CRISC Information Technology and Security Practice Question
A retail company is migrating its e-commerce order database to a public cloud provider. The database stores customer names, addresses, and partial payment card numbers. The risk practitioner must determine who is accountable for protecting this data once it resides with the provider. Which of the following principles BEST guides this determination?
⚠ Common exam trap
The trap here is believing that outsourcing infrastructure also outsources accountability, when governance responsibility for data remains with the originating organization.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Accountability follows the shared responsibility model, where the retailer remains accountable for its data regardless of where it is hosted.
Cloud adoption changes where data resides but not who is answerable for it. In the shared responsibility model the provider secures facilities, hardware, and the hypervisor, while the customer remains accountable for data classification, access management, encryption choices, and regulatory compliance. The retailer therefore keeps accountability for customer records and must design controls and contracts accordingly, regardless of the service tier purchased.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Accountability is transferred to the provider only when the retailer purchases the highest-tier support plan.
Why it's wrong here
Support tiers affect response times and technical assistance, not legal or regulatory accountability for data protection. No commercial support agreement shifts the customer's obligation to safeguard personal data. Tying accountability to a support plan confuses service level commitments with governance responsibility under the shared responsibility model.
- ✗
The cloud provider assumes full accountability for data protection once the data is stored in its environment.
Why it's wrong here
Public cloud providers operate on a shared responsibility model in which the customer retains accountability for its data, classification, and access decisions. A provider secures the underlying infrastructure but does not take ownership of customer data protection obligations. Assuming full provider accountability misstates the model and leaves the retailer's compliance duties unmanaged.
- ✓
Accountability follows the shared responsibility model, where the retailer remains accountable for its data regardless of where it is hosted.
Why this is correct
Under the shared responsibility model, the provider secures the cloud infrastructure while the customer remains accountable for the security of its data, identities, and configurations. Moving data to a public cloud does not transfer regulatory or contractual accountability. This principle correctly frames how the retailer must govern protection of customer records.
- ✗
Accountability is jointly held, so the retailer and provider must each protect the data equally and can rely on the other's controls.
Why it's wrong here
Shared responsibility divides duties by layer rather than duplicating them equally, and each party must independently meet its own obligations. The retailer cannot rely on provider controls to satisfy its own regulatory duties, nor can it assume the provider covers application-level weaknesses. Describing the model as equal joint custody obscures the customer's non-delegable accountability.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.