Courseiva

CCNA Governance, Risk, and Compliance Questions

68 of 143 questions · Page 2/2 · Governance, Risk, and Compliance · Answers revealed

76
MCQhard

A security architect is designing a new cloud-native application for a healthcare provider. The application will process protected health information (PHI) and must comply with HIPAA. The architect must ensure that all data at rest and in transit is encrypted, and that access is logged and auditable. Which of the following controls BEST meets the requirement for auditing access to PHI?

A.Implement application-level logging that records user identity, timestamp, and the specific PHI records accessed, and store logs securely.
B.Use AWS Config to monitor resource configurations and alert on changes to security groups.
C.Deploy a web application firewall (WAF) to log all incoming HTTP requests and block malicious traffic.
D.Enable AWS CloudTrail to log all API activity and store logs in an immutable S3 bucket.
AnswerA

HIPAA requires audit controls that record and examine activity in information systems containing or using electronic protected health information (ePHI). Application-level logging that captures user identity, timestamp, and the specific records accessed directly satisfies this. Storing logs securely ensures integrity and availability for audits. This is the most precise control for auditing access to PHI.

Why this answer

HIPAA's Security Rule requires audit controls that record and examine activity in systems containing ePHI. Application-level logging that captures user identity, timestamp, and the specific PHI accessed provides the necessary audit trail. Other controls like CloudTrail, AWS Config, or WAFs address different aspects of security but do not provide the granular access auditing required for PHI.

Exam trap

The trap here is assuming that infrastructure logging tools like CloudTrail or WAF logs are sufficient for HIPAA audit controls, when they lack the granularity to track access to specific PHI records.

77
MCQeasy

A software company wants to demonstrate to prospective enterprise customers that its cloud-hosted product meets recognized security and availability controls without exposing its internal procedures. The security manager must select an attestation that an independent auditor issues after testing the design and operating effectiveness of controls over a period. Which report type should the manager obtain?

A.A SOC 1 Type II report covering the relevant trust services criteria.
B.A SOC 2 Type I report covering the relevant trust services criteria.
C.A SOC 3 general use report covering the relevant trust services criteria.
D.A SOC 2 Type II report covering the relevant trust services criteria.
AnswerD

A SOC 2 Type II report is issued by an independent auditor after testing whether controls were designed appropriately and operated effectively throughout a defined period, which is exactly the assurance enterprise customers seek when evaluating a cloud provider's security and availability posture.

Why this answer

A SOC 2 Type II report provides independent auditor testing of both control design and operating effectiveness across a review period, which is the standard evidence enterprise buyers request from cloud providers. Type I lacks the period of operation, SOC 3 omits the detail customers need, and SOC 1 targets financial reporting rather than trust services criteria.

Exam trap

The trap here is confusing the point-in-time design assurance of a Type I report with the period-based operating effectiveness testing of a Type II report.

78
Multi-Selectmedium

A security architect is designing a data lifecycle management program. Which TWO of the following are phases of the data lifecycle? (Select TWO.)

Select 2 answers
A.Data replication
B.Data anonymization
C.Data creation
D.Data destruction
E.Data monetization
AnswersC, D

Data creation is the lifecycle phase where new data is generated, captured or acquired, establishing the asset before any classification or protection controls apply. It satisfies the stem's requirement to identify genuine lifecycle phases within a data lifecycle management programme.

Why this answer

Option C (Data creation) is correct because the data lifecycle begins when data is generated or acquired, making creation the first recognized phase in lifecycle models such as the one described in ISO/IEC 27001 and NIST guidance. Option D (Data destruction) is correct because the lifecycle concludes with secure disposal or destruction of data once it is no longer needed, ensuring it cannot be recovered and reducing residual risk. Data replication (A) is a storage or availability technique, not a lifecycle phase.

Data anonymization (B) is a privacy-enhancing technique applied during processing, not a distinct lifecycle phase. Data monetization (E) is a business objective or use case, not a formal phase of the data lifecycle.

Exam trap

CAS-005 often tests whether candidates can distinguish lifecycle phases (creation, storage, usage, sharing, archiving, destruction) from techniques and business activities (replication, anonymization, monetization) — the distractors sound data-related but are not phases of the lifecycle.

79
MCQmedium

A multinational retailer must comply with PCI DSS v4.0 for its cardholder data environment. The security manager is asked to define the scope of the CDE. Which of the following best describes the first step in scoping the CDE according to PCI DSS?

A.Conduct a penetration test on all internet-facing systems to determine which ones are in scope.
B.Review the PCI DSS Self-Assessment Questionnaire (SAQ) to determine which requirements apply.
C.Identify all system components that store, process, or transmit cardholder data (CHD) or sensitive authentication data (SAD).
D.Segment the network by placing all cardholder data systems behind a firewall and then document the segmentation.
AnswerC

PCI DSS scoping begins with identifying all system components that store, process, or transmit CHD or SAD, as well as those that could impact the security of the CDE. This includes connected systems and security-impacting systems. Without this inventory, the scope cannot be accurately defined, and the assessment will be incomplete. This is the foundational step mandated by PCI DSS.

Why this answer

The correct answer is to identify all system components that store, process, or transmit CHD or SAD. PCI DSS scoping requires a thorough inventory of people, processes, and technologies that handle cardholder data or could impact its security. This inventory forms the basis for defining the CDE and determining which requirements apply.

Without it, segmentation and validation efforts are misdirected.

Exam trap

The trap here is assuming that network segmentation or penetration testing is the first step in PCI DSS scoping, when in fact a complete data-flow inventory must precede any scope-reduction technique.

80
Multi-Selecthard

A regional bank is preparing for its annual regulatory examination and must demonstrate that its third-party risk management program is mature. The examiner asks which practices provide continuous, rather than point-in-time, oversight of critical vendors. (Choose two.)

Select 2 answers
A.Establishing contractual rights to audit, receive breach notifications within defined timeframes, and obtain regular independent assurance reports
B.Relying on the vendor's own marketing materials and public certifications page to confirm its security posture
C.Ranking vendors solely by annual contract value and assigning oversight resources proportionally to spend
D.Collecting a completed security questionnaire from each vendor once during initial onboarding and archiving the response
E.Requiring critical vendors to submit to annual on-site or virtual control assessments with documented findings and remediation tracking
AnswersA, E

Contractual audit rights, notification obligations, and requirements for independent assurance such as SOC 2 reports give the bank ongoing visibility into vendor control status between assessments. These provisions create enforceable expectations and information flow, so the bank learns of control changes or incidents without waiting for the next scheduled review, which is exactly the continuous oversight the examiner seeks.

Why this answer

Continuous third-party oversight combines recurring independent validation with enforceable contractual information rights. Periodic assessments with remediation tracking confirm that identified weaknesses are corrected, while audit rights, breach notification clauses, and independent assurance requirements keep the bank informed between reviews. One-time questionnaires, spend-based ranking, and reliance on vendor marketing all capture stale or unverified information.

Exam trap

The trap here is confusing initial due diligence artifacts, such as an onboarding questionnaire, with the recurring validation and contractual visibility that constitute ongoing oversight.

81
MCQmedium

A security analyst is performing a quantitative risk assessment for a server that processes payment card data. The server has an asset value of $50,000. Based on historical data, the exposure factor (EF) for a ransomware attack is 80%, and the annualized rate of occurrence (ARO) is 0.5. What is the annualized loss expectancy (ALE)?

A.$20,000
B.$40,000
C.$50,000
D.$25,000
AnswerA

SLE equals asset value ($50,000) multiplied by exposure factor (0.80), giving $40,000. ALE is SLE multiplied by ARO (0.5), yielding $20,000. This quantifies expected annual loss for the payment card server, satisfying the quantitative assessment requirement.

Why this answer

The Annualized Loss Expectancy (ALE) is calculated as Single Loss Expectancy (SLE) multiplied by Annualized Rate of Occurrence (ARO). SLE is Asset Value (AV) times Exposure Factor (EF). Here, AV = $50,000, EF = 0.8, so SLE = $40,000.

ARO = 0.5, so ALE = $40,000 * 0.5 = $20,000.

Exam trap

CAS-005 often tests confusion between SLE and ALE, or misapplication of the formula by forgetting to multiply by ARO or using AV directly instead of SLE.

How to eliminate wrong answers

Option B is wrong because $40,000 is the SLE, not the ALE; it omits multiplication by ARO. Option C is wrong because $50,000 is the asset value, not the ALE. Option D is wrong because $25,000 would result from using AV * ARO without applying EF, or halving AV incorrectly.

82
Multi-Selectmedium

A security manager is developing a third-party risk management program. The organization wants to ensure that vendors handling sensitive data are subject to appropriate oversight. Which two of the following are the most effective methods for ongoing monitoring of a vendor's security posture? (Choose two.)

Select 2 answers
A.Asking the vendor to self-attest to security compliance annually
B.Conducting periodic on-site security assessments of the vendor
C.Reviewing the vendor's marketing materials for security claims
D.Requiring the vendor to provide annual SOC 2 Type II reports
E.Monitoring the vendor's stock price for fluctuations
AnswersB, D

Periodic on-site assessments allow the organization to directly verify the vendor's security controls, practices, and compliance with contractual requirements. They provide firsthand evidence and can uncover issues not visible in documentation. This method is effective for ongoing monitoring, especially for critical vendors, and complements other oversight activities.

Why this answer

Effective ongoing vendor monitoring requires objective, independent evidence of security controls. SOC 2 Type II reports provide third-party attestation over time, and periodic on-site assessments allow direct verification. Other options like marketing materials, self-attestation, and stock price monitoring lack the rigor and specificity needed for security oversight.

Exam trap

The trap here is considering self-attestation or marketing claims as sufficient for vendor monitoring, when independent verification is necessary.

83
MCQeasy

A security analyst is reviewing the organization's risk register and notices a risk that has been assigned a risk score of 15 on a scale of 1 to 25. The risk owner has decided to purchase cyber insurance to transfer the financial impact of the risk. Which risk treatment strategy is being applied?

A.Risk acceptance
B.Risk mitigation
C.Risk transfer
D.Risk avoidance
AnswerC

Risk transfer involves shifting the financial impact of a risk to a third party, such as an insurance company. Purchasing cyber insurance is a classic example of risk transfer. The organization retains the risk but transfers the potential financial loss to the insurer, which aligns with the risk owner's decision in this scenario.

Why this answer

Purchasing cyber insurance shifts the financial consequences of a risk to an insurer, which is the definition of risk transfer. Risk avoidance would eliminate the activity, mitigation would reduce likelihood or impact, and acceptance would involve bearing the risk without transfer. The scenario clearly describes transfer.

Exam trap

The trap here is confusing risk transfer with risk mitigation, as both involve taking action, but transfer shifts financial impact while mitigation reduces the risk itself.

84
MCQeasy

Which of the following is the correct order of the security policy hierarchy from highest to lowest?

A.Policy → Standard → Guideline → Procedure
B.Standard → Policy → Guideline → Procedure
C.Policy → Guideline → Standard → Procedure
D.Procedure → Guideline → Standard → Policy
AnswerA

Policy sits at the top of the hierarchy, establishing mandatory high-level intent, followed by standards that specify enforceable requirements. Guidelines then offer non-mandatory recommendations, and procedures come last, detailing the step-by-step actions needed to implement the higher-level directives. This ordering satisfies the stem's highest-to-lowest constraint.

Why this answer

The security policy hierarchy from highest to lowest is Policy, Standard, Guideline, Procedure. Policies are high-level statements of management intent. Standards are mandatory requirements that support policies.

