CRISC Risk Response and Reporting Practice Question
Which type of control is primarily designed to prevent an unwanted event from occurring?
⚠ Common exam trap
CRISC often tests the distinction between preventive and detective controls, with candidates confusing 'detect' with 'prevent' when the question asks about stopping an event before it occurs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Preventive control
A preventive control is designed to stop an unwanted event from occurring in the first place, such as a firewall blocking malicious traffic or a lock preventing unauthorized access. It acts before the event, unlike detective or corrective controls that act after.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Corrective control
Why it's wrong here
Corrective controls restore systems or data after an incident has already occurred, so they cannot stop the unwanted event itself. They are tempting because they genuinely reduce impact and are the right choice when the requirement is recovery, such as restoring from backup after ransomware encryption or reversing an unauthorised change.
- ✗
Detective control
Why it's wrong here
Detective controls identify unwanted events after they have occurred, through logs, alerts or reviews, so they cannot stop the event itself. They are tempting because they are essential for timely incident identification and forensic evidence, and would be the right choice where the requirement is to discover or monitor an event rather than prevent it.
- ✗
Directive control
Why it's wrong here
Directive controls shape behaviour through policies, procedures and awareness training, so they guide staff toward compliant action rather than blocking an event outright. They are tempting because they genuinely reduce risk and suit scenarios needing governance, standards or mandated user conduct. Here, the stem asks for a control that stops an unwanted event, which is preventive, not directive.
- ✓
Preventive control
Why this is correct
Preventive controls intervene on the causal pathway before the unwanted event materialises, stopping it from occurring at all. Detective controls identify events after the fact and corrective controls restore conditions afterwards, so only preventive satisfies the stem's prevention requirement.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.