Courseiva

CCSP Legal, Risk, and Compliance Practice Question

A company is adopting a multi-cloud strategy to reduce concentration risk. Which two benefits are directly associated with this approach? (Choose two.)

⚠ Common exam trap

The trap is assuming multi-cloud simplifies everything — candidates pick 'simplified compliance' or 'unified security controls' because they sound like benefits, when in fact multi-cloud multiplies compliance and security complexity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Reduced vendor lock-in

Option A (Reduced vendor lock-in) is correct because spreading workloads across multiple providers means the company is not dependent on a single vendor's proprietary services, pricing, or roadmap, making it easier to migrate or renegotiate. Option B (Increased resilience) is correct because a multi-cloud strategy reduces concentration risk: an outage, regional failure, or service disruption at one provider does not take down the entire estate, since workloads can fail over to another cloud. Option C is not directly associated because compliance obligations (e.g., GDPR, HIPAA, PCI DSS) must still be met per provider and per region, and multi-cloud often complicates rather than simplifies compliance management. Option D is not directly associated because each cloud has its own IAM, logging, and security tooling, so unified security controls typically require additional third-party tooling or significant integration effort. Option E is not directly associated because adding more providers and cross-cloud traffic generally increases network latency and complexity rather than lowering it.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Reduced vendor lock-in

    Why this is correct

    Spreading workloads across multiple providers means no single vendor's proprietary interfaces or commercial terms dictate the estate, directly reducing vendor lock-in. This satisfies the stated concentration-risk reduction goal by removing dependency on one provider's ecosystem.

  • ✓

    Increased resilience

    Why this is correct

    Distributing workloads across independent providers means an outage or failure at one does not take down the whole estate, directly increasing resilience. This satisfies the concentration-risk reduction goal by eliminating a single provider as a single point of failure.

  • ✗

    Simplified compliance management

    Why it's wrong here

    Multi-cloud spreads workloads across providers, so each jurisdiction's data-residency, audit and reporting obligations must be met separately, multiplying compliance overhead rather than simplifying it. It is tempting because consolidating onto one provider's compliance programme genuinely simplifies attestation and evidence collection — the correct choice when regulatory scope is narrow and concentration risk is not a driver.

  • ✗

    Unified security controls

    Why it's wrong here

    Each cloud provider supplies its own identity, logging and policy tooling, so multi-cloud multiplies control planes instead of unifying them. It tempts because a single pane of glass is desirable, but achieving unified security controls requires deliberate third-party integration, not the multi-cloud strategy itself.

  • ✗

    Lower network latency

    Why it's wrong here

    Multi-cloud spreads workloads across providers, which typically adds WAN hops between environments and increases latency rather than lowering it. It tempts because providers do offer low-latency regions, but that benefit comes from geographic placement, not from adopting multiple clouds to reduce concentration risk.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.