Guidelines are recommendations. Procedures are step-by-step instructions for implementing policies and standards. This order reflects the decreasing level of authority and increasing level of detail.

Exam trap

CAS-005 often tests the misconception that guidelines are mandatory or that standards are higher than policies, confusing the hierarchy.

How to eliminate wrong answers

Option B is wrong because it places Standard above Policy, but policies are the highest-level documents that drive standards. Option C is wrong because it places Guideline above Standard, but standards are mandatory while guidelines are discretionary, so standards must be higher. Option D is wrong because it reverses the entire hierarchy, placing Procedure at the top, which is incorrect as procedures are the most detailed and lowest-level documents.

85
MCQmedium

A company processes personal data of EU citizens and wants to implement privacy by design. Which of the following is the BEST first step in this process?

A.Appointing a Data Protection Officer (DPO)
B.Implementing data encryption at rest and in transit
C.Developing a data retention policy
D.Conducting a Privacy Impact Assessment (PIA)
AnswerD

A Privacy Impact Assessment identifies what personal data is processed, why, and where risks arise, giving the documented basis for designing controls before processing begins. Conducting it first satisfies the privacy-by-design requirement to embed protection at the earliest stage of any EU personal-data initiative.

Why this answer

A Privacy Impact Assessment (PIA) — also called a Data Protection Impact Assessment (DPIA) under GDPR Article 35 — is the foundational first step in privacy by design because it forces the organization to systematically identify and mitigate privacy risks before processing begins. It maps data flows, identifies personal data elements, assesses legal bases, and evaluates risks to data subjects, which then informs all subsequent controls like encryption, retention, and DPO involvement. Without this assessment, other measures are implemented blindly and may not address the actual risks.

GDPR explicitly requires a DPIA for high-risk processing, making it a legal prerequisite in many cases.

Exam trap

The trap here is confusing a necessary governance role (DPO) or a common technical control (encryption) with the foundational risk-assessment step that must logically precede them; candidates often pick encryption because it feels concrete, but privacy by design starts with understanding risks, not applying fixes.

How to eliminate wrong answers

Option A is wrong because appointing a DPO is an organizational governance step that may be required for certain organizations, but it does not itself implement privacy by design; the DPO's role is to advise and monitor, not to perform the initial risk assessment. Option B is wrong because encryption is a technical safeguard that should be selected based on risks identified during a PIA; implementing it first without assessment may protect the wrong data or miss other privacy risks like excessive collection or lack of consent. Option C is wrong because a data retention policy is a downstream control that depends on knowing what data is collected, why, and for how long it is needed — all outputs of a PIA; creating it first would be premature and likely misaligned with actual processing purposes.

86
MCQhard

An organization is implementing a privacy by design approach for a new customer-facing application. Which of the following actions best exemplifies this principle?

A.Adding a privacy notice to the application post-launch
B.Conducting a privacy impact assessment after the application is deployed
C.Minimizing data collection to only what is necessary for the application's function
D.Encrypting data at rest and in transit
AnswerC

Privacy by design mandates data minimisation: collecting only what the application's function requires limits exposure and compliance risk at source. This is a structural safeguard embedded in design, unlike consent notices or retention policies applied after collection.

Why this answer

Privacy by design, codified in GDPR Article 25 as 'data protection by design and by default,' requires privacy to be embedded into systems from the outset. Data minimization — collecting only what is strictly necessary for the stated purpose — is a foundational PbD principle because it reduces the attack surface, limits breach impact, and satisfies the 'by default' requirement. It is a design-time decision, not a post-hoc control.

Exam trap

CAS-005 often tests the distinction between design-time principles (minimization, default settings) and post-deployment controls (notices, encryption, PIAs) — candidates must pick the action that reflects embedding privacy into the design itself.

How to eliminate wrong answers

Option A is wrong because adding a privacy notice post-launch is a transparency measure applied after the fact, not a design principle embedded into the application. Option B is wrong because a PIA conducted after deployment is reactive — PbD requires the assessment during design, before deployment. Option D is wrong because encryption is a security control that protects data once collected; it does not exemplify PbD's core tenet of minimizing collection in the first place (encryption is a supporting control, not the defining PbD action).

87
MCQhard

An organization has implemented a risk treatment plan that includes purchasing cyber insurance for potential data breach costs. Which risk treatment option does this represent?

A.Risk mitigation
B.Risk avoidance
C.Risk acceptance
D.Risk transfer
AnswerD

Purchasing cyber insurance shifts the financial consequence of a data breach to an insurer rather than eliminating or reducing the risk itself. This is risk transfer, matching the treatment plan's intent to cover potential breach costs through a third party.

Why this answer

Purchasing cyber insurance transfers the financial consequences of a data breach to a third-party insurer, which is the definition of risk transfer. The organization does not eliminate the risk or reduce its likelihood — it shifts the monetary impact to another party. This is a classic example of risk transfer in risk treatment planning.

Exam trap

The trap here is confusing risk transfer with risk mitigation, as both involve taking action; candidates may think insurance reduces risk, but it only shifts financial impact.

How to eliminate wrong answers

Option A is wrong because risk mitigation involves implementing controls (e.g., firewalls, encryption) to reduce the likelihood or impact of a threat, not shifting financial responsibility. Option B is wrong because risk avoidance means discontinuing the activity that introduces the risk entirely (e.g., not storing sensitive data), which is not what insurance does. Option C is wrong because risk acceptance means acknowledging the risk and taking no action to transfer or mitigate it, often with a formal sign-off.

88
MCQmedium

An organization is implementing a risk management framework and wants to align with a standard that emphasizes a continuous, iterative process for identifying, assessing, and responding to risk. Which framework is most appropriate?

A.FAIR
B.ISO 27005
C.COBIT
D.NIST RMF
AnswerD

The NIST Risk Management Framework prescribes a continuous, iterative cycle — Prepare, Categorise, Select, Implement, Assess, Authorise and Monitor — so risk identification, assessment and response recur throughout the system lifecycle rather than as a one-off exercise.

Why this answer

The NIST Risk Management Framework (RMF) is explicitly designed as a continuous, iterative process for identifying, assessing, and responding to risk. It consists of six steps: Categorize, Select, Implement, Assess, Authorize, and Monitor, which are repeated throughout the system lifecycle. This aligns perfectly with the requirement for a continuous, iterative approach.

ISO 27005 provides guidelines for risk management but is not as prescriptive about the continuous process as NIST RMF. FAIR is a quantitative risk analysis methodology, and COBIT is a governance framework for IT management, not specifically a risk management framework with a continuous iterative process.

Exam trap

CAS-005 often tests the distinction between risk management frameworks and risk analysis methodologies, causing candidates to confuse FAIR (quantitative analysis) with a full framework like NIST RMF.

How to eliminate wrong answers

Option A is wrong because FAIR (Factor Analysis of Information Risk) is a quantitative risk analysis model, not a comprehensive risk management framework with a continuous iterative process. Option B is wrong because ISO 27005 provides risk management guidelines but does not emphasize a continuous, iterative process to the same extent as NIST RMF; it is more about the risk management process itself. Option C is wrong because COBIT is an IT governance framework that includes risk management as one component, but it is not primarily a risk management framework focused on continuous iterative risk identification, assessment, and response.

89
MCQhard

A security manager at a defense contractor is reviewing the organization's risk register. A critical vulnerability in a widely used open-source library has been identified. The vendor has not released a patch, and the library is embedded in a custom application that cannot be easily replaced. The manager decides to implement a virtual patching solution at the network perimeter. Which risk treatment strategy does this represent?

A.Risk transfer
B.Risk mitigation
C.Risk avoidance
D.Risk acceptance
AnswerB

Virtual patching reduces the likelihood or impact of exploitation by blocking attack vectors, even without a vendor patch. This is a form of risk mitigation because it lowers the risk to an acceptable level through compensating controls. It does not eliminate the vulnerability but manages it effectively.

Why this answer

Virtual patching is a compensating control that reduces the likelihood of exploitation by filtering malicious traffic. Since the underlying vulnerability remains but its risk is lowered, this is risk mitigation. Transfer, acceptance, and avoidance do not involve actively reducing the risk through controls, making mitigation the correct classification.

Exam trap

The trap here is confusing virtual patching with risk transfer, because a third-party tool is used, but the risk remains with the organization.

90
MCQhard

An organization must satisfy a regulatory requirement to demonstrate that security controls operate effectively over time, not just that they are documented. The compliance manager proposes collecting screenshots of control configurations taken on the last day of each quarter. Which approach should the security manager recommend instead to provide stronger, continuous assurance?

A.Annual third-party penetration testing of the in-scope systems
B.A control self-assessment survey completed by each system owner twice a year
C.Quarterly screenshots retained with a documented review sign-off
D.Continuous control monitoring that ingests configuration and log data from the control systems
AnswerD

Continuous control monitoring automatically collects and evaluates configuration and log evidence from the systems enforcing each control, providing near-real-time assurance that controls operate as intended across the entire period. This directly answers the regulator's demand for evidence of sustained effectiveness and is far stronger than periodic screenshots that capture only a single moment.

Why this answer

The regulator wants proof that controls operate effectively over time, not merely that they were configured correctly on specific dates. Continuous control monitoring ingests live configuration and log data and evaluates it automatically, producing objective evidence across the full period. Penetration tests, quarterly screenshots, and semi-annual self-assessments all sample control state at isolated points and cannot demonstrate sustained operation.

Exam trap

The trap here is equating more frequent manual evidence collection with continuous assurance, when any periodic snapshot still leaves the gaps between captures unverified and unaudited.

91
MCQmedium

During a vendor risk assessment, a security analyst reviews a SOC 2 Type II report from a cloud provider. What is the primary value of this report?

A.It provides assurance over the design and operating effectiveness of controls over a period.
B.It offers a snapshot of the vendor's security posture at a single point in time.
C.It provides a real-time vulnerability scan of the vendor's network.
D.It verifies the vendor's compliance with PCI DSS.
AnswerA

A SOC 2 Type II report covers an audit period, not a single point in time, so it evidences that controls were designed and actually operated effectively throughout that window. This lets the analyst judge sustained control performance rather than relying on a Type I snapshot.

Why this answer

A SOC 2 Type II report provides assurance over the design and operating effectiveness of a service organization's controls over a specified period, typically 3–12 months. This period-based testing distinguishes it from Type I, which only assesses design at a point in time. For vendor risk management, Type II gives the analyst evidence that controls actually operated effectively throughout the audit window.

Exam trap

CAS-005 often tests the Type I vs Type II distinction — candidates pick 'point-in-time snapshot' thinking it sounds rigorous, but that describes Type I, not Type II.

How to eliminate wrong answers

Option B is wrong because a point-in-time snapshot of security posture describes a SOC 2 Type I report, not Type II. Option C is wrong because SOC 2 is an attestation of controls, not a real-time vulnerability scan; it does not provide live network scanning data. Option D is wrong because SOC 2 is based on the AICPA Trust Services Criteria (security, availability, processing integrity, confidentiality, privacy) and does not certify PCI DSS compliance — PCI DSS has its own ROC/SAQ process.

92
MCQmedium

A financial services firm operates in several countries and must demonstrate that its security controls are effective and independently validated for regulators and enterprise customers. Executives want a report that auditors can rely on regarding the design and operating effectiveness of controls over a period of time. Which document should the security team provide?

A.SOC 2 Type II report
B.SOC 2 Type I report
C.SOC 3 general use report
D.ISO/IEC 27001 certificate
AnswerA

A SOC 2 Type II report covers the design and operating effectiveness of controls over a defined review period, using the Trust Services Criteria. Because it tests controls across time rather than a single moment, it gives regulators and customers independently validated evidence that controls operated effectively throughout the period, matching the stated objective.

