CAS-004 Governance, Risk, and Compliance Practice Question
A healthcare organization is required to comply with HIPAA. During an audit, the auditor requests evidence of access controls for electronic protected health information (ePHI). Which of the following would be the BEST evidence to provide?
⚠ Common exam trap
The trap is selecting a policy document or training record as evidence of access controls, when auditors require proof of implementation and monitoring, such as logs or review records.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Access review logs showing periodic reviews of user permissions
Access review logs showing periodic reviews of user permissions provide direct evidence that access controls are being enforced and monitored over time. HIPAA requires covered entities to implement policies and procedures to authorize and supervise access to ePHI, and periodic reviews demonstrate ongoing compliance. A policy alone does not prove implementation, and training or network diagrams do not show actual access control effectiveness.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A report of employee security training completion
Why it's wrong here
Training completion records demonstrate workforce awareness, not the technical access controls restricting ePHI. Auditors expect system-generated logs or access reports showing who accessed what. Training evidence would be the right artefact when the request concerns HIPAA's workforce security or awareness requirements rather than access control implementation.
- ✗
A signed copy of the access control policy
Why it's wrong here
A signed policy documents intent, not enforcement; it cannot show that access to ePHI is actually restricted. Auditors require operational evidence such as access logs, role assignments or system configuration exports. A signed policy would be the correct artefact when the request concerns documented governance or management commitment rather than implemented controls.
- ✓
Access review logs showing periodic reviews of user permissions
Why this is correct
Access review logs directly evidence periodic recertification of user permissions, satisfying HIPAA's access control and audit requirements for ePHI. Unlike configuration screenshots or policy documents, these logs prove ongoing enforcement through documented reviewer decisions and timestamps, demonstrating that least-privilege access is actively maintained rather than merely defined.
- ✗
A network diagram of the IT infrastructure
Why it's wrong here
A network diagram shows topology and data flows, not who is authorised to reach ePHI or what they did. Access control evidence requires identity, role and permission data. A network diagram would be the right artefact when the request concerns infrastructure segmentation, boundary protection or data-flow mapping under the Security Rule.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.