Courseiva
easyMultiple Choice

CRISC Practice Question: Is the BEST practice for determining the…

Which of the following is the BEST practice for determining the frequency of control monitoring activities?

⚠ Common exam trap

Candidates often choose Option C (regulatory minimums) because they confuse compliance-driven minimums with best practice, failing to recognize that risk-based monitoring is more adaptive and effective for real-world risk management.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Align monitoring frequency with risk level and control effectiveness assessment

Control monitoring frequency should be driven by the assessed risk level and the effectiveness of existing controls. High-risk areas or controls with lower effectiveness require more frequent monitoring to ensure timely detection of failures, while low-risk or highly effective controls can be monitored less often, optimizing resource allocation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Standardize all controls to quarterly monitoring

    Why it's wrong here

    A fixed quarterly cadence ignores each control's risk profile, change velocity and prior test results, so high-risk controls go unmonitored for months while stable ones are over-tested. Risk-based frequency is the goal. Uniform scheduling suits low-maturity environments needing a baseline before risk-tiering is possible.

  • ✗

    Monitor only after a control failure is detected

    Why it's wrong here

    Monitoring only after a failure leaves the control unobserved between incidents, so degradation goes undetected. It is tempting because failure-driven review feels efficient, yet monitoring frequency should follow the control's risk, criticality and rate of change, not reactive triggers.

  • ✗

    Set frequency based solely on regulatory minimum requirements

    Why it's wrong here

    Regulatory minima set a floor, not the required cadence; controls protecting higher inherent risk need monitoring beyond that threshold, and compliance-only schedules leave residual risk unaddressed. Regulatory drivers are the correct basis only where a control exists solely to satisfy a mandated obligation with no other risk exposure.

  • ✓

    Align monitoring frequency with risk level and control effectiveness assessment

    Why this is correct

    Monitoring frequency should reflect the risk each control addresses and how well it currently performs, so higher-risk or weaker controls are tested more often. This risk-based alignment directs limited assurance effort where exposure is greatest, rather than applying a uniform schedule.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.