CAS-004 Governance, Risk, and Compliance Practice Question
A security governance committee is reviewing the organization's risk register after a merger. The committee wants to apply risk treatment strategies that transfer or share risk with another party rather than reducing it internally. Which two actions represent risk transference? (Choose two.)
⚠ Common exam trap
Candidates often confuse risk reduction controls, such as deploying detection agents, with transference, which requires another party to absorb the consequence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Outsourcing the payment card processing function to a PCI DSS validated third-party service provider under contract.
Risk transference shifts the financial or operational consequence to another party. Cyber insurance and outsourcing card processing to a validated provider both move risk to external entities through contracts or policies, whereas detection controls, acceptance, and diversification change or retain the risk internally.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploying endpoint detection and response agents across all workstations to catch malicious activity earlier.
Why it's wrong here
Endpoint detection and response is a preventive and detective control that lowers the likelihood and impact of incidents internally. It reduces risk rather than transferring it, because the organization still owns and operates the control and retains the residual consequence if it fails.
- ✗
Diversifying the cloud provider portfolio so no single vendor outage halts all critical services.
Why it's wrong here
Diversifying providers reduces dependence and lowers the aggregate impact of a single failure, which is risk reduction or avoidance of concentration risk. It does not shift liability or financial consequence to another party, so it does not qualify as transference under the committee's criteria.
- ✓
Outsourcing the payment card processing function to a PCI DSS validated third-party service provider under contract.
Why this is correct
Contracting a validated service provider to handle card processing moves operational responsibility and much of the associated risk to that vendor. This is transference or sharing, since the provider assumes defined obligations and liabilities through the agreement, though the organization retains oversight and compliance accountability.
- ✗
Accepting the risk of a legacy application because remediation cost exceeds the potential loss.
Why it's wrong here
Accepting a risk means the organization consciously retains it with no third-party involvement. This is the acceptance treatment, not transference, since no external party absorbs the financial or operational consequence and the organization bears the full impact if the risk materializes.
- ✓
Purchasing a cyber liability insurance policy that covers breach response costs and regulatory fines where insurable.
Why this is correct
Cyber liability insurance shifts the financial consequence of a realized risk to the insurer in exchange for premiums. This is the classic transference treatment because the organization pays a third party to absorb the monetary impact, even though the underlying likelihood of an incident is unchanged.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.