Courseiva

CAS-004 Governance, Risk, and Compliance Practice Question

A security architect is designing a new cloud-native application for a healthcare provider. The application will process protected health information (PHI) and must comply with HIPAA. The architect must ensure that all data at rest and in transit is encrypted, and that access is logged and auditable. Which of the following controls BEST meets the requirement for auditing access to PHI?

⚠ Common exam trap

The trap here is assuming that infrastructure logging tools like CloudTrail or WAF logs are sufficient for HIPAA audit controls, when they lack the granularity to track access to specific PHI records.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement application-level logging that records user identity, timestamp, and the specific PHI records accessed, and store logs securely.

HIPAA's Security Rule requires audit controls that record and examine activity in systems containing ePHI. Application-level logging that captures user identity, timestamp, and the specific PHI accessed provides the necessary audit trail. Other controls like CloudTrail, AWS Config, or WAFs address different aspects of security but do not provide the granular access auditing required for PHI.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implement application-level logging that records user identity, timestamp, and the specific PHI records accessed, and store logs securely.

    Why this is correct

    HIPAA requires audit controls that record and examine activity in information systems containing or using electronic protected health information (ePHI). Application-level logging that captures user identity, timestamp, and the specific records accessed directly satisfies this. Storing logs securely ensures integrity and availability for audits. This is the most precise control for auditing access to PHI.

  • ✗

    Use AWS Config to monitor resource configurations and alert on changes to security groups.

    Why it's wrong here

    AWS Config monitors resource configurations and can alert on changes, but it does not track access to PHI. It is a configuration compliance tool, not an audit log for data access. While useful for maintaining a secure baseline, it does not fulfill the requirement to log and audit access to patient data. The focus is on configuration state, not user activity.

  • ✗

    Deploy a web application firewall (WAF) to log all incoming HTTP requests and block malicious traffic.

    Why it's wrong here

    A WAF logs incoming requests and can help detect attacks, but it does not provide an audit trail of authenticated user access to specific PHI records. WAF logs are primarily for security monitoring, not for compliance auditing of data access. They may capture URLs but not the identity of the user or the data accessed. This control addresses network threats, not access auditing.

  • ✗

    Enable AWS CloudTrail to log all API activity and store logs in an immutable S3 bucket.

    Why it's wrong here

    CloudTrail logs API activity, which is useful for auditing infrastructure changes, but it does not capture application-level access to PHI. For HIPAA auditing, you need logs of who accessed what patient data and when. CloudTrail alone does not provide that granularity. It is a foundational control but insufficient for the specific requirement of auditing access to PHI.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.