Courseiva
hardMultiple Select

CRISC Practice Question: Which THREE of the following are effective risk…

Which THREE of the following are effective risk identification techniques for a cloud migration project? (Select exactly THREE.)

⚠ Common exam trap

Candidates often confuse post-migration validation activities (UAT) or on-premises-focused scans with proactive risk identification techniques that are specifically designed to uncover cloud migration risks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Vendor lock-in analysis

Vendor lock-in analysis (A) is a valid risk identification technique because it surfaces strategic and exit risks tied to proprietary APIs, managed services, and data egress costs that can constrain future portability during a cloud migration. Cloud security assessment (C) is correct because it identifies threats and control gaps in the shared responsibility model, including IAM misconfigurations, encryption coverage, and compliance exposure specific to the target cloud. Data classification (D) is correct because it reveals which datasets are sensitive, regulated, or business-critical, driving risks around residency, sovereignty, access control, and migration sequencing. User acceptance testing (B) is a validation activity performed after implementation to confirm the solution meets business needs, not a technique for identifying risks up front. Network scanning of on-premises infrastructure (E) is a technical discovery or vulnerability assessment activity; while it may feed risk data, it is not itself a risk identification technique for the migration project.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Vendor lock-in analysis

    Why this is correct

    Vendor lock-in analysis identifies risks arising from proprietary cloud services, non-portable data formats and contractual exit barriers. It is effective for cloud migration because dependency on a single provider constrains future flexibility, a risk absent from traditional on-premises hosting.

  • ✗

    User acceptance testing (UAT)

    Why it's wrong here

    UAT validates functional fitness after deployment, not risks before or during migration. It is tempting because testing surfaces defects, but risk identification requires techniques such as assumption analysis, checklists and interviews that expose threats before cutover; UAT occurs too late and addresses quality, not risk.

  • ✓

    Cloud security assessment

    Why this is correct

    A cloud security assessment evaluates the provider's controls, shared responsibility boundaries and configuration against recognised standards, surfacing gaps before migration. It is effective here because it identifies risks specific to the cloud environment rather than reusing on-premises assumptions.

  • ✓

    Data classification

    Why this is correct

    Data classification determines which information is regulated, sensitive or critical, revealing where migration to shared cloud infrastructure creates exposure. It is effective because residency, handling and access risks cannot be identified without first knowing the data's sensitivity.

  • ✗

    Network scanning of on-premises infrastructure

    Why it's wrong here

    Scanning on-premises infrastructure inventories existing assets; it does not identify cloud migration risks such as data residency, provider lock-in or shared responsibility gaps. It is tempting because discovery informs planning, but the technique examines the source environment, whereas migration risk identification must assess the target cloud and transition itself.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.