20+ practice questions focused on Governance, Risk, and Compliance — one of the most tested topics on the CompTIA SecurityX (CAS-005) exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Governance, Risk, and Compliance PracticeA healthcare organization must comply with HIPAA. Which of the following is a key requirement for protecting electronic protected health information (ePHI)?
Explanation: HIPAA's Security Rule explicitly requires covered entities to implement encryption of ePHI both at rest and in transit as an addressable implementation specification, and it is widely considered a key safeguard for protecting ePHI. Encryption ensures that even if data is intercepted or a storage medium is compromised, the information remains unreadable without the decryption keys. This directly addresses the confidentiality and integrity requirements of the HIPAA Security Rule.
A security manager is selecting metrics to present to the board. Which two of the following are key risk indicators (KRIs) that would be most relevant for executive oversight? (Choose two.)
Explanation: Option C is correct because the number of security incidents per quarter is a lagging key risk indicator that directly quantifies realized risk exposure, giving the board a trendable measure of how often the organization's risk is materializing. Option E is correct because the percentage of systems with critical vulnerabilities is a leading key risk indicator that reflects the current exploitable attack surface and residual risk posture, which executives need to judge whether risk is within tolerance. These two metrics combine a backward-looking outcome (incidents) with a forward-looking exposure measure (unpatched critical systems), which is exactly what board-level risk oversight requires. Option A (average time to patch) and Option B (MTTD) are operational performance metrics for the security team rather than strategic risk indicators. Option D (training completions) is a compliance/awareness activity metric and does not by itself express risk magnitude or likelihood.
A security manager is developing key risk indicators (KRIs) for the organization's cybersecurity program. Which THREE of the following are examples of KRIs? (Select THREE.)
Explanation: Option A is correct because the number of failed login attempts per day is a leading indicator that measures the frequency of a potential attack activity, making it a valid KRI. Option D is correct because the number of unpatched critical vulnerabilities is a measurable exposure metric that indicates the organization's current risk posture and is commonly used as a KRI. Option E is correct because the percentage of users without multifactor authentication quantifies a control gap that directly increases account compromise risk, fitting the definition of a KRI. Option B is not a KRI because the total number of security incidents is a lagging outcome metric (a KPI), reflecting events that already occurred rather than an indicator of future risk. Option C is not a KRI because mean time to detect (MTTD) is a performance/efficiency metric of the detection process, not a direct measure of risk exposure or likelihood.
A security analyst is calculating the annualized loss expectancy (ALE) for a server that has an asset value of $100,000, an exposure factor (EF) of 0.5, and an annualized rate of occurrence (ARO) of 2. What is the ALE?
Explanation: The correct answer is $100,000. The Annualized Loss Expectancy (ALE) is calculated as Single Loss Expectancy (SLE) multiplied by Annualized Rate of Occurrence (ARO). First, compute SLE = Asset Value × Exposure Factor = $100,000 × 0.5 = $50,000. Then ALE = SLE × ARO = $50,000 × 2 = $100,000. This matches option A.
An organization is required to comply with PCI DSS. Which of the following is a mandatory requirement for protecting cardholder data?
Explanation: PCI DSS requires that cardholder data be encrypted when stored (at rest) as a mandatory requirement to protect it from unauthorized access. While other practices like network segmentation and MFA are important, encryption of stored cardholder data is explicitly required by PCI DSS Requirement 3.
+15 more Governance, Risk, and Compliance questions available
Practice all Governance, Risk, and Compliance questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Governance, Risk, and Compliance. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Governance, Risk, and Compliance questions on the CAS-005 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Governance, Risk, and Compliance is tested as part of the CompTIA SecurityX (CAS-005) blueprint. Practicing with targeted Governance, Risk, and Compliance questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free CAS-005 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Governance, Risk, and Compliance is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Governance, Risk, and Compliance practice session with instant scoring and detailed explanations.
Start Governance, Risk, and Compliance Practice →