Courseiva

CAS-004 Governance, Risk, and Compliance Practice Question

A financial services firm operates a trading platform in which a 15-minute outage causes direct contractual penalties. The CISO must present a recommendation to the board on how to treat the residual risk of a ransomware event that could halt trading. The firm already has immutable offline backups and a tested recovery runbook. Which risk treatment action is MOST appropriate to recommend?

⚠ Common exam trap

The trap here is reflexively choosing risk transfer through insurance whenever a large financial loss is mentioned, even when the scenario's real constraint is recovery time.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Mitigate the risk further by engineering automated failover and rehearsing recovery to meet the 15-minute recovery time objective.

The scenario isolates recovery speed as the binding constraint, since backups and runbooks already exist. Further mitigation through automated failover and rehearsed recovery directly attacks the 15-minute recovery time objective, whereas insurance only offsets financial loss, acceptance contradicts the evident risk appetite, and avoidance would destroy the business line. Treatment should map to the specific residual risk driver rather than to generic control categories.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Transfer the risk by purchasing a cyber insurance policy that covers business interruption.

    Why it's wrong here

    Insurance transfers some financial consequence but cannot restore trading within 15 minutes, and insurers increasingly exclude or sublimit ransomware and business interruption. Because the firm already has immutable backups and a tested runbook, the residual risk is mainly operational continuity rather than pure financial loss, so transfer alone would not address the contractual penalties tied to outage duration.

  • ✓

    Mitigate the risk further by engineering automated failover and rehearsing recovery to meet the 15-minute recovery time objective.

    Why this is correct

    Because the dominant residual exposure is time-to-recover against a hard 15-minute threshold, additional mitigation through automated failover and validated recovery exercises directly reduces the likelihood and impact of missing that objective. This aligns treatment with the actual risk driver, complements the existing backup controls, and gives the board measurable evidence that the residual risk now sits within appetite.

  • ✗

    Avoid the risk by shutting down the trading platform until ransomware can be fully eliminated.

    Why it's wrong here

    Avoidance would eliminate the risk only by eliminating the business activity, which is not viable for a revenue-generating trading platform subject to its own contractual obligations. Total elimination of ransomware risk is also unachievable. Avoidance is appropriate for activities whose risk cannot be reduced to acceptable levels, not for a core platform where targeted mitigation can close the remaining gap.

  • ✗

    Accept the residual risk because immutable backups and a tested runbook already exist.

    Why it's wrong here

    Acceptance is only defensible when residual risk falls within the board-approved risk appetite. A 15-minute outage triggering contractual penalties is likely above appetite, and acceptance provides no additional reduction. Documenting acceptance without evidence that leadership formally approved that exposure would also weaken the firm's governance position during regulatory review or post-incident scrutiny.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.