CAS-004 Governance, Risk, and Compliance Practice Question
During a vendor risk assessment, a third-party vendor refuses to provide a SOC 2 report but offers a completed security questionnaire. The vendor handles sensitive customer data. Which of the following is the BEST course of action?
⚠ Common exam trap
CAS-005 often tests vendor risk management judgment — candidates either overreact (terminate) or underreact (accept the questionnaire), missing the balanced control of a right-to-audit clause for independent verification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Require a right-to-audit clause to conduct an on-site assessment.
When a vendor handling sensitive customer data refuses to provide a SOC 2 report, the best course is to require a right-to-audit clause in the contract and conduct an on-site assessment. This gives the organization direct assurance over the vendor's controls without relying solely on self-attested questionnaires, which are not independent evidence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Immediately terminate the relationship.
Why it's wrong here
Termination may be premature; negotiation is possible.
- ✗
Lower the data classification to reduce risk.
Why it's wrong here
Reclassifying data to dodge vendor risk inverts the control: classification drives required protections, so lowering it misrepresents sensitivity and breaches governance. It tempts because classification reviews are legitimate when data genuinely changes. Here the vendor still handles sensitive customer data, so the correct path is pursuing compensating assurance or escalation, not relabelling.
- ✓
Require a right-to-audit clause to conduct an on-site assessment.
Why this is correct
A right-to-audit clause contractually grants the company the ability to assess the vendor's controls directly, compensating for the missing SOC 2 report. Since the vendor handles sensitive customer data, on-site assessment provides independent verification that a self-completed questionnaire alone cannot.
- ✗
Accept the questionnaire as sufficient evidence.
Why it's wrong here
A self-attested questionnaire supplies no independent verification of control operation, unlike a SOC 2 report covering security, availability, and confidentiality. It tempts because questionnaires are cheap, fast, and useful as a screening input before full assessment. For sensitive customer data, unverified vendor assertions cannot substitute for independent assurance or contractual remedies.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.