hardMultiple Choice
CRISC Practice Question: A risk assessment for a cloud migration project…
A risk assessment for a cloud migration project identifies that the cloud provider does not support encryption keys managed by the customer. Which of the following risk scenarios is MOST directly related to this finding?
⚠ Common exam trap
Candidates often confuse encryption key management with data residency or misconfiguration risks, but the core issue is that provider-managed keys eliminate the customer's ability to prevent the provider from decrypting their data, directly enabling unauthorized access by provider employees.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Unauthorized access by cloud provider employees
When the cloud provider does not support customer-managed encryption keys, the provider retains control over the key material. This means that provider employees with administrative access to the key management system could potentially decrypt and access customer data, leading to unauthorized access. This directly creates a risk scenario of unauthorized access by cloud provider employees, as the customer loses the ability to enforce separation of duties and key sovereignty.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Service availability disruption
Why it's wrong here
Availability disruption stems from outages, capacity or redundancy failures, none of which the key-management finding describes. Losing customer-managed keys concerns confidentiality and control of data at rest, so availability is the wrong risk axis here.
- ✗
Data loss due to misconfiguration
Why it's wrong here
Misconfiguration causes exposure through settings errors, not through the absence of customer-managed keys. The finding concerns who controls and holds the encryption keys, so the directly related scenario is loss of control over data at rest, not accidental misconfiguration.
- ✓
Unauthorized access by cloud provider employees
Why this is correct
Without customer-managed keys, the provider holds and can access the encryption keys, so provider personnel could decrypt stored data. This scenario directly addresses the loss of key custody identified in the finding, making insider access at the provider the most direct consequence.
- ✗
Non-compliance with data residency requirements
Why it's wrong here
Data residency concerns where data is stored geographically, which the provider's key-management limitation does not affect. The finding is about who controls encryption keys, so residency compliance is unrelated; key custody, not location, is the issue.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.