CAS-004 Governance, Risk, and Compliance Practice Question
A company is implementing continuous compliance monitoring for PCI DSS. Which TWO activities are most appropriate for this approach? (Select TWO.)
⚠ Common exam trap
CAS-005 often tests the distinction between continuous and periodic activities. Candidates may select quarterly scanning or annual audits because they are required by PCI DSS, but they are not continuous monitoring.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Automated daily file integrity monitoring on critical systems
Option B is correct because continuous compliance monitoring relies on automated, recurring controls such as daily file integrity monitoring (FIM) on critical systems, which detects unauthorized changes to system files in near real time and supports PCI DSS Requirement 11.5. Option E is correct because real-time monitoring of firewall and IDS logs provides continuous visibility into security events and supports PCI DSS Requirements 10 and 11.4, enabling prompt detection and response rather than point-in-time checks. Option A is not appropriate because monthly manual log review is periodic and labor-intensive, not continuous or automated. Option C is not appropriate because an annual QSA on-site audit is a point-in-time assessment, not continuous monitoring. Option D is not appropriate because quarterly vulnerability scanning, while required by PCI DSS, is periodic rather than continuous monitoring.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Manual review of access logs every month
Why it's wrong here
Monthly manual log review is periodic and human-driven, so it cannot deliver continuous, automated compliance evidence. It is tempting because log review is a genuine PCI DSS control, and would be correct where the requirement is retrospective audit sampling rather than ongoing monitoring.
- ✓
Automated daily file integrity monitoring on critical systems
Why this is correct
Automated daily file integrity monitoring directly satisfies PCI DSS continuous monitoring by detecting unauthorised changes to critical system files between point-in-time assessments. Unlike periodic manual reviews, it provides the ongoing, evidence-generating oversight the stem demands, flagging tampering or drift promptly so remediation occurs before the next audit cycle.
- ✗
Annual on-site audit by a Qualified Security Assessor (QSA)
Why it's wrong here
An annual QSA on-site assessment is a point-in-time audit, not continuous monitoring, so it produces no ongoing telemetry between assessments. It is tempting because QSA validation is central to PCI DSS certification, and would be correct for the formal annual Report on Compliance.
- ✗
Automated quarterly vulnerability scanning of the cardholder data environment
Why it's wrong here
Quarterly scanning is periodic, not continuous; PCI DSS continuous monitoring requires automated, ongoing control checks feeding near-real-time dashboards. It is tempting because quarterly ASV scans are a mandated PCI DSS requirement, and would be correct for satisfying the standard's scheduled external scanning obligation.
- ✓
Real-time monitoring of firewall and intrusion detection system logs
Why this is correct
Continuous monitoring requires ongoing telemetry rather than periodic snapshots. Real-time monitoring of firewall and IDS logs detects security events as they occur, satisfying PCI DSS requirement 10's demand for continuous logging and alerting across the cardholder data environment.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.