Courseiva

CAS-004 Governance, Risk, and Compliance Practice Question

An organization is developing a policy exception management process. Which three of the following are essential components of an effective exception process? (Choose three.)

⚠ Common exam trap

CAS-005 often tests the confusion between policy enforcement and exception management, leading candidates to select technical controls as an essential component when the focus should be on governance elements like justification, risk assessment, and expiration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Documented business justification for the exception

Option A is correct because every exception must be supported by a documented business justification that explains why the policy cannot be met and what compensating value the exception provides, giving approvers the rationale needed to make an informed decision. Option B is correct because exceptions must have an expiration date (or defined review period) so they are temporary and time-bound, preventing them from becoming permanent de facto policy and forcing periodic re-evaluation. Option D is correct because a risk assessment quantifies the residual risk introduced by the exception, allowing management to accept that risk knowingly and to define compensating controls. Option C is not essential to the exception process itself; automatic enforcement is a policy implementation mechanism, and an exception by definition suspends or modifies enforcement rather than applying it. Option E is not essential because attaching the entire policy hierarchy is unnecessary documentation; the exception only needs to reference the specific policy clause being excepted, not reproduce the whole hierarchy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Documented business justification for the exception

    Why this is correct

    A documented business justification records why the policy cannot be met and what compensating value the exception delivers. It satisfies the need for an auditable, defensible reason before approvers authorise deviation from the standard control.

  • ✓

    An expiration date for the exception

    Why this is correct

    An expiration date enforces time-bound risk acceptance, ensuring each exception is reviewed before it lapses rather than persisting indefinitely. This directly satisfies the scenario's need for controlled, auditable exceptions, since permanent waivers accumulate unmanaged risk. The date also triggers reassessment, letting the organization confirm the original justification still holds or remediate the underlying control gap.

  • ✗

    Automatic enforcement of policy via technical controls

    Why it's wrong here

    Automatic enforcement removes the exception entirely, contradicting the process's purpose of permitting documented deviations. It is tempting because enforcement is central to policy management, and it would be correct when implementing baseline controls rather than governing approved exceptions.

  • ✓

    A risk assessment of the exception

    Why this is correct

    A risk assessment quantifies the exposure introduced by granting the exception, enabling informed acceptance rather than blind approval. It satisfies the stem's requirement for an essential component by documenting the compensating controls and residual risk, ensuring each exception is justified, time-bound and reviewed before renewal.

  • ✗

    A copy of the entire policy hierarchy

    Why it's wrong here

    Reproducing the whole policy hierarchy adds no decision criteria for granting, approving, or expiring exceptions. It is tempting because exceptions must reference the policy being waived, and a full copy would be correct when publishing policy documentation rather than operating an exception workflow.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.