Courseiva

CAS-004 Governance, Risk, and Compliance Practice Question

A multinational financial services firm is aligning its enterprise risk management program with the NIST Risk Management Framework (RMF). The Chief Risk Officer wants to ensure that risk response decisions are formally authorized before changes are made to production systems. Which RMF step is responsible for providing that authorization?

⚠ Common exam trap

Candidates often confuse the assessment of controls with the formal acceptance of residual risk, which occurs only at the authorization decision.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Authorize the system

Authorization is the RMF step where an authorizing official formally accepts residual risk and permits the system to operate. It follows categorization, control selection, implementation, and assessment, and it is the point at which risk decisions become official. Continuous monitoring then sustains that authorization over time. Because the CRO requires formal risk acceptance before production changes, the Authorize step is the correct fit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Assess security controls

    Why it's wrong here

    The Assess step evaluates whether selected controls are implemented correctly and operating as intended. It produces assessment findings that inform the authorization decision, but it does not grant approval to operate. The scenario specifically requires a formal authorization before production changes, which occurs in a later RMF step after assessment results are reviewed by the authorizing official.

  • ✗

    Categorize the system

    Why it's wrong here

    Categorization defines the system's impact level based on confidentiality, integrity, and availability, which drives the baseline control selection. It does not grant formal authorization to operate or accept residual risk; that authority is exercised later in the RMF lifecycle. In this scenario, categorizing the system would occur before controls are selected and assessed, so it cannot satisfy the requirement for a documented risk acceptance decision.

  • ✗

    Monitor security controls

    Why it's wrong here

    Continuous monitoring tracks control effectiveness, changes to the system, and evolving threats after authorization. It supports ongoing risk management but does not itself authorize production changes or accept risk on behalf of the organization. In this scenario, monitoring would be part of the evidence used during the Authorize step and would continue afterward, but it is not the formal authorization activity the CRO is asking about.

  • ✓

    Authorize the system

    Why this is correct

    The Authorize step is where a senior official reviews the security assessment results, the plan of action and milestones, and the continuous monitoring strategy, then formally accepts the residual risk and grants an authorization to operate. This directly satisfies the Chief Risk Officer's requirement that risk decisions be authorized before production changes are made, because the authorization decision is documented and tied to explicit risk acceptance.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.