Courseiva
Information Technology and SecuritymediumMultiple ChoiceObjective-mapped

CRISC Information Technology and Security Practice Question

An organization is developing a new cloud-based application that will process personal data of EU citizens. The risk manager is assessing the shared responsibility model with the cloud service provider (CSP). Which of the following is the MOST critical risk to address in the risk assessment?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Data sovereignty and cross-border data transfer restrictions

In the shared responsibility model, the customer is responsible for data classification and access controls. Data sovereignty is a key concern when processing EU personal data, as the CSP may store data in jurisdictions that do not provide equivalent protection. The risk manager must ensure contractual and technical measures align with GDPR requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Lack of encryption at rest

    Why it's wrong here

    Encryption at rest is a control but not the most critical risk; data sovereignty and legal compliance take precedence.

  • Vendor lock-in due to proprietary APIs

    Why it's wrong here

    Vendor lock-in is a business risk but not the most critical for data protection compliance.

  • Data sovereignty and cross-border data transfer restrictions

    Why this is correct

    Data sovereignty is critical for compliance with GDPR and other privacy regulations, as data may be stored in jurisdictions with inadequate protection.

  • Multi-tenancy isolation failures

    Why it's wrong here

    Multi-tenancy isolation is important but typically addressed by the CSP's security controls; the customer's primary responsibility is data protection.

About these practice questions

Courseiva writes every CRISC question from scratch — 983 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.