Courseiva

CCNA Casp Grc Questions

75 of 143 questions · Page 1/2 · Casp Grc topic · Answers revealed

1
MCQeasy

A newly hired Chief Information Security Officer is establishing a governance structure and wants to define who is accountable for accepting residual risk that exceeds the organization's stated risk appetite. According to common governance practice, which role holds that accountability?

A.The board of directors or an executive risk committee with authority delegated by the board.
B.The internal audit director who reports findings to the audit committee.
C.The third-party managed security service provider under the outsourcing agreement.
D.The security operations center manager who oversees day-to-day monitoring and incident response.
AnswerA

Accountability for risk that exceeds the approved appetite rests with the board or a committee it empowers, since governance ultimately owns organizational risk. Executives and security staff implement and monitor controls, but accepting risk beyond the tolerance level requires the governing body's authority and oversight.

Why this answer

Governance accountability for accepting risk beyond the approved appetite belongs to the board of directors or a delegated executive risk committee. Operational and assurance roles support risk management but do not own the decision to retain risk at the enterprise level.

Exam trap

The trap here is assuming that whoever manages security operations day to day also owns the authority to accept risk that exceeds the organization's appetite.

2
MCQmedium

A security manager is reviewing a set of documents: an organizational security policy, a standard for encryption, a guideline for remote access, and a procedure for incident response. Which document is at the highest level in the policy hierarchy?

A.Remote access guideline
B.Encryption standard
C.Organizational security policy
D.Incident response procedure
AnswerC

The organizational security policy sits at the top of the hierarchy, establishing management's mandatory intent and direction. Standards, guidelines and procedures all derive from and must align with it, so it satisfies the stem's requirement for the highest-level document.

Why this answer

The organizational security policy is the top-level governance document — it states management's intent, scope, and high-level requirements. Standards, guidelines, and procedures all derive from and must align with the policy, making it the highest document in the hierarchy.

Exam trap

The trap is conflating 'most detailed' or 'most operational' with 'highest level'; candidates must remember that the policy is the highest authority even though it is the least specific document.

How to eliminate wrong answers

Option A is wrong because a remote access guideline is advisory and sits below standards and policies in the hierarchy. Option B is wrong because an encryption standard is a mandatory, specific requirement that implements policy but is subordinate to it. Option D is wrong because an incident response procedure is a step-by-step operational document that implements policy and standards at the lowest level of the hierarchy.

3
MCQeasy

A retail company is building a new mobile application that will collect customer location data. The legal team asks the security manager to ensure the design follows privacy by design principles from the earliest stages. Which action best demonstrates privacy by design in this scenario?

A.Add a privacy policy link to the application store listing after the application is released
B.Encrypt location data at rest and assume that encryption alone satisfies privacy requirements
C.Perform a privacy impact assessment and design data minimization controls before development begins
D.Collect precise location data continuously so that future marketing features have a rich data set
AnswerC

Privacy by design requires that privacy be considered proactively and embedded into the design rather than added after deployment. Conducting a privacy impact assessment early identifies risks and informs decisions about what data to collect, how long to keep it, and how to protect it. Designing data minimization controls at the start directly implements the principle of limiting collection to what is necessary and demonstrates privacy by design in this scenario.

Why this answer

Privacy by design means embedding privacy into systems and processes from the outset, not retrofitting it later. An early privacy impact assessment combined with data minimization controls during design directly implements that principle. The other actions either collect excessive data, react after release, or rely on a single control that does not address purpose limitation and minimization, so they do not meet the legal team's request.

Exam trap

The trap here is equating privacy by design with encryption alone, when it actually requires proactive minimization and purpose limitation before development begins.

4
MCQeasy

A hospital's security manager is aligning internal documents after a policy refresh. The board approved a statement that defines the organization's overall security intent and assigns responsibility to executive leadership, but it deliberately avoids naming specific products or technical settings. Which document type has the board approved?

A.A security standard
B.A security policy
C.A security procedure
D.A security guideline
AnswerB

A policy is a high-level, management-approved statement of intent that defines the organization's security objectives and assigns responsibility without prescribing technical detail. The board's document matches this exactly: it sets overall direction, delegates accountability to executives, and intentionally avoids product-specific or configuration-level content. That places it at the top of the governance hierarchy, above standards and procedures.

Why this answer

A policy is the management-approved, high-level statement that expresses security intent and assigns accountability without dictating products or settings. Standards enforce specific mandatory requirements, procedures describe operational steps, and guidelines offer optional advice. Because the board's document sets direction and delegates responsibility at an enterprise level while avoiding technical specificity, it is a policy sitting at the top of the governance hierarchy.

Exam trap

The trap here is assuming that because the document avoids technical detail it must be a guideline, when the board's formal approval and assignment of responsibility make it a mandatory policy.

5
MCQmedium

A security analyst is reviewing the organization's business continuity plan (BCP). The plan specifies a recovery time objective (RTO) of 4 hours for a critical e-commerce application. Which of the following BEST describes the meaning of this RTO?

A.The time required to fully restore the application from backups.
B.The maximum time the application can be down before it significantly impacts the business.
C.The frequency at which backups of the application are performed.
D.The maximum acceptable amount of data loss measured in time.
AnswerB

The recovery time objective (RTO) is the maximum acceptable time that an application or system can be unavailable after a disruption. It defines how quickly the business needs the service restored. In this scenario, an RTO of 4 hours means the e-commerce application must be back online within 4 hours to avoid unacceptable business impact. This is the correct definition.

