CAS-004 Governance, Risk, and Compliance Practice Question
A financial services firm's third-party risk team is onboarding a new SaaS payroll provider. The provider refuses to share its internal audit reports but will allow the firm to send its own assessor on-site to inspect the provider's controls. Which risk assessment method should the firm use to obtain assurance in this situation?
⚠ Common exam trap
The trap here is assuming that any recognized artifact such as a SOC 2 report or ISO certificate automatically satisfies third-party assurance needs, when the actual constraint is what evidence the provider will permit access to.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
On-site assessment performed by the firm's own assessors
Because the provider withholds internal audit reports yet allows assessors on-site, the only method that yields independently verified, first-hand evidence of control effectiveness is a direct on-site assessment. Self-assessments and certifications provide weaker, provider-controlled evidence, and the SOC 2 report is unavailable by the provider's own refusal, leaving the on-site inspection as the reliable path.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Review of the provider's SOC 2 Type I report
Why it's wrong here
A SOC 2 Type I report covers the suitability of controls at a single point in time and is produced by the provider's chosen auditor. Here the provider refuses to share audit reports, so this evidence is unavailable, and even if it were, a point-in-time report gives weaker assurance than direct inspection for an ongoing payroll relationship.
- ✗
Acceptance of the provider's ISO/IEC 27001 certificate as sufficient evidence
Why it's wrong here
An ISO/IEC 27001 certificate demonstrates that a management system exists but does not show which specific controls protect this firm's payroll data or how well they operate. The provider has declined to share audit detail, so accepting the certificate alone would substitute a general certification for concrete, scenario-specific assurance.
- ✓
On-site assessment performed by the firm's own assessors
Why this is correct
The provider has blocked access to internal audit reports but explicitly permits the firm to send assessors on-site. A direct on-site assessment lets the firm independently inspect the provider's controls, interview staff, and review evidence first-hand, generating the assurance the questionnaire or report-based approaches could not deliver under these constraints.
- ✗
Self-assessment questionnaire completed by the provider's security team
Why it's wrong here
A self-assessment questionnaire relies entirely on the provider's own attestation and does not involve independent verification of controls. In this scenario the provider has refused to disclose internal audit reports, so relying on its self-reported answers would leave the firm with unverified assurances and no direct visibility into how the payroll data is actually protected.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.