Courseiva

CAS-004 Governance, Risk, and Compliance Practice Question

A mid-sized retailer wants to demonstrate to customers that its payment card handling meets industry security requirements. The company does not store, process, or transmit cardholder data; it only uses a validated third-party payment page that handles all card data. Which PCI DSS self-assessment questionnaire is most appropriate?

⚠ Common exam trap

The trap here is selecting the most comprehensive questionnaire, SAQ D, out of caution when the merchant's fully outsourced model qualifies for the much simpler SAQ A.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SAQ A

PCI DSS self-assessment questionnaire eligibility depends on how cardholder data is handled. A merchant that completely outsources card data functions to a validated third party and never stores, processes, or transmits the data qualifies for SAQ A. The other questionnaires apply to environments with direct card data handling, standalone IP terminals, or validated point-to-point encryption solutions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SAQ D for Merchants

    Why it's wrong here

    SAQ D is the most comprehensive questionnaire, required when a merchant stores, processes, or transmits cardholder data or does not meet eligibility criteria for a shorter SAQ. Because this retailer fully outsources card data handling, SAQ D is unnecessarily broad and not the correct choice.

  • ✓

    SAQ A

    Why this is correct

    SAQ A is designed for merchants that fully outsource all cardholder data functions to PCI DSS validated third parties and do not store, process, or transmit cardholder data electronically. The retailer's use of a validated third-party payment page matches this profile exactly. Completing SAQ A is the correct and least burdensome validation path here.

  • ✗

    SAQ B-IP

    Why it's wrong here

    SAQ B-IP applies to merchants using standalone, hardware-based payment terminals with IP connectivity that are not connected to any other systems. The scenario involves a hosted payment page, not standalone IP terminals, so SAQ B-IP does not match the environment.

  • ✗

    SAQ P2PE

    Why it's wrong here

    SAQ P2PE is for merchants using PCI-listed point-to-point encryption solutions with hardware payment terminals. It applies when card data is encrypted at the point of interaction through a validated P2PE solution, which is not what a hosted payment page represents. Therefore it is not the right questionnaire.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.