Courseiva
hardMultiple Select

CAS-004 Data Mapping Practice Question

A multinational corporation is subject to GDPR and the California Consumer Privacy Act (CCPA). A security architect is designing a data governance solution to meet both regulations. Which TWO controls are most appropriate?

⚠ Common exam trap

CAS-005 often tests the distinction between foundational governance controls (mapping, classification) and technical enforcement controls (DLP, SIEM), causing candidates to select DLP when the question asks for the most appropriate governance controls for privacy regulations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement data mapping to track personal data across systems and jurisdictions.

Option A is correct because data mapping (also called data inventory or record of processing activities) is foundational to both GDPR and CCPA compliance: GDPR Article 30 requires maintaining records of processing activities, and CCPA requires businesses to know what personal information they collect, where it flows, and to whom it is disclosed, which is impossible without mapping data across systems and jurisdictions. Option B is correct because data classification policies let the organization categorize personal data by sensitivity and regulatory category (e.g., GDPR special categories vs. CCPA personal information), which drives the appropriate handling, access, and protection controls mandated by both laws. Option C is not the best fit because DLP monitors exfiltration but does not by itself establish the governance framework of knowing and categorizing regulated data that GDPR and CCPA demand. Option D is not the best fit because retention schedules address storage limitation (GDPR Art. 5(1)(e)) but are a downstream control that depends on the mapping and classification provided by A and B. Option E is not the best fit because SIEM log analysis supports detection and incident response, not the core data governance obligations of data inventory and classification required by these privacy regulations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implement data mapping to track personal data across systems and jurisdictions.

    Why this is correct

    Data mapping records where personal data flows across systems and jurisdictions, establishing the visibility GDPR and CCPA both demand for subject access, deletion and transfer requests. Without this inventory, the architect cannot demonstrate lawful processing or respond to cross-border data obligations.

  • ✓

    Establish data classification policies to categorize information based on sensitivity.

    Why this is correct

    Classification policies tag data by sensitivity, enabling GDPR and CCPA obligations such as purpose limitation, retention and access restriction to be applied consistently. Categorising information lets the architect enforce handling rules per jurisdiction, satisfying both regulations' requirement to govern personal data according to its risk level.

  • ✗

    Deploy data loss prevention (DLP) technology to monitor data exfiltration.

    Why it's wrong here

    DLP monitors and blocks exfiltration of sensitive data in motion, which addresses confidentiality but not GDPR or CCPA obligations such as subject access, erasure and consent. It is tempting because DLP classifies personal data, yet the stem asks for governance controls covering both regulations' data-subject rights.

  • ✗

    Define a data retention schedule that automatically deletes data after a set period.

    Why it's wrong here

    A retention schedule with automatic deletion satisfies GDPR storage limitation but does not by itself deliver CCPA consumer rights such as access, deletion on request and opt-out of sale. It is tempting because retention limits are a recognised privacy control, yet the stem requires controls addressing both regulations' obligations.

  • ✗

    Integrate a security information and event management (SIEM) system for log analysis.

    Why it's wrong here

    SIEM log analysis supports breach detection and incident response, not the data-subject rights and lawful-processing records that GDPR and CCPA demand. It is tempting because monitoring demonstrates accountability, but logging activity does not implement access, erasure or consent management for personal data.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.