Courseiva
IT Risk Assessment →easyMultiple Choice

CRISC IT Risk Assessment Practice Question

Which control type is designed to stop a risk event from occurring?

⚠ Common exam trap

CRISC often tests the timing distinction between control types — preventive (before), detective (during/after), corrective (after) — and candidates frequently confuse 'compensating' as a timing category rather than an alternative-implementation category.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Preventive

Preventive controls are designed to stop a risk event from occurring in the first place, such as firewalls, access controls, encryption, and segregation of duties. They act before the event, reducing likelihood. This is the defining characteristic that distinguishes them from detective and corrective controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Detective

    Why it's wrong here

    Detective controls identify that a risk event has already occurred, for example through logging or alerting, so they cannot stop it. Prevention requires a preventive control that blocks the action before impact. Detective controls would be correct where the objective is timely discovery and evidence gathering after an event.

  • ✗

    Compensating

    Why it's wrong here

    Compensating controls substitute for an unavailable primary control, addressing the same risk through an alternative mechanism rather than inherently stopping the event. The question asks for the control type designed to prevent occurrence. Compensating controls would be correct where a primary preventive control cannot be implemented and an alternative must cover the gap.

  • ✓

    Preventive

    Why this is correct

    Preventive controls act before or during an event to block it from occurring, such as segregation of duties, approvals, or firewalls. This directly satisfies the requirement to stop a risk event rather than detect or mitigate its consequences afterwards.

  • ✗

    Corrective

    Why it's wrong here

    Corrective controls restore systems and data after a risk event has happened, such as backups or remediation, so they do not stop occurrence. Stopping an event before impact demands a preventive control. Corrective controls would be correct when the goal is recovery and damage limitation following an incident.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.