ITIL4F Key Concepts of ITIL 4 Practice Question
An organization uses an external cloud provider for its email service. Which of the following risks is MOST likely transferred from the consumer to the provider?
⚠ Common exam trap
Candidates often mistakenly believe that all risks (including compliance, insider threats, and disaster impact) are transferred to the cloud provider, ignoring the ITIL 4 concept that the consumer retains accountability for data governance, user behavior, and business continuity planning.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk of hardware failure in the provider's data center
When an organization uses an external cloud provider for email services, the provider is responsible for the physical infrastructure, including servers, storage, and networking hardware. The risk of hardware failure in the provider's data center is therefore transferred to the provider, as they must maintain redundancy (e.g., RAID, UPS, failover clusters) and ensure service continuity under their SLA. This aligns with the ITIL 4 concept of 'shared responsibility' where the consumer retains risks related to data and compliance, while the provider assumes risks tied to the underlying technology stack.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Risk of non-compliance with industry regulations
Why it's wrong here
When an organization uses a cloud provider, the ultimate accountability for compliance with industry-specific regulations (e.g., GDPR, HIPAA, PCI DSS) typically remains with the consumer. While the provider ensures their services meet certain compliance standards, the consumer is responsible for ensuring their overall data handling, configurations, and processes within the cloud environment adhere to all applicable regulatory requirements. Therefore, the risk of non-compliance is not fully transferred but rather shared, with significant responsibility still resting on the consumer.
- ✗
Risk of data breach due to insider threats
Why it's wrong here
Data security in a cloud environment operates under a shared responsibility model. The cloud provider is responsible for the security *of* the cloud (e.g., physical security, underlying infrastructure), but the consumer is responsible for security *in* the cloud, which includes managing access controls, data encryption, and protecting against threats originating from their own users or applications. Insider threats, whether from the consumer's own staff or misconfigurations of user access, fall primarily under the consumer's domain for data protection, meaning this risk is not entirely transferred.
- ✗
Risk of service unavailability due to a natural disaster
Why it's wrong here
While a natural disaster affecting a cloud provider's data center can certainly cause service unavailability, the risk is not entirely transferred to the provider. Cloud providers typically implement robust disaster recovery and business continuity plans, often involving geographically dispersed data centers, to mitigate such risks. However, the consumer organization still bears the risk of impact to their own operations and must have their own continuity plans, including strategies for data backup and alternative access, to ensure resilience beyond the provider's immediate recovery capabilities. This makes the risk shared, not fully transferred.
- ✓
Risk of hardware failure in the provider's data center
Why this is correct
When an organization outsources its email services to an external cloud provider, the provider assumes full responsibility for the underlying physical infrastructure, including all servers, storage arrays, and networking hardware within their data centers. Consequently, the direct risk associated with the failure of any of this hardware, and the operational burden of its maintenance, repair, or replacement, is entirely transferred from the consumer to the cloud provider as part of the service agreement. The consumer is abstracted from these infrastructure-level concerns.
Quick reference
RAID Level Comparison
| RAID Level | Min Disks | Fault Tolerance | Read | Write | Usable Capacity |
|---|---|---|---|---|---|
| RAID 0 | 2 | None | Excellent | Excellent | 100% |
| RAID 1 | 2 | 1 disk | Good | Moderate | 50% |
| RAID 5 | 3 | 1 disk | Good | Moderate | 67–94% |
| RAID 6 | 4 | 2 disks | Good | Lower | 50–88% |
| RAID 10 | 4 | 1 disk per mirror | Excellent | Good | 50% |
RAID is not a backup strategy — it protects against disk failure but not against accidental deletion, ransomware, or site-level events.
Go deeper
Related to this question
About these practice questions
This ITIL4F question is part of Courseiva's 805-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This ITIL4F practice question is part of Courseiva's free PeopleCert certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ITIL4F exam.