You must map controls and artifacts to specific regulatory and policy requirements, then justify the best evidence. The single most important thing: know the policy hierarchy order and which document type is mandatory versus advisory, since ordering and evidence-selection questions depend on it.
Start practicing
Governance, Risk, and Compliance — choose a session length
Free · No account required
Domain overview
Governance, Risk, and Compliance is 20% of SecurityX (CAS-005), covering policy hierarchy, risk frameworks, regulatory obligations, and audit evidence. Questions are scenario-based: you map controls to requirements, select metrics, and identify which artifacts prove compliance. Expect HIPAA, GDPR, and patch-management scenarios requiring you to choose the best evidence or ordering rather than recall definitions.
Exam objectives
Ordering the security policy hierarchy: policy, standards, baselines, procedures, and guidelines from highest to lowest authority.
Selecting audit evidence such as access control logs, RBAC matrices, and audit trails for ePHI under HIPAA.
Choosing patch metrics like mean time to remediate (MTTR) for critical vulnerabilities to gauge program speed.
Identifying GDPR data subject rights: access, erasure, portability, rectification, restriction, and objection.
Confusing standards with guidelines: standards are mandatory and specific, guidelines are discretionary recommendations, so hierarchy questions hinge on that distinction.
Treating GDPR data subject rights as optional best practices rather than enforceable obligations requiring demonstrable evidence.
Picking raw patch counts or deployment totals instead of time-based remediation metrics when asked how quickly critical patches are applied.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A security analyst is calculating the annualized loss expectancy (ALE) for a server. The single loss expectancy (SLE) is $5,000 and the annualized rate of occurrence (ARO) is 0.2. What is the ALE?
2A company wants to ensure that its data handling practices align with the principle of 'privacy by design'. Which of the following actions best supports this principle?
3A financial institution is required to comply with SOX. Which of the following is a primary focus of this regulation?
4An organization has identified a vulnerability in a legacy system that cannot be patched. The system is critical for operations, and the cost of mitigating the vulnerability exceeds the potential loss. Which risk treatment option is most appropriate?
5A security manager is evaluating two risk quantification approaches: Factor Analysis of Information Risk (FAIR) and a qualitative heat map. Which of the following is a key advantage of using FAIR over the qualitative heat map?
6During a vendor risk assessment, a company receives a SOC 2 Type II report from a cloud service provider. What does this report primarily attest to?
7An organization is implementing continuous compliance monitoring. Which of the following metrics would best indicate whether the organization is maintaining compliance with PCI DSS Requirement 10 (log management)?
8Which of the following is the correct order of the security policy hierarchy from highest to lowest?
9A security architect is designing a data classification scheme. Which of the following is the highest level of sensitivity that would typically require the most stringent controls?
10An organization is reviewing its third-party risk management process. Which of the following clauses should be included in contracts with critical vendors to ensure ongoing visibility into their security posture?
11A company is considering adopting the NIST Risk Management Framework (RMF). Which of the following steps is unique to NIST RMF compared to ISO 27005?
12A security team is measuring the effectiveness of its incident response process. Which of the following metrics would best indicate how quickly the team can contain an incident after it is detected?
13A small business is implementing a privacy impact assessment (PIA) for a new application that processes personal data of EU citizens. Which TWO of the following are required under GDPR?
14A security manager is selecting key risk indicators (KRIs) for the organization's risk management program. Which THREE of the following are examples of KRIs that can provide early warning of increasing risk?
15An organization is reviewing its supply chain risk management. Which TWO of the following are effective strategies to manage fourth-party risk?
16A financial institution is evaluating a cloud service provider for hosting customer data. During the due diligence process, which report would best help the institution assess the provider's control environment and compliance with SOC 2?
17An organization is implementing a data classification scheme. Which data type should be given the highest protection and is typically restricted to a very small number of individuals?
18A security analyst calculates the annualized loss expectancy (ALE) for a server. The single loss expectancy (SLE) is $50,000, and the annualized rate of occurrence (ARO) is 0.2. What is the ALE?
