Courseiva

CAS-004 Governance, Risk, and Compliance Practice Question

An organization is implementing continuous compliance monitoring. Which of the following metrics would best indicate whether the organization is maintaining compliance with PCI DSS Requirement 10 (log management)?

⚠ Common exam trap

CAS-005 often tests the mapping of metrics to specific PCI DSS requirements — candidates pick a security-sounding metric like MTTD or failed logins when the question asks about log management coverage specifically.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Percentage of systems with centralized logging enabled

PCI DSS Requirement 10 requires that audit logs be collected, retained, and reviewed, and centralized logging is a key control to ensure logs from all in-scope systems are captured in a tamper-resistant manner. The percentage of systems with centralized logging enabled directly measures coverage of this control. A high percentage indicates the organization is maintaining the log management requirement across its cardholder data environment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Number of failed login attempts per day

    Why it's wrong here

    Failed login counts are log content, not evidence that logging itself is compliant. It is tempting because the metric derives from authentication logs and looks security-relevant, but Requirement 10 demands proof that logs are generated, retained and reviewed — a volume figure cannot demonstrate those controls.

  • ✓

    Percentage of systems with centralized logging enabled

    Why this is correct

    Requirement 10 depends on audit logs being captured and retained centrally for correlation and review. The proportion of in-scope systems forwarding logs to the central platform directly measures coverage of that control, exposing any system whose logs remain local and therefore unmonitored.

  • ✗

    Mean time to detect (MTTD) for security incidents

    Why it's wrong here

    MTTD measures detection speed, which depends on monitoring and analysis rather than on log management controls. It is tempting because faster detection suggests logs are working, but Requirement 10 requires demonstrable log generation, retention and review; MTTD can improve while retention periods remain non-compliant.

  • ✗

    Vulnerability scan pass rate

    Why it's wrong here

    Vulnerability scan pass rates evidence patching and vulnerability management, mapping to Requirement 6 and 11 rather than log management. It is tempting because scan metrics are easy to collect continuously, but Requirement 10 concerns log capture, retention and review, which scan results say nothing about.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.