Courseiva

CRISC Information Technology and Security Practice Question

A retail company is migrating its customer loyalty application to a cloud provider. During a risk assessment, the risk practitioner notes that the provider's infrastructure is shared across many tenants. Which of the following is the MOST significant risk that this multi-tenancy introduces?

⚠ Common exam trap

The trap here is assuming that any risk related to cloud, such as provider insolvency or pricing, is the most significant, rather than focusing on the specific threat introduced by sharing resources.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A vulnerability in the provider's isolation controls could allow one tenant to access another tenant's data.

Multi-tenancy introduces the risk that logical isolation controls may fail, allowing one tenant to access another tenant's data or workloads. This directly threatens confidentiality and integrity and is unique to shared cloud environments. Other risks such as provider failure, loss of scanning, or price changes are important but are not caused by the shared infrastructure model itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A vulnerability in the provider's isolation controls could allow one tenant to access another tenant's data.

    Why this is correct

    Multi-tenancy relies on logical isolation mechanisms such as hypervisors, containers, and network segmentation to keep tenants separate. A flaw in these controls can lead to data leakage or cross-tenant attacks, which is a direct and severe risk specific to shared environments. This is the most critical risk because it can compromise confidentiality and integrity of customer data without the organization's direct control.

  • ✗

    The cost of cloud services may increase unexpectedly due to provider pricing changes.

    Why it's wrong here

    Pricing volatility is a financial and contractual risk that affects all cloud consumers, regardless of multi-tenancy. It does not stem from sharing infrastructure with other tenants. This risk is managed through contracts and budgets, but it is not the most significant security risk introduced by multi-tenancy. The primary concern is the potential compromise of data isolation between tenants.

  • ✗

    The organization loses the ability to perform its own vulnerability scanning on the underlying infrastructure.

    Why it's wrong here

    Loss of direct scanning capability is a governance and assurance challenge, not a direct risk introduced by multi-tenancy. The provider typically performs scanning and may allow limited customer scanning. While this can reduce visibility, it does not inherently create a cross-tenant threat. The more significant risk is the potential for isolation failure that could expose data to other tenants.

  • ✗

    The cloud provider may go out of business, causing an abrupt loss of service.

    Why it's wrong here

    Provider insolvency is a business continuity risk that exists with any outsourced service, but it is not specific to multi-tenancy. The shared infrastructure model itself does not increase the likelihood of vendor failure. This risk can be mitigated through contractual provisions and exit strategies, but it is not the primary concern when multiple tenants share the same physical and logical resources.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.