CRISC - Risk Response and Reporting (32% of the exam) - Section 3.7

Implement controls and integrate them into business processes and the technology environment.

Implement controls by integrating them into business processes and the technology environment so they operate reliably rather than in isolation. Apply a defence in depth approach to layer multiple controls against each significant risk, reducing reliance on any single control objective.

Control implementationProcess integrationControl objectivesDefence in depth

Practice question for this objective

Free sampleRisk Response and Reportingmedium

A risk practitioner is implementing controls to protect privileged administrative access to a core finance system, applying defence in depth so the objective is not lost if one safeguard fails. Which implementation approach best reflects defence in depth for this objective?

  • ADeploy the strongest available multi-factor authentication mechanism and concentrate the implementation effort on hardening that single control thoroughly
  • BPlace a network firewall in front of the finance system so that all privileged access traffic must first pass through the perimeter device
  • CSchedule a quarterly review of privileged accounts so any inappropriate access is detected and removed within the following review cycle
  • DCombine multi-factor authentication, just-in-time access approval and independent session logging so a failure in one layer does not by itself grant uncontrolled access Correct
Apply defence in depth by layering preventive, approval and detective controls so no single failure leaves a critical objective unprotected. Defence in depth means no single control failure should compromise the objective. For privileged administrative access, combining a preventive authentication control, a just-in-time approval gate and independent session logging creates overlapping layers, so a weakness in one is contained by the others. Concentrating on one strong control, a single perimeter device, or a periodic review alone all reintroduce a single point of failure, which is the opposite of what defence in depth is designed to prevent.

Why A is wrong: Investing heavily in one strong control is tempting, but defence in depth specifically avoids relying on a single layer, since its failure would then leave the objective exposed.

Why B is wrong: A perimeter firewall is one useful layer, but resting the whole objective on a single network control repeats the single-point-of-failure weakness defence in depth is meant to remove.

Why C is wrong: Periodic review is a valuable detective layer, but on its own it allows misuse to persist until the next cycle and does not provide the preventive depth the objective needs.

Why D is correct: Layering authentication, approval and monitoring controls means no single failure leaves privileged access uncontrolled, which is exactly what defence in depth seeks for a critical objective.

See more CRISC practice questions, answers explained.

Exam traps in Risk Response and Reporting

Answers that look right on this material and are not. Each one is a distractor from a different question in the CRISC bank for this domain.

  • Concentrate investment in a single strong perimeter firewall, since a well-configured boundary stops most external attacks reaching the application

    Why it is wrong: A strong perimeter is helpful, but relying on one boundary control creates a single point of failure, so once it is bypassed the data is fully exposed, which defence in depth exists to avoid.

  • Producing a daily exception report that lists every payment above the threshold for management to review later

    Why it is wrong: A daily report is a useful detective control, but it identifies issues only after funds may have left, so it supports oversight rather than the stated objective of prevention.

  • Design the control to generate the most detailed audit logs available so investigators can fully reconstruct the rare outage afterwards

    Why it is wrong: Rich logging aids post-incident analysis, but it records the failure rather than preventing or surviving it, so it does not keep the control effective at the moment of the outage.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.