hardMultiple Choice
CRISC Practice Question: The risk manager for a multinational corporation…
You are the risk manager for a multinational corporation that relies heavily on a cloud-based ERP system. The system is critical for financial reporting and supply chain management. Recently, the company experienced a significant increase in the number of failed user authentication attempts, which were traced to a misconfiguration in the identity management module. The misconfiguration was detected by the security operations center (SOC) through log analysis, but it took three days to identify and resolve. The root cause was a change made by a cloud administrator without following the change management process. The incident resulted in a temporary denial of service for external users. The company's risk appetite for system availability is low, with a tolerance for downtime of no more than one hour per month. The current monitoring controls include quarterly access reviews and SOC monitoring of logs with a 24-hour review cycle. The board has requested a report on the incident and recommendations to prevent recurrence. What is the MOST effective recommendation to improve monitoring and reduce the likelihood of similar incidents?
⚠ Common exam trap
The trap is choosing preventive controls like CAB approval or training when the question asks for improving monitoring to reduce likelihood of similar incidents.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement automated real-time monitoring of critical configuration changes with alerts.
The most effective recommendation is to implement automated real-time monitoring of critical configuration changes with alerts. This directly addresses the root cause: a misconfiguration that went undetected for three days. Real-time monitoring would detect such changes immediately, allowing rapid response and reducing the likelihood of similar incidents. Other options are less effective: CAB approval is a preventive control but doesn't improve monitoring; increasing access reviews frequency is not directly related to configuration changes; additional training is useful but not as immediate and reliable as automated monitoring.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implement automated real-time monitoring of critical configuration changes with alerts.
Why this is correct
Automated real-time monitoring of critical configuration changes detects misconfigurations immediately, replacing the 24-hour log review cycle that let the incident persist three days. This directly reduces likelihood of recurrence and supports the low availability risk appetite, since faster detection shortens the denial-of-service window.
- ✗
Require all change requests to be approved by the change advisory board (CAB).
Why it's wrong here
CAB approval gates changes before deployment, yet the misconfiguration was already live and the stem asks for monitoring improvement; it does not shorten the 24-hour log review cycle that let the fault persist three days. It tempts as classic change control, and would be correct for preventing unauthorised changes, but not for detection speed.
- ✗
Increase the frequency of access reviews to monthly.
Why it's wrong here
Monthly access reviews examine who holds entitlements, not configuration drift or authentication failures, so they cannot detect a misconfigured identity module faster than the existing 24-hour log cycle. It tempts because reviews are a known identity control, and would be correct for reducing excessive standing access, but the incident was a change-management failure.
- ✗
Provide additional training to cloud administrators on security policies.
Why it's wrong here
Training addresses administrator behaviour but adds no detection capability, leaving the 24-hour log review cycle unchanged, so a misconfiguration could still run for days. It tempts because the root cause was procedural non-compliance, and would be correct for reducing human error over time, but it does not improve monitoring as the stem requires.
Visual reference
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.