Why this answer

A SOC 2 Type II report is the appropriate artifact because it attests to both the design and operating effectiveness of controls across a defined period. Type I reports only cover design at a point in time, and the other documents do not provide period-wide control testing evidence.

Exam trap

The trap here is treating a SOC 2 Type I report or an ISO/IEC 27001 certificate as equivalent evidence of control effectiveness over time when neither tests operating effectiveness across a period.

93
MCQeasy

Which document in a security policy hierarchy provides specific step-by-step instructions for performing a task?

A.Guideline
B.Procedure
C.Standard
D.Policy
AnswerB

A procedure sits below policy and standard in the hierarchy, translating them into detailed, sequential steps for a specific task. It tells staff exactly how to perform the activity, unlike policy, which states intent and mandatory requirements.

Why this answer

A procedure is the only document in a security policy hierarchy that provides detailed, step-by-step instructions for performing a specific task. It translates high-level policies and standards into actionable steps that employees can follow to ensure consistency and compliance. Procedures are operational in nature and answer 'how' to implement the requirements.

Exam trap

The trap here is confusing the terms 'standard' and 'procedure' because both are more specific than policy; candidates may forget that procedures are the only ones with step-by-step instructions, while standards specify requirements without steps.

How to eliminate wrong answers

Option A is wrong because a guideline offers recommendations and best practices, not mandatory step-by-step instructions. Option C is wrong because a standard defines specific technical or operational requirements (e.g., password length, encryption algorithms) but does not provide procedural steps. Option D is wrong because a policy is a high-level statement of management intent that outlines principles and responsibilities without detailing how to execute tasks.

94
MCQhard

A cloud provider's security team is preparing for a regulatory examination and must demonstrate that a specific production system meets a documented set of security requirements. The regulator wants evidence of who approved the requirements, what was tested, when testing occurred, and what exceptions were granted. Which activity produces this evidence MOST directly?

A.Running an unauthenticated external vulnerability scan against the production system
B.Publishing the system's configuration baseline to the internal configuration management database
C.Performing a formal security assessment or authorization review with documented approval and exception records
D.Conducting an internal control self-assessment questionnaire with system owners
AnswerC

A formal assessment and authorization process, such as an Authority to Operate review, produces exactly the artifacts described: approved security requirements, the assessment scope and methods, testing dates, findings, and documented exceptions with risk acceptance. It establishes accountability by naming the authorizing official, which is why it directly satisfies a regulator asking for traceable governance evidence.

Why this answer

A formal security assessment and authorization review generates the full chain of evidence the regulator wants: approved requirements, the authorizing official's decision, assessment scope and methods, testing dates, and documented exceptions with risk acceptance. Scanning, self-assessment, and configuration baselines each contribute supporting data but none produce the approval, scope, timing, and exception record together in a traceable form.

Exam trap

The trap here is treating a technical scan or self-assessment as equivalent to a formal authorization decision with documented approvals and exceptions.

95
MCQmedium

A healthcare organization is required to comply with HIPAA. During an audit, the auditor requests evidence of access controls for electronic protected health information (ePHI). Which of the following would be the BEST evidence to provide?

A.A report of employee security training completion
B.A signed copy of the access control policy
C.Access review logs showing periodic reviews of user permissions
D.A network diagram of the IT infrastructure
AnswerC

Access review logs directly evidence periodic recertification of user permissions, satisfying HIPAA's access control and audit requirements for ePHI. Unlike configuration screenshots or policy documents, these logs prove ongoing enforcement through documented reviewer decisions and timestamps, demonstrating that least-privilege access is actively maintained rather than merely defined.

Why this answer

Access review logs showing periodic reviews of user permissions provide direct evidence that access controls are being enforced and monitored over time. HIPAA requires covered entities to implement policies and procedures to authorize and supervise access to ePHI, and periodic reviews demonstrate ongoing compliance. A policy alone does not prove implementation, and training or network diagrams do not show actual access control effectiveness.

Exam trap

The trap is selecting a policy document or training record as evidence of access controls, when auditors require proof of implementation and monitoring, such as logs or review records.

How to eliminate wrong answers

Option A is wrong because employee security training completion only shows awareness, not the actual access controls in place for ePHI. Option B is wrong because a signed policy is a document stating intent, but it does not provide evidence that the controls are implemented or effective. Option D is wrong because a network diagram shows infrastructure layout, not access control enforcement or review processes.

96
MCQmedium

A healthcare organization subject to HIPAA must ensure that patients can access their medical records. This requirement is an example of which data subject right under privacy regulations?

A.Right to be forgotten
B.Right to data portability
C.Right to rectification
D.Right to access
AnswerD

HIPAA's patient right to inspect and obtain a copy of their medical records maps directly to the right to access. It lets individuals obtain their own data, distinct from rectification, erasure or portability, satisfying the requirement that records be made available on request.

Why this answer

The right to access under privacy regulations (including HIPAA's patient rights and GDPR Article 15) gives individuals the ability to obtain a copy of their personal data and confirm what is being processed. HIPAA's Privacy Rule specifically grants patients the right to inspect and obtain a copy of their protected health information. This maps directly to the right to access.

Exam trap

CAS-005 often tests the distinction between the right to access and the right to data portability — candidates conflate 'getting my data' with portability, but access is simply viewing/receiving a copy.

How to eliminate wrong answers

Option A is wrong because the right to be forgotten (erasure) allows individuals to request deletion of their data, which is not what the scenario describes. Option B is wrong because the right to data portability allows individuals to receive their data in a structured, machine-readable format and transmit it to another controller — a distinct right from mere access. Option C is wrong because the right to rectification allows individuals to correct inaccurate data, not simply view it.

97
MCQhard

An organization is using the FAIR framework to quantify risk. The analyst estimates the probable loss event frequency (LEF) as 4 per year and the probable loss magnitude (LM) as $25,000 per event. What is the annualized loss expectancy (ALE) under FAIR?

A.$6,250
B.$125,000
C.$100,000
D.$25,000
AnswerC

FAIR derives annualised loss expectancy by multiplying loss event frequency by loss magnitude, so 4 × $25,000 yields $100,000. This satisfies the stem's requirement to quantify ALE from the supplied LEF and LM values, giving the expected yearly loss the organisation faces from that risk scenario.

Why this answer

Under the FAIR (Factor Analysis of Information Risk) framework, Annualized Loss Expectancy (ALE) is calculated as Loss Event Frequency (LEF) multiplied by Loss Magnitude (LM). Here, LEF = 4 events per year and LM = $25,000 per event, so ALE = 4 × $25,000 = $100,000. This represents the expected annual financial loss from the risk scenario.

Exam trap

The trap here is confusing ALE with Loss Magnitude (LM) or inverting the formula (LM ÷ LEF); candidates must remember ALE = LEF × LM and not simply pick the per-event dollar figure.

How to eliminate wrong answers

Option A ($6,250) is wrong because it results from dividing LM by LEF (25,000 / 4), which is not a FAIR formula. Option B ($125,000) is wrong because it results from multiplying LEF by 5 × LM or some other incorrect arithmetic — it does not correspond to 4 × 25,000. Option D ($25,000) is wrong because it is simply the single-event loss magnitude (LM), not the annualized figure; it ignores the frequency of 4 events per year.

98
MCQmedium

A security analyst is reviewing the organization's third-party risk management program. The organization recently onboarded a new SaaS provider that will process sensitive customer data. The provider has provided a SOC 2 Type II report, but the analyst notices that the report is over 18 months old and covers a different service than the one being used. Which of the following should the analyst recommend?

A.Accept the existing SOC 2 Type II report since it demonstrates the provider's overall security posture.
B.Request a current SOC 2 Type II report that specifically covers the service being used, or conduct an on-site assessment if one is not available.
C.Perform a penetration test against the provider's service to validate its security controls.
D.Rely on the provider's self-attestation of compliance with industry best practices.
AnswerB

A SOC 2 Type II report must be current and scoped to the relevant service to provide assurance. An outdated report covering a different service is insufficient. Requesting an updated report or performing an on-site assessment ensures the organization obtains accurate, relevant information about the provider's controls, enabling informed risk decisions and compliance with due diligence requirements.

Why this answer

Third-party risk management requires current and relevant assurance. A SOC 2 Type II report must be recent and cover the specific service in use. Requesting an updated report or conducting an on-site assessment ensures the organization has accurate information to assess the provider's controls.

Other options rely on outdated, unverified, or inappropriate methods.

Exam trap

The trap here is assuming that any SOC 2 report is sufficient, when in fact its recency and scope are critical for it to be meaningful for the specific service.

99
MCQmedium

A multinational financial services firm is preparing to adopt a new enterprise risk management approach. The CISO wants a quantitative method that expresses risk in monetary terms to prioritize investments. Which of the following should the CISO implement?

A.NIST Risk Management Framework (RMF)
B.OCTAVE Allegro
C.Factor Analysis of Information Risk (FAIR)
D.ISO/IEC 27005
AnswerC

FAIR is a quantitative risk analysis framework that expresses risk in financial terms by modeling loss event frequency and loss magnitude. It enables the CISO to prioritize investments based on monetary impact, aligning with the goal of expressing risk in monetary terms. Unlike qualitative approaches, FAIR provides defensible, data-driven estimates for enterprise risk management.

Why this answer

The CISO needs a quantitative risk analysis method that expresses risk in monetary terms. FAIR is specifically designed to quantify risk in financial terms, enabling prioritization of investments based on potential monetary loss. Other options are either qualitative or framework-oriented without inherent financial quantification.

Exam trap

The trap here is confusing comprehensive risk management frameworks with quantitative risk analysis methodologies that express risk in monetary terms.

100
MCQhard

An organization is implementing continuous compliance monitoring. Which of the following metrics would best indicate whether the organization is maintaining compliance with PCI DSS Requirement 10 (log management)?

A.Number of failed login attempts per day
B.Percentage of systems with centralized logging enabled
C.Mean time to detect (MTTD) for security incidents
D.Vulnerability scan pass rate
AnswerB

Requirement 10 depends on audit logs being captured and retained centrally for correlation and review. The proportion of in-scope systems forwarding logs to the central platform directly measures coverage of that control, exposing any system whose logs remain local and therefore unmonitored.

Why this answer

PCI DSS Requirement 10 requires that audit logs be collected, retained, and reviewed, and centralized logging is a key control to ensure logs from all in-scope systems are captured in a tamper-resistant manner. The percentage of systems with centralized logging enabled directly measures coverage of this control. A high percentage indicates the organization is maintaining the log management requirement across its cardholder data environment.

Exam trap

CAS-005 often tests the mapping of metrics to specific PCI DSS requirements — candidates pick a security-sounding metric like MTTD or failed logins when the question asks about log management coverage specifically.

How to eliminate wrong answers

Option A is wrong because failed login attempts per day is a security event metric, not a compliance coverage metric for Requirement 10. Option C is wrong because MTTD measures incident response effectiveness, which relates more to Requirement 12 (security policies) than to log management coverage. Option D is wrong because vulnerability scan pass rate relates to PCI DSS Requirement 11 (security testing), not Requirement 10 (log management).

101
MCQmedium

During a vendor risk assessment, a third-party vendor refuses to provide a SOC 2 report but offers a completed security questionnaire. The vendor handles sensitive customer data. Which of the following is the BEST course of action?