19Which risk treatment option involves reducing the likelihood or impact of a risk through controls?
20Which key performance indicator (KPI) is most useful for measuring the effectiveness of an incident response process?
21When conducting a vendor risk assessment, which contractual clause is most important for ensuring ongoing visibility into the vendor's security posture?
22An organization is implementing a privacy program based on privacy by design. Which principle requires that privacy controls be integrated into the system's default settings?
23A company is required to comply with PCI DSS. What is the primary purpose of conducting quarterly network vulnerability scans?
24Which document in a security policy hierarchy provides specific step-by-step instructions for performing a task?
25An organization discovers that a third-party vendor has a subcontractor that processes its data. The organization did not have a contract with the subcontractor. This is an example of which type of risk?
26Using the FAIR model, which of the following best describes the factor that represents the probable frequency of a threat acting on a vulnerability?
27An organization is developing a policy exception management process. Which three of the following are essential components of an effective exception process? (Choose three.)
28A security analyst is prioritizing remediation of vulnerabilities. Which three of the following factors should be considered when determining the risk level of a vulnerability? (Choose three.)
29A security analyst is performing a quantitative risk assessment for a server that processes payment card data. The server has an asset value of $50,000. Based on historical data, the exposure factor (EF) for a ransomware attack is 80%, and the annualized rate of occurrence (ARO) is 0.5. What is the annualized loss expectancy (ALE)?
30A multinational corporation that processes personal data of EU residents is required to appoint a Data Protection Officer (DPO) and implement data protection impact assessments. Which regulation primarily drives these requirements?
31An organization is adopting the NIST Risk Management Framework (RMF). During which step would the security team select and implement security controls, and how does this map to the organization's governance structure?
32A company's security policy requires all sensitive data to be encrypted at rest. However, a business unit requests an exception to store certain data unencrypted due to performance constraints. Which document should govern the exception process?
33During a vendor risk assessment, a security analyst reviews a SOC 2 Type II report from a cloud provider. What is the primary value of this report?
34A financial institution is implementing a privacy program based on GDPR principles. Which of the following best describes the concept of 'privacy by design'?
35Which security metric measures the average time it takes to detect a security incident after it has occurred?
36A security manager is reviewing a set of documents: an organizational security policy, a standard for encryption, a guideline for remote access, and a procedure for incident response. Which document is at the highest level in the policy hierarchy?
37An organization has implemented a risk treatment plan that includes purchasing cyber insurance for potential data breach costs. Which risk treatment option does this represent?
38Under the GDPR, which of the following is a data subject right?
39A security team is evaluating the effectiveness of their patching program. Which metric would best indicate how quickly the organization applies critical patches?
40A company is conducting a third-party risk assessment for a SaaS provider. The provider has provided a SOC 2 Type II report, penetration test results, and a completed security questionnaire. Which of these provides the most independent and comprehensive view of the provider's control environment over time?
41A security architect is designing a data lifecycle management program. Which TWO of the following are phases of the data lifecycle? (Select TWO.)
42A company is implementing continuous compliance monitoring for PCI DSS. Which TWO activities are most appropriate for this approach? (Select TWO.)
43A company processes personal data of EU citizens and wants to implement privacy by design. Which of the following is the BEST first step in this process?
44An organization is evaluating a third-party vendor that will have access to its customer database. The vendor provides a SOC 2 Type II report dated six months ago. Which of the following is the BEST next step?
45An organization's security policy defines that all sensitive data must be encrypted. However, a business unit has a legacy application that cannot support encryption without a major rewrite. The risk owner decides to accept the risk. This is an example of which risk treatment strategy?
46Which of the following is a key difference between a security guideline and a security procedure?
47A security manager is reviewing Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs) for the security program. Which of the following is an example of a KRI?
48A company wants to implement continuous compliance monitoring. Which of the following approaches BEST supports this goal?
49Which risk management framework is specifically designed for U.S. federal agencies and includes a six-step process: Categorize, Select, Implement, Assess, Authorize, and Monitor?
50A healthcare organization subject to HIPAA must ensure that patients can access their medical records. This requirement is an example of which data subject right under privacy regulations?
