Courseiva

CAS-004 Governance, Risk, and Compliance Practice Question

A security manager is implementing a policy exception management process. Which TWO of the following are essential components of an effective exception management process?

⚠ Common exam trap

The trap is selecting options that sound efficient (automatic approval, immediate policy revision) but actually undermine the control and accountability that exception management is meant to provide.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A defined expiration date for each exception

An effective exception management process requires a formal request and approval workflow (C) so that each exception is documented, justified, risk-assessed, and authorized by the appropriate authority rather than granted informally. It also requires a defined expiration date for each exception (B), ensuring exceptions are temporary, time-bound, and reviewed or renewed before they become permanent policy gaps. Together, these components provide accountability and limit risk exposure. Option A is wrong because blanket denial of all exceptions is impractical and prevents legitimate business needs from being addressed. Option D is wrong because automatic approval of temporary workarounds bypasses risk review and oversight. Option E is wrong because immediately revising policy to eliminate every exception is not always feasible and does not constitute an exception management process.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A policy that all exceptions are denied

    Why it's wrong here

    Denying every exception removes the risk-acceptance mechanism, so genuine business-justified deviations cannot be tracked or time-limited. It is tempting as a zero-trust stance, but a deny-all policy is correct only where no compensating controls or documented risk ownership exist.

  • ✓

    A defined expiration date for each exception

    Why this is correct

    Expiration dates enforce time-bound risk acceptance, ensuring exceptions are reviewed and renewed rather than persisting indefinitely. This directly satisfies the process requirement for periodic reassessment, preventing stale waivers from silently accumulating. Without expiry, exceptions become permanent policy bypasses, undermining governance and auditability across Microsoft Entra ID and other controlled environments.

  • ✓

    A formal request and approval workflow

    Why this is correct

    A formal request and approval workflow ensures every exception is documented, justified and authorised by the appropriate authority before it takes effect. This satisfies the stem's requirement for an essential component by creating accountability and an auditable trail, preventing undocumented risk acceptance that would otherwise bypass policy controls entirely.

  • ✗

    Automatic approval for temporary workarounds

    Why it's wrong here

    Automatic approval bypasses the risk assessment and authorisation that make exceptions auditable and time-bound. It is tempting to speed up temporary workarounds, but automation is correct only for pre-approved low-risk categories with defined expiry and compensating controls already validated.

  • ✗

    Immediate policy revision to eliminate the need for exceptions

    Why it's wrong here

    Revising policy immediately to remove the need for exceptions defeats the controlled deviation process and cannot address every legitimate case. It is tempting as a root-cause fix, but policy revision is correct only after exceptions reveal a systemic gap warranting permanent change.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.