Courseiva

CAS-005 · domain

Governance, Risk, and Compliance

Governance, Risk, and Compliance is 20% of SecurityX (CAS-005), covering policy hierarchy, risk frameworks, regulatory obligations, and audit evidence. Questions are scenario-based: you map controls to requirements, select metrics, and identify which artifacts prove compliance. Expect HIPAA, GDPR, and patch-management scenarios requiring you to choose the best evidence or ordering rather than recall definitions.

143 questions29 easy65 medium49 hard

Focused practice

Practice Governance, Risk, and Compliance questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Governance, Risk, and Compliance

You must map controls and artifacts to specific regulatory and policy requirements, then justify the best evidence. The single most important thing: know the policy hierarchy order and which document type is mandatory versus advisory, since ordering and evidence-selection questions depend on it.

Ordering the security policy hierarchy: policy, standards, baselines, procedures, and guidelines from highest to lowest authority.

Selecting audit evidence such as access control logs, RBAC matrices, and audit trails for ePHI under HIPAA.

Choosing patch metrics like mean time to remediate (MTTR) for critical vulnerabilities to gauge program speed.

Identifying GDPR data subject rights: access, erasure, portability, rectification, restriction, and objection.

Watch out for

Common Governance, Risk, and Compliance exam traps

  • ▸Confusing standards with guidelines: standards are mandatory and specific, guidelines are discretionary recommendations, so hierarchy questions hinge on that distinction.
  • ▸Treating GDPR data subject rights as optional best practices rather than enforceable obligations requiring demonstrable evidence.
  • ▸Picking raw patch counts or deployment totals instead of time-based remediation metrics when asked how quickly critical patches are applied.

Question index

All Governance, Risk, and Compliance questions (143)

Click any question to see the full explanation, or start a practice session above.

1

A newly hired Chief Information Security Officer is establishing a governance structure and wants to define who is accountable for accepting residual risk that exceeds the organization's stated risk appetite. According to common governance practice, which role holds that accountability?

Easy
2

A security manager is reviewing a set of documents: an organizational security policy, a standard for encryption, a guideline for remote access, and a procedure for incident response. Which document is at the highest level in the policy hierarchy?

Medium
3

A retail company is building a new mobile application that will collect customer location data. The legal team asks the security manager to ensure the design follows privacy by design principles from the earliest stages. Which action best demonstrates privacy by design in this scenario?

Easy
4

A hospital's security manager is aligning internal documents after a policy refresh. The board approved a statement that defines the organization's overall security intent and assigns responsibility to executive leadership, but it deliberately avoids naming specific products or technical settings. Which document type has the board approved?

Easy
5

A security analyst is reviewing the organization's business continuity plan (BCP). The plan specifies a recovery time objective (RTO) of 4 hours for a critical e-commerce application. Which of the following BEST describes the meaning of this RTO?

Medium
6

Which risk treatment option involves reducing the likelihood or impact of a risk through controls?

Easy
7

Which security metric measures the average time it takes to detect a security incident after it has occurred?

Easy
8

An organization is evaluating a third-party vendor that will have access to its customer database. The vendor provides a SOC 2 Type II report dated six months ago. Which of the following is the BEST next step?

Medium
9

A company is implementing continuous compliance monitoring for PCI DSS. Which TWO activities are most appropriate for this approach? (Select TWO.)

Medium
10

Which of the following risk treatment options involves transferring the financial impact of a risk to a third party, such as through insurance?

Easy
11

A multinational corporation that processes personal data of EU residents is required to appoint a Data Protection Officer (DPO) and implement data protection impact assessments. Which regulation primarily drives these requirements?

Easy
12

A company wants to ensure that a third-party vendor allows them to perform an audit of the vendor's security controls. Which clause should be included in the contract?

Easy
13

An organization is implementing a data classification scheme. Which data type should be given the highest protection and is typically restricted to a very small number of individuals?

Medium
14

A company is conducting a vendor risk assessment and receives a SOC 2 Type II report from a cloud service provider. The report covers a 12-month period and includes an opinion on the effectiveness of controls. Which of the following is the primary benefit of using this report?

Hard
15

A software company suffers a breach exposing customer records. Legal counsel determines the incident meets the regulatory threshold for notification. The incident response lead must decide which external parties receive notice and within what timeframe, balancing regulatory duties against contractual obligations. Which action best satisfies the organization's notification obligations?

