Courseiva
Risk Response and MitigationhardMultiple ChoiceObjective-mapped

CRISC Risk Response and Mitigation Practice Question

A healthcare organization is migrating its electronic health records (EHR) system to a cloud provider. The risk assessment shows that the cloud provider has strong security certifications (e.g., SOC 2 Type II, ISO 27001). However, the organization's legal team is concerned about data sovereignty laws that require patient data to remain within the country. The cloud provider's data centers are located in three regions: one in-country, and two outside. The project manager proposes using only the in-country data center. The IT director warns that this will increase latency and reduce redundancy. The risk manager must propose a response. Which is the BEST option?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configure the EHR system to store primary data in the in-country data center, and use the other two centers for disaster recovery with data residency controls ensuring data does not leave the country unless encrypted and with legal approval.

It balances compliance with data sovereignty laws (using the in-country data center for primary storage) and maintains redundancy for disaster recovery with data residency controls. Option A is wrong because simply accepting the legal risk based on certifications is not sufficient; data sovereignty laws are regulatory requirements that must be adhered to, and the certifications do not override those laws. Option B is wrong because automatic failover to data centers outside the country would violate data sovereignty laws by allowing patient data to leave the country without proper controls. Option D is wrong because using only one data center increases availability risk and does not address the legal concerns properly; it avoids the legal risk but introduces high operational risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Accept the legal risk because the cloud provider's certifications are sufficient, and document the decision.

    Why it's wrong here

    Accepting the legal risk is inappropriate because data sovereignty laws require patient data to remain in the country; relying solely on certifications does not address legal compliance.

  • Use all three data centers with automatic failover, and rely on the cloud provider's contractual guarantees of data residency.

    Why it's wrong here

    Using all three data centers with automatic failover violates data sovereignty if data replicates to outside centers without controls; contractual guarantees may not satisfy regulatory requirements.

  • Configure the EHR system to store primary data in the in-country data center, and use the other two centers for disaster recovery with data residency controls ensuring data does not leave the country unless encrypted and with legal approval.

    Why this is correct

    This option balances compliance by storing primary data in-country and using other centers for DR with data residency controls, addressing both legal and availability concerns.

  • Use only the in-country data center and accept the increased availability risk.

    Why it's wrong here

    Using only the in-country data center increases availability risk due to lack of redundancy; this is a risk acceptance that may be unacceptable for critical health records.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 983 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.