mediumMultiple Choice
CRISC Practice Question: After a significant cybersecurity incident, the…
After a significant cybersecurity incident, the board requests a report on the effectiveness of the security controls that were in place. Which reporting approach would BEST demonstrate the controls' performance?
⚠ Common exam trap
A common mix-up: candidates confuse operational metrics (like patching counts or incident timelines) with control effectiveness reporting, which must be tied to risk appetite and KRIs to demonstrate whether controls are actually managing risk within acceptable boundaries.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Compare control test results against defined KRIs and risk appetite
Comparing control test results against defined Key Risk Indicators (KRIs) and risk appetite directly demonstrates whether the controls are operating within acceptable risk thresholds. This approach provides the board with a clear, quantitative assessment of control effectiveness relative to the organization's risk tolerance, which is the core objective of risk and control monitoring and reporting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
List all controls and their test results
Why it's wrong here
A raw list of controls with test results gives the board exhaustive detail without connecting performance to the incident that occurred. This format suits audit or compliance evidence packs, whereas demonstrating effectiveness after an incident requires mapping which controls operated, and how well, against the actual event.
- ✗
Show the number of vulnerabilities patched
Why it's wrong here
Patch counts are operational metrics, not a measure of control effectiveness.
- ✗
Provide a summary of the incident timeline
Why it's wrong here
An incident timeline narrates what happened but does not assess whether the controls in place performed as intended. Timelines suit post-incident reviews and lessons-learned sessions, whereas the board's question about control effectiveness needs results showing detection, prevention and response outcomes against expected behaviour.
- ✓
Compare control test results against defined KRIs and risk appetite
Why this is correct
Comparing control test results against defined KRIs and risk appetite directly evidences whether controls performed within tolerated limits, satisfying the board's demand for effectiveness rather than mere activity. KRIs quantify control performance, while risk appetite supplies the benchmark, so deviations expose residual risk in business terms the board can act on.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.