mediumMultiple Choice
CRISC Practice Question: A risk practitioner notices that a key control is…
A risk practitioner notices that a key control is tested only once a year, but the associated risk has a high velocity of change. What is the BEST recommendation?
⚠ Common exam trap
Many exam-takers confuse 'meets regulatory requirements' (Option C) with 'adequate risk management,' failing to recognize that compliance is the floor, not the ceiling, when risk velocity is high.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Increase testing frequency to quarterly or monthly
A high velocity of change means the risk profile can shift rapidly between annual tests, leaving the organization exposed for months. Increasing testing frequency to quarterly or monthly ensures that control effectiveness is validated in near real-time, aligning monitoring cadence with risk dynamics. This is a core principle of risk-based monitoring: the testing interval must match the speed at which the risk can materialize.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Remove the control if it cannot be tested more often
Why it's wrong here
Removing the control leaves the high-velocity risk entirely unmitigated, which is never acceptable when treatment is required. The recommendation should instead increase test frequency to match the risk's rate of change. Control removal is tempting when a control is costly or ineffective, but that scenario calls for redesign or replacement, not abandonment.
- ✗
Wait for a control failure before increasing frequency
Why it's wrong here
Waiting for a failure means the risk materialises before testing frequency changes, which is reactive rather than proactive. It tempts as a way to justify current effort, but high-velocity risks demand testing aligned to their rate of change, not to observed incidents.
- ✗
Continue annual testing because it meets regulatory requirements
Why it's wrong here
Annual testing leaves a high-velocity risk unmonitored for most of the year, so control effectiveness cannot be assured between cycles. It tempts because regulatory minimums exist, but compliance with a baseline frequency does not address the risk's actual rate of change.
- ✓
Increase testing frequency to quarterly or monthly
Why this is correct
Quarterly or monthly testing matches control verification to the risk's high velocity of change, closing the exposure window that annual testing leaves open. Frequent retesting detects control degradation before it materially affects residual risk, satisfying the stem's requirement that assurance cadence align with how quickly the underlying risk landscape shifts.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.