CAS-004 Governance, Risk, and Compliance Practice Question
A retail company is building a new mobile application that will collect customer location data. The legal team asks the security manager to ensure the design follows privacy by design principles from the earliest stages. Which action best demonstrates privacy by design in this scenario?
⚠ Common exam trap
The trap here is equating privacy by design with encryption alone, when it actually requires proactive minimization and purpose limitation before development begins.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Perform a privacy impact assessment and design data minimization controls before development begins
Privacy by design means embedding privacy into systems and processes from the outset, not retrofitting it later. An early privacy impact assessment combined with data minimization controls during design directly implements that principle. The other actions either collect excessive data, react after release, or rely on a single control that does not address purpose limitation and minimization, so they do not meet the legal team's request.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add a privacy policy link to the application store listing after the application is released
Why it's wrong here
Publishing a privacy policy is a transparency and notice activity, but doing it after release is reactive and does not embed privacy into the design. Privacy by design emphasizes proactive measures during requirements, architecture, and development. A policy link alone does not reduce data collection, limit retention, or implement safeguards, so it does not satisfy the legal team's request to follow privacy by design from the earliest stages.
- ✗
Encrypt location data at rest and assume that encryption alone satisfies privacy requirements
Why it's wrong here
Encryption is an important security control, but privacy by design is broader than confidentiality. It includes purpose limitation, data minimization, retention limits, and user control. Encrypting data that should not have been collected in the first place does not address the underlying privacy risk. In this scenario, the organization must first decide what location data is truly necessary and then apply encryption as one layer among several.
- ✓
Perform a privacy impact assessment and design data minimization controls before development begins
Why this is correct
Privacy by design requires that privacy be considered proactively and embedded into the design rather than added after deployment. Conducting a privacy impact assessment early identifies risks and informs decisions about what data to collect, how long to keep it, and how to protect it. Designing data minimization controls at the start directly implements the principle of limiting collection to what is necessary and demonstrates privacy by design in this scenario.
- ✗
Collect precise location data continuously so that future marketing features have a rich data set
Why it's wrong here
Collecting more data than is needed for a defined purpose violates the data minimization principle, which is a core element of privacy by design. Retaining precise location data for unspecified future uses increases privacy risk and regulatory exposure. Privacy by design calls for limiting collection to what is necessary for the stated purpose and for implementing safeguards such as aggregation or coarsening rather than maximizing the data set.
Visual reference
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.