Medium
16

When conducting a vendor risk assessment, which contractual clause is most important for ensuring ongoing visibility into the vendor's security posture?

Medium
17

A security architect is designing a data classification scheme. Which of the following is the highest level of sensitivity that would typically require the most stringent controls?

Medium
18

A global pharmaceutical company must comply with the EU GDPR for clinical trial data. The Data Protection Officer is reviewing the data protection impact assessment (DPIA) process. Which of the following situations requires a DPIA under GDPR?

Medium
19

A security governance team is drafting a new data handling standard for a research subsidiary that processes both regulated personal data and proprietary intellectual property. The team must select controls that directly support data classification and labeling objectives. Which two of the following controls best fulfill this requirement? (Choose two.)

Medium
20

A security analyst is reviewing metrics for the security program. Which metric best measures the effectiveness of incident response processes?

Medium
21

A company wants to ensure that its data handling practices align with the principle of 'privacy by design'. Which of the following actions best supports this principle?

Easy
22

A security analyst is calculating the annualized loss expectancy (ALE) for a server that has an asset value of $50,000 and an exposure factor (EF) of 0.2. The annualized rate of occurrence (ARO) is estimated at 4. What is the ALE?

Easy
23

A multinational financial services firm must comply with the General Data Protection Regulation (GDPR). The Chief Information Security Officer (CISO) asks the security team to implement a mechanism that allows data subjects to request and receive a copy of their personal data in a structured, commonly used, and machine-readable format. Which of the following technical controls BEST addresses this requirement?

Medium
24

A multinational retailer must comply with the EU General Data Protection Regulation for its European customers and with several U.S. state privacy laws for its American customers. The privacy team wants a single internal control framework that satisfies the strictest common denominator across all jurisdictions. Which approach should the privacy team take?

Medium
25

A multinational manufacturing firm is expanding into the European Union and must demonstrate accountability for personal data processing under GDPR. The Chief Privacy Officer asks the security team to implement a mechanism that proves the organization's compliance posture to supervisory authorities without requiring prior authorization from them. Which of the following should the team implement?

Hard
26

A security architect is designing a new system that processes sensitive customer data. The organization must comply with multiple regulations, including GDPR and PCI DSS. The architect needs to ensure that data protection controls are integrated from the outset. Which approach best aligns with the principle of privacy by design?

Medium
27

Under the GDPR, which of the following is a data subject right?

Easy
28

A security manager is reviewing the organization's risk register and notes that a critical vulnerability in a legacy application has been accepted for two years. The business owner argues that the cost of remediation exceeds the potential loss. The security manager must present an alternative that aligns with the organization's risk appetite while addressing the residual risk. Which of the following is the BEST recommendation?

Hard
29

A security analyst is prioritizing remediation of vulnerabilities. Which three of the following factors should be considered when determining the risk level of a vulnerability? (Choose three.)

Hard
30

An organization discovers that a third-party vendor has a subcontractor that processes its data. The organization did not have a contract with the subcontractor. This is an example of which type of risk?

Medium
31

A security governance team is defining the scope of its enterprise risk management (ERM) program. Which TWO of the following activities are core components of ERM as described in frameworks such as ISO 31000 and COSO ERM? (Choose two.)

Hard
32

A company's security team is reviewing its risk register. A risk related to an outdated internal application has been assigned an owner, but the owner has taken no action for two quarters. The Chief Information Security Officer wants to ensure the risk is tracked and escalated appropriately. Which action should the security team take first?

Hard
33

A mid-sized retailer wants to demonstrate to customers that its payment card handling meets industry security requirements. The company does not store, process, or transmit cardholder data; it only uses a validated third-party payment page that handles all card data. Which PCI DSS self-assessment questionnaire is most appropriate?

Easy
34

A financial services firm operates a trading platform in which a 15-minute outage causes direct contractual penalties. The CISO must present a recommendation to the board on how to treat the residual risk of a ransomware event that could halt trading. The firm already has immutable offline backups and a tested recovery runbook. Which risk treatment action is MOST appropriate to recommend?

Hard
35

During a policy gap analysis, it is discovered that the organization has a policy stating that sensitive data must be encrypted, but there are no procedures for implementing encryption on mobile devices. This is an example of a gap between:

Medium
36

A security governance committee is reviewing the organization's risk register after a merger. The committee wants to apply risk treatment strategies that transfer or share risk with another party rather than reducing it internally. Which two actions represent risk transference? (Choose two.)

