CAS-004 Governance, Risk, and Compliance Practice Question
A multinational financial services firm is subject to GDPR and must transfer personal data from its EU offices to a data analytics vendor in the United States. The vendor is not certified under the EU-U.S. Data Privacy Framework. Which mechanism should the firm use to lawfully transfer the data while meeting GDPR Chapter V requirements?
⚠ Common exam trap
The trap here is assuming that any vendor security certification, such as ISO/IEC 27001, automatically satisfies GDPR cross-border transfer requirements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Standard Contractual Clauses (SCCs) with a transfer impact assessment
Because the U.S. vendor lacks Data Privacy Framework certification, the firm must rely on an Article 46 safeguard. Standard Contractual Clauses are the European Commission's pre-approved contractual terms for such transfers, and after Schrems II they must be supplemented by a transfer impact assessment evaluating the destination's surveillance laws. This combination lawfully supports routine transfers to the analytics provider.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Obtaining explicit consent from every data subject for each transfer
Why it's wrong here
Consent can be a derogation under Article 49, but it is intended for occasional, non-repetitive transfers. Using consent for routine, systematic transfers to an analytics vendor is discouraged by the EDPB because it cannot be withdrawn easily and does not provide enduring safeguards. It is not the appropriate mechanism for ongoing transfers.
- ✓
Standard Contractual Clauses (SCCs) with a transfer impact assessment
Why this is correct
SCCs are pre-approved contractual terms adopted by the European Commission that provide appropriate safeguards for international data transfers when the destination country lacks an adequacy decision. Pairing them with a transfer impact assessment satisfies the Schrems II requirement to evaluate local surveillance laws. Because the vendor lacks Data Privacy Framework certification, SCCs are the correct lawful transfer mechanism here.
- ✗
Relying on the vendor's ISO/IEC 27001 certification as an adequacy mechanism
Why it's wrong here
ISO/IEC 27001 is a voluntary information security management certification; it is not recognized under GDPR as a transfer safeguard or adequacy decision. Certification demonstrates security posture but does not address the legal requirements of Chapter V. Therefore it cannot legitimize the transfer of EU personal data to the United States.
- ✗
Binding Corporate Rules (BCRs) approved by the lead supervisory authority
Why it's wrong here
BCRs are appropriate only for intra-group transfers within a corporate group, not for transfers to an external vendor. They require lengthy approval by the competent supervisory authority and would not cover an unrelated analytics provider. Since the scenario involves a third-party vendor outside the corporate group, BCRs do not apply.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.