Courseiva
Legal, Risk, and Compliance →mediumMultiple Choice

CCSP Legal, Risk, and Compliance Practice Question

A company is evaluating the risk of using a single cloud provider for all critical workloads. Which risk is most directly associated with this scenario?

⚠ Common exam trap

CCSP often tests the distinction between generic third-party risk and concentration risk — candidates pick 'third-party risk' because it sounds broader, missing that the scenario's single-provider dependency is the textbook definition of concentration risk.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Concentration risk

Concentration risk is the danger that over-reliance on a single provider, service, or region creates a single point of failure whose disruption affects all dependent workloads simultaneously. Using one cloud provider for all critical workloads concentrates operational, financial, and availability exposure in that vendor, so an outage, contract dispute, or bankruptcy cascades across the entire estate. This is precisely the risk regulators and frameworks like the EBA and DORA flag for cloud concentration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Inherent risk of shared infrastructure

    Why it's wrong here

    Shared infrastructure risk addresses multi-tenancy exposure within one provider's platform, not dependence on that provider alone. It tempts because tenants sharing hypervisors, storage and network genuinely create isolation and side-channel concerns, making it correct when assessing co-tenancy. The stem's single-provider concentration is a provider-level failure and lock-in exposure instead.

  • ✗

    Third-party risk

    Why it's wrong here

    Third-party risk covers any external supplier dependency, so it is broader than the concentration exposure the stem describes. It tempts because relying on one vendor's security, compliance and continuity genuinely is third-party risk, and it would be correct where the concern is vendor governance generally. Here the specific issue is correlated failure across all workloads.

  • ✓

    Concentration risk

    Why this is correct

    Concentration risk arises when dependence on one provider means a single outage, failure or contractual dispute simultaneously affects all critical workloads, with no failover alternative. This directly matches the stem's scenario of using a single cloud provider for everything.

  • ✗

    Control effectiveness risk

    Why it's wrong here

    Control effectiveness risk concerns whether implemented controls actually operate as intended, not provider concentration. It tempts because weak or unverified controls genuinely undermine security assurance, making it the right answer when assessing whether existing safeguards work. Here, the stem's single-provider dependency is an availability and lock-in exposure, not a control performance issue.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.