Hard
37

A multinational retailer operates under GDPR for its EU customers and must demonstrate accountability to supervisory authorities. The Chief Privacy Officer wants a mechanism that documents, on an ongoing basis, which processing activities occur, what data categories are involved, and how long each is retained. Which GDPR instrument should the privacy team maintain to satisfy this requirement?

Medium
38

An organization's security team has drafted a new acceptable use policy that defines how employees may handle company devices, email, and internet access. Before the policy is published and enforced, which action is most important to complete?

Easy
39

An organization is implementing a privacy program based on privacy by design. Which principle requires that privacy controls be integrated into the system's default settings?

Hard
40

A security manager is updating the organization's risk register. A new risk has been identified: a critical vendor may fail to provide timely security patches, potentially leading to a breach. The manager decides to purchase cyber insurance to cover potential financial losses from such a breach. Which risk treatment strategy does this represent?

Easy
41

A security manager is implementing a policy exception management process. Which TWO of the following are essential components of an effective exception management process?

Medium
42

An organization is implementing a privacy program to comply with GDPR. Which of the following BEST describes the concept of 'privacy by design' as it applies to a new customer relationship management (CRM) system?

Hard
43

A security architect is designing a data classification scheme aligned with a new privacy regulation. Which THREE of the following are common data classification levels used in enterprise environments? (Select THREE.)

Hard
44

A multinational retailer must demonstrate compliance with the EU General Data Protection Regulation while also honoring local data-residency laws in a country where it operates. Legal counsel advises that a single global retention schedule cannot satisfy both regimes. Which governance artifact should the security manager produce to reconcile these competing obligations?

Hard
45

An organization's security team is reviewing security metrics to present to the board. Which THREE of the following are commonly used Key Performance Indicators (KPIs) for a security program? (Select THREE.)

Medium
46

An organization is adopting the NIST Risk Management Framework (RMF). During which step would the security team select and implement security controls, and how does this map to the organization's governance structure?

Hard
47

During a vendor risk assessment, a company receives a SOC 2 Type II report from a cloud service provider. What does this report primarily attest to?

Medium
48

Under GDPR, which of the following is a data subject right that allows an individual to request that their personal data be erased?

Easy
49

A security architect is designing a new cloud-based system that must comply with the Payment Card Industry Data Security Standard (PCI DSS). The architect needs to ensure that cardholder data is protected both at rest and in transit. Which TWO of the following controls are required by PCI DSS to protect cardholder data in this scenario? (Choose two.)

Hard
50

Which key performance indicator (KPI) is most useful for measuring the effectiveness of an incident response process?

Easy
51

An organization is using the FAIR model to quantify risk. Which of the following is a primary component of the FAIR taxonomy?

Medium
52

A financial institution must comply with the Sarbanes-Oxley Act (SOX). Which of the following is a primary focus of SOX compliance?

Easy
53

A company is required to comply with PCI DSS. What is the primary purpose of conducting quarterly network vulnerability scans?

Medium
54

A risk manager is applying the FAIR model to quantify a risk. Which TWO of the following are primary components used in FAIR analysis? (Select TWO.)

Medium
55

An organization is implementing a vendor risk management program and is reviewing a contract that includes a right-to-audit clause. Which THREE of the following are common elements that should be verified during such an audit? (Select THREE.)

Hard
56

A security analyst calculates the annualized loss expectancy (ALE) for a server. The single loss expectancy (SLE) is $50,000, and the annualized rate of occurrence (ARO) is 0.2. What is the ALE?

Hard
57

A multinational financial services firm is aligning its enterprise risk management program with the NIST Risk Management Framework (RMF). The Chief Risk Officer wants to ensure that risk response decisions are formally authorized before changes are made to production systems. Which RMF step is responsible for providing that authorization?

Medium
58

A hospital is preparing for a compliance audit and must demonstrate that it has implemented administrative safeguards required by the HIPAA Security Rule. Which activity best provides this evidence?

Medium
59

An organization's security policy defines that all sensitive data must be encrypted. However, a business unit has a legacy application that cannot support encryption without a major rewrite. The risk owner decides to accept the risk. This is an example of which risk treatment strategy?

