Courseiva
IT Risk Assessment →hardMultiple Select

CRISC IT Risk Assessment Practice Question

An organization is assessing control effectiveness for a firewall. Which THREE factors should be evaluated to determine control effectiveness? (Select THREE)

⚠ Common exam trap

CRISC often tests the difference between control effectiveness criteria (design, operation, relevance) and control selection criteria (cost, complexity) — candidates pick cost or update frequency because they sound operational.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Design adequacy of the firewall rules

Design adequacy of the firewall rules (A) is correct because control effectiveness begins with whether the ruleset is properly architected to enforce the intended security policy, including correct default-deny posture, rule ordering, and coverage of required traffic flows. Operating effectiveness of the firewall (B) is correct because even a well-designed ruleset must be verified to actually function as intended in production, through testing, monitoring, and evidence that the control operates consistently over time. Relevance to the specific risk scenario (D) is correct because a control is only effective if it directly addresses the identified risk; a technically sound firewall that does not mitigate the specific threat in scope provides no assurance for that scenario. Cost of the firewall (C) is not a factor in determining control effectiveness, as it relates to budgeting and cost-benefit rather than whether the control actually mitigates risk. Frequency of rule updates (E) is not itself an effectiveness factor, since the quality and appropriateness of changes matter more than how often they occur, and it is subsumed under design adequacy and operating effectiveness.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Design adequacy of the firewall rules

    Why this is correct

    Design adequacy examines whether the firewall rule set, architecture and coverage are capable of mitigating the identified risk if operating as intended. This satisfies the stem's effectiveness assessment because a control with flawed or incomplete design cannot deliver the required protection, regardless of how reliably it runs day to day.

  • ✓

    Operating effectiveness of the firewall

    Why this is correct

    Operating effectiveness verifies the firewall actually enforces its rules consistently in production, through monitoring, testing and change control. This satisfies the stem's effectiveness assessment because a well-designed rule set that is misconfigured, bypassed or degraded in practice delivers no reliable risk reduction.

  • ✗

    Cost of the firewall

    Why it's wrong here

    Purchase and licensing cost is a budgetary metric and says nothing about whether the firewall blocks or permits traffic as intended. It is tempting because cost feeds investment decisions, and it would be the correct factor in a financial appraisal or total-cost-of-ownership review.

  • ✓

    Relevance to the specific risk scenario

    Why this is correct

    Relevance to the specific risk scenario confirms the firewall's rules actually address the threats and data flows the organisation faces, rather than generic traffic. This satisfies the stem's control-effectiveness assessment because a well-designed control aimed at the wrong risk provides no real mitigation, leaving the scenario exposed.

  • ✗

    Frequency of rule updates

    Why it's wrong here

    Rule update frequency describes operational maintenance cadence, not whether the firewall enforces the intended policy correctly. It is tempting because stale rulesets cause drift, and it would be the right factor when assessing change management or configuration currency rather than control effectiveness.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.