CAS-004 Governance, Risk, and Compliance Practice Question
A financial institution is implementing a privacy program based on GDPR principles. Which of the following best describes the concept of 'privacy by design'?
⚠ Common exam trap
The trap is confusing privacy by design with other GDPR principles like data subject rights or DPO appointment; candidates may pick A because it sounds like a privacy control, but privacy by design is specifically about proactive embedding into system architecture.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Embedding privacy controls into the design and architecture of systems and processes
Privacy by design is a foundational GDPR principle (Article 25) that requires data protection measures to be integrated into the design and architecture of systems and business processes from the outset, rather than added as an afterthought. This means embedding privacy controls such as data minimization, pseudonymization, and access controls into the very structure of applications and workflows. Option C accurately captures this proactive, architecture-level approach.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ensuring that data subjects can exercise their rights upon request
Why it's wrong here
Enabling data subjects to exercise their rights is a GDPR compliance obligation covering access, erasure and portability, not the proactive embedding of privacy into design. It is tempting because both concern privacy protection, but privacy by design addresses architecture, default settings and data minimisation before processing begins.
- ✗
Appointing a Data Protection Officer to oversee all privacy matters
Why it's wrong here
Appointing a Data Protection Officer is an accountability and governance requirement under GDPR, not the embedding of privacy into systems and processes from the outset. It is tempting because the DPO does oversee privacy, but privacy by design concerns default settings, data minimisation and architecture, not a single appointed role.
- ✓
Embedding privacy controls into the design and architecture of systems and processes
Why this is correct
Privacy by design means data protection controls are built into system architecture and business processes from the outset, not bolted on afterwards. Embedding them at design time satisfies GDPR's requirement that protection be integral to processing, covering minimisation, purpose limitation and default settings.
- ✗
Conducting a privacy impact assessment after a data breach
Why it's wrong here
A privacy impact assessment after a breach is reactive remediation, whereas privacy by design embeds data protection into systems before processing begins. It is tempting because PIAs are a genuine GDPR accountability tool, and one performed post-incident would be the right choice when assessing a breach's scope and notifying the supervisory authority.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.