Courseiva
hardMultiple Choice

CAS-004 Practice Question: During a third-party risk assessment, a security…

During a third-party risk assessment, a security architect discovers that a vendor's data retention policy does not align with the organization's legal requirements. Which of the following is the BEST course of action?

⚠ Common exam trap

CompTIA often tests the misconception that compensating controls can fully substitute for vendor compliance, but the trap here is that legal requirements demand the vendor's own policy and processes be compliant, not just the organization's technical workarounds.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Request the vendor to update its retention policy to align with legal requirements.

The vendor's data retention policy must comply with the organization's legal requirements, such as GDPR or HIPAA, which mandate specific data lifecycle controls. Requesting the vendor to update its policy is the most direct and effective way to achieve compliance, as it addresses the root cause without prematurely terminating a business relationship or relying on compensating controls that may not fully satisfy regulatory obligations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Request the vendor to update its retention policy to align with legal requirements.

    Why this is correct

    Requesting the vendor to align its retention policy with the organisation's legal requirements directly closes the identified compliance gap while preserving the vendor relationship. Termination or acceptance would leave the organisation exposed to legal and regulatory breach, so remediation is the best course.

  • ✗

    Accept the risk and document it in the risk register.

    Why it's wrong here

    Acceptance leaves a live legal compliance gap unaddressed, and the organisation cannot simply absorb a contractual or regulatory breach. It tempts because risk acceptance is legitimate for low-impact residual risks within appetite, but misaligned retention obligations demand remediation or escalation instead.

  • ✗

    Immediately terminate the vendor contract.

    Why it's wrong here

    Terminating the contract discards the vendor relationship before any remediation is attempted, and retention misalignment rarely breaches termination clauses. It is tempting as a decisive risk-avoidance move, and would be right where the vendor refuses remediation or the data processing is unlawful outright.

  • ✗

    Implement compensating controls to enforce data deletion after the required period.

    Why it's wrong here

    Compensating controls cannot substitute for the vendor's own retention obligations; the vendor still holds and processes the data under its own policy, so deletion after the required period is not enforceable by the customer. It would suit internal systems the organisation itself controls.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.