51An organization is using the FAIR framework to quantify risk. The analyst estimates the probable loss event frequency (LEF) as 4 per year and the probable loss magnitude (LM) as $25,000 per event. What is the annualized loss expectancy (ALE) under FAIR?
52During a policy gap analysis, it is discovered that the organization has a policy stating that sensitive data must be encrypted, but there are no procedures for implementing encryption on mobile devices. This is an example of a gap between:
53An organization is implementing a vendor risk management program and is reviewing a contract that includes a right-to-audit clause. Which THREE of the following are common elements that should be verified during such an audit? (Select THREE.)
54A compliance officer is preparing for an audit and needs to collect evidence. Which TWO of the following are considered acceptable forms of audit evidence? (Select TWO.)
55A security analyst is calculating the annualized loss expectancy (ALE) for a server that has an asset value of $50,000 and an exposure factor (EF) of 0.2. The annualized rate of occurrence (ARO) is estimated at 4. What is the ALE?
56A company is evaluating a new cloud service provider. The provider offers a SOC 2 Type II report, a third-party penetration test summary, and a completed security questionnaire. However, the company's procurement team discovers that the provider uses a subcontractor for data storage. Which of the following is the BEST next step for the security team?
57An organization is implementing a privacy program to comply with GDPR. Which of the following BEST describes the concept of 'privacy by design' as it applies to a new customer relationship management (CRM) system?
58A financial institution must comply with the Sarbanes-Oxley Act (SOX). Which of the following is a primary focus of SOX compliance?
59After a risk assessment, a company identifies that the residual risk for a critical application is higher than the risk appetite. The risk owner proposes implementing additional controls to reduce the risk further. Which risk treatment option does this represent?
60A healthcare organization is required to comply with HIPAA. During an audit, the auditor requests evidence of access controls for electronic protected health information (ePHI). Which of the following would be the BEST evidence to provide?
61An organization wants to implement continuous compliance monitoring for PCI DSS. Which of the following tools would be MOST effective for this purpose?
62A multinational corporation is implementing a data classification scheme. Which of the following data types should be classified as 'restricted'?
63During a vendor risk assessment, a third-party vendor refuses to provide a SOC 2 report but offers a completed security questionnaire. The vendor handles sensitive customer data. Which of the following is the BEST course of action?
64A security manager is implementing a policy exception management process. Which TWO of the following are essential components of an effective exception management process?
65A compliance officer is preparing for a GDPR audit. Which THREE of the following are key data subject rights under GDPR that the organization must be able to demonstrate?
66A security analyst is calculating the annualized loss expectancy (ALE) for a server that processes credit card data. The server has a $100,000 asset value, and the exposure factor for a security breach is 0.4. Historical data shows that such breaches occur twice per year. What is the ALE?
67An organization is implementing a risk management framework and wants to align with a standard that emphasizes a continuous, iterative process for identifying, assessing, and responding to risk. Which framework is most appropriate?
68A company is conducting a vendor risk assessment and receives a SOC 2 Type II report from a cloud service provider. The report covers a 12-month period and includes an opinion on the effectiveness of controls. Which of the following is the primary benefit of using this report?
69Which of the following risk treatment options involves transferring the financial impact of a risk to a third party, such as through insurance?
70An organization is implementing a privacy by design approach for a new customer-facing application. Which of the following actions best exemplifies this principle?
71Under GDPR, which of the following is a data subject right that allows an individual to request that their personal data be erased?
72A security analyst is reviewing metrics for the security program. Which metric best measures the effectiveness of incident response processes?
73Which of the following is a key difference between compliance and security?
74A company wants to ensure that a third-party vendor allows them to perform an audit of the vendor's security controls. Which clause should be included in the contract?
75An organization is using the FAIR model to quantify risk. Which of the following is a primary component of the FAIR taxonomy?
76A security officer is reviewing continuous compliance monitoring tools. Which TWO of the following are primary benefits of implementing such tools? (Select TWO.)
