Courseiva
mediumMultiple Choice

CRISC Practice Question: During an IT risk assessment for a new…

During an IT risk assessment for a new cloud-based customer relationship management (CRM) system, the risk practitioner identifies that the vendor's data center is located in a country with different data protection regulations. Which of the following is the MOST appropriate next step?

⚠ Common exam trap

The trap here is that candidates often jump to technical controls (encryption) as a universal solution, overlooking that regulatory compliance is a legal and contractual issue that cannot be fully resolved by encryption alone.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conduct a legal review to assess regulatory implications and contractual safeguards.

When a cloud vendor's data center is in a jurisdiction with different data protection regulations, the immediate priority is to understand the legal and contractual implications before making any technical or risk acceptance decisions. A legal review will identify specific regulatory conflicts (e.g., GDPR vs. local law) and assess whether existing contractual safeguards (such as Standard Contractual Clauses or Binding Corporate Rules) adequately address the gap. This step ensures that subsequent risk treatment decisions are informed by compliance requirements rather than assumptions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Conduct a legal review to assess regulatory implications and contractual safeguards.

    Why this is correct

    Cross-border data flows trigger distinct legal obligations, so a legal review identifies applicable transfer restrictions and whether contractual safeguards such as standard contractual clauses adequately mitigate them. This directly addresses the regulatory divergence constraint before technical or operational controls are considered.

  • ✗

    Recommend migrating to a different cloud provider.

    Why it's wrong here

    Migrating providers is a remediation decision, not the next step in a risk assessment; the practitioner must first analyse the regulatory exposure and document findings before recommending action. It is tempting because relocation removes the jurisdictional issue entirely, and would be correct once analysis confirms the transfer cannot be lawfully managed through contractual or other safeguards.

  • ✗

    Implement technical controls to encrypt data in transit and at rest.

    Why it's wrong here

    Encryption in transit and at rest does not resolve the lawful basis for transferring personal data into a jurisdiction with different data protection regulations; the regulatory exposure persists. It is tempting because encryption is a standard data-protection control, and would be the right response to interception or storage-compromise threats rather than to cross-border legal risk.

  • ✗

    Accept the risk because the vendor is compliant with industry standards.

    Why it's wrong here

    Industry-standard compliance does not address the cross-border transfer of personal data to a jurisdiction with differing data protection regulations, so accepting the risk bypasses the required assessment of legal and regulatory exposure. Acceptance is tempting once controls and vendor certifications appear adequate, and would be valid only after that transfer risk has been formally evaluated and accepted by accountable owners.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.