Courseiva
hardMultiple ChoiceObjective-mapped

CRISC Practice Question: A multinational corporation is identifying risks…

A multinational corporation is identifying risks associated with cross-border data transfers. Which regulation's risk identification requirements are most relevant?

⚠ Common exam trap

Watch out — candidates often confuse PCI DSS or HIPAA as relevant because they involve sensitive data, but they lack the specific cross-border transfer risk identification requirements that GDPR mandates, leading to an incorrect choice based on data sensitivity rather than regulatory scope.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

GDPR

The General Data Protection Regulation (GDPR) is the most relevant regulation for risk identification in cross-border data transfers because it explicitly governs the transfer of personal data from the European Economic Area (EEA) to third countries. GDPR requires organizations to identify and assess risks related to adequacy decisions, Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), and potential data localization conflicts. This regulation directly addresses the legal and technical risks of moving data across borders, such as exposure to differing privacy laws and surveillance regimes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • PCI DSS

    Why it's wrong here

    PCI DSS is specific to payment card data.

  • GDPR

    Why this is correct

    GDPR requires risk assessments for international data transfers.

  • HIPAA

    Why it's wrong here

    HIPAA applies to US healthcare data, not general cross-border.

  • SOX

    Why it's wrong here

    SOX is about financial controls, not data transfer risks.

About these practice questions

Courseiva writes every CRISC question from scratch — 983 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.