A.Immediately terminate the relationship.
B.Lower the data classification to reduce risk.
C.Require a right-to-audit clause to conduct an on-site assessment.
D.Accept the questionnaire as sufficient evidence.
AnswerC

A right-to-audit clause contractually grants the company the ability to assess the vendor's controls directly, compensating for the missing SOC 2 report. Since the vendor handles sensitive customer data, on-site assessment provides independent verification that a self-completed questionnaire alone cannot.

Why this answer

When a vendor handling sensitive customer data refuses to provide a SOC 2 report, the best course is to require a right-to-audit clause in the contract and conduct an on-site assessment. This gives the organization direct assurance over the vendor's controls without relying solely on self-attested questionnaires, which are not independent evidence.

Exam trap

CAS-005 often tests vendor risk management judgment — candidates either overreact (terminate) or underreact (accept the questionnaire), missing the balanced control of a right-to-audit clause for independent verification.

How to eliminate wrong answers

Option A is wrong because immediately terminating the relationship is a disproportionate response — it may be unnecessary if the vendor can demonstrate adequate controls through an audit, and it could disrupt business operations. Option B is wrong because lowering the data classification to reduce risk is a form of risk avoidance by mislabeling, which is unethical and does not actually reduce the risk to the data — it just hides it. Option D is wrong because a self-completed security questionnaire is not independent evidence; it is vendor-asserted and lacks the assurance of a third-party audit like SOC 2.

102
MCQmedium

A software company is acquiring a smaller competitor that maintains its own identity provider, endpoint management platform, and network infrastructure. The integration team must fold the acquired company's users and devices into the parent's environment without disrupting business operations. Which activity should occur first to establish governance over the combined environment?

A.Migrate the acquired company's production workloads into the parent's cloud tenancy to consolidate billing
B.Perform a security assessment of the acquired company's identity, endpoint, and network controls to identify gaps before integration
C.Immediately federate the acquired company's identity provider with the parent's directory to unify single sign-on
D.Deploy the parent's endpoint detection agents to all acquired devices during the first maintenance window
AnswerB

Merger and acquisition integration begins with due diligence on the acquired environment so leadership understands inherited risk, control gaps, and remediation cost before merging identities or networks. Assessing the identity provider, endpoint management, and network controls first produces the risk picture that drives integration sequencing, budget, and acceptance decisions, preventing the parent from unknowingly absorbing compromised or unmanaged assets.

Why this answer

Merger and acquisition security governance starts with assessment. Before identities, endpoints, or workloads are merged, the acquiring organization must understand the inherited risk posture so it can prioritize remediation, set integration sequencing, and make informed acceptance decisions. Federating identities, deploying agents, or migrating workloads first can import vulnerabilities and weaken the parent's controls rather than extend them.

Exam trap

The trap here is choosing the most visible integration action, such as identity federation, instead of the assessment that must precede any trust or control changes.

103
MCQeasy

Which of the following is a key difference between a security guideline and a security procedure?

A.Both are equally enforceable
B.Procedures are high-level; guidelines are detailed
C.Guidelines are recommended; procedures are mandatory
D.Guidelines are mandatory; procedures are optional
AnswerC

Guidelines provide discretionary recommendations, whereas procedures are mandatory step-by-step instructions that must be followed. This distinction satisfies the stem's requirement for a key difference: guidelines advise on achieving objectives, while procedures enforce specific actions, making compliance compulsory rather than optional within a security framework.

Why this answer

A security guideline is a recommended, non-mandatory statement of best practice that advises how to align with policy, while a security procedure is a mandatory, step-by-step instruction that must be followed to accomplish a specific task. This distinction in enforceability and specificity is the defining difference between the two document types. Guidelines offer flexibility; procedures prescribe exact actions.

Exam trap

The trap is reversing the enforceability and specificity of guidelines versus procedures — candidates often assume guidelines are mandatory because they sound authoritative.

How to eliminate wrong answers

Option A is wrong because guidelines and procedures are not equally enforceable — guidelines are recommendations, while procedures are mandatory. Option B is wrong because it reverses the hierarchy: procedures are detailed and operational, while guidelines are high-level recommendations. Option D is wrong because it inverts the definitions — guidelines are not mandatory, and procedures are not optional.

104
MCQmedium

A multinational financial services firm is expanding operations into a new jurisdiction. The legal team has identified that the new country requires all personal data of its citizens to be stored on servers physically located within its borders. The security architect must recommend an approach that satisfies this requirement while maintaining the firm's global security standards. Which of the following should the architect recommend?

A.Implement tokenization so that only non-sensitive tokens are stored in the new jurisdiction while actual data remains in the central repository.
B.Use a content delivery network (CDN) to cache personal data at edge locations closest to the new jurisdiction's users.
C.Encrypt all personal data with customer-managed keys and store it in the firm's existing central data center.
D.Implement data localization by deploying dedicated infrastructure in the new jurisdiction and applying the firm's global security baselines to those systems.
AnswerD

Data localization laws require data to remain within the jurisdiction's borders. Deploying dedicated in-country infrastructure and enforcing the firm's global security baselines satisfies the legal requirement without compromising security consistency. This approach directly addresses the sovereignty mandate while allowing the organization to maintain its standard controls, monitoring, and hardening practices across all environments.

Why this answer

Data localization laws require that personal data of a jurisdiction's citizens be stored on physical servers within that jurisdiction. Deploying dedicated in-country infrastructure and applying the organization's global security baselines directly satisfies this legal requirement while ensuring consistent security controls. Other options either store data outside the jurisdiction or fail to guarantee in-country residency.

Exam trap

The trap here is assuming that encryption or tokenization eliminates the need for physical data residency, when the law explicitly requires data to be stored within the jurisdiction's borders.

105
MCQeasy

A security analyst is calculating the annualized loss expectancy (ALE) for a server. The single loss expectancy (SLE) is $5,000 and the annualized rate of occurrence (ARO) is 0.2. What is the ALE?

A.$0
B.$5,200
C.$1,000
D.$25,000
AnswerC

Multiplying SLE by ARO gives $5,000 × 0.2 = $1,000, the annualised loss expectancy. This satisfies the stem's requirement to quantify expected yearly loss from the server risk, expressing exposure as a single monetary figure rather than a frequency or per-incident cost.

Why this answer

The Annualized Loss Expectancy (ALE) is calculated as SLE × ARO. With an SLE of $5,000 and an ARO of 0.2, the ALE is $5,000 × 0.2 = $1,000. This represents the expected yearly financial loss from the risk event, factoring in how often it is expected to occur.

Exam trap

CAS-005 often tests whether candidates confuse the ALE formula (SLE × ARO) with related formulas like SLE (AV × EF) or with additive/multiplicative errors, catching those who add SLE and ARO or invert the division.

How to eliminate wrong answers

Option A is wrong because $0 would imply either no loss (SLE=0) or no occurrence (ARO=0), neither of which applies here. Option B is wrong because $5,200 is the sum of SLE and ARO, which is not a valid risk formula — ALE is multiplicative, not additive. Option D is wrong because $25,000 is SLE divided by ARO (5,000 / 0.2), which is the inverse of the correct calculation and has no meaning in risk analysis.

106
MCQhard

Using the FAIR model, which of the following best describes the factor that represents the probable frequency of a threat acting on a vulnerability?

A.Threat event frequency (TEF)
B.Vulnerability
C.Loss event frequency (LEF)
D.Control effectiveness
AnswerA

Threat event frequency (TEF) quantifies how often a threat agent is likely to act against an asset within a given period, directly answering the stem's requirement for probable frequency of action on a vulnerability. It sits alongside vulnerability and loss magnitude as a core FAIR factor, distinct from contact frequency or probability of action.

Why this answer

Threat event frequency (TEF) is the FAIR factor that quantifies how often a threat agent is expected to act against an asset within a given timeframe. It directly measures the probable frequency of a threat acting on a vulnerability, independent of whether the action succeeds. TEF is a primary input to calculating loss event frequency (LEF).

Exam trap

The trap here is confusing threat event frequency (TEF) with loss event frequency (LEF); candidates often pick LEF because it sounds like the frequency of threat actions, but LEF incorporates vulnerability and represents actual loss events, not just threat actions.

How to eliminate wrong answers

Option B is wrong because vulnerability in FAIR is the probability that a threat event becomes a loss event, not the frequency of the threat action itself. Option C is wrong because loss event frequency (LEF) is the probable frequency of loss events, derived from TEF and vulnerability, not the raw threat action frequency. Option D is wrong because control effectiveness is not a core FAIR factor; it is a modifier that influences vulnerability and TEF, but does not represent the frequency of threat actions.

107
MCQhard

After a risk assessment, a company identifies that the residual risk for a critical application is higher than the risk appetite. The risk owner proposes implementing additional controls to reduce the risk further. Which risk treatment option does this represent?

A.Risk transfer
B.Risk mitigation
C.Risk acceptance
D.Risk avoidance
AnswerB

Adding controls to lower residual risk below the risk appetite is risk mitigation: the organisation reduces likelihood or impact rather than avoiding, transferring or accepting the risk. The risk owner's proposal modifies the risk itself, matching mitigation.

Why this answer

Risk mitigation involves implementing additional controls to reduce the likelihood or impact of a risk. Since the residual risk exceeds the risk appetite, the risk owner proposes further controls to lower it, which is the definition of risk mitigation. This aligns with the goal of bringing risk within acceptable limits.

Exam trap

The trap here is confusing risk mitigation with risk acceptance or avoidance, especially when the scenario mentions residual risk exceeding appetite; candidates might think acceptance is implied, but the proposal of additional controls clearly indicates mitigation.

How to eliminate wrong answers

Option A is wrong because risk transfer shifts the risk to a third party (e.g., insurance), not reducing it through controls. Option C is wrong because risk acceptance means acknowledging the risk without taking action, which is inappropriate when residual risk exceeds appetite. Option D is wrong because risk avoidance involves eliminating the activity or process that generates the risk, not adding controls to reduce it.

108
MCQmedium

A financial services firm is undergoing a SOC 2 Type II examination. The auditor asks the CISO to demonstrate that the organization continuously monitors whether the controls described in the system description operated effectively throughout the review period. Which activity should the CISO present as the primary evidence supporting this requirement?

A.Collecting and retaining timestamped system-generated logs and control execution records across the entire audit period
B.Delivering the organization's information security policy manual and a list of planned future controls
C.Scheduling a one-time penetration test two weeks before the auditor's fieldwork begins
D.Providing a completed security questionnaire signed by the CISO on the last day of the audit period
AnswerA

A SOC 2 Type II opinion covers control operating effectiveness over a defined period, so the auditor needs evidence gathered continuously, not at a single point. Timestamped logs, ticket histories, change records, and monitoring artifacts spanning the full window demonstrate that controls such as access review, change approval, and incident handling actually ran as described throughout the period.

Why this answer

SOC 2 Type II differs from Type I because it reports on control operating effectiveness over a period rather than design at a point in time. The strongest evidence is contemporaneous, system-generated, and timestamped, covering the full window. Signed questionnaires, single penetration tests, and policy manuals only show intent or a snapshot, so they cannot demonstrate that the described controls ran effectively on an ongoing basis.

Exam trap

The trap here is assuming a signed management attestation or policy document can substitute for period-wide evidence, when Type II demands proof that controls actually operated throughout the audited window.

109
MCQeasy

An organization wants to implement continuous compliance monitoring for PCI DSS. Which of the following tools would be MOST effective for this purpose?

