Q: 17
An organization's IT team has proposed the adoption of cloud computing as a cost-saving measure
for the business. Which of the following should be of GREATEST concern to the risk practitioner?
Options
Discussion
A or D but leaning A here. Without proper due diligence on the cloud vendor, you can't be sure about their security or compliance posture, which could expose the org to way bigger risks than unclear architecture roles. Similar question showed up in some practice sets.
Had something like this in a mock and picked D, not sure if that's right though.
I see why D might jump out since unclear architecture roles can cause confusion and gaps, especially during a cloud move. D
Option D makes sense to me because if architecture responsibilities aren't defined, critical controls could get missed or overlap. I saw a similar scenario flagged on a practice set. I might be off though if due diligence is totally skipped.
Probably A. . If no due diligence is done, you have no visibility into service or risk at all.
Be respectful. No spam.