77A security analyst calculates the annual loss expectancy (ALE) for a critical asset. The single loss expectancy (SLE) is $50,000, and the annualized rate of occurrence (ARO) is 0.2. What is the annual loss expectancy?
78A security architect is designing a data classification scheme aligned with a new privacy regulation. Which THREE of the following are common data classification levels used in enterprise environments? (Select THREE.)
79An organization's security team is reviewing security metrics to present to the board. Which THREE of the following are commonly used Key Performance Indicators (KPIs) for a security program? (Select THREE.)
80During a compliance audit for PCI DSS, the auditor identifies that cardholder data is stored beyond the required retention period. The organization wants to implement proper data lifecycle management. Which THREE of the following should the organization include in its data retention policy? (Select THREE.)
81A risk manager is applying the FAIR model to quantify a risk. Which TWO of the following are primary components used in FAIR analysis? (Select TWO.)
82A multinational financial services firm is preparing to adopt a new enterprise risk management approach. The CISO wants a quantitative method that expresses risk in monetary terms to prioritize investments. Which of the following should the CISO implement?
83A healthcare organization is implementing a new telehealth platform that stores electronic protected health information (ePHI). The security team must ensure compliance with the HIPAA Security Rule. Which of the following is a required implementation specification for access control under the HIPAA Security Rule?
84A multinational manufacturing firm is expanding into the European Union and must demonstrate accountability for personal data processing under GDPR. The Chief Privacy Officer asks the security team to implement a mechanism that proves the organization's compliance posture to supervisory authorities without requiring prior authorization from them. Which of the following should the team implement?
85A multinational retailer is expanding into the European Union and must transfer employee payroll data from its EU subsidiary to its US-based HR platform. Legal counsel recommends relying on the EU-US Data Privacy Framework rather than implementing Standard Contractual Clauses. Which action must the retailer take FIRST to rely on this transfer mechanism?
86A financial services company is conducting a risk assessment for a new online banking platform. The risk team must prioritize identified risks. Which TWO of the following factors are most critical in determining the priority for risk treatment? (Choose two.)
87A security manager is developing a third-party risk management program. The organization wants to ensure that vendors handling sensitive data are subject to appropriate oversight. Which two of the following are the most effective methods for ongoing monitoring of a vendor's security posture? (Choose two.)
88A defense contractor must comply with DFARS clause 252.204-7012 and achieve a passing score in its NIST SP 800-171 self-assessment before a contract award. The security lead discovers that several controls in the CUI environment are only partially implemented. Which action should the security lead take to meet the assessment requirement?
89A multinational financial services firm is subject to GDPR and must transfer personal data from its EU offices to a data analytics vendor in the United States. The vendor is not certified under the EU-U.S. Data Privacy Framework. Which mechanism should the firm use to lawfully transfer the data while meeting GDPR Chapter V requirements?
90A multinational financial services firm is expanding operations into the European Union. The legal team asks the security architect to ensure the new customer onboarding portal complies with the General Data Protection Regulation (GDPR). Which of the following should the security architect implement FIRST to align with GDPR's data protection principles?
91A security analyst is reviewing the organization's risk register and notices a risk that has been assigned a risk score of 15 on a scale of 1 to 25. The risk owner has decided to purchase cyber insurance to transfer the financial impact of the risk. Which risk treatment strategy is being applied?
92A multinational financial services firm is expanding operations into a new jurisdiction. The legal team has identified that the new country requires all personal data of its citizens to be stored on servers physically located within its borders. The security architect must recommend an approach that satisfies this requirement while maintaining the firm's global security standards. Which of the following should the architect recommend?
93A multinational financial services firm is aligning its enterprise risk management program with the NIST Risk Management Framework (RMF). The Chief Risk Officer wants to ensure that risk response decisions are formally authorized before changes are made to production systems. Which RMF step is responsible for providing that authorization?
94A financial services firm operates in several countries and must demonstrate that its security controls are effective and independently validated for regulators and enterprise customers. Executives want a report that auditors can rely on regarding the design and operating effectiveness of controls over a period of time. Which document should the security team provide?