Why this answer

The recovery time objective (RTO) defines the maximum acceptable downtime for a system after a disruption. In this case, a 4-hour RTO means the e-commerce application must be restored within 4 hours. RTO is distinct from RPO, which deals with data loss.

The other options describe RPO, actual recovery time, or backup frequency, none of which define RTO.

Exam trap

The trap here is mixing up RTO with RPO or actual recovery time; RTO is the target downtime, not the data loss tolerance or backup schedule.

6
MCQeasy

Which risk treatment option involves reducing the likelihood or impact of a risk through controls?

A.Mitigate
B.Avoid
C.Accept
D.Transfer
AnswerA

Mitigation applies controls to reduce risk.

Why this answer

Mitigation involves implementing controls to reduce the likelihood or impact of a risk. This is the definition of risk mitigation in risk management frameworks like NIST and ISO 31000. It is distinct from avoidance (eliminating the activity), acceptance (retaining the risk), and transfer (shifting to a third party).

Exam trap

CAS-005 often tests the distinction between risk treatment options, and candidates frequently confuse mitigation with avoidance or transfer, especially when the question mentions 'controls' which could be misconstrued as transfer via insurance.

How to eliminate wrong answers

Option B is wrong because avoidance means eliminating the risk by not performing the activity that introduces it, not reducing it through controls. Option C is wrong because acceptance means acknowledging the risk and deciding to bear it without additional controls. Option D is wrong because transfer shifts the risk to another party, such as through insurance or outsourcing, rather than reducing it.

7
MCQeasy

Which security metric measures the average time it takes to detect a security incident after it has occurred?

A.Mean Time to Detect (MTTD)
B.Mean Time Between Failures (MTBF)
C.Mean Time to Respond (MTTR)
D.Mean Time to Recover (MTTR)
AnswerA

Mean Time to Detect measures the average elapsed time between an incident occurring and its detection, exactly matching the metric described. It isolates detection speed from response or resolution timing, which are covered by separate metrics.

Why this answer

Mean Time to Detect (MTTD) is the metric that specifically measures the average elapsed time between when a security incident actually occurs and when it is detected by monitoring, alerting, or analyst investigation. It is a core SOC efficiency metric used to evaluate detection capabilities.

Exam trap

The trap is the overlapping 'MTTR' acronyms — candidates must distinguish Mean Time to Respond from Mean Time to Recover, and not confuse either with detection (MTTD).

How to eliminate wrong answers

Option B is wrong because MTBF measures reliability — the average time between system failures, not detection speed. Option C is wrong because MTTR (Mean Time to Respond) measures how long it takes to respond after detection, not to detect. Option D is wrong because Mean Time to Recover measures restoration time after an outage, which is a resilience metric, not a detection metric.

8
MCQmedium

An organization is evaluating a third-party vendor that will have access to its customer database. The vendor provides a SOC 2 Type II report dated six months ago. Which of the following is the BEST next step?

A.Conduct a vendor risk assessment using a security questionnaire
B.Accept the SOC 2 report as sufficient evidence
C.Perform an on-site audit of the vendor
D.Request a new penetration test report from the vendor
AnswerA

A SOC 2 Type II report covers controls over a period, but it is six months old and may not address your specific data flows. A risk assessment using a security questionnaire gathers current, scenario-specific evidence about how the vendor protects your customer database.

Why this answer

Even with a recent SOC 2 Type II report, the organization should still perform its own vendor risk assessment using a security questionnaire to evaluate controls specific to the engagement, scope, and data sensitivity. A SOC 2 report covers the vendor's controls but does not address the organization's specific risk tolerance, contractual requirements, or gaps not in the report's scope. This is the best next step because it validates and contextualizes the report.

Exam trap

CAS-005 often tests the misconception that a SOC 2 report alone satisfies vendor due diligence, when in fact it is an input to—not a replacement for—a risk-based assessment.

How to eliminate wrong answers

Option B is wrong because accepting the SOC 2 report as sufficient evidence ignores the need to map the report's scope and exceptions to the organization's specific requirements and risk appetite. Option C is wrong because an on-site audit is disproportionate and typically reserved for high-risk vendors after a risk assessment identifies gaps; it is not the immediate next step. Option D is wrong because requesting a new penetration test report is not the standard next step and does not replace a risk assessment; pen tests are point-in-time and may not cover the relevant scope.

9
Multi-Selectmedium

A company is implementing continuous compliance monitoring for PCI DSS. Which TWO activities are most appropriate for this approach? (Select TWO.)

Select 2 answers
A.Manual review of access logs every month
B.Automated daily file integrity monitoring on critical systems
C.Annual on-site audit by a Qualified Security Assessor (QSA)
D.Automated quarterly vulnerability scanning of the cardholder data environment
E.Real-time monitoring of firewall and intrusion detection system logs
AnswersB, E

Automated daily file integrity monitoring directly satisfies PCI DSS continuous monitoring by detecting unauthorised changes to critical system files between point-in-time assessments. Unlike periodic manual reviews, it provides the ongoing, evidence-generating oversight the stem demands, flagging tampering or drift promptly so remediation occurs before the next audit cycle.

Why this answer

Option B is correct because continuous compliance monitoring relies on automated, recurring controls such as daily file integrity monitoring (FIM) on critical systems, which detects unauthorized changes to system files in near real time and supports PCI DSS Requirement 11.5. Option E is correct because real-time monitoring of firewall and IDS logs provides continuous visibility into security events and supports PCI DSS Requirements 10 and 11.4, enabling prompt detection and response rather than point-in-time checks. Option A is not appropriate because monthly manual log review is periodic and labor-intensive, not continuous or automated.

