Courseiva
mediumMultiple Choice

CRISC Practice Question: A risk practitioner notices that a key control is…

A risk practitioner notices that a key control is tested only once a year, but the associated risk has a high velocity of change. What is the BEST recommendation?

⚠ Common exam trap

Many exam-takers confuse 'meets regulatory requirements' (Option C) with 'adequate risk management,' failing to recognize that compliance is the floor, not the ceiling, when risk velocity is high.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Increase testing frequency to quarterly or monthly

A high velocity of change means the risk profile can shift rapidly between annual tests, leaving the organization exposed for months. Increasing testing frequency to quarterly or monthly ensures that control effectiveness is validated in near real-time, aligning monitoring cadence with risk dynamics. This is a core principle of risk-based monitoring: the testing interval must match the speed at which the risk can materialize.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Remove the control if it cannot be tested more often

    Why it's wrong here

    Removing the control leaves the high-velocity risk entirely unmitigated, which is never acceptable when treatment is required. The recommendation should instead increase test frequency to match the risk's rate of change. Control removal is tempting when a control is costly or ineffective, but that scenario calls for redesign or replacement, not abandonment.

  • ✗

    Wait for a control failure before increasing frequency

    Why it's wrong here

    Waiting for a failure means the risk materialises before testing frequency changes, which is reactive rather than proactive. It tempts as a way to justify current effort, but high-velocity risks demand testing aligned to their rate of change, not to observed incidents.

  • ✗

    Continue annual testing because it meets regulatory requirements

    Why it's wrong here

    Annual testing leaves a high-velocity risk unmonitored for most of the year, so control effectiveness cannot be assured between cycles. It tempts because regulatory minimums exist, but compliance with a baseline frequency does not address the risk's actual rate of change.

  • ✓

    Increase testing frequency to quarterly or monthly

    Why this is correct

    Quarterly or monthly testing matches control verification to the risk's high velocity of change, closing the exposure window that annual testing leaves open. Frequent retesting detects control degradation before it materially affects residual risk, satisfying the stem's requirement that assurance cadence align with how quickly the underlying risk landscape shifts.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.