CAS-004 Governance, Risk, and Compliance Practice Question
A defense contractor is required to comply with NIST SP 800-171 for protecting controlled unclassified information (CUI). The security team is implementing the required security requirements. Which of the following best describes the purpose of the System Security Plan (SSP) in this context?
⚠ Common exam trap
The trap here is equating the SSP with a data inventory or test report, when its core purpose is to explain how each security requirement is satisfied.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It documents how the organization implements each security requirement and describes any planned remediation.
The System Security Plan (SSP) documents how the organization implements each of the NIST SP 800-171 security requirements and identifies any gaps with remediation plans. It is the primary artifact used to demonstrate compliance with DFARS 252.204-7012. It is not a data inventory, contract, or test report, although it may reference those. The SSP provides a structured narrative of the security posture for the CUI environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It provides a detailed inventory of all CUI data elements and their locations.
Why it's wrong here
While an SSP may reference where CUI is stored, its primary purpose is not to serve as a data inventory. The inventory is a separate artifact. The SSP documents how security requirements are met, not just where data resides. Confusing the SSP with a data map is a common misunderstanding that can lead to an incomplete SSP.
- ✓
It documents how the organization implements each security requirement and describes any planned remediation.
Why this is correct
NIST SP 800-171 defines the SSP as the document that describes how the organization meets each of the 110 security requirements. It includes descriptions of implemented controls, identifies any requirements not yet met, and outlines remediation plans. The SSP is a key deliverable for compliance and is often required for contracts involving CUI. It provides a clear picture of the security posture.
- ✗
It contains the results of penetration testing and vulnerability scans for the CUI environment.
Why it's wrong here
The SSP may reference security assessment results, but its main purpose is not to store test results. Assessment reports are separate documents. The SSP focuses on how requirements are implemented, not on the raw output of security testing. Including extensive test results would clutter the SSP and obscure its primary function.
- ✗
It serves as a legal contract between the contractor and the Department of Defense.
Why it's wrong here
An SSP is not a legal contract; it is a compliance document. Contracts are separate legal instruments. The SSP is used to demonstrate compliance to the government but does not itself create legal obligations. Treating it as a contract misunderstands its role in the compliance process.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.