hardMultiple Choice
CAS-004 Practice Question: A multinational corporation is implementing a…
A multinational corporation is implementing a privacy program that must comply with both GDPR and CCPA. Which approach to privacy impact assessments (PIAs) is most appropriate?
⚠ Common exam trap
CAS-005 often tests the misconception that each privacy regulation requires a completely separate assessment, when in fact a unified PIA can satisfy multiple frameworks and is considered best practice.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct a single PIA that covers both regulations' requirements
A single, unified PIA that addresses the requirements of both GDPR and CCPA is the most efficient and consistent approach, as many of the core elements (data mapping, risk assessment, mitigation) overlap. It avoids duplication and ensures that the organization has a holistic view of privacy risks across jurisdictions. This approach is recommended by privacy professionals when regulations share common principles.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Perform separate PIAs for GDPR and CCPA requirements
Why it's wrong here
Duplicating assessments per regulation produces inconsistent risk findings and duplicated effort across overlapping requirements. A unified PIA mapping both GDPR and CCPA controls satisfies each regime simultaneously. Separate PIAs suit organisations operating wholly within one jurisdiction's framework.
- ✗
Skip PIAs for existing processing activities
Why it's wrong here
Exempting existing processing leaves legacy data flows unassessed, breaching GDPR accountability and CCPA obligations that apply to current activities, not just new ones. PIAs must cover established processing too. Skipping them would only be defensible where no personal data is processed at all.
- ✓
Conduct a single PIA that covers both regulations' requirements
Why this is correct
A single consolidated PIA mapping overlapping GDPR and CCPA requirements avoids duplicated assessments, since both regimes share core principles around data processing, individual rights and risk. One assessment covering the stricter obligation of each area satisfies both regulators efficiently.
- ✗
Only perform PIAs when processing high-risk data
Why it's wrong here
Restricting PIAs to high-risk processing omits CCPA's broader assessment expectations and GDPR's requirement to assess processing likely to result in high risk plus other accountability triggers. A risk-tiered programme covering all processing is appropriate. High-risk-only screening suits a narrow, single-regulation context.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.