Courseiva

CAS-004 Governance, Risk, and Compliance Practice Question

A financial services firm's third-party risk team is onboarding a new SaaS payroll provider. The provider refuses to share its internal audit reports but will allow the firm to send its own assessor on-site to inspect the provider's controls. Which risk assessment method should the firm use to obtain assurance in this situation?

⚠ Common exam trap

The trap here is assuming that any recognized artifact such as a SOC 2 report or ISO certificate automatically satisfies third-party assurance needs, when the actual constraint is what evidence the provider will permit access to.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

On-site assessment performed by the firm's own assessors

Because the provider withholds internal audit reports yet allows assessors on-site, the only method that yields independently verified, first-hand evidence of control effectiveness is a direct on-site assessment. Self-assessments and certifications provide weaker, provider-controlled evidence, and the SOC 2 report is unavailable by the provider's own refusal, leaving the on-site inspection as the reliable path.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Review of the provider's SOC 2 Type I report

    Why it's wrong here

    A SOC 2 Type I report covers the suitability of controls at a single point in time and is produced by the provider's chosen auditor. Here the provider refuses to share audit reports, so this evidence is unavailable, and even if it were, a point-in-time report gives weaker assurance than direct inspection for an ongoing payroll relationship.

  • ✗

    Acceptance of the provider's ISO/IEC 27001 certificate as sufficient evidence

    Why it's wrong here

    An ISO/IEC 27001 certificate demonstrates that a management system exists but does not show which specific controls protect this firm's payroll data or how well they operate. The provider has declined to share audit detail, so accepting the certificate alone would substitute a general certification for concrete, scenario-specific assurance.

  • ✓

    On-site assessment performed by the firm's own assessors

    Why this is correct

    The provider has blocked access to internal audit reports but explicitly permits the firm to send assessors on-site. A direct on-site assessment lets the firm independently inspect the provider's controls, interview staff, and review evidence first-hand, generating the assurance the questionnaire or report-based approaches could not deliver under these constraints.

  • ✗

    Self-assessment questionnaire completed by the provider's security team

    Why it's wrong here

    A self-assessment questionnaire relies entirely on the provider's own attestation and does not involve independent verification of controls. In this scenario the provider has refused to disclose internal audit reports, so relying on its self-reported answers would leave the firm with unverified assurances and no direct visibility into how the payroll data is actually protected.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.