mediumMultiple ChoiceObjective-mapped
CRISC Practice Question: During an IT risk assessment for a new…
During an IT risk assessment for a new cloud-based customer relationship management (CRM) system, the risk practitioner identifies that the vendor's data center is located in a country with different data protection regulations. Which of the following is the MOST appropriate next step?
⚠ Common exam trap
The trap here is that candidates often jump to technical controls (encryption) as a universal solution, overlooking that regulatory compliance is a legal and contractual issue that cannot be fully resolved by encryption alone.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct a legal review to assess regulatory implications and contractual safeguards.
When a cloud vendor's data center is in a jurisdiction with different data protection regulations, the immediate priority is to understand the legal and contractual implications before making any technical or risk acceptance decisions. A legal review will identify specific regulatory conflicts (e.g., GDPR vs. local law) and assess whether existing contractual safeguards (such as Standard Contractual Clauses or Binding Corporate Rules) adequately address the gap. This step ensures that subsequent risk treatment decisions are informed by compliance requirements rather than assumptions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Conduct a legal review to assess regulatory implications and contractual safeguards.
Why this is correct
Legal review ensures compliance and identifies necessary controls.
- ✗
Recommend migrating to a different cloud provider.
Why it's wrong here
Migration is premature without analyzing legal risks.
- ✗
Implement technical controls to encrypt data in transit and at rest.
Why it's wrong here
Technical controls cannot substitute for legal compliance.
- ✗
Accept the risk because the vendor is compliant with industry standards.
Why it's wrong here
Accepting the risk without understanding legal implications is inappropriate.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 983 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.