Hard
60

During a compliance audit for PCI DSS, the auditor identifies that cardholder data is stored beyond the required retention period. The organization wants to implement proper data lifecycle management. Which THREE of the following should the organization include in its data retention policy? (Select THREE.)

Hard
61

A security team is evaluating the effectiveness of their patching program. Which metric would best indicate how quickly the organization applies critical patches?

Medium
62

A financial institution is evaluating a cloud service provider for hosting customer data. During the due diligence process, which report would best help the institution assess the provider's control environment and compliance with SOC 2?

Medium
63

An organization is reviewing its third-party risk management process. Which of the following clauses should be included in contracts with critical vendors to ensure ongoing visibility into their security posture?

Medium
64

A security analyst is calculating the annualized loss expectancy (ALE) for a server that processes credit card data. The server has a $100,000 asset value, and the exposure factor for a security breach is 0.4. Historical data shows that such breaches occur twice per year. What is the ALE?

Medium
65

A company is considering adopting the NIST Risk Management Framework (RMF). Which of the following steps is unique to NIST RMF compared to ISO 27005?

Hard
66

A financial services firm's third-party risk team is onboarding a new SaaS payroll provider. The provider refuses to share its internal audit reports but will allow the firm to send its own assessor on-site to inspect the provider's controls. Which risk assessment method should the firm use to obtain assurance in this situation?

Medium
67

A security analyst calculates the annual loss expectancy (ALE) for a critical asset. The single loss expectancy (SLE) is $50,000, and the annualized rate of occurrence (ARO) is 0.2. What is the annual loss expectancy?

Medium
68

A newly hired CISO is reviewing the organization's risk register and finds that a legacy payment application carries a high inherent risk rating, but after accounting for the web application firewall, tokenization, and quarterly penetration testing already in place, the rating drops substantially. Which risk concept explains the difference between these two ratings?

Easy
69

A security manager is reviewing Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs) for the security program. Which of the following is an example of a KRI?

Medium
70

A financial services company is conducting a risk assessment for a new online banking platform. The risk team must prioritize identified risks. Which TWO of the following factors are most critical in determining the priority for risk treatment? (Choose two.)

Medium
71

An organization has identified a vulnerability in a legacy system that cannot be patched. The system is critical for operations, and the cost of mitigating the vulnerability exceeds the potential loss. Which risk treatment option is most appropriate?

Medium
72

A security compliance officer is mapping the organization's controls to the NIST Cybersecurity Framework (CSF) 2.0. The officer needs to ensure that the organization's governance and risk management processes are adequately covered. Which CSF 2.0 function primarily addresses the development and implementation of cybersecurity policies, procedures, and risk management strategies?

Medium
73

Which risk management framework is specifically designed for U.S. federal agencies and includes a six-step process: Categorize, Select, Implement, Assess, Authorize, and Monitor?

Easy
74

A financial services firm is selecting a cloud provider to host regulated customer data. The vendor risk team wants contractual language that lets the firm independently verify the provider's security posture over time rather than relying only on the provider's self-reported questionnaires. (Choose two.)

Hard
75

A security officer is reviewing continuous compliance monitoring tools. Which TWO of the following are primary benefits of implementing such tools? (Select TWO.)

Medium
76

A security architect is designing a new cloud-native application for a healthcare provider. The application will process protected health information (PHI) and must comply with HIPAA. The architect must ensure that all data at rest and in transit is encrypted, and that access is logged and auditable. Which of the following controls BEST meets the requirement for auditing access to PHI?

Hard
77

A software company wants to demonstrate to prospective enterprise customers that its cloud-hosted product meets recognized security and availability controls without exposing its internal procedures. The security manager must select an attestation that an independent auditor issues after testing the design and operating effectiveness of controls over a period. Which report type should the manager obtain?

Easy
78

A security architect is designing a data lifecycle management program. Which TWO of the following are phases of the data lifecycle? (Select TWO.)

Medium
79

A multinational retailer must comply with PCI DSS v4.0 for its cardholder data environment. The security manager is asked to define the scope of the CDE. Which of the following best describes the first step in scoping the CDE according to PCI DSS?

Medium
80

A regional bank is preparing for its annual regulatory examination and must demonstrate that its third-party risk management program is mature. The examiner asks which practices provide continuous, rather than point-in-time, oversight of critical vendors. (Choose two.)

