Courseiva

CAS-004 Governance, Risk, and Compliance Practice Question

A financial institution is implementing a privacy program based on GDPR principles. Which of the following best describes the concept of 'privacy by design'?

⚠ Common exam trap

The trap is confusing privacy by design with other GDPR principles like data subject rights or DPO appointment; candidates may pick A because it sounds like a privacy control, but privacy by design is specifically about proactive embedding into system architecture.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Embedding privacy controls into the design and architecture of systems and processes

Privacy by design is a foundational GDPR principle (Article 25) that requires data protection measures to be integrated into the design and architecture of systems and business processes from the outset, rather than added as an afterthought. This means embedding privacy controls such as data minimization, pseudonymization, and access controls into the very structure of applications and workflows. Option C accurately captures this proactive, architecture-level approach.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Ensuring that data subjects can exercise their rights upon request

    Why it's wrong here

    Enabling data subjects to exercise their rights is a GDPR compliance obligation covering access, erasure and portability, not the proactive embedding of privacy into design. It is tempting because both concern privacy protection, but privacy by design addresses architecture, default settings and data minimisation before processing begins.

  • ✗

    Appointing a Data Protection Officer to oversee all privacy matters

    Why it's wrong here

    Appointing a Data Protection Officer is an accountability and governance requirement under GDPR, not the embedding of privacy into systems and processes from the outset. It is tempting because the DPO does oversee privacy, but privacy by design concerns default settings, data minimisation and architecture, not a single appointed role.

  • ✓

    Embedding privacy controls into the design and architecture of systems and processes

    Why this is correct

    Privacy by design means data protection controls are built into system architecture and business processes from the outset, not bolted on afterwards. Embedding them at design time satisfies GDPR's requirement that protection be integral to processing, covering minimisation, purpose limitation and default settings.

  • ✗

    Conducting a privacy impact assessment after a data breach

    Why it's wrong here

    A privacy impact assessment after a breach is reactive remediation, whereas privacy by design embeds data protection into systems before processing begins. It is tempting because PIAs are a genuine GDPR accountability tool, and one performed post-incident would be the right choice when assessing a breach's scope and notifying the supervisory authority.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.