Courseiva

CAS-004 Governance, Risk, and Compliance Practice Question

A security architect is designing a new system that processes sensitive customer data. The organization must comply with multiple regulations, including GDPR and PCI DSS. The architect needs to ensure that data protection controls are integrated from the outset. Which approach best aligns with the principle of privacy by design?

⚠ Common exam trap

The trap here is equating consent or encryption with privacy by design, when the principle fundamentally requires proactive risk assessment and integration of privacy controls throughout the development lifecycle.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conduct a data protection impact assessment (DPIA) before development begins.

Conducting a data protection impact assessment before development begins is a core privacy by design practice. It proactively identifies privacy risks and ensures controls are integrated into the system architecture from the start. Encryption after deployment, default settings, and consent are either reactive or insufficient to meet the principle of privacy by design.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Obtain consent from all customers for data processing.

    Why it's wrong here

    Consent is one lawful basis for processing under GDPR, but it is not a design approach. Privacy by design involves technical and organizational measures like data minimization, pseudonymization, and access controls. Consent alone does not ensure data protection is integrated into the system architecture. It also may not be feasible for all processing activities, such as those required for contract fulfillment.

  • ✗

    Rely on the cloud provider's default security settings.

    Why it's wrong here

    Default settings are often not sufficient for sensitive data and may not meet regulatory requirements. Privacy by design requires the organization to take responsibility for configuring controls appropriately. Relying on defaults shifts responsibility and can lead to non-compliance. The architect should design specific controls tailored to the regulations and data sensitivity.

  • ✓

    Conduct a data protection impact assessment (DPIA) before development begins.

    Why this is correct

    A DPIA is a GDPR requirement for processing that likely results in high risk to data subjects. It identifies and mitigates privacy risks early in the design phase, directly implementing privacy by design. By conducting it before development, the architect ensures controls are built in, not bolted on, and addresses multiple regulatory requirements proactively.

  • ✗

    Implement encryption for data at rest after the system is deployed.

    Why it's wrong here

    Encrypting data at rest is a valuable control, but doing it after deployment is reactive and does not embody privacy by design, which requires proactive integration. Privacy by design mandates considering privacy throughout the development lifecycle, not retrofitting controls. This approach may also be more costly and less effective than designing encryption from the start.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.