Courseiva

CAS-004 Governance, Risk, and Compliance Practice Question

A security governance team is drafting a new data handling standard for a research subsidiary that processes both regulated personal data and proprietary intellectual property. The team must select controls that directly support data classification and labeling objectives. Which two of the following controls best fulfill this requirement? (Choose two.)

⚠ Common exam trap

The trap here is selecting training or access control because they feel foundational to data protection, when the question specifically asks for controls that perform classification and labeling rather than consume or support them indirectly.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Automated sensitive-data discovery that tags files with the appropriate classification label at creation

Controls that directly support classification and labeling must either identify and mark data according to its sensitivity or enforce handling based on those markings. Automated discovery that tags data at creation and template-embedded labels enforced through data loss prevention both do this. Firewall reviews, awareness training, and role-based access control address network hygiene, human behavior, and authorization respectively, but none of them classify or label information assets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Automated sensitive-data discovery that tags files with the appropriate classification label at creation

    Why this is correct

    Automated discovery that assigns classification labels at the point of creation enforces the labeling objective at the earliest possible moment and removes reliance on users to remember the scheme. It directly operationalizes the classification standard by ensuring every artifact carries its sensitivity marking, which downstream controls such as encryption and access rules can then act upon consistently.

  • ✗

    Role-based access control applied to the subsidiary's file shares

    Why it's wrong here

    Role-based access control limits who can reach data but does not determine how sensitive each item is or mark it accordingly. It is a downstream consumer of classification, not a mechanism that creates or enforces labels, so on its own it fails to fulfill the labeling objective described in the standard.

  • ✓

    Mandatory classification labels embedded in document templates and enforced by data loss prevention policies

    Why this is correct

    Embedding labels in templates makes classification the default rather than an optional step, and enforcing them through data loss prevention ensures the marking drives real handling decisions such as blocking external transfer of restricted content. Together these mechanisms turn the classification scheme from guidance into an enforceable control aligned with the standard's objective.

  • ✗

    A quarterly review of firewall rule sets against the approved network baseline

    Why it's wrong here

    Firewall rule reviews validate network access controls and reduce configuration drift, but they do not classify or label data. This activity belongs to network security governance rather than a data handling standard, so it does not satisfy the objective of ensuring data is properly categorized and marked according to sensitivity.

  • ✗

    Annual security awareness training that mentions the existence of the data classification policy

    Why it's wrong here

    Awareness training creates understanding but does not itself classify or label data. A single annual mention of the policy is especially weak because it neither enforces handling rules nor applies markings to information assets, so it cannot satisfy the standard's requirement for controls that directly support classification and labeling objectives.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.