CRISC Information Technology and Security Practice Question
A financial institution is adopting a cloud-based analytics platform. The data includes sensitive customer information subject to multiple jurisdictions' data residency laws. Which of the following poses the greatest compliance risk?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data sovereignty and cross-border data transfer restrictions
Data sovereignty issues arise when data is stored in jurisdictions with conflicting or unknown legal frameworks, posing significant compliance risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Multi-tenancy isolation vulnerabilities
Why it's wrong here
Multi-tenancy isolation vulnerabilities risk cross-customer data exposure, a confidentiality issue rather than a residency one. Isolation is the dominant concern in multi-tenant architectures handling competitor data, but jurisdiction rules are breached by where data resides, not by tenant separation weaknesses.
- ✗
Vendor lock-in due to proprietary APIs
Why it's wrong here
Proprietary APIs affect portability and exit cost, not where data is stored or processed. Lock-in becomes the primary concern when an organisation needs to migrate between providers, whereas residency obligations are breached by storage location, not by interface design.
- ✗
Shared responsibility model gaps
Why it's wrong here
Shared responsibility gaps concern unclear ownership of security controls, not the geographic placement of data. This matters most when duties for patching, identity or monitoring are ambiguous; residency laws are violated by processing data in a prohibited region regardless of who manages the control.
- ✓
Data sovereignty and cross-border data transfer restrictions
Why this is correct
Data residency laws restrict where customer data may be stored and transferred, so a cloud analytics platform spanning jurisdictions risks unlawful cross-border movement of sensitive records. This legal constraint, not generic breach exposure, creates the greatest compliance risk for the institution.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.