Courseiva
mediumMultiple ChoiceObjective-mapped

CRISC Practice Question: After a significant cybersecurity incident, the…

After a significant cybersecurity incident, the board requests a report on the effectiveness of the security controls that were in place. Which reporting approach would BEST demonstrate the controls' performance?

⚠ Common exam trap

A common mix-up: candidates confuse operational metrics (like patching counts or incident timelines) with control effectiveness reporting, which must be tied to risk appetite and KRIs to demonstrate whether controls are actually managing risk within acceptable boundaries.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Compare control test results against defined KRIs and risk appetite

Comparing control test results against defined Key Risk Indicators (KRIs) and risk appetite directly demonstrates whether the controls are operating within acceptable risk thresholds. This approach provides the board with a clear, quantitative assessment of control effectiveness relative to the organization's risk tolerance, which is the core objective of risk and control monitoring and reporting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • List all controls and their test results

    Why it's wrong here

    A raw list does not provide a meaningful assessment of effectiveness.

  • Show the number of vulnerabilities patched

    Why it's wrong here

    Patch counts are operational metrics, not a measure of control effectiveness.

  • Provide a summary of the incident timeline

    Why it's wrong here

    An incident timeline does not measure control performance.

  • Compare control test results against defined KRIs and risk appetite

    Why this is correct

    This links control outcomes to risk tolerance, demonstrating effectiveness.

About these practice questions

One of 983 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.