easyMultiple Choice
Threat Modeling: Most Effective for Cloud Migration Risk Identification
A company is migrating its customer database to a public cloud provider. During the planning phase, which of the following is the MOST effective approach to identify risks specific to this migration?
Quick Answer
The answer is conducting a threat modeling exercise focusing on the cloud architecture. This is the most effective approach for cloud migration risk identification because it systematically maps data flows, trust boundaries, and attack vectors unique to the public cloud environment, such as misconfigured APIs or insecure data transit, using frameworks like STRIDE or PASTA. On the CRISC exam, this question tests your ability to differentiate proactive, architecture-specific analysis from generic audits or checklist reviews—a common trap is choosing a broad risk assessment that misses cloud-native threats like shared responsibility gaps. For a memory tip, remember that threat modeling is like a blueprint review for a new house: you inspect the foundation (architecture) before moving in, not after.
⚠ Common exam trap
Many exam-takers choose a compliance checklist (C) or industry reports (A) because they seem thorough and authoritative, but the CRISC exam emphasizes that risk identification must be proactive and architecture-specific, not reactive or generic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct a threat modeling exercise focusing on the cloud architecture
Conducting a threat modeling exercise (D) is the most effective approach because it systematically identifies threats, vulnerabilities, and attack vectors specific to the cloud architecture, data flow, and trust boundaries of the migration. Unlike generic reviews, threat modeling (e.g., using STRIDE or PASTA) directly addresses the unique risks of moving a customer database to a public cloud, such as misconfigured access controls, insecure APIs, or data exposure during transit.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Review industry risk reports for similar migrations
Why it's wrong here
Industry reports describe generic patterns from other organisations, not this company's architecture, data classification, or migration design, so they cannot identify its specific risks. They are tempting because they offer benchmark data, and would be correct for contextualising risk trends rather than assessing a particular migration.
- ✗
Rely on the cloud provider's published risk documentation
Why it's wrong here
Provider documentation covers the provider's shared infrastructure, not the company's own data flows, configurations, and integration points, so it misses migration-specific risks. It is tempting because it is readily available and authoritative, and would be correct for understanding the provider's own controls and service-level commitments.
- ✗
Perform a compliance checklist review
Why it's wrong here
A compliance checklist verifies adherence to known requirements; it does not surface risks arising from the migration's architecture, data flows, or provider dependencies. Checklists are tempting because they are structured and repeatable, and would be correct for confirming regulatory control coverage rather than identifying migration-specific risks.
- ✓
Conduct a threat modeling exercise focusing on the cloud architecture
Why this is correct
Threat modelling systematically examines the cloud architecture's data flows, trust boundaries and entry points, exposing migration-specific risks such as misconfigured storage exposure or insecure APIs. This directly satisfies the planning-phase requirement to identify risks before controls are designed, unlike generic checklists or post-migration audits.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CRISC
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An organization is considering migrating its customer database to a public cloud provider. Which of the following is the PRIMARY risk identification technique that should be used to identify potential data exposure risks?
easy- A.Vulnerability scanning
- ✓ B.Threat modeling
- C.Penetration testing
- D.Business impact analysis
Why B: Threat modeling is the primary risk identification technique for proactively identifying potential data exposure risks during a cloud migration. It systematically analyzes the system architecture, data flows, and trust boundaries to uncover threats such as misconfigured access controls, insecure APIs, or data leakage between tenants. Unlike reactive techniques, threat modeling focuses on design-level vulnerabilities before they are exploited.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.