CRISC Information Technology and Security Practice Question
When assessing cloud computing risk, which of the following is a key concern related to data sovereignty?
⚠ Common exam trap
The trap is confusing data sovereignty with other cloud risks like shared responsibility or multi-tenancy; candidates must focus on the legal jurisdiction aspect.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data may be stored in jurisdictions with different privacy laws
Data sovereignty is a key concern in cloud computing risk because data may be stored in jurisdictions with different privacy laws. This means that data could be subject to legal requirements that conflict with the organization's own compliance obligations, such as GDPR or HIPAA.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Shared responsibility model misunderstandings
Why it's wrong here
Shared responsibility misunderstandings concern unclear division of security duties between provider and customer, not the legal jurisdiction governing stored data. It is a real cloud governance risk, but it answers questions about accountability gaps, not sovereignty.
- ✓
Data may be stored in jurisdictions with different privacy laws
Why this is correct
Data sovereignty concerns arise because cloud providers may replicate or store data in jurisdictions whose privacy laws differ from the organisation's own, potentially breaching regulatory obligations. This legal exposure, not encryption or availability, is the key risk when assessing cloud computing.
- ✗
Multi-tenancy isolation gaps
Why it's wrong here
Multi-tenancy isolation gaps concern logical separation between cloud customers, not where data is physically stored or which jurisdiction's laws apply. It is a genuine cloud risk, but it would be the answer to a question about tenant segregation or hypervisor escape.
- ✗
Vendor lock-in due to proprietary APIs
Why it's wrong here
Vendor lock-in concerns portability and switching cost from proprietary APIs, unrelated to the legal jurisdiction where data resides. It is a legitimate cloud risk, but it would be the correct answer to a question about exit strategy or interoperability, not sovereignty.
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.