CAS-004 Governance, Risk, and Compliance Practice Question
A multinational retailer must comply with PCI DSS v4.0 for its cardholder data environment. The security manager is asked to define the scope of the CDE. Which of the following best describes the first step in scoping the CDE according to PCI DSS?
⚠ Common exam trap
The trap here is assuming that network segmentation or penetration testing is the first step in PCI DSS scoping, when in fact a complete data-flow inventory must precede any scope-reduction technique.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identify all system components that store, process, or transmit cardholder data (CHD) or sensitive authentication data (SAD).
The correct answer is to identify all system components that store, process, or transmit CHD or SAD. PCI DSS scoping requires a thorough inventory of people, processes, and technologies that handle cardholder data or could impact its security. This inventory forms the basis for defining the CDE and determining which requirements apply. Without it, segmentation and validation efforts are misdirected.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Conduct a penetration test on all internet-facing systems to determine which ones are in scope.
Why it's wrong here
Penetration testing is a requirement for certain PCI DSS controls, but it is not the initial scoping step. Penetration testing helps validate the security of systems already identified as in scope. Using it to determine scope would be inefficient and could miss systems that do not have external exposure but still handle CHD internally.
- ✗
Review the PCI DSS Self-Assessment Questionnaire (SAQ) to determine which requirements apply.
Why it's wrong here
The SAQ is a validation tool used after scoping to document compliance. It does not help identify which systems are in scope. Selecting an SAQ requires knowing the scope first. Reviewing the SAQ before scoping would be premature and could lead to an inaccurate assessment of applicable requirements.
- ✓
Identify all system components that store, process, or transmit cardholder data (CHD) or sensitive authentication data (SAD).
Why this is correct
PCI DSS scoping begins with identifying all system components that store, process, or transmit CHD or SAD, as well as those that could impact the security of the CDE. This includes connected systems and security-impacting systems. Without this inventory, the scope cannot be accurately defined, and the assessment will be incomplete. This is the foundational step mandated by PCI DSS.
- ✗
Segment the network by placing all cardholder data systems behind a firewall and then document the segmentation.
Why it's wrong here
Segmentation is a method to reduce scope, but it is not the first step. You must first identify where CHD resides before you can effectively segment. Placing systems behind a firewall without knowing what data they handle may leave other systems in scope or incorrectly excluded. Segmentation follows the inventory and scoping process, not precedes it.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.