nerdexam
Isaca

CRISC · Question #401

It was discovered that a service provider's administrator was accessing sensitive information without the approval of the customer in an Infrastructure as a Service (laaS) model. Which of the followin

The correct answer is D. Contractual requirements. To prevent future unauthorized access by a service provider's administrator in an IaaS model, the best protection involves establishing clear contractual requirements.

Submitted by chen.hong· Apr 18, 2026Governance

Question

It was discovered that a service provider's administrator was accessing sensitive information without the approval of the customer in an Infrastructure as a Service (laaS) model. Which of the following would BEST protect against a future recurrence?

Options

  • AData encryption
  • BIntrusion prevention system (IPS)
  • CTwo-factor authentication
  • DContractual requirements

How the community answered

(39 responses)
  • A
    8% (3)
  • B
    23% (9)
  • C
    13% (5)
  • D
    56% (22)

Why each option

To prevent future unauthorized access by a service provider's administrator in an IaaS model, the best protection involves establishing clear contractual requirements.

AData encryption

Data encryption protects data confidentiality but does not prevent an authorized administrator (who might possess decryption keys or privileged access) from performing unauthorized actions.

BIntrusion prevention system (IPS)

An IPS might detect some malicious network activity, but it wouldn't prevent an administrator with legitimate system access credentials from misusing their authorized privileges.

CTwo-factor authentication

Two-factor authentication protects against unauthorized access to accounts, but if the administrator *is* authorized to the system, 2FA won't prevent them from misusing that access.

DContractual requirementsCorrect

Contractual requirements explicitly define the scope of access, responsibilities, and accountability for service providers, establishing a legal framework to prevent and address unauthorized actions by their personnel. These agreements can include clauses for auditing, penalties for breaches, and data handling protocols, providing a strong preventative measure.

Concept tested: Cloud provider risk mitigation and governance

Topics

#Third-party risk#Cloud security#Contractual agreements#Vendor management

Community Discussion

No community discussion yet for this question.

Full CRISC Practice