CCSP Legal, Risk, and Compliance Practice Question
A multinational corporation uses multiple cloud service providers for its critical applications. The board is concerned about concentration risk. Which strategy would best address this risk?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Adopting a multi-cloud strategy that distributes applications across multiple cloud providers
Concentration risk refers to over-reliance on a single provider. A multi-cloud strategy reduces this risk by distributing workloads across multiple providers, avoiding a single point of failure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Negotiating a longer contract with the primary cloud provider to ensure stability
Why it's wrong here
Longer contracts deepen reliance on one provider, increasing rather than reducing concentration risk. Multi-cloud portability and provider diversity are the actual mitigations. Contract duration addresses commercial stability and pricing predictability, so it would suit a scenario where the concern was cost volatility or renewal leverage, not resilience across providers.
- ✗
Implementing a hybrid cloud model with on-premises infrastructure only
Why it's wrong here
On-premises-only infrastructure removes multi-provider dependency but abandons cloud elasticity and the resilience the board actually wants. The option is tempting because owning infrastructure feels like control, yet concentration risk is addressed by distributing workloads across independent providers with portable architectures, not by retreating from cloud entirely.
- ✓
Adopting a multi-cloud strategy that distributes applications across multiple cloud providers
Why this is correct
Distributing workloads across several providers directly reduces concentration risk by removing dependence on any single vendor's availability, pricing, or failure domain. Because the corporation already uses multiple cloud service providers, this approach satisfies the board's concern about over-reliance, ensuring no single provider outage or policy change can disrupt all critical applications simultaneously.
- ✗
Requiring each business unit to use the same cloud provider for consistency
Why it's wrong here
Mandating one provider for all business units creates the very concentration risk the board fears, deepening single-vendor exposure. The option is tempting because standardisation simplifies contracts and operations, but the correct strategy is spreading critical workloads across independent providers with exit and portability provisions.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.