CRISC - Risk Response and Reporting (32% of the exam) - Section 3.5

Classify control types and apply control standards and frameworks to the control environment.

Classify controls as preventive, detective, or corrective, and further by whether they are administrative, technical, or physical. Apply control frameworks to evaluate whether the control environment provides adequate coverage across each risk category.

Preventive controlsDetective controlsCorrective controlsControl frameworks

Practice question for this objective

Free sampleRisk Response and Reportingmedium

A risk practitioner reviews a firewall rule that drops inbound traffic on ports not used by a critical application before any packet reaches the host. By control type, how should this rule be classified?

  • ADetective, because the firewall rule actively inspects each packet and logs the traffic it observes
  • BCorrective, because the firewall rule restores the network to a safe state after an intrusion occurs
  • CCompensating, because the firewall rule substitutes for an absent control the design originally intended
  • DPreventive, because the firewall rule stops disallowed traffic from reaching the host before harm occurs Correct
Classify a control that blocks an event before it happens as a preventive control rather than detective, corrective, or compensating. Control type is decided by when and how a control acts relative to the event. A rule that denies disallowed traffic at the perimeter operates before any harm reaches the asset, which is the defining behaviour of a preventive control, so it is classified as preventive even though it also produces log entries.

Why A is wrong: Logging makes the rule look detective, but the rule blocks traffic before any harm reaches the host, so its primary purpose is prevention rather than after the fact discovery.

Why B is wrong: Corrective controls act after an incident to restore service, yet this rule stops the traffic up front, so nothing has gone wrong for it to correct.

Why C is wrong: A compensating control fills in for a missing primary control, but nothing here indicates a gap being covered, so this misreads a normal preventive measure.

Why D is correct: A preventive control acts before an event to stop it happening, and blocking disallowed packets at the perimeter denies the threat any chance to reach the asset.

See more CRISC practice questions, answers explained.

Exam traps in Risk Response and Reporting

Answers that look right on this material and are not. Each one is a distractor from a different question in the CRISC bank for this domain.

  • A detective reconciliation run weekly that lists payments where the same person both created and released a transaction

    Why it is wrong: Weekly detection finds breaches after funds have moved, so it limits but does not prevent loss; it is useful as a backstop yet weaker than stopping the conflict at source.

  • Preventive, because the arrangement stops an idle privileged session from being misused before any unauthorised action can occur on the application

    Why it is wrong: Preventive controls block an event before it happens, but alerting on a session that is already idle acts after the condition arises, so this misjudges when the control operates.

  • Corrective, because the alert it raises sets in motion the recovery steps that return affected systems to a known good state after the incident

    Why it is wrong: Corrective controls restore a position after an event, but the system itself only identifies and reports the activity; the later recovery steps are a separate control, not the function of the detection.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.