nerdexam
Isaca

CRISC · Question #430

An organization uses a web application hosted by a cloud service that is populated by data sent to the vendor via email on a monthly basis. Which of the following should be the FIRST consideration…

The correct answer is C. Whether the data has been appropriately classified. The initial consideration when analyzing risk for an application that processes data is to determine the data's classification, as this dictates the necessary security controls and compliance requirements.

Submitted by sofia.br· Apr 18, 2026IT Risk Assessment

Question

An organization uses a web application hosted by a cloud service that is populated by data sent to the vendor via email on a monthly basis. Which of the following should be the FIRST consideration when analyzing the risk associated with the application?

Options

  • AWhether the service provider's data center is located in the same country
  • BWhether the data sent by email has been encrypted
  • CWhether the data has been appropriately classified
  • DWhether the service provider contract allows right of onsite audit

How the community answered

(53 responses)
  • A
    15% (8)
  • B
    4% (2)
  • C
    74% (39)
  • D
    8% (4)

Why each option

The initial consideration when analyzing risk for an application that processes data is to determine the data's classification, as this dictates the necessary security controls and compliance requirements.

AWhether the service provider's data center is located in the same country

While data residency is important for compliance, the necessity of having the data center in the same country is directly dependent on the data's classification and associated regulatory requirements.

BWhether the data sent by email has been encrypted

Whether the data sent by email has been encrypted is a control consideration, but the necessity and strength of that encryption are determined by the data's classification.

CWhether the data has been appropriately classifiedCorrect

The first consideration should always be data classification because it determines the sensitivity, regulatory requirements, and the appropriate level of protection needed for the data. Knowing the data classification guides all subsequent risk analysis steps, including encryption requirements, jurisdictional concerns, and audit rights, by establishing the baseline criticality.

DWhether the service provider contract allows right of onsite audit

The service provider contract's allowance for a right of onsite audit is a critical oversight control, but its importance and focus are determined by the sensitivity and classification of the data being processed.

Concept tested: Data classification as first step in risk analysis

Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/data-classification-labeling

Topics

#Data Classification#Risk Analysis#Third-Party Risk#Cloud Security

Community Discussion

No community discussion yet for this question.

Full CRISC Practice