hardMultiple Choice
CRISC Practice Question: A multinational organization is assessing the…
A multinational organization is assessing the risk of a new cloud service that stores data across multiple geographic regions. The service provider offers standard contractual terms and does not commit to specific data residency requirements. What is the primary risk that should be evaluated?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Non-compliance with data protection regulations due to data location uncertainty.
The primary risk is non-compliance with data protection regulations due to uncertain data location (Option B). Because the provider does not commit to specific data residency, the organization cannot guarantee compliance with laws like GDPR that impose strict requirements on where data is stored and processed. This legal exposure outweighs the other options, as it could lead to fines and legal penalties.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Service availability and uptime commitments.
Why it's wrong here
Availability commitments concern uptime and resilience, not where data physically resides. This risk would be primary if the provider offered weak service-level agreements for uptime, but the stem's missing residency commitments point to legal and regulatory exposure instead.
- ✓
Non-compliance with data protection regulations due to data location uncertainty.
Why this is correct
Without contractual data residency commitments, data may be stored or processed in jurisdictions with differing legal requirements, creating regulatory exposure. The primary risk is therefore non-compliance with data protection laws governing cross-border transfers, not availability or performance.
- ✗
Unauthorized access to data by cloud provider employees.
Why it's wrong here
Insider access by provider staff is a confidentiality risk independent of geography. This risk would be primary if the provider lacked background checks or least-privilege controls, but the stem's absent residency commitments create regulatory and legal exposure, not unauthorised access.
- ✗
Inadequate encryption of data at rest and in transit.
Why it's wrong here
Encryption protects data confidentiality during storage and transmission regardless of location. This risk would be primary if the provider refused to disclose or attest to cryptographic controls, but the stem concerns absent residency commitments, which encryption does not address.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.