nerdexam
Isaca

CRISC · Question #35

A global company s business continuity plan (BCP) requires the transfer of its customer information....event of a disaster. Which of the following should be the MOST important risk consideration?

The correct answer is B. The cloud computing environment is shared with another company. When transferring customer information during a disaster, the MOST important risk consideration is whether the cloud computing environment is shared, as this introduces potential data isolation and security concerns.

Submitted by noor.lb· Apr 18, 2026IT Risk Assessment

Question

A global company s business continuity plan (BCP) requires the transfer of its customer information....event of a disaster. Which of the following should be the MOST important risk consideration?

Options

  • AThe difference In the management practices between each company
  • BThe cloud computing environment is shared with another company
  • CThe lack of a service level agreement (SLA) in the vendor contract
  • DThe organizational culture differences between each country

How the community answered

(16 responses)
  • A
    13% (2)
  • B
    75% (12)
  • C
    6% (1)
  • D
    6% (1)

Why each option

When transferring customer information during a disaster, the MOST important risk consideration is whether the cloud computing environment is shared, as this introduces potential data isolation and security concerns.

AThe difference In the management practices between each company

Differences in management practices are important for operational efficiency but are not the primary risk for the security and integrity of customer data during a disaster transfer itself.

BThe cloud computing environment is shared with another companyCorrect

A shared cloud computing environment introduces significant risks, particularly for sensitive customer data during a disaster recovery scenario. There's an increased potential for data commingling, insecure segmentation, or unauthorized access from other tenants if proper isolation mechanisms are not rigorously implemented and tested, directly impacting data confidentiality and integrity.

CThe lack of a service level agreement (SLA) in the vendor contract

Lack of an SLA is a contractual and operational risk, impacting service availability and performance guarantees, but it is not the most direct security risk to data confidentiality and integrity during a transfer, which is heightened by a shared environment.

DThe organizational culture differences between each country

Organizational culture differences can affect collaboration but are not the primary technical or security risk to customer data during a transfer in the event of a disaster.

Concept tested: Shared cloud environment data risk

Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/shared-responsibility

Topics

#Business Continuity Planning#Cloud Security#Data Protection#Third-Party Risk

Community Discussion

No community discussion yet for this question.

Full CRISC Practice