CRISC Risk Response and Reporting Practice Question
An organization is implementing continuous monitoring for its critical systems. Which THREE of the following activities are examples of continuous monitoring? (Select three.)
⚠ Common exam trap
Watch out — candidates often confuse periodic reviews (like quarterly or annual audits) with continuous monitoring, failing to recognize that continuous monitoring requires frequent, automated, or real-time data collection rather than infrequent manual checks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Weekly vulnerability scanning of all servers
Weekly vulnerability scanning of all servers (B) is continuous monitoring because it runs on a recurring, automated schedule that repeatedly detects new weaknesses and configuration drift across the environment. Real-time monitoring of firewall logs for anomalies (C) qualifies because it continuously ingests and inspects traffic events to detect suspicious activity as it occurs. Automated correlation of security events via SIEM (D) is continuous monitoring because the SIEM aggregates and correlates log data from multiple sources in near real time to generate alerts. In contrast, an annual internal audit of access controls (A) and a quarterly review of user access rights (E) are periodic, point-in-time assessments rather than ongoing automated monitoring activities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Annual internal audit of access controls
Why it's wrong here
Continuous monitoring relies on automated, near-real-time telemetry; an annual internal audit is a point-in-time assurance exercise covering a single snapshot of the year. It is tempting because audits do examine access controls, but an annual audit is the correct choice when the objective is independent periodic assurance rather than ongoing detection.
- ✓
Weekly vulnerability scanning of all servers
Why this is correct
Weekly vulnerability scanning runs on a recurring, automated schedule across all servers, giving ongoing visibility of emerging weaknesses rather than a one-off assessment. This recurring cadence satisfies the continuous monitoring requirement, distinguishing it from periodic point-in-time audits.
- ✓
Real-time monitoring of firewall logs for anomalies
Why this is correct
Real-time monitoring of firewall logs detects anomalies as they occur, providing immediate visibility of suspicious network activity rather than after-the-fact review. This continuous, automated observation of critical systems satisfies the ongoing detection requirement central to continuous monitoring.
- ✓
Automated correlation of security events via SIEM
Why this is correct
SIEM automated correlation links events from multiple sources in real time, surfacing patterns that isolated logs would miss. This continuous aggregation and analysis of security events across critical systems satisfies the ongoing detection requirement, distinguishing it from manual, periodic log review.
- ✗
Quarterly review of user access rights by managers
Why it's wrong here
Continuous monitoring is automated and near-real-time; a quarterly manual manager review is periodic attestation, leaving up to three months of undetected entitlement drift. It is tempting because access reviews are a genuine control, but they are the correct choice when the requirement is scheduled recertification rather than ongoing automated detection.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.