Courseiva
easyMultiple ChoiceObjective-mapped

Threat Modeling: Most Effective for Cloud Migration Risk Identification

A company is migrating its customer database to a public cloud provider. During the planning phase, which of the following is the MOST effective approach to identify risks specific to this migration?

Quick Answer

The answer is conducting a threat modeling exercise focusing on the cloud architecture. This is the most effective approach for cloud migration risk identification because it systematically maps data flows, trust boundaries, and attack vectors unique to the public cloud environment, such as misconfigured APIs or insecure data transit, using frameworks like STRIDE or PASTA. On the CRISC exam, this question tests your ability to differentiate proactive, architecture-specific analysis from generic audits or checklist reviews—a common trap is choosing a broad risk assessment that misses cloud-native threats like shared responsibility gaps. For a memory tip, remember that threat modeling is like a blueprint review for a new house: you inspect the foundation (architecture) before moving in, not after.

⚠ Common exam trap

Many exam-takers choose a compliance checklist (C) or industry reports (A) because they seem thorough and authoritative, but the CRISC exam emphasizes that risk identification must be proactive and architecture-specific, not reactive or generic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Conduct a threat modeling exercise focusing on the cloud architecture

Conducting a threat modeling exercise (D) is the most effective approach because it systematically identifies threats, vulnerabilities, and attack vectors specific to the cloud architecture, data flow, and trust boundaries of the migration. Unlike generic reviews, threat modeling (e.g., using STRIDE or PASTA) directly addresses the unique risks of moving a customer database to a public cloud, such as misconfigured access controls, insecure APIs, or data exposure during transit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Review industry risk reports for similar migrations

    Why it's wrong here

    Generic reports may not cover specific cloud provider risks.

  • Rely on the cloud provider's published risk documentation

    Why it's wrong here

    Vendor docs are not a substitute for proactive risk identification.

  • Perform a compliance checklist review

    Why it's wrong here

    Checklists focus on compliance, not all technical risks.

  • Conduct a threat modeling exercise focusing on the cloud architecture

    Why this is correct

    Threat modeling identifies environment-specific threats like data exposure and misconfigurations.

About these practice questions

One of 983 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CRISC

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An organization is considering migrating its customer database to a public cloud provider. Which of the following is the PRIMARY risk identification technique that should be used to identify potential data exposure risks?

easy
  • A.Vulnerability scanning
  • B.Threat modeling
  • C.Penetration testing
  • D.Business impact analysis

Why B: Threat modeling is the primary risk identification technique for proactively identifying potential data exposure risks during a cloud migration. It systematically analyzes the system architecture, data flows, and trust boundaries to uncover threats such as misconfigured access controls, insecure APIs, or data leakage between tenants. Unlike reactive techniques, threat modeling focuses on design-level vulnerabilities before they are exploited.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.