Courseiva
hardMultiple ChoiceObjective-mapped

CAS-004 Practice Question: The exhibit shows results from a CIS Controls…

Exhibit

Refer to the exhibit.

CIS Controls Assessment Results:
Control 3: Data Protection — Score: 2/5
  - Subcontrol 3.1: Inventory of sensitive data — 0/5 (Not implemented)
  - Subcontrol 3.2: Encryption of sensitive data at rest — 4/5
  - Subcontrol 3.3: Encryption of sensitive data in transit — 3/5
Control 8: Incident Response — Score: 3/5
  - Subcontrol 8.1: Incident response plan — 5/5
  - Subcontrol 8.2: Incident response testing — 1/5
Control 13: Network Monitoring and Defense — Score: 1/5
  - Subcontrol 13.1: Centralized logging — 2/5
  - Subcontrol 13.2: Intrusion detection — 0/5

The exhibit shows results from a CIS Controls assessment. Based on the findings, which control deficiency poses the greatest risk to the organization and should be prioritized for remediation?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Network monitoring and defense (Control 13) because it has the lowest overall score and intrusion detection is missing

The network monitoring and defense control (Control 13) has the lowest overall score (1/5), and within it, intrusion detection is completely unimplemented (0/5), leaving the organization blind to active attacks. Option A is wrong because incident response (Control 8) has a score of 3/5, which is higher, and testing at 1/5 is a partial implementation; while testing is low, the overall risk is lower than network monitoring. Option C is wrong because data protection (Control 3) has a score of 2/5 with some subcontrols partially implemented; the missing sensitive data inventory is concerning but not as critical as the lack of network monitoring. Option D is wrong because data encryption at rest (Subcontrol 3.2) has a score of 4/5, indicating it's already highly implemented and not a priority.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Incident response (Control 8) because testing is only at 1/5

    Why it's wrong here

    Incident response scores 3/5 overall, relatively good; testing is a gap but not the most critical.

  • Network monitoring and defense (Control 13) because it has the lowest overall score and intrusion detection is missing

    Why this is correct

    This control has the lowest score (1/5) and lacks intrusion detection, which is vital for detecting threats.

  • Data protection (Control 3) because sensitive data inventory is not implemented

    Why it's wrong here

    Data protection scores 2/5 overall, which is moderate; inventory is a gap but not the highest risk.

  • Data encryption at rest (Subcontrol 3.2) because it received a score of 4/5, indicating room for improvement

    Why it's wrong here

    A score of 4/5 indicates strong implementation; this is not a pressing deficiency.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.