95A CISO is presenting a risk register to the board. The register shows a ransomware risk with a single loss expectancy of $2,000,000 and an annualized rate of occurrence of 0.25. The board asks for the expected annual financial exposure. What is the annualized loss expectancy (ALE) for this risk?
96A security manager at a defense contractor is reviewing the organization's risk register. A critical vulnerability in a widely used open-source library has been identified. The vendor has not released a patch, and the library is embedded in a custom application that cannot be easily replaced. The manager decides to implement a virtual patching solution at the network perimeter. Which risk treatment strategy does this represent?
97A security manager is reviewing the organization's risk register and notes that a critical vulnerability in a legacy application has been accepted for two years. The business owner argues that the cost of remediation exceeds the potential loss. The security manager must present an alternative that aligns with the organization's risk appetite while addressing the residual risk. Which of the following is the BEST recommendation?
98A security architect is designing a new system that will process personal data of European Union citizens. The architect must ensure that data protection principles are embedded into the design. Which of the following best exemplifies the principle of data minimization under the General Data Protection Regulation (GDPR)?
99A software company is preparing to release a new payment feature that processes cardholder data. The security architect must ensure the feature design meets PCI DSS requirements for protecting stored data and for securing transmission over open, public networks. Which two design choices satisfy these requirements? (Choose two.)
100A security governance committee is reviewing the organization's risk register after a merger. The committee wants to apply risk treatment strategies that transfer or share risk with another party rather than reducing it internally. Which two actions represent risk transference? (Choose two.)
101A multinational retailer must comply with PCI DSS v4.0 for its cardholder data environment. The security manager is asked to define the scope of the CDE. Which of the following best describes the first step in scoping the CDE according to PCI DSS?
102A security architect is designing a new system that processes sensitive customer data. The organization must comply with multiple regulations, including GDPR and PCI DSS. The architect needs to ensure that data protection controls are integrated from the outset. Which approach best aligns with the principle of privacy by design?
103A security analyst is reviewing the organization's incident response plan. The plan includes a section on communication with external parties. Which of the following best describes the primary purpose of a communication plan during a security incident?
104A security analyst is reviewing the organization's incident response plan and notices that it lacks a formal process for communicating with external stakeholders during a breach. Which of the following should the analyst recommend to address this gap?
105A software company is pursuing ISO/IEC 27001 certification. The ISMS scope covers its cloud-hosted product and corporate IT. An auditor requests evidence that management reviews the ISMS at planned intervals. Which artifact should the security manager provide?
106A retail company is building a new mobile application that will collect customer location data. The legal team asks the security manager to ensure the design follows privacy by design principles from the earliest stages. Which action best demonstrates privacy by design in this scenario?
107A multinational retailer operates under GDPR for its EU customers and must demonstrate accountability to supervisory authorities. The Chief Privacy Officer wants a mechanism that documents, on an ongoing basis, which processing activities occur, what data categories are involved, and how long each is retained. Which GDPR instrument should the privacy team maintain to satisfy this requirement?
108A newly hired Chief Information Security Officer is establishing a governance structure and wants to define who is accountable for accepting residual risk that exceeds the organization's stated risk appetite. According to common governance practice, which role holds that accountability?
109A financial services firm is undergoing a SOC 2 Type II examination. The auditor asks the CISO to demonstrate that the organization continuously monitors whether the controls described in the system description operated effectively throughout the review period. Which activity should the CISO present as the primary evidence supporting this requirement?
110A multinational financial services firm must comply with the General Data Protection Regulation (GDPR). The Chief Information Security Officer (CISO) asks the security team to implement a mechanism that allows data subjects to request and receive a copy of their personal data in a structured, commonly used, and machine-readable format. Which of the following technical controls BEST addresses this requirement?
111A financial institution is adopting a risk management framework based on NIST SP 800-37. The CISO wants to ensure that risk responses are integrated into the enterprise architecture. Which of the following activities best supports this integration during the Risk Response step?
