Courseiva

CAS-004 Governance, Risk, and Compliance Practice Question

A financial services firm operates in several countries and must demonstrate that its security controls are effective and independently validated for regulators and enterprise customers. Executives want a report that auditors can rely on regarding the design and operating effectiveness of controls over a period of time. Which document should the security team provide?

⚠ Common exam trap

The trap here is treating a SOC 2 Type I report or an ISO/IEC 27001 certificate as equivalent evidence of control effectiveness over time when neither tests operating effectiveness across a period.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SOC 2 Type II report

A SOC 2 Type II report is the appropriate artifact because it attests to both the design and operating effectiveness of controls across a defined period. Type I reports only cover design at a point in time, and the other documents do not provide period-wide control testing evidence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    SOC 2 Type II report

    Why this is correct

    A SOC 2 Type II report covers the design and operating effectiveness of controls over a defined review period, using the Trust Services Criteria. Because it tests controls across time rather than a single moment, it gives regulators and customers independently validated evidence that controls operated effectively throughout the period, matching the stated objective.

  • ✗

    SOC 2 Type I report

    Why it's wrong here

    A SOC 2 Type I report addresses only the suitability of control design at a single point in time. It does not test whether controls operated effectively over a period, so it cannot demonstrate sustained effectiveness. The executives specifically asked for operating effectiveness over time, which a Type I cannot provide.

  • ✗

    SOC 3 general use report

    Why it's wrong here

    A SOC 3 report is a general-use seal or summary intended for public distribution and lacks the detailed control descriptions and test results needed for auditor reliance. It does not supply the depth of evidence about design and operating effectiveness that regulators and enterprise customers require for due diligence.

  • ✗

    ISO/IEC 27001 certificate

    Why it's wrong here

    An ISO/IEC 27001 certificate attests that a management system conforms to the standard, but it is not a report on the operating effectiveness of individual controls over a period. It provides a certification mark rather than detailed control testing results, so it does not meet the request for independently validated control effectiveness.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.