CAS-004 Governance, Risk, and Compliance Practice Question
A cloud provider's security team is preparing for a regulatory examination and must demonstrate that a specific production system meets a documented set of security requirements. The regulator wants evidence of who approved the requirements, what was tested, when testing occurred, and what exceptions were granted. Which activity produces this evidence MOST directly?
⚠ Common exam trap
The trap here is treating a technical scan or self-assessment as equivalent to a formal authorization decision with documented approvals and exceptions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Performing a formal security assessment or authorization review with documented approval and exception records
A formal security assessment and authorization review generates the full chain of evidence the regulator wants: approved requirements, the authorizing official's decision, assessment scope and methods, testing dates, and documented exceptions with risk acceptance. Scanning, self-assessment, and configuration baselines each contribute supporting data but none produce the approval, scope, timing, and exception record together in a traceable form.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Running an unauthenticated external vulnerability scan against the production system
Why it's wrong here
A vulnerability scan identifies technical weaknesses on a system but does not document approved requirements, approval authorities, or granted exceptions. It produces findings, not a traceable record of requirement approval and testing decisions. The regulator is asking for governance evidence linking requirements to approvers and exceptions, which scanning alone cannot supply, even if it contributes technical input.
- ✗
Publishing the system's configuration baseline to the internal configuration management database
Why it's wrong here
A configuration management database records the system's approved baseline settings and relationships, which supports change control and inventory accuracy. However, it does not capture requirement approval, assessment scope, testing dates, or exception decisions. Publishing a baseline is a supporting control, not the authorization evidence the regulator requested, so it would leave the core questions unanswered.
- ✓
Performing a formal security assessment or authorization review with documented approval and exception records
Why this is correct
A formal assessment and authorization process, such as an Authority to Operate review, produces exactly the artifacts described: approved security requirements, the assessment scope and methods, testing dates, findings, and documented exceptions with risk acceptance. It establishes accountability by naming the authorizing official, which is why it directly satisfies a regulator asking for traceable governance evidence.
- ✗
Conducting an internal control self-assessment questionnaire with system owners
Why it's wrong here
A self-assessment captures the system owner's opinion about control status but relies on the same team being assessed, so it lacks independent verification. It also does not inherently record who approved the requirements or what exceptions were formally granted. While useful for gap identification, it would not satisfy a regulator seeking documented approval, testing scope, timing, and exception records.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.