Courseiva

CAS-004 Governance, Risk, and Compliance Practice Question

A financial institution is adopting a risk management framework based on NIST SP 800-37. The CISO wants to ensure that risk responses are integrated into the enterprise architecture. Which of the following activities best supports this integration during the Risk Response step?

⚠ Common exam trap

It's easy for candidates to confuse documentation or testing activities with the actual architectural integration of controls, which requires explicit mapping to system components.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Mapping selected security controls to specific architectural components and documenting the relationships.

Mapping selected security controls to architectural components is the key activity that integrates risk responses into enterprise architecture. NIST SP 800-37's Risk Response step involves selecting controls, allocating them to systems, and documenting how they are implemented. By explicitly linking controls to architecture, the organization ensures that risk mitigation is designed into systems rather than bolted on later. This supports traceability and continuous monitoring.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Developing a risk register that lists identified risks and their owners.

    Why it's wrong here

    A risk register is a valuable tool for tracking risks, but it does not directly integrate risk responses into enterprise architecture. The register documents risks and assigns ownership, but it lacks the architectural linkage needed to ensure that controls are embedded in system designs. Integration requires mapping controls to architectural components and processes.

  • ✗

    Performing a business impact analysis (BIA) to identify critical business processes.

    Why it's wrong here

    A BIA is part of the risk assessment process (Categorize and Assess steps), helping to identify critical processes and dependencies. While its output informs risk response, it does not itself integrate responses into architecture. The integration occurs when controls are selected and mapped to architectural elements, not during the BIA.

  • ✓

    Mapping selected security controls to specific architectural components and documenting the relationships.

    Why this is correct

    During Risk Response, NIST SP 800-37 emphasizes selecting, tailoring, and implementing controls. Mapping those controls to architectural components ensures that risk responses are not abstract but are embedded in the system's design. This documentation also facilitates continuous monitoring and change management. It directly supports integration into enterprise architecture by showing where each control resides.

  • ✗

    Conducting a tabletop exercise to validate the effectiveness of the risk response plan.

    Why it's wrong here

    Tabletop exercises are useful for validating plans and identifying gaps, but they occur after controls are implemented. They do not integrate risk responses into architecture; rather, they test the existing integration. The activity is more aligned with the Assess step or ongoing monitoring, not the initial integration of responses into architecture.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.