CAS-004 Governance, Risk, and Compliance Practice Question
A multinational manufacturing firm is expanding into the European Union and must demonstrate accountability for personal data processing under GDPR. The Chief Privacy Officer asks the security team to implement a mechanism that proves the organization's compliance posture to supervisory authorities without requiring prior authorization from them. Which of the following should the team implement?
⚠ Common exam trap
The trap here is assuming that Standard Contractual Clauses provide the same group-wide accountability as Binding Corporate Rules, when SCCs are transfer-specific and do not cover intra-group processing comprehensively.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Binding Corporate Rules (BCRs)
Binding Corporate Rules are a GDPR-approved mechanism for multinational corporations to establish a comprehensive, legally binding framework for intra-group data transfers and accountability. They are approved by supervisory authorities and eliminate the need for separate authorizations, directly addressing the need to demonstrate compliance posture. SCCs are transfer-specific, Privacy Shield is invalid, and consent is a processing basis, not an accountability mechanism.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Consent from data subjects
Why it's wrong here
Consent is one of several lawful bases for processing, but it is not a mechanism to demonstrate accountability to supervisory authorities. It can be withdrawn and does not provide a structural compliance framework. For a multinational's complex processing activities, relying solely on consent is impractical and does not satisfy the accountability principle under GDPR.
- ✗
Standard Contractual Clauses (SCCs)
Why it's wrong here
SCCs are contractual clauses used for transfers of personal data to third countries, but they do not provide an overarching accountability mechanism for a corporate group's internal processing. They require separate agreements per transfer and do not demonstrate a comprehensive compliance posture to supervisory authorities. For a multinational's intra-group data flows, SCCs are less efficient than a group-wide framework.
- ✗
Privacy Shield certification
Why it's wrong here
Privacy Shield was invalidated by the Court of Justice of the European Union in 2020, so it no longer provides a valid transfer mechanism. It was a US-EU framework for transatlantic data transfers, not a general accountability tool for a multinational's global operations. Relying on it would expose the organization to legal risk and non-compliance.
- ✓
Binding Corporate Rules (BCRs)
Why this is correct
BCRs are approved by the competent supervisory authority and serve as a documented, enforceable framework for intra-group transfers and accountability. They demonstrate GDPR compliance without needing case-by-case authorization for each transfer, making them suitable for a multinational expanding into the EU. They are specifically designed for corporate groups with multiple entities, providing a transparent and legally binding mechanism.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.