easyMultiple Choice
CAS-004 Practice Question: Wants to ensure that its employees understand…
An organization wants to ensure that its employees understand their responsibilities regarding data protection. Which of the following is the MOST effective way to achieve this?
⚠ Common exam trap
CompTIA often tests the distinction between passive information dissemination (posters, emails, contract clauses) and active, verifiable training programs, trapping candidates who think any form of communication is sufficient for ensuring employee understanding.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct regular security awareness training with assessments
The most effective because it combines regular, recurring training with assessments that verify comprehension, ensuring employees actively engage with data protection responsibilities rather than passively receiving information. This aligns with the continuous improvement cycle required by frameworks like NIST SP 800-50 and GDPR Article 39, which mandate ongoing awareness programs and demonstrable understanding. Assessments provide measurable evidence of employee competence, which is critical for compliance audits and reducing human-error-related breaches.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Include a clause in the employment contract
Why it's wrong here
A contractual clause establishes legal obligation but delivers no instruction, so employees may still not understand their responsibilities. It is tempting because it creates enforceable accountability, and would be correct where the goal is to bind staff to confidentiality terms rather than to educate them.
- ✗
Post posters in common areas
Why it's wrong here
Posters convey awareness passively and cannot confirm that employees have read or understood their specific data protection duties. They are tempting because they reinforce a security culture cheaply, and would be the right choice for sustaining general awareness alongside formal training, not for ensuring comprehension.
- ✗
Distribute a data protection policy annually via email
Why it's wrong here
Emailing a policy annually documents distribution, not comprehension; employees can ignore it without any knowledge check. It is tempting because policy circulation satisfies audit evidence of communication, and would suit a compliance requirement to notify staff of updates rather than to verify their understanding.
- ✓
Conduct regular security awareness training with assessments
Why this is correct
Regular security awareness training with assessments repeatedly educates employees on data protection duties and verifies comprehension through testing, directly building the understanding the organisation requires. One-off communications or policy documents alone cannot confirm that responsibilities are understood.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.