nerdexam
Isaca

CRISC · Question #36

Which of the following is the BEST approach to mitigate the risk associated with a control deficiency?

The correct answer is B. Implement compensating controls.. The best approach to mitigate risk associated with a control deficiency is to implement compensating controls. These are alternative measures that reduce the risk when a primary control is ineffective or absent.

Submitted by priya_blr· Apr 18, 2026Risk Response and Reporting

Question

Which of the following is the BEST approach to mitigate the risk associated with a control deficiency?

Options

  • APerform a business case analysis
  • BImplement compensating controls.
  • CConduct a control sell-assessment (CSA)
  • DBuild a provision for risk

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    83% (24)
  • C
    3% (1)
  • D
    10% (3)

Why each option

The best approach to mitigate risk associated with a control deficiency is to implement compensating controls. These are alternative measures that reduce the risk when a primary control is ineffective or absent.

APerform a business case analysis

Performing a business case analysis helps in decision-making but does not directly mitigate the risk associated with an existing control deficiency.

BImplement compensating controls.Correct

Implementing compensating controls is the most direct and effective way to mitigate risk stemming from a control deficiency. When a primary control is found to be inadequate or absent, a compensating control acts as an alternative measure to reduce the specific risk to an acceptable level until the primary control can be fixed or replaced.

CConduct a control sell-assessment (CSA)

Conducting a control self-assessment (CSA) identifies control deficiencies but does not, by itself, mitigate the risk; it's an assessment tool, not a mitigation strategy.

DBuild a provision for risk

Building a provision for risk (e.g., financial reserve) addresses the financial impact of a risk event but does not prevent or reduce the likelihood or impact of the risk itself from a control perspective.

Concept tested: Control deficiency mitigation

Source: https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/credential-guard-considerations#compensating-controls

Topics

#Control Self-Assessment (CSA)#Risk Mitigation#Control Deficiency#Risk Monitoring

Community Discussion

No community discussion yet for this question.

Full CRISC Practice