Courseiva

CISM Data Residency Practice Question

A multinational corporation is migrating its on-premises data center to a hybrid cloud environment. The organization processes highly sensitive financial data subject to strict regulatory requirements (e.g., GDPR, SOX). During the risk assessment, the information security manager discovers that the cloud service provider (CSP) stores data in multiple geographic regions, some of which do not meet the organization's data residency requirements. Additionally, the CSP's encryption key management is not fully under the organization's control, and the incident response plan does not include specific procedures for cloud-based breaches. The organization's risk appetite is low, and the board has mandated that all risks must be mitigated to an acceptable level. Which of the following is the BEST course of action?

⚠ Common exam trap

Candidates may mistakenly believe that accepting risk is viable when the CSP has strong certifications, but the board's mandate requires mitigation, not acceptance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Require the CSP to provide dedicated hardware security modules and restrict data storage to approved regions through contractual terms

It directly addresses the root causes: data residency non-compliance and lack of control over encryption keys. Requiring dedicated hardware security modules (HSMs) and restricting data storage to approved regions through contractual terms ensures that the organization retains control over key management and meets regulatory requirements. This aligns with the low risk appetite and the board's mandate to mitigate risks to an acceptable level. Option B (accept the risk) is incorrect because it contradicts the board's mandate to mitigate all risks, and certifications alone do not guarantee compliance. Option C (cancel migration) is too drastic and costly; the organization can achieve compliance with the CSP rather than abandoning the cloud migration. Option D (transfer risk via insurance) does not achieve regulatory compliance; fines may still be imposed regardless of insurance coverage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Require the CSP to provide dedicated hardware security modules and restrict data storage to approved regions through contractual terms

    Why this is correct

    Dedicated HSMs place cryptographic key custody under the organisation's control, while contractual region restrictions enforce data residency, directly addressing both identified gaps. Because the board's low risk appetite demands mitigation to an acceptable level, these controls reduce the CSP-dependent risks rather than merely accepting or transferring them.

  • ✗

    Accept the risk because the CSP has strong security certifications and the likelihood of a breach is low

    Why it's wrong here

    Acceptance leaves the residency violation, provider-held keys and missing cloud incident-response procedures in place, contradicting the board's mandate that all risks be mitigated. It is tempting when a provider holds strong certifications and breach likelihood is low, but certification does not satisfy GDPR or SOX residency obligations, and low risk appetite precludes accepting these gaps.

  • ✗

    Cancel the cloud migration and build a new private data center in a compliant location

    Why it's wrong here

    Cancelling the migration and rebuilding privately abandons the hybrid cloud requirement entirely, and a new data centre still demands the same residency, key-management and incident-response controls. It is tempting as the only option guaranteeing full control, but it fails the board's mandate to mitigate risks to an acceptable level while meeting the stated hybrid cloud objective.

  • ✗

    Transfer the risk by purchasing cyber insurance that covers regulatory fines

    Why it's wrong here

    Cyber insurance transfers financial loss but leaves the residency breach, uncontrolled key management and absent cloud incident-response procedures unmitigated, so regulatory non-compliance persists. It is tempting because insurance addresses residual financial impact, yet it cannot satisfy a low risk appetite where the board requires risks reduced to an acceptable level, not merely compensated.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.