Option C is not appropriate because an annual QSA on-site audit is a point-in-time assessment, not continuous monitoring. Option D is not appropriate because quarterly vulnerability scanning, while required by PCI DSS, is periodic rather than continuous monitoring.

Exam trap

CAS-005 often tests the distinction between continuous and periodic activities. Candidates may select quarterly scanning or annual audits because they are required by PCI DSS, but they are not continuous monitoring.

10
MCQeasy

Which of the following risk treatment options involves transferring the financial impact of a risk to a third party, such as through insurance?

A.Avoid
B.Accept
C.Transfer
D.Mitigate
AnswerC

Transfer shifts the financial consequences of a risk to a third party, typically an insurer, while the risk itself remains. Insurance is the classic example, matching the stem's requirement to move financial impact rather than avoid, reduce or accept the risk.

Why this answer

Risk transfer shifts the financial consequence of a risk to a third party, most commonly through insurance, contractual indemnification, or outsourcing. The organization retains the risk event's possibility but offloads the monetary impact to another party. This is distinct from avoiding, accepting, or mitigating the risk.

Exam trap

The trap is confusing transfer with mitigation — candidates may pick 'mitigate' because insurance feels like a control, but transfer specifically addresses shifting financial impact to a third party.

How to eliminate wrong answers

Option A is wrong because risk avoidance eliminates the activity or process that creates the risk entirely, rather than shifting its financial impact. Option B is wrong because risk acceptance means the organization acknowledges the risk and absorbs the potential loss itself, with no third-party involvement. Option D is wrong because risk mitigation reduces the likelihood or impact of the risk through controls, not by transferring financial responsibility to another party.

11
MCQeasy

A multinational corporation that processes personal data of EU residents is required to appoint a Data Protection Officer (DPO) and implement data protection impact assessments. Which regulation primarily drives these requirements?

A.PCI DSS
B.SOX
C.GDPR
D.HIPAA
AnswerC

The GDPR mandates appointing a Data Protection Officer for large-scale monitoring or special-category processing, and requires data protection impact assessments for high-risk processing. These obligations are explicit GDPR articles, matching the stem's EU personal-data scenario rather than CCPA, HIPAA or SOX.

Why this answer

The GDPR (General Data Protection Regulation) is the EU regulation that mandates appointing a Data Protection Officer (DPO) in certain cases and requires Data Protection Impact Assessments (DPIAs) for high-risk processing. It applies to any organization processing personal data of EU residents, regardless of the organization's location, making it the primary driver of these requirements.

Exam trap

CAS-005 often tests the overlap between privacy regulations, so candidates who see 'personal data' and 'DPO' may incorrectly pick HIPAA or PCI DSS instead of recognizing the EU-specific GDPR triggers.

How to eliminate wrong answers

Option A is wrong because PCI DSS is a payment card industry standard focused on cardholder data security, not on DPO appointment or DPIAs. Option B is wrong because SOX (Sarbanes-Oxley) governs financial reporting and internal controls for public companies, not personal data protection. Option D is wrong because HIPAA governs protected health information in the US, not EU residents' personal data or DPO/DPIA requirements.

12
MCQeasy

A company wants to ensure that a third-party vendor allows them to perform an audit of the vendor's security controls. Which clause should be included in the contract?

A.Indemnification clause
B.Right-to-audit clause
C.Non-disclosure agreement (NDA)
D.Service level agreement (SLA)
AnswerB

A right-to-audit clause contractually grants the company permission to examine the vendor's security controls, evidence and records. It directly satisfies the requirement to perform an audit, giving enforceable access rather than relying on the vendor's voluntary cooperation.

Why this answer

A right-to-audit clause explicitly grants the contracting organization the contractual authority to inspect, audit, and verify the vendor's security controls, policies, and practices. Without this clause, the vendor has no legal obligation to permit audits, regardless of what security assurances they claim. This is a foundational third-party risk management control required by frameworks like SOC 2, ISO 27001, and PCI DSS.

Exam trap

The trap here is confusing contractual risk-transfer mechanisms (indemnification, SLA) with contractual risk-visibility mechanisms (right-to-audit); candidates often pick NDA or SLA because they sound security-related but do not grant audit authority.

How to eliminate wrong answers

Option A is wrong because an indemnification clause only addresses financial compensation for losses or damages caused by one party, not the right to inspect security controls. Option C is wrong because an NDA protects the confidentiality of shared information but does not grant audit rights over the vendor's environment. Option D is wrong because an SLA defines performance and availability commitments (uptime, response times) but does not inherently include the right to audit the vendor's security posture.

13
MCQmedium

An organization is implementing a data classification scheme. Which data type should be given the highest protection and is typically restricted to a very small number of individuals?

A.Restricted
B.Confidential
C.Internal
D.Public
AnswerA

Restricted data demands the highest protection level, typically limited to a very small number of authorised individuals with strict need-to-know. It sits above confidential, internal and public classifications, matching the scenario's requirement for the most tightly controlled category.

Why this answer

Restricted data is the highest classification tier in most data classification schemes, reserved for the most sensitive information whose unauthorized disclosure would cause severe harm. Access is typically limited to a very small number of named individuals with explicit need-to-know and often additional controls like encryption, logging, and physical security. Examples include trade secrets, M&A plans, and certain regulated personal data.

Exam trap

CAS-005 often tests the ordering of classification tiers; candidates confuse Confidential with Restricted, not realizing Restricted is the top tier limited to a very small number of individuals.

