Courseiva
mediumMultiple Select

CRISC Practice Question: Which THREE are best practices for control…

Which THREE are best practices for control monitoring?

⚠ Common exam trap

A common misconception is that annual testing is sufficient for control monitoring, but the CRISC exam emphasizes continuous, risk-driven monitoring over fixed-interval testing, and that control owner self-assessment is not a substitute for independent monitoring.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a risk-based approach to prioritize.

Option A is correct because a risk-based approach directs monitoring resources toward the controls that mitigate the highest-impact risks, aligning effort with organizational risk appetite and materiality. Option D is correct because combining automated monitoring (e.g., continuous control monitoring, SIEM/SCA tooling) with manual reviews (e.g., walkthroughs, sampling, inspection) provides broader coverage and compensates for the limitations of each method alone. Option E is correct because documenting monitoring results, exceptions, and remediation actions creates the audit trail and evidence needed for governance, audit, and continuous improvement. Option B is not a best practice because monitoring frequency should be risk-based rather than a fixed annual cycle; high-risk controls may need continuous or more frequent testing. Option C is not a best practice because relying solely on control owners introduces self-assessment bias and removes independent oversight, weakening the reliability of monitoring.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use a risk-based approach to prioritize.

    Why this is correct

    Monitoring effort is finite, so scarce resources must target controls addressing the highest inherent and residual risk. A risk-based approach directs testing frequency and depth where exposure is greatest, satisfying the need to prioritise monitoring rather than spread coverage uniformly.

  • ✗

    Test controls at least annually.

    Why it's wrong here

    A fixed annual cycle leaves controls unmonitored for long periods, so degradation between tests goes undetected. It is tempting because annual testing satisfies many compliance calendars, but monitoring frequency should reflect the control's risk and change rate, not a single arbitrary interval.

  • ✗

    Rely solely on control owners.

    Why it's wrong here

    Relying solely on control owners removes independent verification and lets self-assessment bias hide failures. It is tempting because owners hold the deepest operational knowledge of their controls, but monitoring requires corroboration from independent testing, metrics or audit evidence.

  • ✓

    Combine automated and manual monitoring.

    Why this is correct

    Automated tooling gives continuous, repeatable coverage of high-volume technical controls, while manual review catches judgement-based or qualitative evidence automation cannot interpret. Combining both satisfies the need for breadth plus depth, closing gaps each method alone leaves.

  • ✓

    Document results and actions.

    Why this is correct

    Recording monitoring outcomes, exceptions and remediation actions creates the evidence trail auditors and management rely on. Documentation demonstrates that identified control deficiencies were escalated and resolved, satisfying the requirement for traceable, repeatable monitoring rather than undocumented informal checks.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.