Courseiva
easyMultiple Choice

CAS-004 Practice Question: Wants to ensure that its employees understand…

An organization wants to ensure that its employees understand their responsibilities regarding data protection. Which of the following is the MOST effective way to achieve this?

⚠ Common exam trap

CompTIA often tests the distinction between passive information dissemination (posters, emails, contract clauses) and active, verifiable training programs, trapping candidates who think any form of communication is sufficient for ensuring employee understanding.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conduct regular security awareness training with assessments

The most effective because it combines regular, recurring training with assessments that verify comprehension, ensuring employees actively engage with data protection responsibilities rather than passively receiving information. This aligns with the continuous improvement cycle required by frameworks like NIST SP 800-50 and GDPR Article 39, which mandate ongoing awareness programs and demonstrable understanding. Assessments provide measurable evidence of employee competence, which is critical for compliance audits and reducing human-error-related breaches.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Include a clause in the employment contract

    Why it's wrong here

    A contractual clause establishes legal obligation but delivers no instruction, so employees may still not understand their responsibilities. It is tempting because it creates enforceable accountability, and would be correct where the goal is to bind staff to confidentiality terms rather than to educate them.

  • ✗

    Post posters in common areas

    Why it's wrong here

    Posters convey awareness passively and cannot confirm that employees have read or understood their specific data protection duties. They are tempting because they reinforce a security culture cheaply, and would be the right choice for sustaining general awareness alongside formal training, not for ensuring comprehension.

  • ✗

    Distribute a data protection policy annually via email

    Why it's wrong here

    Emailing a policy annually documents distribution, not comprehension; employees can ignore it without any knowledge check. It is tempting because policy circulation satisfies audit evidence of communication, and would suit a compliance requirement to notify staff of updates rather than to verify their understanding.

  • ✓

    Conduct regular security awareness training with assessments

    Why this is correct

    Regular security awareness training with assessments repeatedly educates employees on data protection duties and verifies comprehension through testing, directly building the understanding the organisation requires. One-off communications or policy documents alone cannot confirm that responsibilities are understood.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.