CAS-004 Governance, Risk, and Compliance Practice Question
During a policy gap analysis, it is discovered that the organization has a policy stating that sensitive data must be encrypted, but there are no procedures for implementing encryption on mobile devices. This is an example of a gap between:
⚠ Common exam trap
The trap is treating 'standards' and 'procedures' as synonyms; the exam expects you to distinguish the mandatory technical requirement (standard) from the step-by-step implementation (procedure).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Policy and procedures
A policy states the mandatory 'what' (sensitive data must be encrypted), while procedures describe the step-by-step 'how' (how to enable encryption on mobile devices, which tools, who does it). The gap described is the absence of implementation procedures supporting an existing policy, so it is a policy-to-procedures gap.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Standards and guidelines
Why it's wrong here
Standards are mandatory specifications, whereas guidelines are discretionary recommendations; the stem contrasts a mandatory policy with missing implementation procedures, not standards against guidelines. It is tempting because both documents sit below policy, but neither is the mandatory procedure layer described.
- ✗
Policy and standards
Why it's wrong here
Standards are mandatory technical specifications; the stem's missing element is the procedural implementation detail, which sits at the procedure level, not standards. It is tempting because standards also derive from policy, but they specify requirements rather than step-by-step mobile encryption procedures.
- ✗
Policy and guidelines
Why it's wrong here
Guidelines are discretionary recommendations, so a missing mandatory procedure cannot be a gap between policy and guidelines. It is tempting because guidelines sit below policy in the hierarchy, but the stem describes absent required procedures, not optional advice.
- ✓
Policy and procedures
Why this is correct
The encryption mandate exists as a stated policy, but no implementing procedures exist for mobile devices. The gap therefore lies between policy and procedures, since the documented requirement lacks the operational steps needed to enact it on that platform.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.