CAS-004 Governance, Risk, and Compliance Practice Question
A defense contractor must comply with DFARS clause 252.204-7012 and achieve a passing score in its NIST SP 800-171 self-assessment before a contract award. The security lead discovers that several controls in the CUI environment are only partially implemented. Which action should the security lead take to meet the assessment requirement?
⚠ Common exam trap
The trap here is believing that partially implemented controls earn partial points or that a contractor can claim credit for compensating controls to reach a passing score.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Document a plan of action with milestones to remediate the partially implemented controls and complete a System Security Plan describing the current state.
When controls are not fully implemented, the accepted method is to document the current state in a System Security Plan and describe remediation in a Plan of Action with milestones. This preserves an honest score while showing the contracting officer a credible path to full implementation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Document a plan of action with milestones to remediate the partially implemented controls and complete a System Security Plan describing the current state.
Why this is correct
NIST SP 800-171 assessments permit a score below 110 only when the contractor documents the deficiencies in a System Security Plan and a Plan of Action with defined milestones, resources, and completion dates. This is the accepted path to demonstrate compliance intent and qualify for award while remediation proceeds, so documenting both artifacts is the required action.
- ✗
Request a variance from the contracting officer to exclude the unimplemented controls from the assessment scope.
Why it's wrong here
Contracting officers cannot waive the DFARS 252.204-7012 requirement to implement NIST SP 800-171 controls, and no variance mechanism removes controls from scope. The obligation applies to the entire system handling covered defense information, so pursuing a variance does not satisfy the assessment requirement and could jeopardize the award.
- ✗
Submit the self-assessment with a perfect score and remediate the gaps after contract award within the first performance period.
Why it's wrong here
Submitting a false perfect score misrepresents the security posture and violates the requirement for an accurate self-assessment. Scoring rules do not allow credit for controls that are merely planned, so this approach risks False Claims Act exposure and contract termination rather than satisfying the compliance obligation.
- ✗
Implement a compensating control for each partial control and claim full credit in the score to reach the required total.
Why it's wrong here
The NIST SP 800-171 scoring methodology awards points only when a control is fully implemented as stated; partial implementation scores zero for that requirement. Compensating controls are not a recognized way to claim credit under this scoring approach, so inflating the score this way would misrepresent the environment and fail scrutiny.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.