CAS-004 Governance, Risk, and Compliance Practice Question
A software company suffers a breach exposing customer records. Legal counsel determines the incident meets the regulatory threshold for notification. The incident response lead must decide which external parties receive notice and within what timeframe, balancing regulatory duties against contractual obligations. Which action best satisfies the organization's notification obligations?
⚠ Common exam trap
The trap here is believing that notification can wait until the forensic investigation is complete or the criminal case ends, when regulatory and contractual clocks start at awareness regardless of investigation status.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Notify regulators and affected data subjects within the applicable legal timeframes, and notify contractual partners per their agreements
Breach notification obligations run in parallel and on different clocks. Regulators and affected individuals must be notified within statutory windows measured from awareness, while contractual partners may have their own deadlines triggered by the same event. Notifying all required parties within their respective timeframes is the only approach that satisfies both legal and contractual duties, whereas waiting for investigation closure or substituting public notices fails those deadlines.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Notify regulators and affected data subjects within the applicable legal timeframes, and notify contractual partners per their agreements
Why this is correct
Regulatory breach-notification regimes impose fixed deadlines measured from awareness, and contracts with partners often impose separate, sometimes tighter deadlines. Notifying regulators, affected individuals, and contractually entitled parties within each applicable window satisfies the full set of obligations. This parallel approach respects that different recipients have different triggers and timelines, which is exactly what the incident lead must coordinate.
- ✗
Notify law enforcement and defer all other notifications until the criminal case concludes
Why it's wrong here
Engaging law enforcement may be required or advisable, but it generally does not suspend statutory or contractual duties to notify regulators and affected individuals within their deadlines. Deferring those notices until a case concludes could take months or years, far beyond regulatory windows. This approach confuses a parallel obligation with a justification for delay and would leave the company in violation.
- ✗
Notify only the affected customers once the forensic investigation is fully complete
Why it's wrong here
Waiting for a fully complete investigation can easily exceed regulatory deadlines, which are typically measured in days from awareness, not from investigation closure. Many regimes require notification even when facts are still developing, with updates provided later. Delaying until the root cause is confirmed risks fines and lost trust, so this approach fails to meet the legal timelines the scenario requires.
- ✗
Publish a general notice on the corporate website in place of direct notification
Why it's wrong here
A website notice does not satisfy regimes that require direct notification to affected individuals and to regulators. Substitute notice is typically permitted only in narrow circumstances, such as when contact information is unavailable or the population is very large. Relying on a public posting alone would leave the company non-compliant with both statutory duties and contractual notification clauses, exposing it to penalties.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.