112A security architect is designing a new cloud-based system that must comply with the Payment Card Industry Data Security Standard (PCI DSS). The architect needs to ensure that cardholder data is protected both at rest and in transit. Which TWO of the following controls are required by PCI DSS to protect cardholder data in this scenario? (Choose two.)
113A financial services firm's third-party risk team is onboarding a new SaaS payroll provider. The provider refuses to share its internal audit reports but will allow the firm to send its own assessor on-site to inspect the provider's controls. Which risk assessment method should the firm use to obtain assurance in this situation?
114A financial services firm is selecting a cloud provider to host regulated customer data. The vendor risk team wants contractual language that lets the firm independently verify the provider's security posture over time rather than relying only on the provider's self-reported questionnaires. (Choose two.)
115A mid-sized retailer wants to demonstrate to customers that its payment card handling meets industry security requirements. The company does not store, process, or transmit cardholder data; it only uses a validated third-party payment page that handles all card data. Which PCI DSS self-assessment questionnaire is most appropriate?
116A company's security team is reviewing its risk register. A risk related to an outdated internal application has been assigned an owner, but the owner has taken no action for two quarters. The Chief Information Security Officer wants to ensure the risk is tracked and escalated appropriately. Which action should the security team take first?
117A security architect is designing a new cloud-native application for a healthcare provider. The application will process protected health information (PHI) and must comply with HIPAA. The architect must ensure that all data at rest and in transit is encrypted, and that access is logged and auditable. Which of the following controls BEST meets the requirement for auditing access to PHI?
118A global pharmaceutical company must comply with the EU GDPR for clinical trial data. The Data Protection Officer is reviewing the data protection impact assessment (DPIA) process. Which of the following situations requires a DPIA under GDPR?
119A multinational retailer must transfer employee personal data from its European Union subsidiary to a processing center in a country without an adequacy decision. Legal counsel wants a transfer mechanism that imposes enforceable data protection obligations on the importer and includes a documented transfer impact assessment. Which mechanism best matches these requirements?
120A security analyst is reviewing the organization's third-party risk management program. The organization recently onboarded a new SaaS provider that will process sensitive customer data. The provider has provided a SOC 2 Type II report, but the analyst notices that the report is over 18 months old and covers a different service than the one being used. Which of the following should the analyst recommend?
121A hospital's security manager is aligning internal documents after a policy refresh. The board approved a statement that defines the organization's overall security intent and assigns responsibility to executive leadership, but it deliberately avoids naming specific products or technical settings. Which document type has the board approved?
122A security governance team is defining the scope of its enterprise risk management (ERM) program. Which TWO of the following activities are core components of ERM as described in frameworks such as ISO 31000 and COSO ERM? (Choose two.)
123A multinational retailer must demonstrate compliance with the EU General Data Protection Regulation while also honoring local data-residency laws in a country where it operates. Legal counsel advises that a single global retention schedule cannot satisfy both regimes. Which governance artifact should the security manager produce to reconcile these competing obligations?
124A hospital is preparing for a compliance audit and must demonstrate that it has implemented administrative safeguards required by the HIPAA Security Rule. Which activity best provides this evidence?
125A defense contractor is required to comply with NIST SP 800-171 for protecting controlled unclassified information (CUI). The security team is implementing the required security requirements. Which of the following best describes the purpose of the System Security Plan (SSP) in this context?
126A software company is acquiring a smaller competitor that maintains its own identity provider, endpoint management platform, and network infrastructure. The integration team must fold the acquired company's users and devices into the parent's environment without disrupting business operations. Which activity should occur first to establish governance over the combined environment?
127A financial services firm operates a trading platform in which a 15-minute outage causes direct contractual penalties. The CISO must present a recommendation to the board on how to treat the residual risk of a ransomware event that could halt trading. The firm already has immutable offline backups and a tested recovery runbook. Which risk treatment action is MOST appropriate to recommend?
128A software company suffers a breach exposing customer records. Legal counsel determines the incident meets the regulatory threshold for notification. The incident response lead must decide which external parties receive notice and within what timeframe, balancing regulatory duties against contractual obligations. Which action best satisfies the organization's notification obligations?
