Courseiva
IT Risk Assessment →easyMultiple Choice

CRISC IT Risk Assessment Practice Question

Which of the following is a detective control for an information system?

⚠ Common exam trap

Test-takers frequently confuse detective controls (which identify incidents after they occur) with preventive controls (which stop incidents before they happen), leading candidates to mistakenly classify firewalls or encryption as detective.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Intrusion detection system

An intrusion detection system (IDS) is a detective control because it monitors network traffic or system activity for malicious actions or policy violations and generates alerts when such events occur. Unlike preventive controls, an IDS does not block or stop the attack; it detects and reports it after the fact, enabling incident response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Data backup

    Why it's wrong here

    Data backup is a corrective or recovery control: it restores data after loss or corruption rather than identifying that an incident occurred. It tempts because backup is a fundamental security safeguard, and would be correct if the question asked how to recover from ransomware, deletion, or hardware failure.

  • ✗

    Encryption

    Why it's wrong here

    Encryption is a preventive control: it renders data unreadable to unauthorised parties before access occurs, rather than detecting an event after the fact. It tempts because encryption is central to data protection, and would be the right answer if the question asked for a preventive control safeguarding confidentiality at rest or in transit.

  • ✗

    Firewall

    Why it's wrong here

    A firewall is a preventive control: it blocks or permits traffic according to rules before any malicious packet reaches the target. It tempts because firewalls log blocked connections, yet their primary function is prevention, and would be correct if the question asked for a preventive network boundary control.

  • ✓

    Intrusion detection system

    Why this is correct

    An intrusion detection system monitors network or host activity and raises alerts on suspicious patterns, identifying incidents after or during occurrence rather than blocking them. That monitoring-and-alerting function is detective by definition, distinguishing it from preventive controls such as firewalls or encryption.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.