Courseiva

CRISC Information Technology and Security Practice Question

When assessing cloud computing risk, which of the following is a key concern related to data sovereignty?

⚠ Common exam trap

The trap is confusing data sovereignty with other cloud risks like shared responsibility or multi-tenancy; candidates must focus on the legal jurisdiction aspect.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Data may be stored in jurisdictions with different privacy laws

Data sovereignty is a key concern in cloud computing risk because data may be stored in jurisdictions with different privacy laws. This means that data could be subject to legal requirements that conflict with the organization's own compliance obligations, such as GDPR or HIPAA.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Shared responsibility model misunderstandings

    Why it's wrong here

    Shared responsibility misunderstandings concern unclear division of security duties between provider and customer, not the legal jurisdiction governing stored data. It is a real cloud governance risk, but it answers questions about accountability gaps, not sovereignty.

  • ✓

    Data may be stored in jurisdictions with different privacy laws

    Why this is correct

    Data sovereignty concerns arise because cloud providers may replicate or store data in jurisdictions whose privacy laws differ from the organisation's own, potentially breaching regulatory obligations. This legal exposure, not encryption or availability, is the key risk when assessing cloud computing.

  • ✗

    Multi-tenancy isolation gaps

    Why it's wrong here

    Multi-tenancy isolation gaps concern logical separation between cloud customers, not where data is physically stored or which jurisdiction's laws apply. It is a genuine cloud risk, but it would be the answer to a question about tenant segregation or hypervisor escape.

  • ✗

    Vendor lock-in due to proprietary APIs

    Why it's wrong here

    Vendor lock-in concerns portability and switching cost from proprietary APIs, unrelated to the legal jurisdiction where data resides. It is a legitimate cloud risk, but it would be the correct answer to a question about exit strategy or interoperability, not sovereignty.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.