Courseiva

CRISC Risk Response and Reporting Practice Question

Which type of control testing is typically performed on a continuous basis using automated tools?

⚠ Common exam trap

CRISC often tests the distinction between continuous automated monitoring and periodic manual testing, and candidates commonly pick 'quarterly internal audit review' because it sounds like ongoing oversight — the trap is that quarterly is periodic, not continuous, and audit is not automated control testing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Continuous monitoring

Continuous monitoring is the control testing approach performed on an ongoing, automated basis using tools such as SIEM, configuration compliance scanners, and automated control assessment platforms. It provides real-time or near-real-time assurance that controls remain effective, unlike periodic manual reviews. This matches the question's description of continuous, automated testing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Annual penetration test

    Why it's wrong here

    An annual penetration test runs once a year, so it cannot provide continuous automated testing; it is a point-in-time adversarial assessment. It is tempting because penetration testing is a recognised control-testing technique, and it would be correct for validating exploitable weaknesses periodically rather than monitoring controls continuously.

  • ✗

    Manual control walkthrough

    Why it's wrong here

    A manual walkthrough is performed by people at a point in time, so it cannot run continuously or be automated. It is tempting because walkthroughs effectively verify control design and operating evidence, and one would be correct for a periodic design assessment rather than continuous automated monitoring.

  • ✗

    Quarterly internal audit review

    Why it's wrong here

    A quarterly internal audit review occurs four times a year, leaving gaps between assessments, so it is not continuous and depends on auditor effort rather than automation. It is tempting because internal audit provides independent assurance, and it would be correct for periodic compliance verification rather than continuous control monitoring.

  • ✓

    Continuous monitoring

    Why this is correct

    Continuous monitoring relies on automated tooling to evaluate controls and configurations persistently, rather than sampling at a point in time. This contrasts with periodic assessments and substantive walkthrough testing, which are performed at intervals and cannot provide the ongoing assurance automation delivers.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.