Courseiva

CRISC Information Technology and Security Practice Question

A hospital's radiology department wants to replace its on-premises PACS archive (DICOM images) with a vendor-hosted SaaS platform. The vendor stores images in its own multitenant cloud and provides a web viewer. Before signing, the risk practitioner must confirm which control MOST directly addresses the risk that a vendor-side compromise could expose patient images to other tenants.

⚠ Common exam trap

The trap here is treating vendor assurance artifacts such as SOC 2 reports or right-to-audit clauses as equivalent to evidence that tenant isolation is actually enforced.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Verify the vendor enforces strict tenant isolation and encryption key separation in the multitenant storage layer.

Because the images would reside in a shared multitenant platform, the risk that matters most is logical separation failure between customers. Confirming enforced tenant isolation with segregated encryption keys directly addresses that failure mode. Audit reports, right-to-audit clauses and internal penetration tests provide valuable assurance and leverage but do not specifically prevent one tenant from accessing another tenant's DICOM data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Require the vendor to publish a SOC 2 Type II report covering the last twelve months.

    Why it's wrong here

    A SOC 2 Type II report gives assurance over the vendor's control environment but does not by itself prove that tenant isolation or per-tenant key separation is correctly implemented for this specific platform. It is useful due diligence evidence, yet it is indirect and may cover only a subset of systems, so it does not most directly address cross-tenant image exposure.

  • ✗

    Require annual penetration testing of the hospital's own internal network by an external firm.

    Why it's wrong here

    Testing the hospital's internal network does not evaluate the vendor's multitenant cloud storage, which is where the cross-tenant exposure would occur. This activity addresses the hospital's own attack surface and would leave the vendor-side isolation risk unexamined, so it cannot be the most direct control for the scenario described.

  • ✗

    Confirm the contract includes a right-to-audit clause allowing the hospital to inspect the vendor's data center.

    Why it's wrong here

    A right-to-audit clause preserves future assurance leverage but does not reduce the technical risk of cross-tenant access today, and physical data center inspection rarely reveals logical isolation flaws in a multitenant storage design. It is a contractual safeguard, not the control that directly prevents one tenant from viewing another tenant's images.

  • ✓

    Verify the vendor enforces strict tenant isolation and encryption key separation in the multitenant storage layer.

    Why this is correct

    In a multitenant SaaS PACS, the dominant exposure is logical separation failure, so confirming that tenant isolation is enforced and that each tenant's encryption keys are segregated directly mitigates cross-tenant image disclosure. This control targets the actual mechanism by which one customer could read another customer's DICOM objects, making it the most direct risk response for the stated scenario.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.