hardMultiple ChoiceObjective-mapped
CAS-004 Practice Question: During a third-party risk assessment, a security…
During a third-party risk assessment, a security architect discovers that a vendor's data retention policy does not align with the organization's legal requirements. Which of the following is the BEST course of action?
⚠ Common exam trap
CompTIA often tests the misconception that compensating controls can fully substitute for vendor compliance, but the trap here is that legal requirements demand the vendor's own policy and processes be compliant, not just the organization's technical workarounds.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Request the vendor to update its retention policy to align with legal requirements.
The vendor's data retention policy must comply with the organization's legal requirements, such as GDPR or HIPAA, which mandate specific data lifecycle controls. Requesting the vendor to update its policy is the most direct and effective way to achieve compliance, as it addresses the root cause without prematurely terminating a business relationship or relying on compensating controls that may not fully satisfy regulatory obligations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Request the vendor to update its retention policy to align with legal requirements.
Why this is correct
This directly addresses the discrepancy and leverages the contractual requirement to follow best practices.
- ✗
Accept the risk and document it in the risk register.
Why it's wrong here
Risk acceptance may be used but only after attempts to mitigate; alignment is expected in contracts.
- ✗
Immediately terminate the vendor contract.
Why it's wrong here
Termination is a drastic measure; negotiation should be attempted first.
- ✗
Implement compensating controls to enforce data deletion after the required period.
Why it's wrong here
Compensating controls can mitigate, but the root cause is the vendor's policy; requesting alignment is better.
Go deeper
Related to this question
About these practice questions
One of 968 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.