mediumMultiple ChoiceObjective-mapped
CRISC Practice Question: An internal audit found that a control designed…
An internal audit found that a control designed to prevent duplicate payments was bypassed in 5% of transactions. The control owner argues that the control is still effective because the bypass rate is low. What is the BEST response from a risk perspective?
⚠ Common exam trap
Test-takers frequently assume a low bypass rate is automatically acceptable (Option A) or that documenting effectiveness is sufficient (Option B), without recognizing that risk management requires understanding and addressing the root cause of control failures, not just measuring their frequency.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Investigate why bypasses occur and implement compensating controls.
The best response because a 5% bypass rate indicates a control weakness that could lead to financial loss or fraud. From a risk perspective, the root cause of the bypasses must be investigated to understand why the control is being overridden, and compensating controls should be implemented to mitigate the residual risk. Simply accepting or documenting the rate without action ignores the potential for systemic issues or targeted exploitation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Accept the bypass rate as within acceptable tolerance.
Why it's wrong here
May still exceed risk appetite.
- ✗
Document that the control is 95% effective and close the finding.
Why it's wrong here
Effectiveness may be insufficient.
- ✓
Investigate why bypasses occur and implement compensating controls.
Why this is correct
Root cause analysis is needed.
- ✗
Re-classify the control as a detective control instead of preventive.
Why it's wrong here
Doesn't fix the weakness.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 983 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.