mediumMultiple Select
CRISC Practice Question: Which THREE are best practices for control…
Which THREE are best practices for control monitoring?
⚠ Common exam trap
A common misconception is that annual testing is sufficient for control monitoring, but the CRISC exam emphasizes continuous, risk-driven monitoring over fixed-interval testing, and that control owner self-assessment is not a substitute for independent monitoring.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a risk-based approach to prioritize.
Option A is correct because a risk-based approach directs monitoring resources toward the controls that mitigate the highest-impact risks, aligning effort with organizational risk appetite and materiality. Option D is correct because combining automated monitoring (e.g., continuous control monitoring, SIEM/SCA tooling) with manual reviews (e.g., walkthroughs, sampling, inspection) provides broader coverage and compensates for the limitations of each method alone. Option E is correct because documenting monitoring results, exceptions, and remediation actions creates the audit trail and evidence needed for governance, audit, and continuous improvement. Option B is not a best practice because monitoring frequency should be risk-based rather than a fixed annual cycle; high-risk controls may need continuous or more frequent testing. Option C is not a best practice because relying solely on control owners introduces self-assessment bias and removes independent oversight, weakening the reliability of monitoring.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use a risk-based approach to prioritize.
Why this is correct
Monitoring effort is finite, so scarce resources must target controls addressing the highest inherent and residual risk. A risk-based approach directs testing frequency and depth where exposure is greatest, satisfying the need to prioritise monitoring rather than spread coverage uniformly.
- ✗
Test controls at least annually.
Why it's wrong here
A fixed annual cycle leaves controls unmonitored for long periods, so degradation between tests goes undetected. It is tempting because annual testing satisfies many compliance calendars, but monitoring frequency should reflect the control's risk and change rate, not a single arbitrary interval.
- ✗
Rely solely on control owners.
Why it's wrong here
Relying solely on control owners removes independent verification and lets self-assessment bias hide failures. It is tempting because owners hold the deepest operational knowledge of their controls, but monitoring requires corroboration from independent testing, metrics or audit evidence.
- ✓
Combine automated and manual monitoring.
Why this is correct
Automated tooling gives continuous, repeatable coverage of high-volume technical controls, while manual review catches judgement-based or qualitative evidence automation cannot interpret. Combining both satisfies the need for breadth plus depth, closing gaps each method alone leaves.
- ✓
Document results and actions.
Why this is correct
Recording monitoring outcomes, exceptions and remediation actions creates the evidence trail auditors and management rely on. Documentation demonstrates that identified control deficiencies were escalated and resolved, satisfying the requirement for traceable, repeatable monitoring rather than undocumented informal checks.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.