Courseiva
easyMultiple Choice

CAS-004 Practice Question: A financial institution must ensure that its data…

A financial institution must ensure that its data classification policy aligns with regulatory requirements for customer financial information. Which of the following actions best demonstrates governance in this context?

⚠ Common exam trap

Watch out — candidates often confuse encryption (a security control) with governance (a policy-driven framework), leading them to select Option D because they assume encryption alone satisfies regulatory compliance, when in fact governance requires classification to define which data must be encrypted and under what conditions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement a formal data classification policy that maps data types to regulatory categories and enforce it via technical controls.

It directly implements governance by establishing a formal data classification policy that maps data types to specific regulatory categories (e.g., PCI DSS, GLBA, SOX) and enforces compliance through technical controls such as Data Loss Prevention (DLP) rules, access control lists (ACLs), and encryption policies. This structured approach ensures that customer financial information is consistently protected according to legal requirements, rather than relying on ad-hoc or incomplete measures.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implement a formal data classification policy that maps data types to regulatory categories and enforce it via technical controls.

    Why this is correct

    Mapping data types to regulatory categories directly satisfies the alignment constraint, while enforcement through technical controls ensures the policy is operational rather than aspirational. Governance therefore spans both definition and enforcement, covering classification, handling and accountability for customer financial information as the stem requires.

  • ✗

    Restrict all customer financial data to a single secure server without labeling.

    Why it's wrong here

    Restricting data to one server without labelling provides no classification metadata, so policy enforcement and audit evidence cannot be demonstrated. It is tempting because consolidation feels secure, but governance requires documented classification and handling rules, which labelling and policy definition supply instead.

  • ✗

    Allow data owners to classify data on an ad-hoc basis as needed.

    Why it's wrong here

    Ad-hoc classification by data owners produces inconsistent labelling, so the policy cannot be evidenced as aligned with regulatory requirements; governance demands a centrally approved, enforced scheme. It is tempting because owner-led classification suits low-regulation settings where business context, not external mandate, drives sensitivity decisions.

  • ✗

    Encrypt all customer data at rest and in transit regardless of classification.

    Why it's wrong here

    Blanket encryption ignores classification entirely, so controls are not proportionate to regulatory categories and the policy-to-requirement mapping is unproven; governance is about defined, risk-based rules. It tempts because encryption is a valid baseline control where no data classification scheme exists yet.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.