Courseiva
IT Risk Assessment →mediumMultiple Choice

CRISC IT Risk Assessment Practice Question

Which of the following is an example of a detective control?

⚠ Common exam trap

Test-takers frequently confuse preventive controls (like firewalls and authentication) with detective controls (like IDS), as candidates often misclassify controls based on their general security function rather than their specific timing relative to the incident.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Intrusion detection system (IDS) alerts

An intrusion detection system (IDS) monitors network traffic for suspicious activity and generates alerts when it detects potential threats. This is a detective control because it identifies and reports security incidents after they occur, rather than preventing them. IDS alerts provide visibility into ongoing or past attacks, enabling incident response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Backup restoration after data loss

    Why it's wrong here

    Backup restoration is corrective, returning systems to operation after data loss has occurred. It is tempting because it is a recovery control within the same resilience family, and would be correct where the objective is restoring availability following an incident rather than discovering that one happened.

  • ✗

    Firewall rules blocking unauthorized traffic

    Why it's wrong here

    Firewall rules blocking traffic are preventive: they stop the event before it occurs, leaving nothing to detect. It is tempting because firewalls generate logs, and would be correct where the control's purpose is to deny unauthorised connections rather than identify activity already underway.

  • ✗

    Requiring two-factor authentication

    Why it's wrong here

    Two-factor authentication is preventive, blocking unauthorised access at the point of logon. It is tempting because authentication events are logged and reviewed, and would be correct where the requirement is stopping credential misuse rather than identifying it after the fact.

  • ✓

    Intrusion detection system (IDS) alerts

    Why this is correct

    An IDS detects and alerts on intrusions after or during occurrence, which is the defining characteristic of a detective control. It satisfies the stem by identifying events rather than preventing them, unlike firewalls or access controls.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.