CAS-004 Governance, Risk, and Compliance Practice Question
A financial services firm operates in several countries and must demonstrate that its security controls are effective and independently validated for regulators and enterprise customers. Executives want a report that auditors can rely on regarding the design and operating effectiveness of controls over a period of time. Which document should the security team provide?
⚠ Common exam trap
The trap here is treating a SOC 2 Type I report or an ISO/IEC 27001 certificate as equivalent evidence of control effectiveness over time when neither tests operating effectiveness across a period.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SOC 2 Type II report
A SOC 2 Type II report is the appropriate artifact because it attests to both the design and operating effectiveness of controls across a defined period. Type I reports only cover design at a point in time, and the other documents do not provide period-wide control testing evidence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
SOC 2 Type II report
Why this is correct
A SOC 2 Type II report covers the design and operating effectiveness of controls over a defined review period, using the Trust Services Criteria. Because it tests controls across time rather than a single moment, it gives regulators and customers independently validated evidence that controls operated effectively throughout the period, matching the stated objective.
- ✗
SOC 2 Type I report
Why it's wrong here
A SOC 2 Type I report addresses only the suitability of control design at a single point in time. It does not test whether controls operated effectively over a period, so it cannot demonstrate sustained effectiveness. The executives specifically asked for operating effectiveness over time, which a Type I cannot provide.
- ✗
SOC 3 general use report
Why it's wrong here
A SOC 3 report is a general-use seal or summary intended for public distribution and lacks the detailed control descriptions and test results needed for auditor reliance. It does not supply the depth of evidence about design and operating effectiveness that regulators and enterprise customers require for due diligence.
- ✗
ISO/IEC 27001 certificate
Why it's wrong here
An ISO/IEC 27001 certificate attests that a management system conforms to the standard, but it is not a report on the operating effectiveness of individual controls over a period. It provides a certification mark rather than detailed control testing results, so it does not meet the request for independently validated control effectiveness.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.