Courseiva

CAS-004 Governance, Risk, and Compliance Practice Question

A newly hired CISO is reviewing the organization's risk register and finds that a legacy payment application carries a high inherent risk rating, but after accounting for the web application firewall, tokenization, and quarterly penetration testing already in place, the rating drops substantially. Which risk concept explains the difference between these two ratings?

⚠ Common exam trap

The trap here is conflating residual risk with risk appetite, since both involve deciding whether an exposure is acceptable, when only residual risk measures what remains after controls are applied.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Residual risk

The high rating represents inherent risk, the exposure before safeguards are considered. Once the firewall, tokenization, and recurring penetration tests are factored in, the remaining exposure is residual risk. Risk appetite is a tolerance threshold, inherent risk is the pre-control baseline, and control risk concerns control failure rather than the net exposure level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Inherent risk

    Why it's wrong here

    Inherent risk is the exposure that exists before any controls are applied, which the scenario already identifies as the high initial rating. The question asks what explains the lower rating after controls are considered, so inherent risk describes the starting point rather than the difference being examined.

  • ✓

    Residual risk

    Why this is correct

    Residual risk is what remains after existing controls are applied to an inherent risk. The firewall, tokenization, and recurring penetration tests reduce the likelihood and impact of exploitation, so the lower rating reflects residual risk. The scenario explicitly describes inherent risk dropping once current controls are considered, which is the definition of residual risk.

  • ✗

    Control risk

    Why it's wrong here

    Control risk refers to the possibility that a control fails to prevent or detect an issue as designed, or that testing reliance on controls is misplaced. It is a component used in audit and risk modeling, not the term for the post-control exposure level itself. The scenario's reduced rating represents remaining exposure, which is classified differently.

  • ✗

    Risk appetite

    Why it's wrong here

    Risk appetite expresses how much risk leadership is willing to accept in pursuit of objectives. It is a threshold used to decide whether a given exposure is tolerable, not a measure of how much controls reduce an identified risk. The scenario describes a numerical rating changing because controls exist, which is unrelated to the organization's stated willingness to accept risk.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.