CAS-004 Governance, Risk, and Compliance Practice Question
A multinational retailer must demonstrate compliance with the EU General Data Protection Regulation while also honoring local data-residency laws in a country where it operates. Legal counsel advises that a single global retention schedule cannot satisfy both regimes. Which governance artifact should the security manager produce to reconcile these competing obligations?
⚠ Common exam trap
The trap here is treating any privacy-focused document, such as a DPIA, as the universal answer for multi-jurisdictional compliance, when the specific need is an artifact that maps obligations per data category and jurisdiction.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A records retention and residency matrix mapping each data category to jurisdictional requirements
Where global retention rules collide with local residency mandates, the organization needs a structured mapping of each data category to the retention period and permitted location required by every jurisdiction involved. A retention and residency matrix makes the conflicts visible and provides auditable, differentiated handling, whereas privacy assessments, use policies, and continuity plans address risk, behavior, and availability rather than reconciling legal obligations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A records retention and residency matrix mapping each data category to jurisdictional requirements
Why this is correct
A retention and residency matrix ties each data category to the specific retention period and storage location mandated by every applicable jurisdiction, making conflicts explicit and resolvable. This is exactly the governance artifact needed when a single global schedule cannot satisfy GDPR and local residency law, because it allows differentiated handling per jurisdiction while preserving an auditable rationale.
- ✗
An updated acceptable use policy signed by all employees who handle customer data
Why it's wrong here
An acceptable use policy governs how employees may use organizational assets and data, but it does not encode jurisdictional retention periods or residency constraints. Signing it creates awareness and accountability, yet it cannot resolve the substantive legal conflict between GDPR retention limits and local residency mandates, so it fails to satisfy the requirement for a reconciling governance artifact.
- ✗
A business continuity plan that documents failover of the retailer's EU data centers
Why it's wrong here
A business continuity plan addresses availability and recovery of systems and data, not the lawful retention or geographic placement of personal data. Failover procedures might even move data across borders, worsening a residency conflict. This artifact answers how operations continue after disruption, which is unrelated to reconciling GDPR and local data-residency obligations.
- ✗
A data protection impact assessment covering the retailer's cross-border transfers
Why it's wrong here
A data protection impact assessment identifies and mitigates privacy risks for high-risk processing, such as large-scale profiling or cross-border transfer. It documents risk and controls, but it does not itself reconcile conflicting retention or residency obligations into an operational rule set. The scenario calls for a governance artifact that maps obligations to enforceable requirements, which a DPIA alone does not provide.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.