CAS-004 Governance, Risk, and Compliance Practice Question
A multinational retailer must comply with the EU General Data Protection Regulation for its European customers and with several U.S. state privacy laws for its American customers. The privacy team wants a single internal control framework that satisfies the strictest common denominator across all jurisdictions. Which approach should the privacy team take?
⚠ Common exam trap
The trap here is assuming that a single framework must be chosen from one law verbatim, when harmonization around the strictest regime with mapped add-ons is the accepted approach.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Adopt the requirements of the EU General Data Protection Regulation as the baseline control set and map additional state-law obligations onto it.
Harmonizing around the most stringent applicable regime gives the retailer one control set that satisfies every jurisdiction, since stricter requirements generally encompass weaker ones. Layering jurisdiction-specific obligations onto that baseline closes residual gaps, such as opt-out rights unique to certain state laws, while avoiding the cost and inconsistency of parallel compliance programs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement each jurisdiction's requirements as a separate, fully independent control set managed by a regional compliance officer.
Why it's wrong here
Building fully independent control sets multiplies audit effort, produces conflicting procedures, and creates gaps where controls overlap; harmonizing around the strictest requirement is far more efficient and defensible than maintaining parallel programs that inevitably drift apart.
- ✗
Apply the least restrictive state privacy law as the baseline because it imposes the fewest operational changes.
Why it's wrong here
Using the least restrictive law as the baseline would leave the organization non-compliant in stricter jurisdictions, exposing it to regulatory fines and enforcement actions; a baseline must satisfy the highest obligation, not the lowest, or the framework fails in the markets that matter most.
- ✓
Adopt the requirements of the EU General Data Protection Regulation as the baseline control set and map additional state-law obligations onto it.
Why this is correct
GDPR is generally the most stringent regime the retailer faces, so using it as the baseline and layering stricter state-specific duties (for example, opt-out of sale or targeted advertising) onto that control set produces one harmonized framework that satisfies every jurisdiction without duplicating effort.
- ✗
Defer framework selection until each regulator publishes an approved cross-mapping, then adopt that mapping verbatim.
Why it's wrong here
Waiting for regulators to publish an approved cross-mapping is not a viable strategy because no single authoritative mapping covers all these regimes, and the organization would operate without controls for an indefinite period while enforcement timelines continue to run.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.