CAS-004 Governance, Risk, and Compliance Practice Question
A financial services firm is selecting a cloud provider to host regulated customer data. The vendor risk team wants contractual language that lets the firm independently verify the provider's security posture over time rather than relying only on the provider's self-reported questionnaires. (Choose two.)
⚠ Common exam trap
The trap here is treating any vendor contract term as security assurance, when only provisions that grant inspection rights or recurring independent audit evidence actually verify the provider's controls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A clause requiring the provider to deliver current SOC 2 Type II reports at least annually
Ongoing independent visibility into a provider's security posture requires contractual rights that produce evidence rather than self-reporting. A right-to-audit establishes the legal ability to inspect and test controls, and a requirement for current SOC 2 Type II reports supplies recurring auditor-attested evidence of control effectiveness. Uptime SLAs, liability caps, and pricing clauses govern availability, financial exposure, and cost, none of which verify how the provider actually secures regulated data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A clause requiring the provider to deliver current SOC 2 Type II reports at least annually
Why this is correct
Requiring current SOC 2 Type II reports gives the firm an independent auditor's opinion on the design and operating effectiveness of the provider's controls over a period of time. Delivering them annually ensures the assurance stays valid rather than relying on a one-time snapshot. This directly supports ongoing, third-party-verified visibility into the provider's security posture and complements other contractual safeguards.
- ✗
A limitation-of-liability cap tied to twelve months of fees
Why it's wrong here
A liability cap defines the maximum financial exposure each party bears if the contract is breached. It is a risk-transfer and financial term, not a mechanism for verifying controls or gaining insight into the provider's security practices. Relying on it would only help recover money after an incident, leaving the firm without the proactive, ongoing assurance the scenario requires.
- ✗
A service level agreement specifying 99.99% uptime credits
Why it's wrong here
An SLA with uptime credits addresses availability performance and financial remedies for outages. It says nothing about the confidentiality, integrity, or control effectiveness of the provider's environment, so it cannot substitute for independent security verification. The scenario explicitly asks for ongoing visibility into security posture, which a performance SLA does not provide, making it an availability instrument rather than a security-assurance control.
- ✗
A most-favored-nation pricing clause
Why it's wrong here
A most-favored-nation clause guarantees the firm receives pricing at least as favorable as other customers. It is purely a commercial term with no bearing on security controls, auditability, or control effectiveness. Including it would not give the firm any visibility into how the provider protects data, so it fails to satisfy the requirement for independent, ongoing security verification.
- ✓
A right-to-audit clause permitting on-site inspections and evidence collection
Why this is correct
A right-to-audit clause gives the firm contractual authority to inspect the provider's controls, review evidence, and validate security claims directly rather than trusting self-attestations. For regulated financial data, this independent verification is often mandated by supervisory guidance, and it preserves leverage if the provider's posture degrades. It is the mechanism that converts the firm's due-diligence obligation into an enforceable, repeatable verification right across the engagement.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.