How to eliminate wrong answers

Option B is wrong because Confidential is typically the second-highest tier, allowing broader access to employees with a business need, and does not require restriction to a very small number of individuals. Option C is wrong because Internal data is intended for general employee access within the organization and carries lower protection requirements. Option D is wrong because Public data is intentionally shareable with anyone and requires no special protection.

14
MCQhard

A company is conducting a vendor risk assessment and receives a SOC 2 Type II report from a cloud service provider. The report covers a 12-month period and includes an opinion on the effectiveness of controls. Which of the following is the primary benefit of using this report?

A.It guarantees the vendor is compliant with all regulations
B.It offers an independent assessment of control effectiveness over time
C.It eliminates the need for a right-to-audit clause
D.It provides real-time monitoring data from the vendor
AnswerB

A SOC 2 Type II report tests controls across a defined audit period rather than a single point in time, so the auditor's opinion addresses whether controls operated effectively throughout those 12 months. This satisfies the vendor risk assessment's need for evidence of sustained control performance.

Why this answer

A SOC 2 Type II report provides an independent auditor's opinion on the effectiveness of a service organization's controls over a period of time (here, 12 months). This temporal coverage is the key benefit: it demonstrates that controls operated effectively throughout the period, not just on a single date. For vendor risk assessment, this gives assurance about sustained control performance rather than a point-in-time snapshot.

Exam trap

The trap is overstating what SOC 2 provides — candidates pick A (guarantees compliance) or D (real-time monitoring) because they conflate attestation with certification or continuous monitoring, but SOC 2 is a periodic, independent opinion on control effectiveness.

How to eliminate wrong answers

Option A is wrong because SOC 2 does not guarantee regulatory compliance — it attests to the design and operating effectiveness of controls against the Trust Services Criteria, which may or may not map to specific regulations. Option C is wrong because a SOC 2 report does not eliminate the need for a right-to-audit clause; many organizations still require contractual audit rights for their own assurance. Option D is wrong because SOC 2 is a periodic attestation report, not a real-time monitoring feed — it covers a historical period and is issued after the fact.

15
MCQmedium

A software company suffers a breach exposing customer records. Legal counsel determines the incident meets the regulatory threshold for notification. The incident response lead must decide which external parties receive notice and within what timeframe, balancing regulatory duties against contractual obligations. Which action best satisfies the organization's notification obligations?

A.Notify regulators and affected data subjects within the applicable legal timeframes, and notify contractual partners per their agreements
B.Notify law enforcement and defer all other notifications until the criminal case concludes
C.Notify only the affected customers once the forensic investigation is fully complete
D.Publish a general notice on the corporate website in place of direct notification
AnswerA

Regulatory breach-notification regimes impose fixed deadlines measured from awareness, and contracts with partners often impose separate, sometimes tighter deadlines. Notifying regulators, affected individuals, and contractually entitled parties within each applicable window satisfies the full set of obligations. This parallel approach respects that different recipients have different triggers and timelines, which is exactly what the incident lead must coordinate.

Why this answer

Breach notification obligations run in parallel and on different clocks. Regulators and affected individuals must be notified within statutory windows measured from awareness, while contractual partners may have their own deadlines triggered by the same event. Notifying all required parties within their respective timeframes is the only approach that satisfies both legal and contractual duties, whereas waiting for investigation closure or substituting public notices fails those deadlines.

Exam trap

The trap here is believing that notification can wait until the forensic investigation is complete or the criminal case ends, when regulatory and contractual clocks start at awareness regardless of investigation status.

16
MCQmedium

When conducting a vendor risk assessment, which contractual clause is most important for ensuring ongoing visibility into the vendor's security posture?

A.Indemnification clause
B.Right-to-audit clause
C.Non-disclosure agreement (NDA)
D.Service level agreement (SLA)
AnswerB

A right-to-audit clause contractually grants the organisation the ability to inspect the vendor's controls, records and security practises on an ongoing basis. This directly satisfies the requirement for continuing visibility into the vendor's security posture, unlike one-off certifications or SLAs, which only report point-in-time or service-level assurances.

Why this answer

A right-to-audit clause contractually grants the customer the ability to inspect the vendor's security controls, processes, and records — either directly or via third-party reports like SOC 2. This is the mechanism that provides ongoing visibility into the vendor's security posture over the life of the relationship, not just at onboarding. Without it, the customer has no enforceable means to verify that controls remain effective.

Exam trap

CAS-005 often tests the confusion between clauses that compensate after an incident (indemnification, SLA credits) and clauses that provide proactive, ongoing visibility (right-to-audit).

How to eliminate wrong answers

Option A is wrong because an indemnification clause only addresses financial compensation after a loss occurs; it provides no visibility into controls and is reactive rather than preventive. Option C is wrong because an NDA protects confidentiality of shared information but says nothing about the vendor's internal security practices or the customer's ability to inspect them. Option D is wrong because an SLA defines performance and availability commitments (uptime, latency) and remedies for misses — it does not grant inspection rights into security controls or evidence.

17
MCQmedium

A security architect is designing a data classification scheme. Which of the following is the highest level of sensitivity that would typically require the most stringent controls?

A.Restricted
B.Public
C.Internal
D.Confidential
AnswerA

Restricted data demands the strictest controls because it covers information whose exposure causes severe harm, such as trade secrets or regulated personal data. It sits above Confidential, Internal and Public in the classification hierarchy, satisfying the stem's requirement for the highest sensitivity tier needing the most stringent protection.

Why this answer

In most data classification schemes, 'Restricted' represents the highest sensitivity level, reserved for data whose unauthorized disclosure would cause severe damage, such as trade secrets, regulated personal data, or national security information. It requires the most stringent controls, including strict access controls, encryption, and auditing. Public, Internal, and Confidential are lower tiers in the typical hierarchy.

