Courseiva
Risk Response and Reporting →mediumMultiple Select

CRISC Risk Response and Reporting Practice Question

Which TWO of the following are examples of detective controls?

⚠ Common exam trap

CRISC often tests the preventive-vs-detective distinction by including strong-sounding controls like encryption and firewalls, so candidates must ask 'does this stop an event or detect it?' rather than picking the most security-sounding option.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Log monitoring and analysis

Log monitoring and analysis (C) is a detective control because it continuously reviews and correlates event logs to identify and alert on suspicious or anomalous activity after it occurs, providing visibility into incidents rather than preventing them. An intrusion detection system (IDS) (D) is likewise detective: it passively inspects network or host traffic and raises alerts when it matches known attack signatures or behavioral anomalies, without blocking the traffic itself. By contrast, encryption of data at rest (A) and firewall rules (B) are preventive controls that stop unauthorized access or disclosure before it happens, and a data backup process (E) is a corrective/recovery control that restores data after a loss event, so none of these three are detective controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Encryption of data at rest

    Why it's wrong here

    Encryption of data at rest is a preventive control, rendering stored data unreadable to unauthorised parties before any incident occurs. It is tempting because encryption supports breach investigations and compliance evidence, but it does not identify events; detective controls include IDS, log review and integrity monitoring.

  • ✗

    Firewall rules

    Why it's wrong here

    Firewall rules are preventive controls: they block or permit traffic before an event occurs, so they cannot detect anything. They are tempting because firewalls generate logs that monitoring tools analyse, but the rule itself enforces policy; detective examples are log review, IDS alerts and file integrity monitoring.

  • ✓

    Log monitoring and analysis

    Why this is correct

    Log monitoring and analysis examines recorded event data to identify incidents after or during occurrence, which is the defining characteristic of a detective control. It does not prevent events, distinguishing it from preventive controls such as firewalls or access restrictions.

  • ✓

    Intrusion detection system (IDS)

    Why this is correct

    An intrusion detection system monitors network or host traffic and raises alerts on malicious activity, detecting incidents rather than blocking them. This passive identification role makes it a detective control, unlike an intrusion prevention system, which is preventive.

  • ✗

    Data backup process

    Why it's wrong here

    Data backup is a corrective and recovery control, restoring systems after an incident rather than identifying that one occurred. It is tempting because backup logs and verification tests can reveal failures, but the process itself recovers data; detective controls include log monitoring, intrusion detection and reconciliation checks.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.