A.Encryption solution
B.Network firewall
C.Vulnerability scanner
D.SIEM system
AnswerD

A SIEM system continuously ingests and correlates log data from cardholder-data environment systems, generating real-time alerts against PCI DSS controls such as access monitoring, file integrity and log review. This satisfies the stem's continuous compliance monitoring requirement, unlike point-in-time assessment tools that only snapshot posture periodically.

Why this answer

A SIEM (Security Information and Event Management) system is the most effective tool for continuous compliance monitoring because it aggregates and correlates log data from across the environment in real time, providing ongoing visibility into security events and control effectiveness. For PCI DSS, this directly supports requirements like 10.x (logging and monitoring), 11.5 (change detection), and 12.10 (incident response), enabling automated alerts and evidence collection. Unlike point-in-time tools, a SIEM continuously ingests data, making it ideal for demonstrating sustained compliance rather than periodic snapshots.

Exam trap

CAS-005 often tests the distinction between tools that provide point-in-time assessments (like vulnerability scanners) and those that enable continuous monitoring (like SIEM), so candidates may incorrectly choose a scanner because it sounds security-focused.

How to eliminate wrong answers

Option A is wrong because an encryption solution protects data confidentiality but does not monitor compliance status or generate continuous evidence across PCI DSS controls. Option B is wrong because a network firewall enforces perimeter access rules but provides only limited, static logging and cannot correlate events across systems for continuous compliance. Option C is wrong because a vulnerability scanner performs periodic assessments (e.g., quarterly external scans per PCI DSS 11.2.2) and does not offer real-time, continuous monitoring of the overall control environment.

110
MCQhard

A financial institution is implementing a privacy program based on GDPR principles. Which of the following best describes the concept of 'privacy by design'?

A.Ensuring that data subjects can exercise their rights upon request
B.Appointing a Data Protection Officer to oversee all privacy matters
C.Embedding privacy controls into the design and architecture of systems and processes
D.Conducting a privacy impact assessment after a data breach
AnswerC

Privacy by design means data protection controls are built into system architecture and business processes from the outset, not bolted on afterwards. Embedding them at design time satisfies GDPR's requirement that protection be integral to processing, covering minimisation, purpose limitation and default settings.

Why this answer

Privacy by design is a foundational GDPR principle (Article 25) that requires data protection measures to be integrated into the design and architecture of systems and business processes from the outset, rather than added as an afterthought. This means embedding privacy controls such as data minimization, pseudonymization, and access controls into the very structure of applications and workflows. Option C accurately captures this proactive, architecture-level approach.

Exam trap

The trap is confusing privacy by design with other GDPR principles like data subject rights or DPO appointment; candidates may pick A because it sounds like a privacy control, but privacy by design is specifically about proactive embedding into system architecture.

How to eliminate wrong answers

Option A is wrong because ensuring data subjects can exercise their rights (access, erasure, etc.) is a separate GDPR requirement about data subject rights, not the definition of privacy by design. Option B is wrong because appointing a Data Protection Officer is an organizational governance requirement under GDPR for certain organizations, but it is not the concept of privacy by design. Option D is wrong because conducting a privacy impact assessment after a data breach is reactive and contrary to the proactive nature of privacy by design; GDPR requires DPIAs before processing in high-risk cases, not after a breach.

111
MCQmedium

A company's security policy requires all sensitive data to be encrypted at rest. However, a business unit requests an exception to store certain data unencrypted due to performance constraints. Which document should govern the exception process?

A.Security policy
B.Risk treatment plan
C.Acceptable use policy
D.Data classification standard
AnswerA

A security policy defines mandatory controls and the formal exception process, so it governs deviations from the encryption-at-rest requirement. It specifies who may approve exceptions, the compensating controls and review periods needed, satisfying the stem's constraint that an exception be authorised rather than informally granted by the business unit.

Why this answer

The security policy is the overarching document that defines the organization's security requirements and typically includes provisions for exceptions, including the process for requesting, reviewing, and approving exceptions to policy. Since the requirement to encrypt sensitive data at rest originates from the security policy, any exception to that requirement must be governed by the same policy's exception process. The security policy should specify who can approve exceptions, under what conditions, and for how long.

Exam trap

The trap is selecting a more specific document like the risk treatment plan or data classification standard, but the question asks which document governs the exception process — that is the security policy itself, as it defines the rules and the mechanism for exceptions.

How to eliminate wrong answers

Option B is wrong because a risk treatment plan documents how identified risks will be managed (mitigated, transferred, accepted, etc.), but it does not govern the exception process itself; it may reference exceptions but is not the governing document. Option C is wrong because an acceptable use policy defines how users may use organizational assets and resources, not how to handle exceptions to encryption requirements. Option D is wrong because a data classification standard defines categories of data and handling requirements, but it does not prescribe the exception process for policy deviations.

112
Multi-Selectmedium

A small business is implementing a privacy impact assessment (PIA) for a new application that processes personal data of EU citizens. Which TWO of the following are required under GDPR?

Select 2 answers
A.Obtain approval from a data protection authority before processing
B.Appoint a data protection officer (DPO)
C.Publish the PIA on the company website
D.Describe the processing operations and purposes
E.Assess the necessity and proportionality of the processing
AnswersD, E

Article 35(7)(a) of GDPR requires the data protection impact assessment to contain a systematic description of the processing operations and the purposes of the processing. This is a mandatory DPIA content element, so describing operations and purposes satisfies that requirement.

Why this answer

Under GDPR Article 35, a Data Protection Impact Assessment (DPIA) must contain a systematic description of the envisaged processing operations and the purposes of the processing, which is exactly what option D requires, so D is correct. Article 35(7)(b) also mandates an assessment of the necessity and proportionality of the processing operations in relation to their purposes, making option E correct. Option A is wrong because GDPR does not generally require prior DPA approval before processing; prior consultation under Article 36 is only needed when a DPIA indicates high residual risk that cannot be mitigated.

Option B is wrong because a DPO is mandatory only under Article 37 conditions (large-scale regular monitoring, large-scale special-category data, or public authority), not for every PIA. Option C is wrong because GDPR does not require publishing the DPIA on a website; the DPIA is documented and made available to the supervisory authority on request.

Exam trap

CAS-005 often tests whether candidates conflate DPIA requirements with DPO appointment or DPA consultation, so picking 'appoint a DPO' or 'obtain DPA approval' reflects a misunderstanding of when those obligations actually trigger.

113
MCQhard

A security manager is evaluating two risk quantification approaches: Factor Analysis of Information Risk (FAIR) and a qualitative heat map. Which of the following is a key advantage of using FAIR over the qualitative heat map?

A.FAIR is the only framework recognized by NIST
B.FAIR is easier to communicate to non-technical stakeholders
C.FAIR requires less data and expertise to implement
D.FAIR provides a monetary value for risk, enabling ROI calculations
AnswerD

FAIR quantifies risk in monetary terms by modelling loss event frequency and loss magnitude, producing annualised loss exposure. This contrasts with qualitative heat maps that rank risks ordinally, and enables cost-benefit and ROI comparisons of proposed security controls.

Why this answer

FAIR (Factor Analysis of Information Risk) is a quantitative risk framework that expresses risk in monetary terms — typically annualized loss expectancy (ALE) derived from loss event frequency and loss magnitude. This monetary output enables direct ROI calculations for security investments and lets leadership compare cyber risk against other business risks in financial terms.

Exam trap

CAS-005 often tests the qualitative-vs-quantitative tradeoff, so candidates who assume FAIR is 'easier' or 'more communicable' pick the wrong advantage — the real advantage is monetary output for ROI.

How to eliminate wrong answers

Option A is wrong because NIST does not endorse FAIR as the only recognized framework — NIST SP 800-30 and the NIST RMF are separate, and FAIR is an Open Group standard, not a NIST-mandated one. Option B is wrong because FAIR's quantitative outputs (dollar ranges, Monte Carlo simulations) are often harder to communicate to non-technical stakeholders than a simple red/yellow/green heat map. Option C is wrong because FAIR typically requires more data, modeling expertise, and time than a qualitative heat map, which relies on subjective ratings.

114
MCQhard

A defense contractor must comply with DFARS clause 252.204-7012 and achieve a passing score in its NIST SP 800-171 self-assessment before a contract award. The security lead discovers that several controls in the CUI environment are only partially implemented. Which action should the security lead take to meet the assessment requirement?

A.Document a plan of action with milestones to remediate the partially implemented controls and complete a System Security Plan describing the current state.
B.Request a variance from the contracting officer to exclude the unimplemented controls from the assessment scope.
C.Submit the self-assessment with a perfect score and remediate the gaps after contract award within the first performance period.
D.Implement a compensating control for each partial control and claim full credit in the score to reach the required total.
AnswerA

NIST SP 800-171 assessments permit a score below 110 only when the contractor documents the deficiencies in a System Security Plan and a Plan of Action with defined milestones, resources, and completion dates. This is the accepted path to demonstrate compliance intent and qualify for award while remediation proceeds, so documenting both artifacts is the required action.

Why this answer

When controls are not fully implemented, the accepted method is to document the current state in a System Security Plan and describe remediation in a Plan of Action with milestones. This preserves an honest score while showing the contracting officer a credible path to full implementation.

Exam trap

The trap here is believing that partially implemented controls earn partial points or that a contractor can claim credit for compensating controls to reach a passing score.

115
MCQhard

A defense contractor is required to comply with NIST SP 800-171 for protecting controlled unclassified information (CUI). The security team is implementing the required security requirements. Which of the following best describes the purpose of the System Security Plan (SSP) in this context?

A.It provides a detailed inventory of all CUI data elements and their locations.
B.It documents how the organization implements each security requirement and describes any planned remediation.
C.It contains the results of penetration testing and vulnerability scans for the CUI environment.
D.It serves as a legal contract between the contractor and the Department of Defense.
AnswerB

NIST SP 800-171 defines the SSP as the document that describes how the organization meets each of the 110 security requirements. It includes descriptions of implemented controls, identifies any requirements not yet met, and outlines remediation plans. The SSP is a key deliverable for compliance and is often required for contracts involving CUI. It provides a clear picture of the security posture.

Why this answer

The System Security Plan (SSP) documents how the organization implements each of the NIST SP 800-171 security requirements and identifies any gaps with remediation plans. It is the primary artifact used to demonstrate compliance with DFARS 252.204-7012. It is not a data inventory, contract, or test report, although it may reference those.

The SSP provides a structured narrative of the security posture for the CUI environment.

Exam trap

The trap here is equating the SSP with a data inventory or test report, when its core purpose is to explain how each security requirement is satisfied.

116
MCQhard

A financial institution is adopting a risk management framework based on NIST SP 800-37. The CISO wants to ensure that risk responses are integrated into the enterprise architecture. Which of the following activities best supports this integration during the Risk Response step?

A.Developing a risk register that lists identified risks and their owners.
B.Performing a business impact analysis (BIA) to identify critical business processes.
C.Mapping selected security controls to specific architectural components and documenting the relationships.
D.Conducting a tabletop exercise to validate the effectiveness of the risk response plan.
AnswerC

During Risk Response, NIST SP 800-37 emphasizes selecting, tailoring, and implementing controls. Mapping those controls to architectural components ensures that risk responses are not abstract but are embedded in the system's design. This documentation also facilitates continuous monitoring and change management. It directly supports integration into enterprise architecture by showing where each control resides.

Why this answer

Mapping selected security controls to architectural components is the key activity that integrates risk responses into enterprise architecture. NIST SP 800-37's Risk Response step involves selecting controls, allocating them to systems, and documenting how they are implemented. By explicitly linking controls to architecture, the organization ensures that risk mitigation is designed into systems rather than bolted on later.

