mediumMultiple ChoiceObjective-mapped
CRISC Practice Question: A risk manager is identifying risks for an…
A risk manager is identifying risks for an organization that uses a hybrid cloud environment. The organization stores sensitive data on-premises and in the cloud. Which of the following is the MOST effective method for identifying risks related to data residency and compliance?
⚠ Common exam trap
Test-takers frequently confuse security testing (penetration tests, configuration reviews) with compliance risk identification, overlooking that data residency and legal requirements demand a process-oriented review of data flows and jurisdictional rules, not just technical controls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Review data flow diagrams and legal requirements for each jurisdiction
Reviewing data flow diagrams alongside legal requirements for each jurisdiction is the most effective method because it directly maps where sensitive data resides, transits, and is processed across on-premises and cloud environments, enabling precise identification of residency and compliance gaps. This approach aligns with CRISC's emphasis on risk identification through understanding data lineage and regulatory obligations, rather than relying on post-deployment security tests or generic reports.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Conduct a penetration test of the cloud environment
Why it's wrong here
Penetration test focuses on vulnerabilities, not compliance risks.
- ✓
Review data flow diagrams and legal requirements for each jurisdiction
Why this is correct
This identifies data movement and regulatory compliance risks.
- ✗
Perform a configuration review of cloud security settings
Why it's wrong here
Configuration review is important but does not fully address data residency compliance.
- ✗
Review the cloud provider's SOC 2 report
Why it's wrong here
SOC 2 report provides assurance but not specific data residency risk identification.
Go deeper
Related to this question
About these practice questions
One of 983 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.