CRISC Risk Response and Reporting Practice Question
Which of the following is a Key Control Indicator (KCI) that measures the effectiveness of a control?
⚠ Common exam trap
CRISC often tests the distinction between KCIs (control effectiveness) and KRIs (risk exposure); candidates who pick 'number of risk events' or 'training completion' confuse risk indicators with control indicators.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Control exception rate
A Key Control Indicator (KCI) measures how well a specific control is operating. Control exception rate — the frequency with which a control fails or is bypassed — directly measures control effectiveness, making it a textbook KCI. The other options measure risk events, audit timing, or training completion, which are KRIs or compliance metrics.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Control exception rate
Why this is correct
Control exception rate quantifies how often a control fails to operate as intended, directly evidencing control effectiveness. Risk appetite thresholds, incident counts and loss totals measure outcomes or tolerance rather than the control's own operating performance.
- ✗
Number of risk events in the last quarter
Why it's wrong here
Risk event counts are Key Risk Indicators, measuring exposure and outcome frequency, not control effectiveness. It is tempting because events suggest control failure, but KRIs track risk levels; a KCI measures whether the control itself functions, such as percentage of controls tested with satisfactory results.
- ✗
Time since last audit
Why it's wrong here
Time since last audit measures assurance frequency, not how well a control performs. It is tempting because audits evaluate controls, but elapsed time is a scheduling metric; a KCI quantifies control operation, such as the percentage of exceptions remediated within the defined threshold.
- ✗
Percentage of employees who completed security awareness training
Why it's wrong here
Training completion percentage is a Key Performance Indicator measuring activity, not control effectiveness. It is tempting because completion is measurable and security-relevant, but a KCI tracks whether a control operates as intended, such as the proportion of access reviews completed accurately, not attendance at training.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.