan; the next step is to test the controls, not reassess the risk.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.