Exam trap

CAS-005 often tests the ordering of classification tiers, tempting candidates to choose 'Confidential' as the highest when 'Restricted' is the top tier in schemes that include both.

How to eliminate wrong answers

Option B is wrong because 'Public' is the lowest classification, intended for information that can be freely shared without harm. Option C is wrong because 'Internal' is a mid-low tier for information meant only for employees, requiring basic controls but far less than Restricted. Option D is wrong because 'Confidential' is typically a high tier but usually sits below Restricted in schemes that include both; Restricted denotes the most severe impact from disclosure and thus the strictest controls.

18
MCQmedium

A global pharmaceutical company must comply with the EU GDPR for clinical trial data. The Data Protection Officer is reviewing the data protection impact assessment (DPIA) process. Which of the following situations requires a DPIA under GDPR?

A.Collecting employee emergency contact information for HR records.
B.Processing personal data for routine patient billing using a standard software platform.
C.Conducting a clinical trial that involves large-scale processing of genetic data and health data.
D.Using CCTV cameras in a single office lobby for physical security.
AnswerC

GDPR Article 35 requires a DPIA when processing is likely to result in a high risk to data subjects, especially when using new technologies and processing special categories of data on a large scale. Clinical trials involving genetic and health data on a large scale clearly meet this threshold. Genetic data and health data are special categories under Article 9, and large-scale processing triggers the DPIA requirement.

Why this answer

A DPIA is mandatory under GDPR when processing is likely to result in a high risk to data subjects, particularly when it involves large-scale processing of special categories of data such as genetic and health data. Clinical trials often involve such data and are conducted on a large scale, making a DPIA a legal requirement. Other scenarios described are routine and low risk, so they do not trigger the mandatory DPIA.

Exam trap

The trap here is assuming that any processing of personal data requires a DPIA, when in fact it is only required for high-risk processing involving special categories at scale or systematic monitoring.

19
Multi-Selectmedium

A security governance team is drafting a new data handling standard for a research subsidiary that processes both regulated personal data and proprietary intellectual property. The team must select controls that directly support data classification and labeling objectives. Which two of the following controls best fulfill this requirement? (Choose two.)

Select 2 answers
A.Automated sensitive-data discovery that tags files with the appropriate classification label at creation
B.Role-based access control applied to the subsidiary's file shares
C.Mandatory classification labels embedded in document templates and enforced by data loss prevention policies
D.A quarterly review of firewall rule sets against the approved network baseline
E.Annual security awareness training that mentions the existence of the data classification policy
AnswersA, C

Automated discovery that assigns classification labels at the point of creation enforces the labeling objective at the earliest possible moment and removes reliance on users to remember the scheme. It directly operationalizes the classification standard by ensuring every artifact carries its sensitivity marking, which downstream controls such as encryption and access rules can then act upon consistently.

Why this answer

Controls that directly support classification and labeling must either identify and mark data according to its sensitivity or enforce handling based on those markings. Automated discovery that tags data at creation and template-embedded labels enforced through data loss prevention both do this. Firewall reviews, awareness training, and role-based access control address network hygiene, human behavior, and authorization respectively, but none of them classify or label information assets.

Exam trap

The trap here is selecting training or access control because they feel foundational to data protection, when the question specifically asks for controls that perform classification and labeling rather than consume or support them indirectly.

20
MCQmedium

A security analyst is reviewing metrics for the security program. Which metric best measures the effectiveness of incident response processes?

A.Mean time to detect (MTTD)
B.Patch compliance percentage
C.Mean time to respond (MTTR)
D.Number of vulnerabilities by severity
AnswerC

MTTR directly quantifies how quickly the team contains and resolves incidents, making it the clearest indicator of response-process effectiveness. It captures elapsed time from detection to resolution, exposing bottlenecks in triage, escalation and containment that other metrics, such as incident counts, cannot reveal.

Why this answer

Mean time to respond (MTTR) measures the average time taken to respond to and resolve incidents, directly reflecting the efficiency of incident response processes. A lower MTTR indicates a more effective and timely response, making it the best metric to assess incident response effectiveness.

Exam trap

CAS-005 often tests the difference between detection and response metrics; candidates may confuse MTTD with MTTR, but MTTD is about detection, while MTTR is about response and resolution.

How to eliminate wrong answers

Option A is wrong because MTTD measures how quickly incidents are detected, not how effectively they are responded to. Option B is wrong because patch compliance percentage measures vulnerability management, not incident response. Option D is wrong because the number of vulnerabilities by severity measures the volume of vulnerabilities, not the response process.

21
MCQeasy

A company wants to ensure that its data handling practices align with the principle of 'privacy by design'. Which of the following actions best supports this principle?

A.Incorporating privacy controls during the initial system architecture
B.Encrypting data at rest only
C.Performing an annual privacy audit
D.Providing privacy training to employees
AnswerA

Embedding privacy controls at the initial system architecture stage satisfies privacy by design, which requires data protection to be built into systems from the outset rather than bolted on after deployment. Retrofitting later cannot match this preventative, architecture-level alignment.

Why this answer

Privacy by design, codified in GDPR Article 25 and the ISO/IEC 27550 framework, requires that privacy protections be embedded into systems and processes from the outset rather than bolted on afterward. Incorporating privacy controls during initial system architecture — data minimization, purpose limitation, access controls, retention policies — is the textbook embodiment of this principle. The other options are reactive or partial measures that do not satisfy the 'by design' requirement.

