Courseiva

CAS-004 Governance, Risk, and Compliance Practice Question

A multinational financial services firm is expanding operations into the European Union. The legal team asks the security architect to ensure the new customer onboarding portal complies with the General Data Protection Regulation (GDPR). Which of the following should the security architect implement FIRST to align with GDPR's data protection principles?

⚠ Common exam trap

The trap here is assuming that technical security controls alone satisfy GDPR, when the regulation first demands a privacy risk assessment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conduct a Data Protection Impact Assessment (DPIA) for the portal's processing activities.

GDPR emphasizes a risk-based approach, requiring organizations to assess privacy risks before processing personal data. A Data Protection Impact Assessment (DPIA) is specifically mandated for high-risk processing and helps identify and mitigate risks, ensuring compliance by design. Other controls like encryption or WAFs are supportive but not the initial compliance step.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implement encryption for all data at rest and in transit.

    Why it's wrong here

    Encryption is a valuable security measure and can support GDPR compliance, but it is not the initial action. GDPR requires a risk-based approach, starting with understanding the data flows and risks. Encryption alone does not address lawful basis, data minimization, or data subject rights, which are core GDPR principles.

  • ✓

    Conduct a Data Protection Impact Assessment (DPIA) for the portal's processing activities.

    Why this is correct

    A DPIA is a GDPR requirement when processing is likely to result in a high risk to data subjects' rights, especially for large-scale or systematic processing. It identifies and mitigates privacy risks before implementation, ensuring accountability and compliance by design. This is the foundational step before deploying technical controls.

  • ✗

    Deploy a web application firewall (WAF) to block SQL injection attacks.

    Why it's wrong here

    A WAF addresses technical vulnerabilities but does not fulfill GDPR's overarching mandate to assess and mitigate privacy risks. It is a security control, not a privacy compliance measure. Without a DPIA, the organization cannot demonstrate accountability or identify specific data protection risks, so this is not the first step.

  • ✗

    Appoint a Data Protection Officer (DPO) to oversee the portal.

    Why it's wrong here

    A DPO is mandatory only for certain organizations, such as public authorities or those engaged in large-scale monitoring. While appointing a DPO can aid compliance, it is not the first step for a new portal. The immediate need is to assess privacy risks through a DPIA, which informs whether a DPO is required.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.