mediumMultiple ChoiceObjective-mapped
CRISC Practice Question: After a significant cybersecurity incident, the…
After a significant cybersecurity incident, the board requests a report on the effectiveness of the security controls that were in place. Which reporting approach would BEST demonstrate the controls' performance?
⚠ Common exam trap
A common mix-up: candidates confuse operational metrics (like patching counts or incident timelines) with control effectiveness reporting, which must be tied to risk appetite and KRIs to demonstrate whether controls are actually managing risk within acceptable boundaries.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Compare control test results against defined KRIs and risk appetite
Comparing control test results against defined Key Risk Indicators (KRIs) and risk appetite directly demonstrates whether the controls are operating within acceptable risk thresholds. This approach provides the board with a clear, quantitative assessment of control effectiveness relative to the organization's risk tolerance, which is the core objective of risk and control monitoring and reporting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
List all controls and their test results
Why it's wrong here
A raw list does not provide a meaningful assessment of effectiveness.
- ✗
Show the number of vulnerabilities patched
Why it's wrong here
Patch counts are operational metrics, not a measure of control effectiveness.
- ✗
Provide a summary of the incident timeline
Why it's wrong here
An incident timeline does not measure control performance.
- ✓
Compare control test results against defined KRIs and risk appetite
Why this is correct
This links control outcomes to risk tolerance, demonstrating effectiveness.
Go deeper
Related to this question
About these practice questions
One of 983 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.