CAS-004 Governance, Risk, and Compliance Practice Question
A company's security team is reviewing its risk register. A risk related to an outdated internal application has been assigned an owner, but the owner has taken no action for two quarters. The Chief Information Security Officer wants to ensure the risk is tracked and escalated appropriately. Which action should the security team take first?
⚠ Common exam trap
The trap here is treating an owner's silence as implicit risk acceptance, when governance requires an explicit, documented decision by the accountable party.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Escalate the overdue risk to the risk owner's management and the risk committee with the current status
The security team should escalate the overdue risk to the owner's management and the risk committee with current status. Escalation preserves accountability, keeps the risk visible, and forces a timely treatment decision by those with authority. Accepting, deleting, or unilaterally transferring the risk would bypass governance and hide the exposure rather than manage it, which is why escalation is the correct first action.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Immediately accept the risk on behalf of the business owner to close the item
Why it's wrong here
Risk acceptance must be made by the appropriate business owner with the authority to accept the consequences, not by the security team unilaterally. Closing the item without the owner's informed decision hides the exposure and violates governance expectations. The scenario describes an owner who has not acted, so the security team should escalate and facilitate a decision rather than accept risk on someone else's behalf, which would undermine accountability.
- ✗
Remove the risk from the register because the owner has implicitly accepted it by doing nothing
Why it's wrong here
Inaction is not a valid form of risk acceptance, and removing the risk from the register would conceal a known exposure from governance oversight. Risk registers exist to maintain visibility and accountability. Deleting the item would also undermine audit and compliance efforts, because there would be no record of the decision or the rationale. The correct approach is to escalate and document, not to erase the risk.
- ✓
Escalate the overdue risk to the risk owner's management and the risk committee with the current status
Why this is correct
When a risk owner fails to act, the security team's role is to escalate through governance channels so that accountable leadership can make a decision. Providing the risk committee with the current status, potential impact, and lack of progress ensures the risk remains visible and that a timely treatment decision is made. This preserves accountability and aligns with risk management practices that require escalation when treatment deadlines are missed.
- ✗
Transfer the risk to an insurance carrier and mark the register item as resolved
Why it's wrong here
Risk transfer through insurance can address financial impact, but it does not eliminate the operational and reputational consequences of an outdated application. Marking the item resolved would also bypass the risk owner's responsibility and the governance process. In this scenario, the immediate problem is the lack of action and oversight, so escalation is required before any treatment decision, including transfer, is formally approved and documented.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.