CAS-004 Governance, Risk, and Compliance Practice Question
An organization is implementing a privacy program based on privacy by design. Which principle requires that privacy controls be integrated into the system's default settings?
⚠ Common exam trap
The trap is mixing up the seven privacy-by-design principles; candidates often pick 'privacy embedded into design' when the question specifically mentions default settings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Privacy as the default setting
Privacy as the default setting is the privacy-by-design principle requiring that privacy protections be built into the system's default configuration, so users do not have to take action to protect their data. It means the most privacy-protective settings are on by default, and users must opt in to share more. This directly matches the question's wording about default settings.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Full functionality – positive-sum, not zero-sum
Why it's wrong here
Full functionality positive-sum concerns avoiding false dichotomies between privacy and other objectives such as security or usability, not default configuration. Privacy by Default governs defaults; positive-sum would be correct where a stem asks about accommodating privacy alongside functionality without trade-off.
- ✗
Privacy embedded into design
Why it's wrong here
Embedding privacy into design concerns architecting controls into systems and infrastructure from the outset, not configuring defaults. Default settings are governed by Privacy by Default; embedding into design would answer a question about integrating privacy into system architecture and data lifecycles.
- ✓
Privacy as the default setting
Why this is correct
Privacy as the default setting requires that systems automatically apply the strictest privacy protections without user intervention, so personal data is protected unless the individual opts otherwise. This directly satisfies the requirement that controls be integrated into default settings.
- ✗
Proactive not reactive; preventative not remedial
Why it's wrong here
Proactive not reactive addresses anticipating and preventing privacy intrusions before they occur, not pre-set defaults. Privacy by Default covers default settings; this principle would be correct for a question about remediating risks before they materialise rather than after.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.