nerdexam
IsacaIsaca

CRISC · Question #164

CRISC Question #164: Real Exam Question with Answer & Explanation

The correct answer is C: A system-generated testing report. A system-generated testing report offers the most reliable evidence of a control's effectiveness because it provides objective, verifiable data from actual operations. Unlike human-driven assessments or attestations, automated reports offer consistent and unbiased proof of contro

Submitted by emma.c· Apr 18, 2026Risk Response and Reporting

Question

Which of the following provides the MOST reliable evidence of a control's effectiveness?

Options

  • AA risk and control self-assessment
  • BSenior management's attestation
  • CA system-generated testing report
  • Ddetailed process walk-through

Explanation

A system-generated testing report offers the most reliable evidence of a control's effectiveness because it provides objective, verifiable data from actual operations. Unlike human-driven assessments or attestations, automated reports offer consistent and unbiased proof of control performance.

Common mistakes.

  • A. A risk and control self-assessment relies on internal personnel's subjective evaluation, which, while useful, is not as objective or verifiable as automated testing.
  • B. Senior management's attestation is a statement of belief or confirmation, but it is not direct, objective evidence of a control's operational effectiveness.
  • D. A detailed process walk-through can help understand how a control is designed to operate, but it does not provide consistent, verifiable data on its continuous effectiveness in the same way a system-generated report does.

Concept tested. Control effectiveness evidence

Topics

#Control effectiveness#Control testing#Evidence reliability#Monitoring controls

Community Discussion

No community discussion yet for this question.

Full CRISC PracticeBrowse All CRISC Questions