This supports traceability and continuous monitoring.

Exam trap

The trap here is confusing documentation or testing activities with the actual architectural integration of controls, which requires explicit mapping to system components.

117
MCQhard

An organization's risk register shows a critical risk with a very high annualized loss expectancy. Executive leadership decides the potential loss is unacceptable but concludes that no cost-effective control exists and that the activity generating the risk is essential to revenue. They formally document the decision, obtain board sign-off, and set a review date. Which risk treatment has leadership applied?

A.Risk avoidance
B.Risk transference
C.Risk acceptance
D.Risk mitigation
AnswerC

Acceptance is the deliberate decision to retain a risk after evaluating treatment options, usually with formal documentation and senior sign-off. Leadership judged the loss unacceptable but found no cost-effective control, kept the essential activity running, recorded the rationale, obtained board approval, and set a review date. Those actions are the defining characteristics of a formally accepted risk rather than avoidance, transference, or mitigation.

Why this answer

Risk acceptance is the conscious decision to retain an identified risk when treatment is not cost-effective or feasible, and it is legitimized through documented rationale, executive or board approval, and scheduled re-evaluation. Leadership continued the essential activity, applied no control, transferred nothing, and formally signed off with a review date. That combination distinguishes acceptance from avoidance, transference, and mitigation.

Exam trap

The trap here is confusing documented acknowledgment of an unremediated risk with mitigation, when the absence of any applied control and the decision to continue the activity indicate formal acceptance.

118
MCQmedium

A security team is measuring the effectiveness of its incident response process. Which of the following metrics would best indicate how quickly the team can contain an incident after it is detected?

A.Mean time to respond (MTTR)
B.Vulnerabilities by severity
C.Patch compliance percentage
D.Mean time to detect (MTTD)
AnswerA

MTTR measures the elapsed time from incident detection to containment, directly quantifying response speed. Other metrics such as MTTD address detection latency, so MTTR is the precise indicator of how quickly the team contains a detected incident.

Why this answer

Mean time to respond (MTTR) measures the average time between incident detection and containment/resolution, directly reflecting how quickly the team can act once an incident is identified. It is the standard metric for response and containment speed in incident response frameworks such as NIST SP 800-61. The other options measure detection speed, vulnerability posture, or patch hygiene, not containment speed.

Exam trap

CAS-005 often tests the confusion between MTTD and MTTR — candidates must read whether the question asks about detecting an incident (MTTD) or responding to/containing it after detection (MTTR).

How to eliminate wrong answers

Option B is wrong because 'vulnerabilities by severity' is a risk-posture metric that counts open vulnerabilities by CVSS severity — it says nothing about how fast the team contains an active incident. Option C is wrong because 'patch compliance percentage' measures how many systems are up to date with patches, which is a preventive control metric, not a response-time metric. Option D is wrong because mean time to detect (MTTD) measures the time from incident occurrence to detection, which is the phase before response — the question specifically asks about containment after detection.

119
MCQhard

A defense contractor must demonstrate compliance with NIST SP 800-171 for controlled unclassified information stored in a contractor-owned system. The compliance lead is preparing evidence for an upcoming assessment and wants to avoid the most common cause of failed assessments. Which activity best prevents assessment failure?

A.Producing a plan of action and milestones that lists every unimplemented requirement with target dates, even if no compensating controls exist.
B.Relying on the cloud service provider's FedRAMP authorization to inherit all 110 security requirements for the contractor system.
C.Maintaining artifacts that show each security requirement is implemented and periodically reviewed, tied to the specific system boundary being assessed.
D.Scheduling the assessment immediately after a penetration test so the most recent findings can serve as proof of implementation.
AnswerC

Assessment failures most often stem from missing or stale evidence rather than absent controls, so maintaining current artifacts that demonstrate each requirement operates within the defined system boundary directly addresses the root cause and lets assessors verify implementation without relying on interviews alone.

Why this answer

Assessments of controlled unclassified information environments fail most often because organizations cannot produce current, boundary-specific evidence for implemented requirements. Sustaining reviewed artifacts tied to the assessed system lets assessors verify each objective directly. Plans of action, provider inheritance, and penetration tests each address only part of the picture and cannot substitute for complete implementation evidence.

Exam trap

The trap here is treating a documented plan of action or inherited provider authorization as equivalent to implemented, evidenced controls within the assessed boundary.

120
MCQmedium

A multinational financial services firm is subject to GDPR and must transfer personal data from its EU offices to a data analytics vendor in the United States. The vendor is not certified under the EU-U.S. Data Privacy Framework. Which mechanism should the firm use to lawfully transfer the data while meeting GDPR Chapter V requirements?

A.Obtaining explicit consent from every data subject for each transfer
B.Standard Contractual Clauses (SCCs) with a transfer impact assessment
C.Relying on the vendor's ISO/IEC 27001 certification as an adequacy mechanism
D.Binding Corporate Rules (BCRs) approved by the lead supervisory authority
AnswerB

SCCs are pre-approved contractual terms adopted by the European Commission that provide appropriate safeguards for international data transfers when the destination country lacks an adequacy decision. Pairing them with a transfer impact assessment satisfies the Schrems II requirement to evaluate local surveillance laws. Because the vendor lacks Data Privacy Framework certification, SCCs are the correct lawful transfer mechanism here.

Why this answer

Because the U.S. vendor lacks Data Privacy Framework certification, the firm must rely on an Article 46 safeguard. Standard Contractual Clauses are the European Commission's pre-approved contractual terms for such transfers, and after Schrems II they must be supplemented by a transfer impact assessment evaluating the destination's surveillance laws. This combination lawfully supports routine transfers to the analytics provider.

Exam trap

The trap here is assuming that any vendor security certification, such as ISO/IEC 27001, automatically satisfies GDPR cross-border transfer requirements.

121
MCQmedium

A software company is pursuing ISO/IEC 27001 certification. The ISMS scope covers its cloud-hosted product and corporate IT. An auditor requests evidence that management reviews the ISMS at planned intervals. Which artifact should the security manager provide?

A.The latest internal audit report and nonconformity log
B.Business continuity and disaster recovery test results
C.The Statement of Applicability listing implemented controls
D.Management review meeting minutes with inputs, decisions, and actions
AnswerD

ISO/IEC 27001 clause 9.3 requires top management to review the ISMS at planned intervals, and documented minutes showing inputs, decisions, and actions are the expected evidence. These records demonstrate that leadership evaluated performance, risks, and opportunities and directed changes. Providing them directly satisfies the auditor's request for management review evidence.

Why this answer

Clause 9.3 of ISO/IEC 27001 mandates that top management review the ISMS at planned intervals, considering status of actions, changes, performance feedback, and risk assessment results. Documented minutes capturing inputs, decisions, and resulting actions are the direct evidence auditors seek. Other artifacts such as internal audit reports or the Statement of Applicability may feed the review but do not demonstrate that it took place.

Exam trap

The trap here is treating any governance-related document, such as the Statement of Applicability, as proof of management review without matching it to clause 9.3.

122
MCQmedium

A multinational financial services firm is expanding operations into the European Union. The legal team asks the security architect to ensure the new customer onboarding portal complies with the General Data Protection Regulation (GDPR). Which of the following should the security architect implement FIRST to align with GDPR's data protection principles?

A.Implement encryption for all data at rest and in transit.
B.Conduct a Data Protection Impact Assessment (DPIA) for the portal's processing activities.
C.Deploy a web application firewall (WAF) to block SQL injection attacks.
D.Appoint a Data Protection Officer (DPO) to oversee the portal.
AnswerB

A DPIA is a GDPR requirement when processing is likely to result in a high risk to data subjects' rights, especially for large-scale or systematic processing. It identifies and mitigates privacy risks before implementation, ensuring accountability and compliance by design. This is the foundational step before deploying technical controls.

Why this answer

GDPR emphasizes a risk-based approach, requiring organizations to assess privacy risks before processing personal data. A Data Protection Impact Assessment (DPIA) is specifically mandated for high-risk processing and helps identify and mitigate risks, ensuring compliance by design. Other controls like encryption or WAFs are supportive but not the initial compliance step.

Exam trap

The trap here is assuming that technical security controls alone satisfy GDPR, when the regulation first demands a privacy risk assessment.

123
MCQhard

A multinational corporation is implementing a data classification scheme. Which of the following data types should be classified as 'restricted'?

A.Internal meeting minutes
B.Customer PII with legal requirements
C.Employee training materials
D.Marketing brochures
AnswerB

Customer PII governed by legal requirements warrants restricted classification because unauthorised disclosure triggers regulatory penalties and contractual breach. Restricted is reserved for data whose exposure causes severe legal, financial or reputational harm, unlike internal or public tiers.

Why this answer

Customer PII with legal requirements should be classified as 'restricted' because it involves personal data protected by laws and regulations (e.g., GDPR, CCPA), and unauthorized disclosure could lead to legal penalties, financial loss, and reputational damage. Restricted data typically requires the highest level of protection.

Exam trap

CAS-005 often tests the confusion between 'confidential' and 'restricted' classifications, where candidates may underestimate the legal implications of PII.

How to eliminate wrong answers

Option A is wrong because internal meeting minutes are typically classified as 'internal' or 'confidential' but not 'restricted' unless they contain sensitive information. Option C is wrong because employee training materials are generally 'internal' or 'public' and do not contain sensitive data. Option D is wrong because marketing brochures are intended for public distribution and are classified as 'public'.

124
MCQmedium

Which of the following is a key difference between compliance and security?

A.Compliance is voluntary, security is mandatory
B.Compliance is proactive, security is reactive
C.Security only applies to technical controls, compliance to administrative
D.Compliance typically represents a minimum bar, while security seeks best practice
AnswerD

Compliance maps to mandated frameworks and regulations, so meeting them satisfies an external minimum threshold. Security pursues defence against evolving threats beyond that floor, adopting controls and practices that exceed regulatory requirements because attackers are not bound by the same baseline.

Why this answer

Compliance frameworks (PCI DSS, HIPAA, ISO 27001) define a baseline set of controls an organization must satisfy to meet regulatory or contractual obligations — they establish a floor, not a ceiling. Security, by contrast, is an ongoing risk-management discipline that aims to reduce risk to an acceptable level using best practices, defense in depth, and continuous improvement. An organization can be fully compliant yet still be insecure because compliance scopes are narrow and point-in-time, whereas security must address the full threat landscape.

Exam trap

CAS-005 often tests the misconception that compliance and security are equivalent or that one is strictly a subset of the other, when in reality compliance is a minimum baseline and security is the broader, continuous risk-reduction discipline.

How to eliminate wrong answers

Option A is wrong because compliance is frequently mandatory (legal/regulatory requirements such as PCI DSS or HIPAA), while security practices are often voluntary beyond what regulations require — the mandatory/voluntary framing is inverted. Option B is wrong because compliance is typically reactive and periodic (audit-driven, snapshot-in-time), while security is the proactive discipline of anticipating and mitigating threats; the labels are reversed. Option C is wrong because both compliance and security span technical, administrative, and physical controls — compliance frameworks explicitly require technical safeguards (encryption, access control) and security programs rely heavily on administrative controls (policies, training).

125
MCQhard

A security architect is designing a new system that will process personal data of European Union citizens. The architect must ensure that data protection principles are embedded into the design. Which of the following best exemplifies the principle of data minimization under the General Data Protection Regulation (GDPR)?