Exam trap

CAS-005 often tests the misconception that any privacy-related control (encryption, audits, training) satisfies 'privacy by design', when the principle specifically requires proactive architectural integration before the system is built.

How to eliminate wrong answers

Option B is wrong because encrypting data at rest is a single technical control, not a design philosophy — it addresses confidentiality but ignores minimization, purpose limitation, and lifecycle governance. Option C is wrong because an annual privacy audit is a detective, after-the-fact control, whereas privacy by design is preventive and proactive. Option D is wrong because employee training addresses human behavior and awareness, not the architectural embedding of privacy controls into systems and data flows.

22
MCQeasy

A security analyst is calculating the annualized loss expectancy (ALE) for a server that has an asset value of $50,000 and an exposure factor (EF) of 0.2. The annualized rate of occurrence (ARO) is estimated at 4. What is the ALE?

A.$10,000
B.$40,000
C.$50,000
D.$200,000
AnswerB

Multiplying asset value by exposure factor gives the single-loss expectancy: $50,000 × 0.2 = $10,000. Annualising by the ARO of 4 yields $40,000, satisfying the stem's requirement to compute ALE from AV, EF and ARO. The $40,000 figure therefore matches the correct calculation.

Why this answer

The ALE is calculated as SLE × ARO, where SLE (Single Loss Expectancy) = Asset Value × Exposure Factor. Here, SLE = $50,000 × 0.2 = $10,000, and ARO = 4, so ALE = $10,000 × 4 = $40,000. This represents the expected annual monetary loss from the risk.

Exam trap

CAS-005 often tests the confusion between SLE and ALE; candidates stop at AV × EF and forget to multiply by ARO, or they skip the EF and multiply AV × ARO instead.

How to eliminate wrong answers

Option A is wrong because $10,000 is the SLE (single loss expectancy), not the annualized figure; it omits multiplication by the ARO. Option C is wrong because $50,000 is the raw asset value and does not account for the exposure factor or occurrence rate. Option D is wrong because $200,000 would result from multiplying asset value by ARO without applying the exposure factor, which overstates the loss.

23
MCQmedium

A multinational financial services firm must comply with the General Data Protection Regulation (GDPR). The Chief Information Security Officer (CISO) asks the security team to implement a mechanism that allows data subjects to request and receive a copy of their personal data in a structured, commonly used, and machine-readable format. Which of the following technical controls BEST addresses this requirement?

A.Implement an API endpoint that allows authenticated data subjects to download their personal data in JSON or CSV format.
B.Establish a records retention policy that automatically deletes personal data after a defined period.
C.Deploy a data loss prevention (DLP) solution to monitor and block unauthorized exfiltration of personal data.
D.Configure database encryption at rest using Transparent Data Encryption (TDE) to protect personal data.
AnswerA

The GDPR right to data portability requires that data subjects can receive their personal data in a structured, commonly used, and machine-readable format. An API endpoint that returns data in JSON or CSV satisfies this requirement and provides a scalable, automated way to fulfill data subject requests. This is the most direct technical control for the requirement.

Why this answer

The GDPR grants data subjects the right to data portability, which requires organizations to provide personal data in a structured, commonly used, and machine-readable format. An API endpoint that allows authenticated users to download their data in JSON or CSV directly satisfies this requirement. Other controls like DLP, encryption, or retention policies address different GDPR obligations and do not enable data subject access requests.

Exam trap

The trap here is confusing data protection controls, such as encryption or DLP, with data subject rights fulfillment mechanisms like portability APIs.

24
MCQmedium

A multinational retailer must comply with the EU General Data Protection Regulation for its European customers and with several U.S. state privacy laws for its American customers. The privacy team wants a single internal control framework that satisfies the strictest common denominator across all jurisdictions. Which approach should the privacy team take?

A.Implement each jurisdiction's requirements as a separate, fully independent control set managed by a regional compliance officer.
B.Apply the least restrictive state privacy law as the baseline because it imposes the fewest operational changes.
C.Adopt the requirements of the EU General Data Protection Regulation as the baseline control set and map additional state-law obligations onto it.
D.Defer framework selection until each regulator publishes an approved cross-mapping, then adopt that mapping verbatim.
AnswerC

GDPR is generally the most stringent regime the retailer faces, so using it as the baseline and layering stricter state-specific duties (for example, opt-out of sale or targeted advertising) onto that control set produces one harmonized framework that satisfies every jurisdiction without duplicating effort.

Why this answer

Harmonizing around the most stringent applicable regime gives the retailer one control set that satisfies every jurisdiction, since stricter requirements generally encompass weaker ones. Layering jurisdiction-specific obligations onto that baseline closes residual gaps, such as opt-out rights unique to certain state laws, while avoiding the cost and inconsistency of parallel compliance programs.

Exam trap

The trap here is assuming that a single framework must be chosen from one law verbatim, when harmonization around the strictest regime with mapped add-ons is the accepted approach.

25
MCQhard

A multinational manufacturing firm is expanding into the European Union and must demonstrate accountability for personal data processing under GDPR. The Chief Privacy Officer asks the security team to implement a mechanism that proves the organization's compliance posture to supervisory authorities without requiring prior authorization from them. Which of the following should the team implement?

A.Consent from data subjects
B.Standard Contractual Clauses (SCCs)
C.Privacy Shield certification
D.Binding Corporate Rules (BCRs)
AnswerD

BCRs are approved by the competent supervisory authority and serve as a documented, enforceable framework for intra-group transfers and accountability. They demonstrate GDPR compliance without needing case-by-case authorization for each transfer, making them suitable for a multinational expanding into the EU. They are specifically designed for corporate groups with multiple entities, providing a transparent and legally binding mechanism.

