CAS-004 Governance, Risk, and Compliance Practice Question
A multinational financial services firm must comply with the General Data Protection Regulation (GDPR). The Chief Information Security Officer (CISO) asks the security team to implement a mechanism that allows data subjects to request and receive a copy of their personal data in a structured, commonly used, and machine-readable format. Which of the following technical controls BEST addresses this requirement?
⚠ Common exam trap
Candidates often confuse data protection controls, such as encryption or DLP, with data subject rights fulfillment mechanisms like portability APIs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement an API endpoint that allows authenticated data subjects to download their personal data in JSON or CSV format.
The GDPR grants data subjects the right to data portability, which requires organizations to provide personal data in a structured, commonly used, and machine-readable format. An API endpoint that allows authenticated users to download their data in JSON or CSV directly satisfies this requirement. Other controls like DLP, encryption, or retention policies address different GDPR obligations and do not enable data subject access requests.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implement an API endpoint that allows authenticated data subjects to download their personal data in JSON or CSV format.
Why this is correct
The GDPR right to data portability requires that data subjects can receive their personal data in a structured, commonly used, and machine-readable format. An API endpoint that returns data in JSON or CSV satisfies this requirement and provides a scalable, automated way to fulfill data subject requests. This is the most direct technical control for the requirement.
- ✗
Establish a records retention policy that automatically deletes personal data after a defined period.
Why it's wrong here
A records retention policy addresses data minimization and storage limitation principles under GDPR, but it does not fulfill the right to data portability. Deleting data after a period may actually conflict with the requirement to provide data upon request if the request occurs before deletion. Retention policies are about lifecycle management, not access fulfillment.
- ✗
Deploy a data loss prevention (DLP) solution to monitor and block unauthorized exfiltration of personal data.
Why it's wrong here
A DLP solution monitors and blocks data exfiltration, but it does not enable data subjects to request and receive their personal data in a machine-readable format. The GDPR right to data portability requires a proactive mechanism to export personal data upon request, which DLP does not provide. DLP is a preventive control, not a data subject access fulfillment tool.
- ✗
Configure database encryption at rest using Transparent Data Encryption (TDE) to protect personal data.
Why it's wrong here
Database encryption at rest protects data confidentiality if the storage medium is compromised, but it does not enable data subjects to access or receive their data. The GDPR right to data portability is about giving individuals control over their data, not about protecting it from physical theft. Encryption is a security control, not a portability mechanism.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.