A.Encrypting all personal data at rest and in transit
B.Obtaining explicit consent before processing personal data
C.Collecting only the personal data that is necessary for the specified purpose
D.Implementing a retention schedule to delete data after a set period
AnswerC

Data minimization under GDPR requires that personal data be adequate, relevant, and limited to what is necessary for the purposes for which it is processed. Collecting only necessary data directly implements this principle. This approach reduces privacy risks and is a core requirement of GDPR Article 5(1)(c).

Why this answer

Data minimization under GDPR means collecting and processing only the personal data that is necessary for the intended purpose. This principle is about limiting the scope of data collection, not about security measures, legal bases, or retention periods. The other options represent different GDPR principles or requirements.

Exam trap

The trap here is conflating data minimization with other GDPR principles like storage limitation, security of processing, or lawful basis, which address different aspects of data protection.

126
MCQmedium

A financial institution is required to comply with SOX. Which of the following is a primary focus of this regulation?

A.Privacy of personal data for EU citizens
B.Accuracy of financial reporting and internal controls
C.Security of health information
D.Protection of cardholder data
AnswerB

SOX focuses on the accuracy and reliability of financial reporting and the effectiveness of internal controls over financial reporting for publicly traded companies. This directly matches the financial institution's compliance obligation, distinguishing it from regulations centred on privacy or payment card data.

Why this answer

SOX (Sarbanes-Oxley Act) primarily focuses on the accuracy of financial reporting and the effectiveness of internal controls for publicly traded companies. It mandates that management assess and report on internal controls over financial reporting, and requires external auditors to attest to those assessments. This ensures transparency and accountability in financial disclosures.

Exam trap

The trap here is confusing SOX with other regulations like GDPR, HIPAA, or PCI DSS, which focus on privacy, health data, or cardholder data respectively.

How to eliminate wrong answers

Option A is wrong because privacy of personal data for EU citizens is governed by GDPR, not SOX. Option C is wrong because security of health information is the focus of HIPAA. Option D is wrong because protection of cardholder data is addressed by PCI DSS.

127
Multi-Selecthard

A security manager is selecting key risk indicators (KRIs) for the organization's risk management program. Which THREE of the following are examples of KRIs that can provide early warning of increasing risk?

Select 3 answers
A.Number of failed login attempts per hour
B.Mean time to detect (MTTD) for incidents
C.Percentage of users with privileged access
D.Number of unpatched critical vulnerabilities
E.Percentage of systems with current backups
AnswersA, C, D

Failed login attempts per hour is a leading indicator of credential-stuffing or brute-force activity, rising before a successful compromise. Monitoring this rate provides early warning of authentication attacks, letting the security manager intervene before an account is breached.

Why this answer

Option A (number of failed login attempts per hour) is a valid KRI because a rising rate of authentication failures is a leading indicator of brute-force, password-spraying, or credential-stuffing attacks, giving early warning before a breach occurs. Option C (percentage of users with privileged access) is a KRI because excessive or growing privileged accounts expand the attack surface and the potential blast radius of a compromise, signaling creeping access-control risk. Option D (number of unpatched critical vulnerabilities) is a KRI because a growing count of unpatched critical CVEs directly raises the likelihood of exploitation and is a measurable, forward-looking exposure metric.

Option B (MTTD) is a key performance indicator of detection efficiency, not an early-warning risk indicator, and Option E (percentage of systems with current backups) is a control-effectiveness or compliance metric rather than a leading indicator of increasing risk.

Exam trap

CAS-005 often tests the confusion between KRIs and Key Performance Indicators (KPIs), where candidates may select lagging metrics like MTTD as KRIs.

128
Multi-Selecthard

An organization is developing a policy exception management process. Which three of the following are essential components of an effective exception process? (Choose three.)

Select 3 answers
A.Documented business justification for the exception
B.An expiration date for the exception
C.Automatic enforcement of policy via technical controls
D.A risk assessment of the exception
E.A copy of the entire policy hierarchy
AnswersA, B, D

A documented business justification records why the policy cannot be met and what compensating value the exception delivers. It satisfies the need for an auditable, defensible reason before approvers authorise deviation from the standard control.

Why this answer

Option A is correct because every exception must be supported by a documented business justification that explains why the policy cannot be met and what compensating value the exception provides, giving approvers the rationale needed to make an informed decision. Option B is correct because exceptions must have an expiration date (or defined review period) so they are temporary and time-bound, preventing them from becoming permanent de facto policy and forcing periodic re-evaluation. Option D is correct because a risk assessment quantifies the residual risk introduced by the exception, allowing management to accept that risk knowingly and to define compensating controls.

Option C is not essential to the exception process itself; automatic enforcement is a policy implementation mechanism, and an exception by definition suspends or modifies enforcement rather than applying it. Option E is not essential because attaching the entire policy hierarchy is unnecessary documentation; the exception only needs to reference the specific policy clause being excepted, not reproduce the whole hierarchy.

Exam trap

CAS-005 often tests the confusion between policy enforcement and exception management, leading candidates to select technical controls as an essential component when the focus should be on governance elements like justification, risk assessment, and expiration.

129
MCQhard

A CISO is presenting a risk register to the board. The register shows a ransomware risk with a single loss expectancy of $2,000,000 and an annualized rate of occurrence of 0.25. The board asks for the expected annual financial exposure. What is the annualized loss expectancy (ALE) for this risk?

A.$500,000
B.$8,000,000
C.$2,000,000
D.$250,000
AnswerA

ALE is calculated as single loss expectancy multiplied by annualized rate of occurrence: $2,000,000 × 0.25 = $500,000. This figure represents the expected average annual loss from the ransomware risk and is the value the board should use for budgeting risk treatment decisions. It is the correct quantitative output for this scenario.

Why this answer

Quantitative risk analysis uses ALE = SLE × ARO. With a single loss expectancy of $2,000,000 and an annualized rate of occurrence of 0.25, the expected annual loss is $500,000. This metric lets the board compare the cost of controls against the financial exposure and decide whether to mitigate, transfer, or accept the ransomware risk.

Exam trap

The trap here is confusing single loss expectancy with annualized loss expectancy and reporting the per-incident cost as the yearly exposure.

130
MCQmedium

A company is evaluating a new cloud service provider. The provider offers a SOC 2 Type II report, a third-party penetration test summary, and a completed security questionnaire. However, the company's procurement team discovers that the provider uses a subcontractor for data storage. Which of the following is the BEST next step for the security team?

A.Require the provider to use only in-house resources.
B.Accept the risk because the provider has a SOC 2 report.
C.Request a right-to-audit clause covering the subcontractor.
D.Immediately terminate the contract due to subcontractor risk.
AnswerC

The subcontractor stores data but sits outside the provider's direct audit scope, so its controls are unverified. A right-to-audit clause extending to subcontractors gives the security team contractual authority to assess that storage environment, closing the assurance gap the procurement team identified.

Why this answer

When a cloud provider uses a subcontractor for data storage, the security team should ensure they have the right to audit the subcontractor's controls, typically through a right-to-audit clause in the contract. This allows the company to verify that the subcontractor meets the required security standards. The other options are either too extreme or insufficient.

Exam trap

CAS-005 often tests the misconception that a SOC 2 report from the primary provider automatically covers all subcontractors; candidates must recognize the need for additional assurance like right-to-audit clauses.

How to eliminate wrong answers

Option A is wrong because requiring only in-house resources is impractical and may not be feasible; it also doesn't address the risk directly. Option B is wrong because a SOC 2 report covers the provider's controls but may not include the subcontractor's controls, so accepting the risk without further assurance is inadequate. Option D is wrong because immediately terminating the contract is a drastic step that may not be necessary if the subcontractor can be audited and meets requirements.

131
Multi-Selectmedium

A security manager is developing a third-party risk management program. Which two of the following are considered best practices for assessing and managing vendor risk throughout the vendor lifecycle? (Choose two.)

Select 2 answers
A.Performing continuous monitoring of the vendor's security posture throughout the contract term.
B.Conducting a thorough pre-contract due diligence assessment of the vendor's security posture.
C.Relying solely on the vendor's self-attestation of compliance with industry standards.
D.Excluding the vendor's subcontractors from the risk assessment scope.
E.Limiting the vendor risk assessment to the initial onboarding phase only.
AnswersA, B

Continuous monitoring ensures that the vendor maintains the agreed-upon security controls and promptly identifies changes that could introduce new risks. It can include periodic reassessments, security ratings, and monitoring for breaches. This is a best practice because risk is not static; a vendor's posture can change due to incidents, mergers, or control failures. Ongoing monitoring supports timely risk mitigation.

Why this answer

Best practices for third-party risk management include conducting pre-contract due diligence and performing continuous monitoring throughout the contract term. These activities ensure that risks are identified before onboarding and managed as they evolve. Relying solely on self-attestation, limiting assessment to onboarding, or excluding subcontractors are all ineffective and can lead to unmanaged risk and compliance failures.

Exam trap

The trap here is thinking that a one-time vendor assessment or self-attestation is sufficient, when effective third-party risk management requires ongoing validation and inclusion of the entire supply chain.

132
Multi-Selectmedium

An organization is reviewing its supply chain risk management. Which TWO of the following are effective strategies to manage fourth-party risk?

Select 2 answers
A.Use only vendors that are SOC 2 certified
B.Reduce reliance on vendors by bringing services in-house
C.Conduct penetration tests on all fourth parties directly
D.Include a right-to-audit clause that covers subcontractors
E.Require vendors to contractually mandate security controls for their subcontractors
AnswersD, E

Extending the right-to-audit clause to subcontractors gives the organisation contractual visibility and audit reach into fourth parties, satisfying the stem's requirement to manage risk beyond direct suppliers. Without this flow-down, subcontractor controls remain unverified, so fourth-party exposure cannot be assessed or enforced.

Why this answer

To manage fourth-party risk, organizations can require their vendors to flow down security requirements to subcontractors and include right-to-audit clauses that extend to subcontractors.

133
Multi-Selecthard

A security team is conducting a risk assessment for a new cloud-based customer relationship management (CRM) system. The team must identify and evaluate risks related to data breaches, compliance, and availability. Which TWO of the following factors are MOST important to consider when determining the likelihood of a data breach in this cloud environment? (Choose two.)

Select 2 answers
A.The cloud provider's history of security incidents and transparency in reporting.
B.The physical location of the organization's headquarters.
C.The sensitivity and volume of data stored in the CRM system.
D.The cloud provider's compliance certifications, such as SOC 2 or ISO 27001.
E.The number of employees in the organization's security team.
AnswersA, C

A cloud provider's history of security incidents and their willingness to disclose them is a direct indicator of their security posture. If the provider has a pattern of breaches or lacks transparency, the likelihood of a future breach increases. This factor is critical in assessing the probability of a data breach, as it reflects the provider's operational security maturity and incident response effectiveness.

Why this answer

When assessing the likelihood of a data breach in a cloud environment, two critical factors are the cloud provider's security incident history and transparency, and the sensitivity and volume of data stored. A provider with a poor track record or lack of transparency increases the probability of a breach. High-value data attracts attackers, raising the likelihood.

Other factors like internal team size, headquarters location, or certifications are less directly related to breach probability.

Exam trap

The trap here is focusing on compliance certifications or internal team size as primary indicators of breach likelihood, when the provider's incident history and data sensitivity are more directly relevant.

134
MCQmedium

A multinational retailer is expanding into the European Union and must transfer employee payroll data from its EU subsidiary to its US-based HR platform. Legal counsel recommends relying on the EU-US Data Privacy Framework rather than implementing Standard Contractual Clauses. Which action must the retailer take FIRST to rely on this transfer mechanism?

