CCSP Legal, Risk, and Compliance Practice Question
A multinational corporation is implementing a multi-cloud strategy to avoid concentration risk. The risk management team is evaluating the inherent risks of using multiple cloud providers. Which THREE risks are specifically associated with a multi-cloud strategy? (Choose three.)
⚠ Common exam trap
The trap is confusing single-cloud risks (lock-in, sovereignty) with multi-cloud-specific risks; candidates must distinguish risks that are amplified or introduced by using multiple providers from those that exist regardless.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Expanded attack surface due to more entry points and APIs
Option B is correct because a multi-cloud strategy adds more entry points and APIs, since each provider exposes its own management consoles, IAM endpoints, and service APIs, expanding the attack surface that must be monitored and secured. Option C is correct because consistent security policies must be enforced across heterogeneous providers with different native controls, identity models, and configuration semantics, making uniform governance and compliance far more complex. Option E is correct because each cloud platform has its own tooling, services, and operational model, so the organization needs specialized skills and expertise for each provider rather than a single unified skill set. Option A is not correct because multi-cloud generally reduces vendor lock-in rather than increasing it, since workloads can be distributed and portability is improved. Option D is not correct because data sovereignty challenges stem from where data is stored and processed across jurisdictions, which is not inherently a risk specific to using multiple cloud providers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Higher likelihood of vendor lock-in due to proprietary services
Why it's wrong here
Multi-cloud reduces lock-in by design, since workloads can migrate between providers; lock-in is the concentration risk that single-cloud adoption creates. The option tempts because proprietary services do cause lock-in, but that applies within one provider, not across several.
- ✓
Expanded attack surface due to more entry points and APIs
Why this is correct
Each additional provider introduces its own public endpoints, management APIs and identity planes, multiplying the number of exploitable entry points an attacker can target. This directly reflects the expanded attack surface inherent to spanning multiple cloud environments.
- ✓
Increased complexity in managing consistent security policies across providers
Why this is correct
Differing native security controls, IAM models and policy semantics across providers make uniform enforcement difficult, so misconfigurations and policy drift become more likely. This governance complexity is an inherent multi-cloud risk, not merely an operational inconvenience.
- ✗
Greater difficulty in meeting data sovereignty requirements across jurisdictions
Why it's wrong here
Multi-cloud spreads data across more jurisdictions, which can ease sovereignty alignment rather than hinder it, since workloads may be placed in-region. The difficulty arises in single-cloud or hybrid designs spanning regions; here the added provider contracts do not themselves create the sovereignty burden described.
- ✓
Need for specialized skills and expertise for each cloud platform
Why this is correct
Each provider has distinct tooling, networking constructs and security services, so staff must acquire and maintain separate competencies. This skills burden is an inherent multi-cloud risk, increasing the chance of misconfiguration and slowing incident response across platforms.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.