Courseiva
mediumMultiple ChoiceObjective-mapped

CAS-004 Practice Question: Wants to ensure that its supply chain vendors are…

An organization wants to ensure that its supply chain vendors are compliant with its security policies. Which of the following is the MOST effective approach?

⚠ Common exam trap

Test-takers frequently choose on-site audits (Option A) as the 'most thorough' approach, failing to recognize that continuous monitoring provides superior real-time visibility and is more scalable for supply chain risk management in modern, dynamic environments.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Implement a continuous monitoring program using automated tools.

Continuous monitoring using automated tools provides real-time visibility into vendor security posture, enabling proactive detection of policy violations, configuration drift, or emerging threats. Unlike point-in-time assessments, automated monitoring can detect changes in vendor environments (e.g., new open ports, SSL/TLS certificate expiration, or exposed credentials) as they happen, aligning with the CAS-004 emphasis on ongoing risk management rather than static compliance checks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Conduct on-site audits of all vendors.

    Why it's wrong here

    On-site audits are resource-intensive and may not be feasible for a large supply chain.

  • Include security requirements in contracts and rely on legal remedies.

    Why it's wrong here

    Contracts alone do not ensure compliance without verification.

  • Require vendors to complete a self-assessment questionnaire.

    Why it's wrong here

    Self-assessments rely on honesty and may not reveal true security posture.

  • Implement a continuous monitoring program using automated tools.

    Why this is correct

    Continuous monitoring provides ongoing visibility into vendor security and reduces manual effort.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.