Why this answer

Binding Corporate Rules are a GDPR-approved mechanism for multinational corporations to establish a comprehensive, legally binding framework for intra-group data transfers and accountability. They are approved by supervisory authorities and eliminate the need for separate authorizations, directly addressing the need to demonstrate compliance posture. SCCs are transfer-specific, Privacy Shield is invalid, and consent is a processing basis, not an accountability mechanism.

Exam trap

The trap here is assuming that Standard Contractual Clauses provide the same group-wide accountability as Binding Corporate Rules, when SCCs are transfer-specific and do not cover intra-group processing comprehensively.

26
MCQmedium

A security architect is designing a new system that processes sensitive customer data. The organization must comply with multiple regulations, including GDPR and PCI DSS. The architect needs to ensure that data protection controls are integrated from the outset. Which approach best aligns with the principle of privacy by design?

A.Obtain consent from all customers for data processing.
B.Rely on the cloud provider's default security settings.
C.Conduct a data protection impact assessment (DPIA) before development begins.
D.Implement encryption for data at rest after the system is deployed.
AnswerC

A DPIA is a GDPR requirement for processing that likely results in high risk to data subjects. It identifies and mitigates privacy risks early in the design phase, directly implementing privacy by design. By conducting it before development, the architect ensures controls are built in, not bolted on, and addresses multiple regulatory requirements proactively.

Why this answer

Conducting a data protection impact assessment before development begins is a core privacy by design practice. It proactively identifies privacy risks and ensures controls are integrated into the system architecture from the start. Encryption after deployment, default settings, and consent are either reactive or insufficient to meet the principle of privacy by design.

Exam trap

The trap here is equating consent or encryption with privacy by design, when the principle fundamentally requires proactive risk assessment and integration of privacy controls throughout the development lifecycle.

27
MCQeasy

Under the GDPR, which of the following is a data subject right?

A.Right to transfer data across borders without restriction
B.Right to unlimited processing
C.Right to erasure (right to be forgotten)
D.Right to sell data
AnswerC

The right to erasure, also called the right to be forgotten, lets a data subject require an organisation to delete personal data without undue delay. It is one of the GDPR's enumerated data subject rights, satisfying the stem's question.

Why this answer

The right to erasure (right to be forgotten) is explicitly listed in Article 17 of the GDPR. It allows data subjects to request deletion of their personal data under certain conditions, such as when the data is no longer necessary for the purpose it was collected. This is one of the core data subject rights alongside access, rectification, and portability.

Exam trap

CAS-005 often tests the specific rights granted by GDPR, and candidates may confuse the right to erasure with other rights like data portability or mistakenly believe there is a right to unrestricted processing.

How to eliminate wrong answers

Option A is wrong because the GDPR does not grant an unrestricted right to transfer data across borders; cross-border transfers are subject to strict conditions (adequacy decisions, standard contractual clauses, etc.). Option B is wrong because the GDPR grants the right to restrict processing, not unlimited processing — unlimited processing would violate the purpose limitation and data minimization principles. Option D is wrong because the GDPR does not grant a right to sell data; in fact, it emphasizes control over personal data and requires a legal basis for any processing, including sale.

28
MCQhard

A security manager is reviewing the organization's risk register and notes that a critical vulnerability in a legacy application has been accepted for two years. The business owner argues that the cost of remediation exceeds the potential loss. The security manager must present an alternative that aligns with the organization's risk appetite while addressing the residual risk. Which of the following is the BEST recommendation?

A.Transfer the risk by purchasing cyber insurance that covers losses from exploitation of the legacy application.
B.Avoid the risk by decommissioning the legacy application immediately, regardless of business impact.
C.Implement compensating controls such as network segmentation and enhanced monitoring to reduce the likelihood and impact of exploitation.
D.Accept the risk permanently and document the business owner's decision in the risk register without further action.
AnswerC

When remediation is not feasible, applying compensating controls can reduce residual risk to an acceptable level. Network segmentation limits lateral movement, and enhanced monitoring improves detection. This approach aligns with the organization's risk appetite by addressing the risk without incurring the full cost of replacing the legacy application, and it demonstrates due diligence in managing accepted risks.

Why this answer

Compensating controls reduce residual risk when remediation is not feasible, aligning with the organization's risk appetite by lowering likelihood and impact without the full cost of replacing the legacy system. Risk transfer, acceptance without action, and avoidance all fail to address the residual risk appropriately in this context.

Exam trap

The trap here is equating risk acceptance with doing nothing, when in fact accepted risks still require periodic review and may need compensating controls to remain within tolerance.

29
Multi-Selecthard

A security analyst is prioritizing remediation of vulnerabilities. Which three of the following factors should be considered when determining the risk level of a vulnerability? (Choose three.)

Select 3 answers
A.Availability of a public exploit
B.Vendor patch availability
C.Asset value or criticality
D.CVSS base score
E.Number of days since the vulnerability was discovered
AnswersA, C, D

A publicly available exploit raises the likelihood of active attacks, since attackers can readily obtain working code. This directly increases the vulnerability's risk level when prioritising remediation, alongside impact factors such as asset criticality and exposure.

Why this answer

Option A (Availability of a public exploit) is correct because a publicly available exploit, especially one weaponized in frameworks like Metasploit or CISA's KEV catalog, dramatically increases the likelihood of active exploitation and thus raises the risk level. Option C (Asset value or criticality) is correct because the same vulnerability poses far greater risk on a high-value asset such as a domain controller or PII database than on an isolated test machine, directly affecting impact. Option D (CVSS base score) is correct because it provides a standardized, vendor-agnostic metric of intrinsic severity based on exploitability and impact, forming a foundational input to risk prioritization.

