正解:D
When dealing with a provider in another country, the most important consideration is the ability to enforce contractual obligations (D). CISM highlights jurisdictional risk, including differences in laws, regulations, and legal enforcement mechanisms. Logical separation (A), SLAs (B), and resiliency (C) are important but depend on enforceable contracts to be meaningful. Without enforceability, the organization may lack effective recourse in the event of security failures or breaches.
References: ISACA CISM Review Manual (Governance-legal, regulatory, and third-party risk); CISM Exam Content Outline (Domain 2).