CAS-004 Governance, Risk, and Compliance Practice Question
A financial services firm is undergoing a SOC 2 Type II examination. The auditor asks the CISO to demonstrate that the organization continuously monitors whether the controls described in the system description operated effectively throughout the review period. Which activity should the CISO present as the primary evidence supporting this requirement?
⚠ Common exam trap
The trap here is assuming a signed management attestation or policy document can substitute for period-wide evidence, when Type II demands proof that controls actually operated throughout the audited window.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Collecting and retaining timestamped system-generated logs and control execution records across the entire audit period
SOC 2 Type II differs from Type I because it reports on control operating effectiveness over a period rather than design at a point in time. The strongest evidence is contemporaneous, system-generated, and timestamped, covering the full window. Signed questionnaires, single penetration tests, and policy manuals only show intent or a snapshot, so they cannot demonstrate that the described controls ran effectively on an ongoing basis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Collecting and retaining timestamped system-generated logs and control execution records across the entire audit period
Why this is correct
A SOC 2 Type II opinion covers control operating effectiveness over a defined period, so the auditor needs evidence gathered continuously, not at a single point. Timestamped logs, ticket histories, change records, and monitoring artifacts spanning the full window demonstrate that controls such as access review, change approval, and incident handling actually ran as described throughout the period.
- ✗
Delivering the organization's information security policy manual and a list of planned future controls
Why it's wrong here
Policy documents describe intended behavior and future plans describe what might happen later; neither proves that controls actually functioned during the audited period. SOC 2 Type II is specifically about operating effectiveness over time, so design-level documents and roadmaps fail to address the auditor's request for evidence of consistent execution across the review window.
- ✗
Scheduling a one-time penetration test two weeks before the auditor's fieldwork begins
Why it's wrong here
A penetration test evaluates the state of security at a point in time and tests technical exploitability, not whether governance controls such as access reviews or change management operated continuously. One test near fieldwork reveals nothing about control performance in earlier months, so it does not satisfy the Type II requirement for evidence of effective operation throughout the period.
- ✗
Providing a completed security questionnaire signed by the CISO on the last day of the audit period
Why it's wrong here
A signed questionnaire reflects management's assertion at one moment and is self-reported, so it cannot demonstrate that controls operated consistently across the whole review window. Type II reporting depends on independent testing of evidence produced over time; a single attestation document gives the auditor no way to verify control execution on the many dates between the period start and end.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.