A.Obtain explicit consent from every EU employee before the payroll records are transmitted to the US platform.
B.Verify that the US HR platform is listed as an active participant on the Data Privacy Framework List maintained by the US Department of Commerce.
C.Conduct a Transfer Impact Assessment documenting that US surveillance laws do not undermine the protection of the payroll data.
D.Execute a Binding Corporate Rules application with the lead supervisory authority in the EU member state where the subsidiary is established.
AnswerB

The EU-US Data Privacy Framework requires the receiving organization to self-certify to the US Department of Commerce and appear on the official Data Privacy Framework List. Only then can EU personal data flow to that importer without SCCs or a derogation. Confirming active certification status is the mandatory prerequisite step before the transfer can lawfully occur.

Why this answer

The EU-US Data Privacy Framework permits transfers to US importers that have self-certified and appear on the Department of Commerce's Data Privacy Framework List. Verifying that the HR platform holds active certification is the foundational requirement; without it, the framework cannot be invoked and another transfer tool would be needed.

Exam trap

The trap here is assuming that any US company is automatically covered by the EU-US Data Privacy Framework instead of confirming the importer's active self-certification on the official list.

135
Multi-Selecteasy

A compliance officer is preparing for an audit and needs to collect evidence. Which TWO of the following are considered acceptable forms of audit evidence? (Select TWO.)

Select 2 answers
A.Screenshots of unofficial reports
B.Verbal statements from employees
C.Written security policies
D.Assumptions about system configurations
E.System access logs
AnswersC, E

Written security policies are documented, approved management directives that auditors accept as evidence of intended control design and governance. This satisfies the stem's acceptable-evidence criterion because they demonstrate the organisation's stated requirements, though they show intent rather than proving the controls actually operate.

Why this answer

Written security policies (C) are acceptable audit evidence because they are documented, approved artifacts that demonstrate the organization's formal security requirements and controls, providing verifiable proof of governance intent. System access logs (E) are acceptable because they are system-generated, tamper-evident records that objectively show actual activity such as authentication events, timestamps, and user actions, which auditors can trace and corroborate. In contrast, screenshots of unofficial reports (A) lack authenticity and provenance since they can be altered and are not from controlled sources, verbal statements from employees (B) are testimonial and unverifiable without documentation, and assumptions about system configurations (D) are unsubstantiated beliefs rather than evidence, so none of these qualify as acceptable audit evidence.

Exam trap

The trap is that candidates select 'verbal statements from employees' because interviews are part of audits — but interviews are inquiry, not evidence, and auditors must corroborate inquiry with documentary or system-generated proof.

136
MCQeasy

A security analyst is reviewing the organization's incident response plan and notices that it lacks a formal process for communicating with external stakeholders during a breach. Which of the following should the analyst recommend to address this gap?

A.Increase the cyber insurance coverage to include crisis management services.
B.Implement a security information and event management (SIEM) system to automate alerting of external parties.
C.Develop a communication plan that includes predefined templates, contact lists, and approval workflows for external notifications.
D.Conduct a tabletop exercise to test the existing incident response plan without modifying it.
AnswerC

A formal communication plan ensures timely, accurate, and approved messaging to external stakeholders such as customers, regulators, and media. Predefined templates and contact lists speed up response, while approval workflows prevent unauthorized disclosures. This directly fills the gap in the incident response plan and aligns with best practices for breach notification and reputational management.

Why this answer

A formal communication plan with predefined templates, contact lists, and approval workflows ensures that external stakeholders receive timely, accurate, and authorized information during a breach. This directly addresses the identified gap. SIEM, tabletop exercises, and insurance do not provide the structured communication process required.

Exam trap

The trap here is confusing tools that support incident response, such as SIEM or insurance, with the actual process needed for external communications.

137
MCQeasy

A security analyst is reviewing the organization's incident response plan. The plan includes a section on communication with external parties. Which of the following best describes the primary purpose of a communication plan during a security incident?

A.To outline the technical steps for containing the incident.
B.To document the chain of custody for forensic evidence.
C.To provide technical details of the incident to the security operations team.
D.To ensure timely and accurate information sharing with stakeholders, regulators, and the public.
AnswerD

A communication plan defines who communicates what, when, and to whom during an incident. Its primary purpose is to manage information flow to internal and external stakeholders, maintain trust, and meet legal obligations. This reduces confusion and helps control the narrative, which is critical for incident response.

Why this answer

The communication plan is a component of incident response that focuses on information sharing with stakeholders, including executives, legal, regulators, and customers. Its primary goal is to ensure timely, accurate, and compliant messaging. Technical containment and evidence handling are separate processes, making the stakeholder communication purpose the correct choice.

Exam trap

The trap here is equating the communication plan with technical response actions, when it actually governs stakeholder messaging.

138
MCQmedium

A company is conducting a third-party risk assessment for a SaaS provider. The provider has provided a SOC 2 Type II report, penetration test results, and a completed security questionnaire. Which of these provides the most independent and comprehensive view of the provider's control environment over time?

A.Penetration test report
B.Security questionnaire
C.Vendor's marketing materials
D.SOC 2 Type II report
AnswerD

A SOC 2 Type II report tests control design and operating effectiveness across a defined audit period, giving an independent, time-spanning view. Penetration tests and questionnaires are point-in-time or self-reported, so only the Type II report meets the stem's requirement for comprehensive evidence over time.

Why this answer

A SOC 2 Type II report provides an independent auditor's opinion on the design and operating effectiveness of controls over a period of time (typically 3-12 months). This gives a comprehensive, time-tested view of the provider's control environment, unlike point-in-time assessments.

Exam trap

The trap is assuming a penetration test or questionnaire provides equivalent assurance; candidates often overvalue point-in-time or self-attested evidence over independent, time-bound audits.

How to eliminate wrong answers

Option A is wrong because a penetration test report is a point-in-time snapshot of vulnerabilities and does not evaluate the ongoing effectiveness of controls. Option B is wrong because a security questionnaire is self-reported by the vendor and lacks independent verification. Option C is wrong because marketing materials are unverified, biased, and not an independent assessment.

139
MCQhard

A multinational retailer must transfer employee personal data from its European Union subsidiary to a processing center in a country without an adequacy decision. Legal counsel wants a transfer mechanism that imposes enforceable data protection obligations on the importer and includes a documented transfer impact assessment. Which mechanism best matches these requirements?

A.An explicit consent obtained from each employee once at the time of hire for all future transfers
B.A certification under an approved code of conduct registered with the subsidiary's data protection authority
C.Standard Contractual Clauses supplemented by a transfer impact assessment and additional safeguards
D.Binding Corporate Rules approved only by the subsidiary's local supervisory authority without any further analysis
AnswerC

Standard Contractual Clauses are pre-approved contractual terms that create enforceable obligations on the data importer, and after the Schrems II ruling they must be paired with a transfer impact assessment of the destination country's laws plus supplementary technical or organizational measures when needed. This combination directly satisfies the requirement for enforceable importer obligations and a documented assessment.

Why this answer

Cross-border transfers outside an adequacy decision require a valid Chapter V mechanism. Standard Contractual Clauses impose enforceable obligations on the importer, and following Schrems II they must be accompanied by a transfer impact assessment and supplementary measures where destination laws undermine protection. Consent, codes of conduct, and improperly approved Binding Corporate Rules do not meet the combined contractual and assessment requirements described.

Exam trap

The trap here is treating any listed transfer mechanism as automatically sufficient, when the scenario specifically requires enforceable importer obligations plus a documented transfer impact assessment.

140
Multi-Selecthard

A software company is preparing to release a new payment feature that processes cardholder data. The security architect must ensure the feature design meets PCI DSS requirements for protecting stored data and for securing transmission over open, public networks. Which two design choices satisfy these requirements? (Choose two.)

Select 2 answers
A.Disable audit logging for the payment feature to reduce storage of sensitive data
B.Enable TLS 1.2 or higher with strong cipher suites for all payment traffic traversing the internet
C.Replace the primary account number with a token in the application database and map it in a separate hardened token vault
D.Store the full primary account number encrypted with a documented key management process
E.Rely on the payment processor's PCI DSS compliance certificate and transmit card data without additional encryption
AnswersB, C

PCI DSS requires strong cryptography and security protocols to safeguard cardholder data during transmission over open, public networks. TLS 1.2 or higher with strong cipher suites and proper certificate validation satisfies that requirement. This directly addresses the scenario's transmission concern and is a standard, auditable control for protecting data in transit between the customer browser, application, and payment processor.

Why this answer

The two correct design choices are tokenization with a hardened token vault and strong TLS for data in transit. Tokenization reduces the value of stored data and can shrink the cardholder data environment, while TLS 1.2 or higher with strong ciphers protects data moving across open, public networks. Together they address both the storage and transmission requirements in the scenario without relying on a third party's compliance to cover the organization's own obligations.

Exam trap

The trap here is assuming that a payment processor's PCI DSS certificate removes the need to encrypt cardholder data that the organization itself transmits.

141
MCQhard

A company wants to implement continuous compliance monitoring. Which of the following approaches BEST supports this goal?

A.Manual review of compliance reports quarterly
B.Deploying a Security Information and Event Management (SIEM) system
C.Implementing automated compliance auditing tools
D.Annual external audits
AnswerC

Automated compliance auditing tools continuously evaluate configurations against benchmarks and frameworks, generating evidence and alerts without manual review cycles. This satisfies the requirement for continuous monitoring rather than periodic point-in-time assessment, enabling prompt detection of drift or non-compliance across the estate.

Why this answer

Continuous compliance monitoring requires automated, real-time checks against policies and regulations. Automated auditing tools can continuously assess controls and generate alerts.

142
Multi-Selecthard

A compliance officer is preparing for a GDPR audit. Which THREE of the following are key data subject rights under GDPR that the organization must be able to demonstrate?

Select 3 answers
A.Right to object to processing
B.Right to unlimited data storage
C.Right to erasure (right to be forgotten)
D.Right to data monetization
E.Right to data portability
AnswersA, C, E

The right to object lets individuals halt processing based on legitimate interests or direct marketing, and controllers must honour it unless they demonstrate compelling grounds. Auditors expect documented workflows and records proving this GDPR right can be exercised and enforced.

Why this answer

GDPR grants data subjects several rights, including the right to erasure (right to be forgotten), right to data portability, and right to object to processing. The right to rectification is also a right but is not listed as an option. The right to data monetization and right to unlimited storage are not GDPR rights.

143
MCQhard

A healthcare organization is implementing a new telehealth platform that stores electronic protected health information (ePHI). The security team must ensure compliance with the HIPAA Security Rule. Which of the following is a required implementation specification for access control under the HIPAA Security Rule?

A.Emergency access procedure
B.Automatic logoff
C.Encryption and decryption
D.Unique user identification
AnswerD

Under the HIPAA Security Rule, unique user identification is a required implementation specification for access control (45 CFR §164.312(a)(2)(i)). It mandates that each user accessing ePHI be assigned a unique identifier to track activity and enforce accountability. This is not optional; it must be implemented to comply with the rule, making it the correct choice for this scenario.

Why this answer

The HIPAA Security Rule distinguishes between required and addressable implementation specifications. Unique user identification is explicitly required for access control, ensuring accountability and traceability. Addressable specifications like emergency access, automatic logoff, and encryption require a risk-based decision but are not mandatory in all cases.

Exam trap

The trap here is assuming that all implementation specifications under the HIPAA Security Rule are mandatory, when some are addressable and allow flexibility.

← PreviousPage 2 of 2 · 143 questions total

Ready to test yourself?

Try a timed practice session using only Governance, Risk, and Compliance questions.