Courseiva

CAS-004 Governance, Risk, and Compliance Practice Question

A financial services firm is undergoing a SOC 2 Type II examination. The auditor asks the CISO to demonstrate that the organization continuously monitors whether the controls described in the system description operated effectively throughout the review period. Which activity should the CISO present as the primary evidence supporting this requirement?

⚠ Common exam trap

The trap here is assuming a signed management attestation or policy document can substitute for period-wide evidence, when Type II demands proof that controls actually operated throughout the audited window.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Collecting and retaining timestamped system-generated logs and control execution records across the entire audit period

SOC 2 Type II differs from Type I because it reports on control operating effectiveness over a period rather than design at a point in time. The strongest evidence is contemporaneous, system-generated, and timestamped, covering the full window. Signed questionnaires, single penetration tests, and policy manuals only show intent or a snapshot, so they cannot demonstrate that the described controls ran effectively on an ongoing basis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Collecting and retaining timestamped system-generated logs and control execution records across the entire audit period

    Why this is correct

    A SOC 2 Type II opinion covers control operating effectiveness over a defined period, so the auditor needs evidence gathered continuously, not at a single point. Timestamped logs, ticket histories, change records, and monitoring artifacts spanning the full window demonstrate that controls such as access review, change approval, and incident handling actually ran as described throughout the period.

  • ✗

    Delivering the organization's information security policy manual and a list of planned future controls

    Why it's wrong here

    Policy documents describe intended behavior and future plans describe what might happen later; neither proves that controls actually functioned during the audited period. SOC 2 Type II is specifically about operating effectiveness over time, so design-level documents and roadmaps fail to address the auditor's request for evidence of consistent execution across the review window.

  • ✗

    Scheduling a one-time penetration test two weeks before the auditor's fieldwork begins

    Why it's wrong here

    A penetration test evaluates the state of security at a point in time and tests technical exploitability, not whether governance controls such as access reviews or change management operated continuously. One test near fieldwork reveals nothing about control performance in earlier months, so it does not satisfy the Type II requirement for evidence of effective operation throughout the period.

  • ✗

    Providing a completed security questionnaire signed by the CISO on the last day of the audit period

    Why it's wrong here

    A signed questionnaire reflects management's assertion at one moment and is self-reported, so it cannot demonstrate that controls operated consistently across the whole review window. Type II reporting depends on independent testing of evidence produced over time; a single attestation document gives the auditor no way to verify control execution on the many dates between the period start and end.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.