Courseiva

CRISC Risk Response and Reporting Practice Question

Which type of control is designed to operate before an event to prevent an undesirable outcome?

⚠ Common exam trap

In the ISACA CRISC exam, candidates often confuse preventive controls (e.g., firewalls, access controls) with detective controls (e.g., intrusion detection systems). Remember that preventive controls act before an event, while detective controls identify events that have already occurred.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Preventive control

A preventive control is designed to operate before an event to stop an undesirable outcome from occurring. In risk management, this includes measures such as firewalls blocking unauthorized traffic before it reaches the internal network, or access control lists (ACLs) preventing unauthorized users from reading sensitive files. These controls proactively enforce security policies to reduce the likelihood of a risk event.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Preventive control

    Why this is correct

    Preventive controls act on the cause before an event occurs, blocking the undesirable outcome rather than detecting it afterwards or compensating for it. This directly satisfies the stem's requirement that the control operates before the event, unlike detective or corrective controls.

  • ✗

    Detective control

    Why it's wrong here

    Detective controls identify and report events after or during their occurrence; they do not stop the undesirable outcome from happening. They are tempting because monitoring, logging and alerting are foundational to any control programme, and they would be correct if the question asked how to discover an event.

  • ✗

    Corrective control

    Why it's wrong here

    Corrective controls act after a detected event to restore operations or limit damage, so they cannot prevent the outcome beforehand. They are tempting because remediation and recovery are essential in any control framework, and they would be the right answer if the question asked how to respond to or recover from an incident.

  • ✗

    Compensating control

    Why it's wrong here

    Compensating controls substitute for a primary control that cannot be implemented, and they may operate at any point in the timeline rather than strictly before an event. They are tempting because they address residual risk when a required control is impractical, which suits legacy or constrained environments.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.