Hard
81

A security analyst is performing a quantitative risk assessment for a server that processes payment card data. The server has an asset value of $50,000. Based on historical data, the exposure factor (EF) for a ransomware attack is 80%, and the annualized rate of occurrence (ARO) is 0.5. What is the annualized loss expectancy (ALE)?

Medium
82

A security manager is developing a third-party risk management program. The organization wants to ensure that vendors handling sensitive data are subject to appropriate oversight. Which two of the following are the most effective methods for ongoing monitoring of a vendor's security posture? (Choose two.)

Medium
83

A security analyst is reviewing the organization's risk register and notices a risk that has been assigned a risk score of 15 on a scale of 1 to 25. The risk owner has decided to purchase cyber insurance to transfer the financial impact of the risk. Which risk treatment strategy is being applied?

Easy
84

Which of the following is the correct order of the security policy hierarchy from highest to lowest?

Easy
85

A company processes personal data of EU citizens and wants to implement privacy by design. Which of the following is the BEST first step in this process?

Medium
86

An organization is implementing a privacy by design approach for a new customer-facing application. Which of the following actions best exemplifies this principle?

Hard
87

An organization has implemented a risk treatment plan that includes purchasing cyber insurance for potential data breach costs. Which risk treatment option does this represent?

Hard
88

An organization is implementing a risk management framework and wants to align with a standard that emphasizes a continuous, iterative process for identifying, assessing, and responding to risk. Which framework is most appropriate?

Medium
89

A security manager at a defense contractor is reviewing the organization's risk register. A critical vulnerability in a widely used open-source library has been identified. The vendor has not released a patch, and the library is embedded in a custom application that cannot be easily replaced. The manager decides to implement a virtual patching solution at the network perimeter. Which risk treatment strategy does this represent?

Hard
90

An organization must satisfy a regulatory requirement to demonstrate that security controls operate effectively over time, not just that they are documented. The compliance manager proposes collecting screenshots of control configurations taken on the last day of each quarter. Which approach should the security manager recommend instead to provide stronger, continuous assurance?

Hard
91

During a vendor risk assessment, a security analyst reviews a SOC 2 Type II report from a cloud provider. What is the primary value of this report?

Medium
92

A financial services firm operates in several countries and must demonstrate that its security controls are effective and independently validated for regulators and enterprise customers. Executives want a report that auditors can rely on regarding the design and operating effectiveness of controls over a period of time. Which document should the security team provide?

Medium
93

Which document in a security policy hierarchy provides specific step-by-step instructions for performing a task?

Easy
94

A cloud provider's security team is preparing for a regulatory examination and must demonstrate that a specific production system meets a documented set of security requirements. The regulator wants evidence of who approved the requirements, what was tested, when testing occurred, and what exceptions were granted. Which activity produces this evidence MOST directly?

Hard
95

A healthcare organization is required to comply with HIPAA. During an audit, the auditor requests evidence of access controls for electronic protected health information (ePHI). Which of the following would be the BEST evidence to provide?

Medium
96

A healthcare organization subject to HIPAA must ensure that patients can access their medical records. This requirement is an example of which data subject right under privacy regulations?

Medium
97

An organization is using the FAIR framework to quantify risk. The analyst estimates the probable loss event frequency (LEF) as 4 per year and the probable loss magnitude (LM) as $25,000 per event. What is the annualized loss expectancy (ALE) under FAIR?

Hard
98

A security analyst is reviewing the organization's third-party risk management program. The organization recently onboarded a new SaaS provider that will process sensitive customer data. The provider has provided a SOC 2 Type II report, but the analyst notices that the report is over 18 months old and covers a different service than the one being used. Which of the following should the analyst recommend?

Medium
99

A multinational financial services firm is preparing to adopt a new enterprise risk management approach. The CISO wants a quantitative method that expresses risk in monetary terms to prioritize investments. Which of the following should the CISO implement?

Medium
100

An organization is implementing continuous compliance monitoring. Which of the following metrics would best indicate whether the organization is maintaining compliance with PCI DSS Requirement 10 (log management)?

Hard
101

During a vendor risk assessment, a third-party vendor refuses to provide a SOC 2 report but offers a completed security questionnaire. The vendor handles sensitive customer data. Which of the following is the BEST course of action?

Medium
102

A software company is acquiring a smaller competitor that maintains its own identity provider, endpoint management platform, and network infrastructure. The integration team must fold the acquired company's users and devices into the parent's environment without disrupting business operations. Which activity should occur first to establish governance over the combined environment?

