easyMultiple Choice
CRISC Practice Question: Is the BEST practice for determining the…
Which of the following is the BEST practice for determining the frequency of control monitoring activities?
⚠ Common exam trap
Candidates often choose Option C (regulatory minimums) because they confuse compliance-driven minimums with best practice, failing to recognize that risk-based monitoring is more adaptive and effective for real-world risk management.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Align monitoring frequency with risk level and control effectiveness assessment
Control monitoring frequency should be driven by the assessed risk level and the effectiveness of existing controls. High-risk areas or controls with lower effectiveness require more frequent monitoring to ensure timely detection of failures, while low-risk or highly effective controls can be monitored less often, optimizing resource allocation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Standardize all controls to quarterly monitoring
Why it's wrong here
A fixed quarterly cadence ignores each control's risk profile, change velocity and prior test results, so high-risk controls go unmonitored for months while stable ones are over-tested. Risk-based frequency is the goal. Uniform scheduling suits low-maturity environments needing a baseline before risk-tiering is possible.
- ✗
Monitor only after a control failure is detected
Why it's wrong here
Monitoring only after a failure leaves the control unobserved between incidents, so degradation goes undetected. It is tempting because failure-driven review feels efficient, yet monitoring frequency should follow the control's risk, criticality and rate of change, not reactive triggers.
- ✗
Set frequency based solely on regulatory minimum requirements
Why it's wrong here
Regulatory minima set a floor, not the required cadence; controls protecting higher inherent risk need monitoring beyond that threshold, and compliance-only schedules leave residual risk unaddressed. Regulatory drivers are the correct basis only where a control exists solely to satisfy a mandated obligation with no other risk exposure.
- ✓
Align monitoring frequency with risk level and control effectiveness assessment
Why this is correct
Monitoring frequency should reflect the risk each control addresses and how well it currently performs, so higher-risk or weaker controls are tested more often. This risk-based alignment directs limited assurance effort where exposure is greatest, rather than applying a uniform schedule.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.