CAS-004 Governance, Risk, and Compliance Practice Question
An organization is reviewing its third-party risk management process. Which of the following clauses should be included in contracts with critical vendors to ensure ongoing visibility into their security posture?
⚠ Common exam trap
The trap is conflating legal/privacy documents (NDA, DPA) or performance documents (SLA) with the specific contractual mechanism that grants inspection and verification rights — the right-to-audit clause.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Right-to-audit clause
A right-to-audit clause contractually grants the organization the ability to inspect, assess, and verify a vendor's security controls, policies, and practices — either directly or via a qualified third party. This is the mechanism that provides ongoing visibility into the vendor's security posture beyond initial due diligence. Without it, the organization has no legal standing to demand evidence of security compliance during the contract term.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Non-disclosure agreement (NDA)
Why it's wrong here
NDA protects confidentiality but does not provide audit rights.
- ✗
Service-level agreement (SLA) for uptime
Why it's wrong here
An uptime SLA defines availability commitments and remedies, not disclosure of security posture, so it provides no ongoing visibility into controls. It is tempting because SLAs are common vendor clauses, and would be correct where the requirement is guaranteed service availability with credits for downtime.
- ✓
Right-to-audit clause
Why this is correct
A right-to-audit clause contractually grants the organisation the ability to inspect a critical vendor's security controls and evidence on demand, satisfying the requirement for ongoing visibility into their security posture rather than relying on one-off assurances.
- ✗
Data processing agreement (DPA)
Why it's wrong here
A DPA governs how personal data is processed and its lawful handling, not continuous reporting of the vendor's security controls, so it fails the visibility requirement. It is tempting because DPAs are mandatory for GDPR compliance, and would be correct where personal data processing terms are the contractual gap.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.