Courseiva
Key Concepts of ITIL 4 →hardMultiple Choice

ITIL4F Key Concepts of ITIL 4 Practice Question

An organization uses an external cloud provider for its email service. Which of the following risks is MOST likely transferred from the consumer to the provider?

⚠ Common exam trap

Candidates often mistakenly believe that all risks (including compliance, insider threats, and disaster impact) are transferred to the cloud provider, ignoring the ITIL 4 concept that the consumer retains accountability for data governance, user behavior, and business continuity planning.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk of hardware failure in the provider's data center

When an organization uses an external cloud provider for email services, the provider is responsible for the physical infrastructure, including servers, storage, and networking hardware. The risk of hardware failure in the provider's data center is therefore transferred to the provider, as they must maintain redundancy (e.g., RAID, UPS, failover clusters) and ensure service continuity under their SLA. This aligns with the ITIL 4 concept of 'shared responsibility' where the consumer retains risks related to data and compliance, while the provider assumes risks tied to the underlying technology stack.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Risk of non-compliance with industry regulations

    Why it's wrong here

    When an organization uses a cloud provider, the ultimate accountability for compliance with industry-specific regulations (e.g., GDPR, HIPAA, PCI DSS) typically remains with the consumer. While the provider ensures their services meet certain compliance standards, the consumer is responsible for ensuring their overall data handling, configurations, and processes within the cloud environment adhere to all applicable regulatory requirements. Therefore, the risk of non-compliance is not fully transferred but rather shared, with significant responsibility still resting on the consumer.

  • ✗

    Risk of data breach due to insider threats

    Why it's wrong here

    Data security in a cloud environment operates under a shared responsibility model. The cloud provider is responsible for the security *of* the cloud (e.g., physical security, underlying infrastructure), but the consumer is responsible for security *in* the cloud, which includes managing access controls, data encryption, and protecting against threats originating from their own users or applications. Insider threats, whether from the consumer's own staff or misconfigurations of user access, fall primarily under the consumer's domain for data protection, meaning this risk is not entirely transferred.

  • ✗

    Risk of service unavailability due to a natural disaster

    Why it's wrong here

    While a natural disaster affecting a cloud provider's data center can certainly cause service unavailability, the risk is not entirely transferred to the provider. Cloud providers typically implement robust disaster recovery and business continuity plans, often involving geographically dispersed data centers, to mitigate such risks. However, the consumer organization still bears the risk of impact to their own operations and must have their own continuity plans, including strategies for data backup and alternative access, to ensure resilience beyond the provider's immediate recovery capabilities. This makes the risk shared, not fully transferred.

  • ✓

    Risk of hardware failure in the provider's data center

    Why this is correct

    When an organization outsources its email services to an external cloud provider, the provider assumes full responsibility for the underlying physical infrastructure, including all servers, storage arrays, and networking hardware within their data centers. Consequently, the direct risk associated with the failure of any of this hardware, and the operational burden of its maintenance, repair, or replacement, is entirely transferred from the consumer to the cloud provider as part of the service agreement. The consumer is abstracted from these infrastructure-level concerns.

Quick reference

RAID Level Comparison

RAID LevelMin DisksFault ToleranceReadWriteUsable Capacity
RAID 02NoneExcellentExcellent100%
RAID 121 diskGoodModerate50%
RAID 531 diskGoodModerate67–94%
RAID 642 disksGoodLower50–88%
RAID 1041 disk per mirrorExcellentGood50%

RAID is not a backup strategy — it protects against disk failure but not against accidental deletion, ransomware, or site-level events.

About these practice questions

This ITIL4F question is part of Courseiva's 805-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ITIL4F practice question is part of Courseiva's free PeopleCert certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ITIL4F exam.