Courseiva

CAS-004 Governance, Risk, and Compliance Practice Question

A regional bank is preparing for its annual regulatory examination and must demonstrate that its third-party risk management program is mature. The examiner asks which practices provide continuous, rather than point-in-time, oversight of critical vendors. (Choose two.)

⚠ Common exam trap

Watch out — candidates often confuse initial due diligence artifacts, such as an onboarding questionnaire, with the recurring validation and contractual visibility that constitute ongoing oversight.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Establishing contractual rights to audit, receive breach notifications within defined timeframes, and obtain regular independent assurance reports

Continuous third-party oversight combines recurring independent validation with enforceable contractual information rights. Periodic assessments with remediation tracking confirm that identified weaknesses are corrected, while audit rights, breach notification clauses, and independent assurance requirements keep the bank informed between reviews. One-time questionnaires, spend-based ranking, and reliance on vendor marketing all capture stale or unverified information.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Establishing contractual rights to audit, receive breach notifications within defined timeframes, and obtain regular independent assurance reports

    Why this is correct

    Contractual audit rights, notification obligations, and requirements for independent assurance such as SOC 2 reports give the bank ongoing visibility into vendor control status between assessments. These provisions create enforceable expectations and information flow, so the bank learns of control changes or incidents without waiting for the next scheduled review, which is exactly the continuous oversight the examiner seeks.

  • ✗

    Relying on the vendor's own marketing materials and public certifications page to confirm its security posture

    Why it's wrong here

    Marketing content and public badge pages are self-selected and unverified, so they provide no reliable evidence about the controls actually protecting the bank's data. Examiners expect independent validation through reports, assessments, or contractual assurances, not vendor-authored promotional claims, which is why this practice fails to demonstrate meaningful continuous oversight.

  • ✗

    Ranking vendors solely by annual contract value and assigning oversight resources proportionally to spend

    Why it's wrong here

    Contract value does not correlate with the sensitivity of data accessed or the operational criticality of the vendor, so spend-based ranking can under-supervise a low-cost vendor holding regulated customer data. Risk tiering should consider data classification, system access, and business dependency, making this approach a misallocation of oversight rather than a continuous monitoring practice.

  • ✗

    Collecting a completed security questionnaire from each vendor once during initial onboarding and archiving the response

    Why it's wrong here

    A questionnaire completed at onboarding captures the vendor's posture on a single date and becomes stale as the vendor's environment, personnel, and controls change. Archiving it without refresh means the bank relies on outdated self-reported information, so this practice reflects initial due diligence rather than the continuous oversight the examination is probing for.

  • ✓

    Requiring critical vendors to submit to annual on-site or virtual control assessments with documented findings and remediation tracking

    Why this is correct

    Recurring assessments with tracked remediation close the loop between identifying a control weakness and confirming it was fixed, which examiners view as evidence of active oversight. Annual reviews keep the risk picture current for critical relationships, and the remediation tracking demonstrates that findings drive action rather than being filed and forgotten, which distinguishes a mature program from a one-time due diligence exercise.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.