129A newly hired CISO is reviewing the organization's risk register and finds that a legacy payment application carries a high inherent risk rating, but after accounting for the web application firewall, tokenization, and quarterly penetration testing already in place, the rating drops substantially. Which risk concept explains the difference between these two ratings?
130A security manager is developing a third-party risk management program. Which two of the following are considered best practices for assessing and managing vendor risk throughout the vendor lifecycle? (Choose two.)
131A regional bank is preparing for its annual regulatory examination and must demonstrate that its third-party risk management program is mature. The examiner asks which practices provide continuous, rather than point-in-time, oversight of critical vendors. (Choose two.)
132A security compliance officer is mapping the organization's controls to the NIST Cybersecurity Framework (CSF) 2.0. The officer needs to ensure that the organization's governance and risk management processes are adequately covered. Which CSF 2.0 function primarily addresses the development and implementation of cybersecurity policies, procedures, and risk management strategies?
133A security governance team is drafting a new data handling standard for a research subsidiary that processes both regulated personal data and proprietary intellectual property. The team must select controls that directly support data classification and labeling objectives. Which two of the following controls best fulfill this requirement? (Choose two.)
134An organization's risk register shows a critical risk with a very high annualized loss expectancy. Executive leadership decides the potential loss is unacceptable but concludes that no cost-effective control exists and that the activity generating the risk is essential to revenue. They formally document the decision, obtain board sign-off, and set a review date. Which risk treatment has leadership applied?
135An organization's security team has drafted a new acceptable use policy that defines how employees may handle company devices, email, and internet access. Before the policy is published and enforced, which action is most important to complete?
136An organization must satisfy a regulatory requirement to demonstrate that security controls operate effectively over time, not just that they are documented. The compliance manager proposes collecting screenshots of control configurations taken on the last day of each quarter. Which approach should the security manager recommend instead to provide stronger, continuous assurance?
137A cloud provider's security team is preparing for a regulatory examination and must demonstrate that a specific production system meets a documented set of security requirements. The regulator wants evidence of who approved the requirements, what was tested, when testing occurred, and what exceptions were granted. Which activity produces this evidence MOST directly?
138A security manager is updating the organization's risk register. A new risk has been identified: a critical vendor may fail to provide timely security patches, potentially leading to a breach. The manager decides to purchase cyber insurance to cover potential financial losses from such a breach. Which risk treatment strategy does this represent?
139A security analyst is reviewing the organization's business continuity plan (BCP). The plan specifies a recovery time objective (RTO) of 4 hours for a critical e-commerce application. Which of the following BEST describes the meaning of this RTO?
140A security team is conducting a risk assessment for a new cloud-based customer relationship management (CRM) system. The team must identify and evaluate risks related to data breaches, compliance, and availability. Which TWO of the following factors are MOST important to consider when determining the likelihood of a data breach in this cloud environment? (Choose two.)
141A multinational retailer must comply with the EU General Data Protection Regulation for its European customers and with several U.S. state privacy laws for its American customers. The privacy team wants a single internal control framework that satisfies the strictest common denominator across all jurisdictions. Which approach should the privacy team take?
142A defense contractor must demonstrate compliance with NIST SP 800-171 for controlled unclassified information stored in a contractor-owned system. The compliance lead is preparing evidence for an upcoming assessment and wants to avoid the most common cause of failed assessments. Which activity best prevents assessment failure?
143A software company wants to demonstrate to prospective enterprise customers that its cloud-hosted product meets recognized security and availability controls without exposing its internal procedures. The security manager must select an attestation that an independent auditor issues after testing the design and operating effectiveness of controls over a period. Which report type should the manager obtain?
You must map controls and artifacts to specific regulatory and policy requirements, then justify the best evidence. The single most important thing: know the policy hierarchy order and which document type is mandatory versus advisory, since ordering and evidence-selection questions depend on it.
The Courseiva CAS-005 question bank contains 143 questions in the Governance, Risk, and Compliance domain, covering the 20% of the exam attributed to this domain in the official CompTIA blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Governance, Risk, and Compliance domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included