hardMultiple Choice
CRISC Practice Question: After a control self-assessment (CSA) workshop,…
After a control self-assessment (CSA) workshop, business units reported that 80% of controls are operating effectively. However, internal audit's recent testing indicates a 30% control failure rate. What is the BEST explanation for this discrepancy?
⚠ Common exam trap
The trap is selecting a plausible-sounding but speculative cause (timing, training, scope) instead of the fundamental methodological difference — CSA is subjective self-reporting, audit is objective evidence-based testing — which is the best explanation for systematic over-reporting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CSA participants may have a biased perception of control effectiveness, while audit uses objective evidence.
The most likely explanation for the gap between CSA self-reported effectiveness (80%) and audit-observed failure (30%) is that CSA participants assess controls subjectively and may overestimate effectiveness due to familiarity, optimism, or lack of objectivity, whereas internal audit tests controls using independent, evidence-based procedures. This perception bias is a well-documented limitation of self-assessment. The other options introduce speculative factors (timing, training, scope) that are not supported by the scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The audit was conducted three months after the CSA, and controls may have degraded.
Why it's wrong here
Timing alone cannot explain a 30% failure rate; degradation over three months would be gradual, not a systematic gap between self-reported and independently tested results. It is tempting because control decay is real, and it would be the best explanation if audit testing showed a modest decline since the CSA.
- ✓
CSA participants may have a biased perception of control effectiveness, while audit uses objective evidence.
Why this is correct
CSA workshops rely on business units self-reporting, which introduces optimism bias and limited sampling, whereas internal audit tests controls against objective evidence such as transaction logs. That difference in evidence quality, not control design, explains the 80% versus 30% gap.
- ✗
CSA participants lacked adequate training on what constitutes a control failure.
Why it's wrong here
Inadequate training is a contributing factor, but the stem's 80% versus 30% split points to self-assessment bias, where business units overrate their own controls. It is tempting because untrained assessors do misjudge failures, and it would be correct if evidence showed participants consistently misapplied failure definitions.
- ✗
The CSA covered a different scope of controls than the audit.
Why it's wrong here
Scope differences would produce incomparable populations, yet the stem presents both figures as covering the same controls, so this does not explain the gap. It is tempting because misaligned CSA and audit universes do cause apparent discrepancies, and it would be correct if the two exercises genuinely assessed different control sets.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.