CCSP Legal, Risk, and Compliance Practice Question
A company is evaluating the risk of using a single cloud provider for all critical workloads. Which risk is most directly associated with this scenario?
⚠ Common exam trap
CCSP often tests the distinction between generic third-party risk and concentration risk — candidates pick 'third-party risk' because it sounds broader, missing that the scenario's single-provider dependency is the textbook definition of concentration risk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Concentration risk
Concentration risk is the danger that over-reliance on a single provider, service, or region creates a single point of failure whose disruption affects all dependent workloads simultaneously. Using one cloud provider for all critical workloads concentrates operational, financial, and availability exposure in that vendor, so an outage, contract dispute, or bankruptcy cascades across the entire estate. This is precisely the risk regulators and frameworks like the EBA and DORA flag for cloud concentration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Inherent risk of shared infrastructure
Why it's wrong here
Shared infrastructure risk addresses multi-tenancy exposure within one provider's platform, not dependence on that provider alone. It tempts because tenants sharing hypervisors, storage and network genuinely create isolation and side-channel concerns, making it correct when assessing co-tenancy. The stem's single-provider concentration is a provider-level failure and lock-in exposure instead.
- ✗
Third-party risk
Why it's wrong here
Third-party risk covers any external supplier dependency, so it is broader than the concentration exposure the stem describes. It tempts because relying on one vendor's security, compliance and continuity genuinely is third-party risk, and it would be correct where the concern is vendor governance generally. Here the specific issue is correlated failure across all workloads.
- ✓
Concentration risk
Why this is correct
Concentration risk arises when dependence on one provider means a single outage, failure or contractual dispute simultaneously affects all critical workloads, with no failover alternative. This directly matches the stem's scenario of using a single cloud provider for everything.
- ✗
Control effectiveness risk
Why it's wrong here
Control effectiveness risk concerns whether implemented controls actually operate as intended, not provider concentration. It tempts because weak or unverified controls genuinely undermine security assurance, making it the right answer when assessing whether existing safeguards work. Here, the stem's single-provider dependency is an availability and lock-in exposure, not a control performance issue.
Visual reference
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.