Courseiva
hardMultiple Choice

CAS-004 Practice Question: A multinational corporation is implementing a…

A multinational corporation is implementing a privacy program that must comply with both GDPR and CCPA. Which approach to privacy impact assessments (PIAs) is most appropriate?

⚠ Common exam trap

CAS-005 often tests the misconception that each privacy regulation requires a completely separate assessment, when in fact a unified PIA can satisfy multiple frameworks and is considered best practice.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conduct a single PIA that covers both regulations' requirements

A single, unified PIA that addresses the requirements of both GDPR and CCPA is the most efficient and consistent approach, as many of the core elements (data mapping, risk assessment, mitigation) overlap. It avoids duplication and ensures that the organization has a holistic view of privacy risks across jurisdictions. This approach is recommended by privacy professionals when regulations share common principles.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Perform separate PIAs for GDPR and CCPA requirements

    Why it's wrong here

    Duplicating assessments per regulation produces inconsistent risk findings and duplicated effort across overlapping requirements. A unified PIA mapping both GDPR and CCPA controls satisfies each regime simultaneously. Separate PIAs suit organisations operating wholly within one jurisdiction's framework.

  • ✗

    Skip PIAs for existing processing activities

    Why it's wrong here

    Exempting existing processing leaves legacy data flows unassessed, breaching GDPR accountability and CCPA obligations that apply to current activities, not just new ones. PIAs must cover established processing too. Skipping them would only be defensible where no personal data is processed at all.

  • ✓

    Conduct a single PIA that covers both regulations' requirements

    Why this is correct

    A single consolidated PIA mapping overlapping GDPR and CCPA requirements avoids duplicated assessments, since both regimes share core principles around data processing, individual rights and risk. One assessment covering the stricter obligation of each area satisfies both regulators efficiently.

  • ✗

    Only perform PIAs when processing high-risk data

    Why it's wrong here

    Restricting PIAs to high-risk processing omits CCPA's broader assessment expectations and GDPR's requirement to assess processing likely to result in high risk plus other accountability triggers. A risk-tiered programme covering all processing is appropriate. High-risk-only screening suits a narrow, single-regulation context.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.