hardMultiple ChoiceObjective-mapped
CRISC Practice Question: A government agency is migrating its critical…
A government agency is migrating its critical applications to a public cloud infrastructure. The risk assessment reveals that the cloud provider uses shared tenancy, and the agency's sensitive data will be stored alongside other customers' data. The agency has a very low risk appetite for data leakage and must comply with strict data sovereignty laws. The cloud provider offers data encryption at rest and in transit, as well as dedicated hardware security modules (HSMs) for key management. However, the provider's physical datacenters are located in another country with different legal frameworks. As the risk practitioner, which of the following should be the PRIMARY risk response?
⚠ Common exam trap
The trap here is that candidates often overestimate the effectiveness of encryption and contractual controls, failing to recognize that physical jurisdiction and shared tenancy introduce residual risks that cannot be fully mitigated, making avoidance the only appropriate response for a very low risk appetite.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Avoid the risk by keeping sensitive data on-premises and using the cloud only for non-sensitive workloads.
The agency's very low risk appetite for data leakage and strict data sovereignty laws cannot be adequately mitigated by encryption or contractual measures when the physical datacenters are in a foreign jurisdiction with different legal frameworks. Shared tenancy in a public cloud inherently increases the attack surface for side-channel attacks and misconfiguration risks, and even with encryption at rest (e.g., AES-256) and in transit (e.g., TLS 1.3), the cloud provider's staff or foreign legal authorities could potentially access decryption keys or compel key disclosure. Avoiding the risk by keeping sensitive data on-premises eliminates the exposure to foreign legal frameworks and shared tenancy, directly aligning with the agency's risk appetite.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Avoid the risk by keeping sensitive data on-premises and using the cloud only for non-sensitive workloads.
Why this is correct
Avoidance is appropriate given low risk appetite.
- ✗
Reduce the risk by negotiating a contract that includes specific data handling clauses and audit rights.
Why it's wrong here
Contract may not be enforceable over foreign jurisdiction.
- ✗
Transfer the risk by requiring the provider to maintain a large cyber insurance policy.
Why it's wrong here
Insurance does not address data sovereignty.
- ✗
Accept the risk after verifying the provider's compliance certifications.
Why it's wrong here
Certifications do not guarantee legal compliance.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
One of 983 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.