Courseiva
hardMultiple Choice

CRISC Practice Question: A risk assessment for a cloud migration project…

A risk assessment for a cloud migration project identifies that the cloud provider does not support encryption keys managed by the customer. Which of the following risk scenarios is MOST directly related to this finding?

⚠ Common exam trap

Candidates often confuse encryption key management with data residency or misconfiguration risks, but the core issue is that provider-managed keys eliminate the customer's ability to prevent the provider from decrypting their data, directly enabling unauthorized access by provider employees.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Unauthorized access by cloud provider employees

When the cloud provider does not support customer-managed encryption keys, the provider retains control over the key material. This means that provider employees with administrative access to the key management system could potentially decrypt and access customer data, leading to unauthorized access. This directly creates a risk scenario of unauthorized access by cloud provider employees, as the customer loses the ability to enforce separation of duties and key sovereignty.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Service availability disruption

    Why it's wrong here

    Availability disruption stems from outages, capacity or redundancy failures, none of which the key-management finding describes. Losing customer-managed keys concerns confidentiality and control of data at rest, so availability is the wrong risk axis here.

  • ✗

    Data loss due to misconfiguration

    Why it's wrong here

    Misconfiguration causes exposure through settings errors, not through the absence of customer-managed keys. The finding concerns who controls and holds the encryption keys, so the directly related scenario is loss of control over data at rest, not accidental misconfiguration.

  • ✓

    Unauthorized access by cloud provider employees

    Why this is correct

    Without customer-managed keys, the provider holds and can access the encryption keys, so provider personnel could decrypt stored data. This scenario directly addresses the loss of key custody identified in the finding, making insider access at the provider the most direct consequence.

  • ✗

    Non-compliance with data residency requirements

    Why it's wrong here

    Data residency concerns where data is stored geographically, which the provider's key-management limitation does not affect. The finding is about who controls encryption keys, so residency compliance is unrelated; key custody, not location, is the issue.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.