CRISC IT Risk Identification Practice Question
A risk practitioner is assessing the effectiveness of the control environment supporting an online trading platform. Management asserts that controls are mature, but the practitioner must determine which activities constitute control monitoring rather than one-time assurance. Which TWO of the following activities are examples of ongoing control monitoring? (Choose two.)
⚠ Common exam trap
The trap here is treating any control-related activity, such as documentation or an annual self-assessment, as monitoring even though it lacks recurring observation, thresholds, and escalation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reviewing a monthly dashboard of failed login attempts and account lockouts against defined thresholds.
Ongoing monitoring relies on recurring observation with defined thresholds, ownership, and escalation. Reviewing authentication dashboards against thresholds and tracking remediation of open findings both provide continuous visibility into whether controls operate as intended and allow timely intervention. Periodic penetration tests, annual self-assessments, and register documentation are point-in-time or record-keeping activities that do not deliver the continuous feedback loop monitoring requires.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Reviewing a monthly dashboard of failed login attempts and account lockouts against defined thresholds.
Why this is correct
Reviewing a recurring dashboard against predefined thresholds is a continuous monitoring activity that detects control degradation or anomalous conditions as they emerge. Because it operates on a defined cadence with escalation criteria, it provides timely evidence that authentication controls continue to function and allows corrective action before losses accumulate. This is characteristic of monitoring rather than a point-in-time audit or assessment performed once and then shelved.
- ✗
Documenting the control environment in the risk register during the annual risk assessment cycle.
Why it's wrong here
Documenting controls in the register during the annual cycle records what controls exist and how they map to risks, which supports analysis but does not observe whether they operate effectively over time. Documentation can become stale the moment processes or systems change. It is a foundational record-keeping activity, not a monitoring mechanism with thresholds, cadence, and escalation that would reveal emerging control degradation.
- ✗
Performing a control self-assessment workshop with process owners at the start of the fiscal year.
Why it's wrong here
A control self-assessment workshop is a periodic, point-in-time evaluation of control design and operation based on owner input. It is valuable for accountability and awareness but does not provide continuous observation between workshops, and it relies on the same owners whose performance is being evaluated. It therefore serves as assessment rather than the ongoing monitoring expected to detect control failures as they occur.
- ✗
Commissioning an external penetration test of the trading platform once every two years.
Why it's wrong here
A biennial penetration test is point-in-time assurance that evaluates the platform's security posture at a moment, not ongoing monitoring of control performance. Between tests, changes to code, configuration, and infrastructure can silently erode effectiveness. While valuable for validating exploitable weaknesses, it lacks the continuous feedback loop, defined thresholds, and timely escalation that distinguish monitoring from periodic assessment.
- ✓
Tracking remediation of open findings from audits and assessments in a centralized register with owners and due dates.
Why this is correct
Tracking open findings with assigned owners, due dates, and status updates is a monitoring activity that maintains visibility into whether agreed corrective actions actually close identified gaps. It provides an ongoing feedback loop and enables escalation when items age or slip, which is exactly what distinguishes monitoring from a one-time review. Without this tracking, findings can be closed on paper while the underlying control weakness persists.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.