Medium
103

Which of the following is a key difference between a security guideline and a security procedure?

Easy
104

A multinational financial services firm is expanding operations into a new jurisdiction. The legal team has identified that the new country requires all personal data of its citizens to be stored on servers physically located within its borders. The security architect must recommend an approach that satisfies this requirement while maintaining the firm's global security standards. Which of the following should the architect recommend?

Medium
105

A security analyst is calculating the annualized loss expectancy (ALE) for a server. The single loss expectancy (SLE) is $5,000 and the annualized rate of occurrence (ARO) is 0.2. What is the ALE?

Easy
106

Using the FAIR model, which of the following best describes the factor that represents the probable frequency of a threat acting on a vulnerability?

Hard
107

After a risk assessment, a company identifies that the residual risk for a critical application is higher than the risk appetite. The risk owner proposes implementing additional controls to reduce the risk further. Which risk treatment option does this represent?

Hard
108

A financial services firm is undergoing a SOC 2 Type II examination. The auditor asks the CISO to demonstrate that the organization continuously monitors whether the controls described in the system description operated effectively throughout the review period. Which activity should the CISO present as the primary evidence supporting this requirement?

Medium
109

An organization wants to implement continuous compliance monitoring for PCI DSS. Which of the following tools would be MOST effective for this purpose?

Easy
110

A financial institution is implementing a privacy program based on GDPR principles. Which of the following best describes the concept of 'privacy by design'?

Hard
111

A company's security policy requires all sensitive data to be encrypted at rest. However, a business unit requests an exception to store certain data unencrypted due to performance constraints. Which document should govern the exception process?

Medium
112

A small business is implementing a privacy impact assessment (PIA) for a new application that processes personal data of EU citizens. Which TWO of the following are required under GDPR?

Medium
113

A security manager is evaluating two risk quantification approaches: Factor Analysis of Information Risk (FAIR) and a qualitative heat map. Which of the following is a key advantage of using FAIR over the qualitative heat map?

Hard
114

A defense contractor must comply with DFARS clause 252.204-7012 and achieve a passing score in its NIST SP 800-171 self-assessment before a contract award. The security lead discovers that several controls in the CUI environment are only partially implemented. Which action should the security lead take to meet the assessment requirement?

Hard
115

A defense contractor is required to comply with NIST SP 800-171 for protecting controlled unclassified information (CUI). The security team is implementing the required security requirements. Which of the following best describes the purpose of the System Security Plan (SSP) in this context?

Hard
116

A financial institution is adopting a risk management framework based on NIST SP 800-37. The CISO wants to ensure that risk responses are integrated into the enterprise architecture. Which of the following activities best supports this integration during the Risk Response step?

Hard
117

An organization's risk register shows a critical risk with a very high annualized loss expectancy. Executive leadership decides the potential loss is unacceptable but concludes that no cost-effective control exists and that the activity generating the risk is essential to revenue. They formally document the decision, obtain board sign-off, and set a review date. Which risk treatment has leadership applied?

Hard
118

A security team is measuring the effectiveness of its incident response process. Which of the following metrics would best indicate how quickly the team can contain an incident after it is detected?

Medium
119

A defense contractor must demonstrate compliance with NIST SP 800-171 for controlled unclassified information stored in a contractor-owned system. The compliance lead is preparing evidence for an upcoming assessment and wants to avoid the most common cause of failed assessments. Which activity best prevents assessment failure?

Hard
120

A multinational financial services firm is subject to GDPR and must transfer personal data from its EU offices to a data analytics vendor in the United States. The vendor is not certified under the EU-U.S. Data Privacy Framework. Which mechanism should the firm use to lawfully transfer the data while meeting GDPR Chapter V requirements?

Medium
121

A software company is pursuing ISO/IEC 27001 certification. The ISMS scope covers its cloud-hosted product and corporate IT. An auditor requests evidence that management reviews the ISMS at planned intervals. Which artifact should the security manager provide?

Medium
122

A multinational financial services firm is expanding operations into the European Union. The legal team asks the security architect to ensure the new customer onboarding portal complies with the General Data Protection Regulation (GDPR). Which of the following should the security architect implement FIRST to align with GDPR's data protection principles?

Medium
123

A multinational corporation is implementing a data classification scheme. Which of the following data types should be classified as 'restricted'?

Hard
124

Which of the following is a key difference between compliance and security?

