CAS-004 Governance, Risk, and Compliance Practice Question
A multinational financial services firm is aligning its enterprise risk management program with the NIST Risk Management Framework (RMF). The Chief Risk Officer wants to ensure that risk response decisions are formally authorized before changes are made to production systems. Which RMF step is responsible for providing that authorization?
⚠ Common exam trap
Candidates often confuse the assessment of controls with the formal acceptance of residual risk, which occurs only at the authorization decision.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Authorize the system
Authorization is the RMF step where an authorizing official formally accepts residual risk and permits the system to operate. It follows categorization, control selection, implementation, and assessment, and it is the point at which risk decisions become official. Continuous monitoring then sustains that authorization over time. Because the CRO requires formal risk acceptance before production changes, the Authorize step is the correct fit.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Assess security controls
Why it's wrong here
The Assess step evaluates whether selected controls are implemented correctly and operating as intended. It produces assessment findings that inform the authorization decision, but it does not grant approval to operate. The scenario specifically requires a formal authorization before production changes, which occurs in a later RMF step after assessment results are reviewed by the authorizing official.
- ✗
Categorize the system
Why it's wrong here
Categorization defines the system's impact level based on confidentiality, integrity, and availability, which drives the baseline control selection. It does not grant formal authorization to operate or accept residual risk; that authority is exercised later in the RMF lifecycle. In this scenario, categorizing the system would occur before controls are selected and assessed, so it cannot satisfy the requirement for a documented risk acceptance decision.
- ✗
Monitor security controls
Why it's wrong here
Continuous monitoring tracks control effectiveness, changes to the system, and evolving threats after authorization. It supports ongoing risk management but does not itself authorize production changes or accept risk on behalf of the organization. In this scenario, monitoring would be part of the evidence used during the Authorize step and would continue afterward, but it is not the formal authorization activity the CRO is asking about.
- ✓
Authorize the system
Why this is correct
The Authorize step is where a senior official reviews the security assessment results, the plan of action and milestones, and the continuous monitoring strategy, then formally accepts the residual risk and grants an authorization to operate. This directly satisfies the Chief Risk Officer's requirement that risk decisions be authorized before production changes are made, because the authorization decision is documented and tied to explicit risk acceptance.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.