nerdexam
Isaca

CGEIT · Question #207

Which of the following is MOST important to consider when planning to implement a cloud-based application for sharing documents with internal and external parties?

The correct answer is D. Third-party access rights. When planning a cloud-based application for sharing documents with internal and external parties, the most critical consideration is managing third-party access rights to ensure data security and compliance.

Submitted by miguelv· Apr 18, 2026Governance of Enterprise IT

Question

Which of the following is MOST important to consider when planning to implement a cloud-based application for sharing documents with internal and external parties?

Options

  • ACloud implementation model
  • BUser experience
  • CInformation ownership
  • DThird-party access rights

How the community answered

(46 responses)
  • A
    4% (2)
  • B
    15% (7)
  • C
    7% (3)
  • D
    74% (34)

Why each option

When planning a cloud-based application for sharing documents with internal and external parties, the most critical consideration is managing third-party access rights to ensure data security and compliance.

ACloud implementation model

The cloud implementation model (e.g., public, private, hybrid) is a foundational decision, but it's a technical implementation detail that supports, rather than dictates, the specific access control needs for external sharing.

BUser experience

User experience is important for adoption and efficiency, but it is secondary to the fundamental security and compliance implications of external data sharing.

CInformation ownership

Information ownership is a key governance aspect, but the *application* of that ownership to control *third-party access* is the critical operational consideration for secure external sharing.

DThird-party access rightsCorrect

When sharing documents with internal and *external* parties, managing third-party access rights is MOST important because it directly controls who can view, modify, or share sensitive information outside the organizational perimeter. Properly defining and enforcing these rights is crucial for data security, compliance, and preventing unauthorized disclosure or data breaches, especially when collaborating with external entities.

Concept tested: Cloud collaboration security

Source: https://learn.microsoft.com/en-us/azure/active-directory/external-identities/what-is-b2b

Topics

#Cloud Security#Access Control#Data Sharing#Third-Party Risk

Community Discussion

No community discussion yet for this question.

Full CGEIT Practice