Medium
125

A security architect is designing a new system that will process personal data of European Union citizens. The architect must ensure that data protection principles are embedded into the design. Which of the following best exemplifies the principle of data minimization under the General Data Protection Regulation (GDPR)?

Hard
126

A financial institution is required to comply with SOX. Which of the following is a primary focus of this regulation?

Medium
127

A security manager is selecting key risk indicators (KRIs) for the organization's risk management program. Which THREE of the following are examples of KRIs that can provide early warning of increasing risk?

Hard
128

An organization is developing a policy exception management process. Which three of the following are essential components of an effective exception process? (Choose three.)

Hard
129

A CISO is presenting a risk register to the board. The register shows a ransomware risk with a single loss expectancy of $2,000,000 and an annualized rate of occurrence of 0.25. The board asks for the expected annual financial exposure. What is the annualized loss expectancy (ALE) for this risk?

Hard
130

A company is evaluating a new cloud service provider. The provider offers a SOC 2 Type II report, a third-party penetration test summary, and a completed security questionnaire. However, the company's procurement team discovers that the provider uses a subcontractor for data storage. Which of the following is the BEST next step for the security team?

Medium
131

A security manager is developing a third-party risk management program. Which two of the following are considered best practices for assessing and managing vendor risk throughout the vendor lifecycle? (Choose two.)

Medium
132

An organization is reviewing its supply chain risk management. Which TWO of the following are effective strategies to manage fourth-party risk?

Medium
133

A security team is conducting a risk assessment for a new cloud-based customer relationship management (CRM) system. The team must identify and evaluate risks related to data breaches, compliance, and availability. Which TWO of the following factors are MOST important to consider when determining the likelihood of a data breach in this cloud environment? (Choose two.)

Hard
134

A multinational retailer is expanding into the European Union and must transfer employee payroll data from its EU subsidiary to its US-based HR platform. Legal counsel recommends relying on the EU-US Data Privacy Framework rather than implementing Standard Contractual Clauses. Which action must the retailer take FIRST to rely on this transfer mechanism?

Medium
135

A compliance officer is preparing for an audit and needs to collect evidence. Which TWO of the following are considered acceptable forms of audit evidence? (Select TWO.)

Easy
136

A security analyst is reviewing the organization's incident response plan and notices that it lacks a formal process for communicating with external stakeholders during a breach. Which of the following should the analyst recommend to address this gap?

Easy
137

A security analyst is reviewing the organization's incident response plan. The plan includes a section on communication with external parties. Which of the following best describes the primary purpose of a communication plan during a security incident?

Easy
138

A company is conducting a third-party risk assessment for a SaaS provider. The provider has provided a SOC 2 Type II report, penetration test results, and a completed security questionnaire. Which of these provides the most independent and comprehensive view of the provider's control environment over time?

Medium
139

A multinational retailer must transfer employee personal data from its European Union subsidiary to a processing center in a country without an adequacy decision. Legal counsel wants a transfer mechanism that imposes enforceable data protection obligations on the importer and includes a documented transfer impact assessment. Which mechanism best matches these requirements?

Hard
140

A software company is preparing to release a new payment feature that processes cardholder data. The security architect must ensure the feature design meets PCI DSS requirements for protecting stored data and for securing transmission over open, public networks. Which two design choices satisfy these requirements? (Choose two.)

Hard
141

A company wants to implement continuous compliance monitoring. Which of the following approaches BEST supports this goal?

Hard
142

A compliance officer is preparing for a GDPR audit. Which THREE of the following are key data subject rights under GDPR that the organization must be able to demonstrate?

Hard
143

A healthcare organization is implementing a new telehealth platform that stores electronic protected health information (ePHI). The security team must ensure compliance with the HIPAA Security Rule. Which of the following is a required implementation specification for access control under the HIPAA Security Rule?

Hard

Frequently asked questions

What does the Governance, Risk, and Compliance domain cover on the CAS-005 exam?
You must map controls and artifacts to specific regulatory and policy requirements, then justify the best evidence. The single most important thing: know the policy hierarchy order and which document type is mandatory versus advisory, since ordering and evidence-selection questions depend on it.
How many questions are in this domain?
This page lists all 143 Governance, Risk, and Compliance questions in the CAS-005 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Governance, Risk, and Compliance questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
casp-plus CASP-PLUS casp grc Practice Questions