hardMultiple ChoiceObjective-mapped
CRISC Practice Question: A multinational organization is assessing the…
A multinational organization is assessing the risk of a new cloud service that stores data across multiple geographic regions. The service provider offers standard contractual terms and does not commit to specific data residency requirements. What is the primary risk that should be evaluated?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Non-compliance with data protection regulations due to data location uncertainty.
The primary risk is non-compliance with data protection regulations due to uncertain data location (Option B). Because the provider does not commit to specific data residency, the organization cannot guarantee compliance with laws like GDPR that impose strict requirements on where data is stored and processed. This legal exposure outweighs the other options, as it could lead to fines and legal penalties.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Service availability and uptime commitments.
Why it's wrong here
Availability is important but not the primary risk when data residency is unspecified.
- ✓
Non-compliance with data protection regulations due to data location uncertainty.
Why this is correct
Without data residency commitments, the organization may violate laws requiring data to stay within certain jurisdictions.
- ✗
Unauthorized access to data by cloud provider employees.
Why it's wrong here
While an access risk, it is secondary to compliance; provider access can often be mitigated contractually.
- ✗
Inadequate encryption of data at rest and in transit.
Why it's wrong here
Encryption is a security control but the immediate regulatory compliance risk from data location is more fundamental.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 983 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.