Courseiva
easyMultiple ChoiceObjective-mapped

CAS-004 Practice Question: Developing a new mobile app that will process…

A company is developing a new mobile app that will process users' biometric data for authentication. The legal team is concerned about compliance with the GDPR's data protection by design. Which of the following is the MOST appropriate control to implement?

⚠ Common exam trap

CompTIA CASP+ often tests the distinction between security controls (encryption, hashing, consent) and governance/compliance controls (DPIA), tricking candidates into picking a technical safeguard instead of the mandated privacy-by-design assessment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Conduct a Data Protection Impact Assessment (DPIA) before development.

Conducting a Data Protection Impact Assessment (DPIA) before development is the most appropriate control because GDPR Article 35 mandates a DPIA when processing biometric data is likely to result in high risk to individuals' rights and freedoms. This aligns with the principle of data protection by design (Article 25), requiring privacy considerations to be embedded into the development process from the outset, not added later.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Obtain explicit consent from users before data collection.

    Why it's wrong here

    Consent is required but does not fulfill the broader 'data protection by design' requirement.

  • Store biometric data in hashed form on the device.

    Why it's wrong here

    Hashing biometric data is a technical control but not the most appropriate for 'by design' principle.

  • Implement strong encryption for data in transit and at rest.

    Why it's wrong here

    Encryption is necessary but not sufficient; the DPIA should come first.

  • Conduct a Data Protection Impact Assessment (DPIA) before development.

    Why this is correct

    DPIA is mandated for high-risk processing and is a key part of data protection by design.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.