Courseiva

CAS-004 Governance, Risk, and Compliance Practice Question

A multinational retailer must transfer employee personal data from its European Union subsidiary to a processing center in a country without an adequacy decision. Legal counsel wants a transfer mechanism that imposes enforceable data protection obligations on the importer and includes a documented transfer impact assessment. Which mechanism best matches these requirements?

⚠ Common exam trap

The trap here is treating any listed transfer mechanism as automatically sufficient, when the scenario specifically requires enforceable importer obligations plus a documented transfer impact assessment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Standard Contractual Clauses supplemented by a transfer impact assessment and additional safeguards

Cross-border transfers outside an adequacy decision require a valid Chapter V mechanism. Standard Contractual Clauses impose enforceable obligations on the importer, and following Schrems II they must be accompanied by a transfer impact assessment and supplementary measures where destination laws undermine protection. Consent, codes of conduct, and improperly approved Binding Corporate Rules do not meet the combined contractual and assessment requirements described.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    An explicit consent obtained from each employee once at the time of hire for all future transfers

    Why it's wrong here

    Consent is a derogation intended for occasional, non-repetitive transfers, not routine multinational HR data flows, and it must be freely given, specific, and withdrawable. Using a single blanket consent at hire for indefinite future transfers is invalid in an employment context due to power imbalance and does not provide the enforceable importer obligations the counsel requested.

  • ✗

    A certification under an approved code of conduct registered with the subsidiary's data protection authority

    Why it's wrong here

    Approved codes of conduct can support transfers only when the importer makes binding and enforceable commitments, and the mechanism is still maturing with limited approved codes. It does not by itself deliver the specific enforceable contractual obligations and transfer impact assessment the counsel demanded, making it a weaker fit than clauses designed precisely for that purpose.

  • ✓

    Standard Contractual Clauses supplemented by a transfer impact assessment and additional safeguards

    Why this is correct

    Standard Contractual Clauses are pre-approved contractual terms that create enforceable obligations on the data importer, and after the Schrems II ruling they must be paired with a transfer impact assessment of the destination country's laws plus supplementary technical or organizational measures when needed. This combination directly satisfies the requirement for enforceable importer obligations and a documented assessment.

  • ✗

    Binding Corporate Rules approved only by the subsidiary's local supervisory authority without any further analysis

    Why it's wrong here

    Binding Corporate Rules are a valid transfer tool for intra-group transfers, but they require approval from the competent supervisory authority and are not simply granted by a local authority on request. They also do not eliminate the need to assess destination-country surveillance laws, so this option misstates both the approval path and the assessment obligation in the scenario.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.