CAS-004 Governance, Risk, and Compliance Practice Question
A company's security policy requires all sensitive data to be encrypted at rest. However, a business unit requests an exception to store certain data unencrypted due to performance constraints. Which document should govern the exception process?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security policy
An exception management process is typically defined within the security policy or a related standard, outlining how to request, approve, and track exceptions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Security policy
Why this is correct
The security policy should include an exception management clause.
- ✗
Risk treatment plan
Why it's wrong here
A risk treatment plan documents specific risk responses, not the overarching exception process.
- ✗
Acceptable use policy
Why it's wrong here
AUP covers appropriate use of systems, not exceptions to encryption.
- ✗
Data classification standard
Why it's wrong here
This defines data categories, not exception procedures.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.