Courseiva
IT Risk Identification →hardMultiple Select

CRISC IT Risk Identification Practice Question

A risk practitioner is identifying risks associated with the decommissioning of a legacy data center. The organization plans to migrate all remaining applications to a cloud environment. Which TWO of the following are the MOST significant risks that should be included in the risk register for this project? (Choose two.)

⚠ Common exam trap

The trap here is selecting cloud-related risks like data residency or cost, which are not specific to the decommissioning project.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Incomplete destruction of sensitive data on decommissioned storage media, leading to unauthorized disclosure.

The decommissioning of a legacy data center involves unique risks. Loss of institutional knowledge can lead to migration errors and outages, while incomplete data destruction can cause data breaches. These two risks are directly tied to the decommissioning process and should be prioritized in the risk register. Regulatory data residency, cloud cost spikes, and continuity plan updates are important but are either related to the cloud migration itself or are control activities, not the primary risks of decommissioning.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Incomplete destruction of sensitive data on decommissioned storage media, leading to unauthorized disclosure.

    Why this is correct

    When decommissioning a data center, ensuring that all sensitive data is securely wiped or destroyed from storage media is critical. If not properly handled, residual data could be recovered by unauthorized parties, leading to a data breach. This is a well-known risk in decommissioning projects and must be included in the risk register. It addresses confidentiality and compliance requirements.

  • ✗

    Failure to update the IT service continuity plan to reflect the new cloud architecture.

    Why it's wrong here

    Updating the IT service continuity plan is important, but it is a control or mitigation activity rather than a risk itself. The risk would be that the continuity plan is not updated, leading to ineffective response during a disaster. However, the scenario asks for risks associated with decommissioning. While this could be a risk, it is more of a project management oversight. The two most significant risks are knowledge loss and data remnants, which directly impact the decommissioning outcome.

  • ✗

    Inability to meet new regulatory requirements for data residency in the cloud environment.

    Why it's wrong here

    While data residency is a valid cloud risk, it is not specifically tied to the decommissioning of a legacy data center. The scenario focuses on the decommissioning project, and data residency would be a risk of the cloud migration itself, which may already be covered. The most significant risks for decommissioning are those directly related to the shutdown and transition, such as knowledge loss and data remnants. This option is less directly relevant to the decommissioning phase.

  • ✗

    Increased cloud subscription costs due to unexpected usage spikes after migration.

    Why it's wrong here

    Cost overruns in the cloud are a financial risk, but they are not directly caused by the decommissioning of the legacy data center. The decommissioning project's primary risks are related to the shutdown process, data security, and knowledge transfer. Cloud cost management is a separate operational risk that should be addressed in the cloud migration plan. This option is less significant for the decommissioning risk register.

  • ✓

    Loss of institutional knowledge about legacy application dependencies as experienced staff leave or retire.

    Why this is correct

    During decommissioning, the departure of staff who understand legacy systems can lead to undocumented dependencies and integration points being overlooked. This can cause migration failures or outages. This is a significant risk because it directly affects the ability to migrate applications successfully and maintain business continuity. It should be captured in the risk register to ensure knowledge transfer and documentation are prioritized.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.