CAS-004 Governance, Risk, and Compliance Practice Question
A security compliance officer is mapping the organization's controls to the NIST Cybersecurity Framework (CSF) 2.0. The officer needs to ensure that the organization's governance and risk management processes are adequately covered. Which CSF 2.0 function primarily addresses the development and implementation of cybersecurity policies, procedures, and risk management strategies?
⚠ Common exam trap
The trap here is selecting Identify because it also deals with risk, but Govern specifically covers policy and strategy development.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Govern (GV)
CSF 2.0 introduced the Govern function to emphasize cybersecurity governance and risk management. It encompasses organizational context, risk management strategy, roles and responsibilities, and policy. This function ensures that cybersecurity is integrated into enterprise risk management, making it the correct choice for policy and procedure development.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Detect (DE)
Why it's wrong here
The Detect function defines activities to identify the occurrence of a cybersecurity event. It is operational and reactive, not focused on governance or policy creation. Detection relies on the governance and protection layers to be effective, so it is not the primary function for policy development.
- ✓
Govern (GV)
Why this is correct
The Govern function, new in CSF 2.0, focuses on establishing and monitoring cybersecurity strategy, policies, and risk management. It ensures that governance structures are in place to support the other functions. This directly addresses the development and implementation of policies and procedures for managing risk.
- ✗
Identify (ID)
Why it's wrong here
The Identify function focuses on understanding the organization's assets, risks, and vulnerabilities. While it informs governance, it does not primarily address the development of policies and procedures. Governance is a broader, higher-level function that sets the tone and direction for risk management.
- ✗
Protect (PR)
Why it's wrong here
The Protect function covers safeguards to ensure delivery of critical services, such as access control and awareness training. It implements controls but does not establish the governance framework. Policy development and risk strategy are foundational and precede protective measures.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.