easyMultiple ChoiceObjective-mapped
Threat Modeling: Most Effective for Cloud Migration Risk Identification
A company is migrating its customer database to a public cloud provider. During the planning phase, which of the following is the MOST effective approach to identify risks specific to this migration?
Quick Answer
The answer is conducting a threat modeling exercise focusing on the cloud architecture. This is the most effective approach for cloud migration risk identification because it systematically maps data flows, trust boundaries, and attack vectors unique to the public cloud environment, such as misconfigured APIs or insecure data transit, using frameworks like STRIDE or PASTA. On the CRISC exam, this question tests your ability to differentiate proactive, architecture-specific analysis from generic audits or checklist reviews—a common trap is choosing a broad risk assessment that misses cloud-native threats like shared responsibility gaps. For a memory tip, remember that threat modeling is like a blueprint review for a new house: you inspect the foundation (architecture) before moving in, not after.
⚠ Common exam trap
Many exam-takers choose a compliance checklist (C) or industry reports (A) because they seem thorough and authoritative, but the CRISC exam emphasizes that risk identification must be proactive and architecture-specific, not reactive or generic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct a threat modeling exercise focusing on the cloud architecture
Conducting a threat modeling exercise (D) is the most effective approach because it systematically identifies threats, vulnerabilities, and attack vectors specific to the cloud architecture, data flow, and trust boundaries of the migration. Unlike generic reviews, threat modeling (e.g., using STRIDE or PASTA) directly addresses the unique risks of moving a customer database to a public cloud, such as misconfigured access controls, insecure APIs, or data exposure during transit.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Review industry risk reports for similar migrations
Why it's wrong here
Generic reports may not cover specific cloud provider risks.
- ✗
Rely on the cloud provider's published risk documentation
Why it's wrong here
Vendor docs are not a substitute for proactive risk identification.
- ✗
Perform a compliance checklist review
Why it's wrong here
Checklists focus on compliance, not all technical risks.
- ✓
Conduct a threat modeling exercise focusing on the cloud architecture
Why this is correct
Threat modeling identifies environment-specific threats like data exposure and misconfigurations.
Go deeper
Related to this question
About these practice questions
One of 983 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CRISC
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An organization is considering migrating its customer database to a public cloud provider. Which of the following is the PRIMARY risk identification technique that should be used to identify potential data exposure risks?
easy- A.Vulnerability scanning
- ✓ B.Threat modeling
- C.Penetration testing
- D.Business impact analysis
Why B: Threat modeling is the primary risk identification technique for proactively identifying potential data exposure risks during a cloud migration. It systematically analyzes the system architecture, data flows, and trust boundaries to uncover threats such as misconfigured access controls, insecure APIs, or data leakage between tenants. Unlike reactive techniques, threat modeling focuses on design-level vulnerabilities before they are exploited.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.