CRISC Risk Response and Reporting Practice Question
Which type of control is designed to operate before an event to prevent an undesirable outcome?
⚠ Common exam trap
In the ISACA CRISC exam, candidates often confuse preventive controls (e.g., firewalls, access controls) with detective controls (e.g., intrusion detection systems). Remember that preventive controls act before an event, while detective controls identify events that have already occurred.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Preventive control
A preventive control is designed to operate before an event to stop an undesirable outcome from occurring. In risk management, this includes measures such as firewalls blocking unauthorized traffic before it reaches the internal network, or access control lists (ACLs) preventing unauthorized users from reading sensitive files. These controls proactively enforce security policies to reduce the likelihood of a risk event.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Preventive control
Why this is correct
Preventive controls act on the cause before an event occurs, blocking the undesirable outcome rather than detecting it afterwards or compensating for it. This directly satisfies the stem's requirement that the control operates before the event, unlike detective or corrective controls.
- ✗
Detective control
Why it's wrong here
Detective controls identify and report events after or during their occurrence; they do not stop the undesirable outcome from happening. They are tempting because monitoring, logging and alerting are foundational to any control programme, and they would be correct if the question asked how to discover an event.
- ✗
Corrective control
Why it's wrong here
Corrective controls act after a detected event to restore operations or limit damage, so they cannot prevent the outcome beforehand. They are tempting because remediation and recovery are essential in any control framework, and they would be the right answer if the question asked how to respond to or recover from an incident.
- ✗
Compensating control
Why it's wrong here
Compensating controls substitute for a primary control that cannot be implemented, and they may operate at any point in the timeline rather than strictly before an event. They are tempting because they address residual risk when a required control is impractical, which suits legacy or constrained environments.
Visual reference
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.