Courseiva
hardMultiple ChoiceObjective-mapped

CAS-004 Practice Question: During a third-party risk assessment, a security…

During a third-party risk assessment, a security architect discovers that a vendor's data retention policy does not align with the organization's legal requirements. Which of the following is the BEST course of action?

⚠ Common exam trap

CompTIA often tests the misconception that compensating controls can fully substitute for vendor compliance, but the trap here is that legal requirements demand the vendor's own policy and processes be compliant, not just the organization's technical workarounds.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Request the vendor to update its retention policy to align with legal requirements.

The vendor's data retention policy must comply with the organization's legal requirements, such as GDPR or HIPAA, which mandate specific data lifecycle controls. Requesting the vendor to update its policy is the most direct and effective way to achieve compliance, as it addresses the root cause without prematurely terminating a business relationship or relying on compensating controls that may not fully satisfy regulatory obligations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Request the vendor to update its retention policy to align with legal requirements.

    Why this is correct

    This directly addresses the discrepancy and leverages the contractual requirement to follow best practices.

  • Accept the risk and document it in the risk register.

    Why it's wrong here

    Risk acceptance may be used but only after attempts to mitigate; alignment is expected in contracts.

  • Immediately terminate the vendor contract.

    Why it's wrong here

    Termination is a drastic measure; negotiation should be attempted first.

  • Implement compensating controls to enforce data deletion after the required period.

    Why it's wrong here

    Compensating controls can mitigate, but the root cause is the vendor's policy; requesting alignment is better.

About these practice questions

One of 968 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.