mediumMultiple Choice
CRISC Practice Question: Refer to the exhibit
Exhibit
{
"controlTest": {
"controlId": "AC-01",
"testId": "T12345",
"testDate": "2023-06-15",
"testResult": "pass",
"notes": "Sample of 30 logins; all authenticated via MFA."
}
}Refer to the exhibit. If the control objective is to prevent unauthorized access via MFA, what does this test result indicate?
⚠ Common exam trap
The trap is treating a passing sample as proof of full control effectiveness; candidates forget that sampling provides reasonable, not absolute, assurance and that conclusions are limited to the tested population.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The control is effective for the sample but may not be for the population.
Sampling only tests a subset of the population, so a passing result on 30 logins provides assurance only about those sampled items — it does not prove the control operates effectively across the entire population. This is the fundamental limitation of audit sampling: the conclusion is limited to the sample unless statistical sampling with a defined confidence level is used.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The control is ineffective because only 30 logins were sampled.
Why it's wrong here
Sample size alone does not make a control ineffective; the exhibit's pass or fail outcomes determine that, and 30 logins can be an adequate sample. A small sample would be the correct concern only where the results were inconclusive or the population was too large to support the conclusion.
- ✗
The control is fully effective.
Why it's wrong here
Claiming full effectiveness ignores any failed or missing MFA entries shown in the exhibit; effectiveness requires every tested login to have enforced MFA. Full effectiveness would be the right conclusion only if the sample showed MFA required and satisfied on all accounts without exception.
- ✗
The control is effective only if MFA is required for all users.
Why it's wrong here
A conditional statement about coverage does not interpret the exhibit's actual pass or fail result; the test either confirms MFA enforcement or reveals gaps. Requiring MFA for all users is the desired control design, but the question asks what the sampled evidence demonstrates, not what policy should ideally state.
- ✓
The control is effective for the sample but may not be for the population.
Why this is correct
Testing a sample cannot prove the MFA control operates across the entire population, so the result supports effectiveness only for tested items. Residual risk remains that untested accounts bypass MFA, meaning the control objective is not fully assured.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.