Option B (Vendor patch availability) is not one of the three because a patch being available reduces exposure but does not itself define the inherent risk level of the vulnerability. Option E (Number of days since discovery) is not selected because age alone is a weak indicator; a long-unpatched critical flaw may be high risk, but time since discovery is not a standard risk-scoring factor like exploit availability, asset criticality, or CVSS.

Exam trap

CAS-005 often tests the difference between intrinsic vulnerability severity (CVSS) and contextual risk factors (asset criticality, exploit availability), so candidates must not treat patch availability or age as core risk determinants.

30
MCQmedium

An organization discovers that a third-party vendor has a subcontractor that processes its data. The organization did not have a contract with the subcontractor. This is an example of which type of risk?

A.Residual risk
B.Third-party risk
C.Fourth-party risk
D.Supply chain risk
AnswerC

Fourth-party risk arises when a subcontractor, contracted by your direct vendor, handles your data without privity of contract with you. The stem's defining constraint — no contract exists between the organisation and the subcontractor — matches this exactly, since the exposure flows through the third party rather than directly.

Why this answer

Fourth-party risk refers to the risk introduced by a vendor's subcontractors or sub-processors — parties with whom the organization has no direct contractual relationship. Since the organization has no contract with the subcontractor, this is a classic fourth-party risk scenario.

Exam trap

CAS-005 often tests the distinction between third-party and fourth-party risk — candidates pick third-party risk because a vendor is involved, missing that the absence of a direct contract with the subcontractor is the defining factor for fourth-party risk.

How to eliminate wrong answers

Option A is wrong because residual risk is the risk that remains after controls have been applied, not a risk arising from a subcontractor relationship. Option B is wrong because third-party risk refers to risks from direct vendors/partners with whom the organization has a contract — here the organization has no contract with the subcontractor, so it is one level removed. Option D is wrong because supply chain risk is a broader umbrella term that encompasses third- and fourth-party risks; the question asks for the specific type exemplified by a subcontractor without a direct contract, which is fourth-party risk.

31
Multi-Selecthard

A security governance team is defining the scope of its enterprise risk management (ERM) program. Which TWO of the following activities are core components of ERM as described in frameworks such as ISO 31000 and COSO ERM? (Choose two.)

Select 2 answers
A.Performing technical vulnerability scans on all production servers weekly
B.Maintaining an inventory of all hardware assets with purchase dates
C.Integrating risk considerations into strategic planning and objective setting
D.Establishing risk appetite and tolerance statements approved by leadership
E.Encrypting all databases containing personally identifiable information
AnswersC, D

COSO ERM emphasizes that risk management must be integrated with strategy-setting and performance, not treated as a separate compliance exercise. Embedding risk into strategic planning ensures objectives are pursued within the organization's risk appetite. This integration is a defining core component of ERM.

Why this answer

ERM frameworks such as ISO 31000 and COSO ERM center on governance, strategy integration, and risk appetite. Defining risk appetite and tolerance gives leadership a benchmark for decisions, while integrating risk into strategic planning ensures objectives are set with awareness of uncertainty. Technical controls and asset inventories support risk management but are not core ERM components themselves.

Exam trap

The trap here is equating ERM with operational security activities like vulnerability scanning or encryption, which are controls rather than enterprise risk governance components.

32
MCQhard

A company's security team is reviewing its risk register. A risk related to an outdated internal application has been assigned an owner, but the owner has taken no action for two quarters. The Chief Information Security Officer wants to ensure the risk is tracked and escalated appropriately. Which action should the security team take first?

A.Immediately accept the risk on behalf of the business owner to close the item
B.Remove the risk from the register because the owner has implicitly accepted it by doing nothing
C.Escalate the overdue risk to the risk owner's management and the risk committee with the current status
D.Transfer the risk to an insurance carrier and mark the register item as resolved
AnswerC

When a risk owner fails to act, the security team's role is to escalate through governance channels so that accountable leadership can make a decision. Providing the risk committee with the current status, potential impact, and lack of progress ensures the risk remains visible and that a timely treatment decision is made. This preserves accountability and aligns with risk management practices that require escalation when treatment deadlines are missed.

Why this answer

The security team should escalate the overdue risk to the owner's management and the risk committee with current status. Escalation preserves accountability, keeps the risk visible, and forces a timely treatment decision by those with authority. Accepting, deleting, or unilaterally transferring the risk would bypass governance and hide the exposure rather than manage it, which is why escalation is the correct first action.

Exam trap

The trap here is treating an owner's silence as implicit risk acceptance, when governance requires an explicit, documented decision by the accountable party.

33
MCQeasy

A mid-sized retailer wants to demonstrate to customers that its payment card handling meets industry security requirements. The company does not store, process, or transmit cardholder data; it only uses a validated third-party payment page that handles all card data. Which PCI DSS self-assessment questionnaire is most appropriate?

A.SAQ D for Merchants
B.SAQ A
C.SAQ B-IP
D.SAQ P2PE
AnswerB

SAQ A is designed for merchants that fully outsource all cardholder data functions to PCI DSS validated third parties and do not store, process, or transmit cardholder data electronically. The retailer's use of a validated third-party payment page matches this profile exactly. Completing SAQ A is the correct and least burdensome validation path here.

Why this answer

PCI DSS self-assessment questionnaire eligibility depends on how cardholder data is handled. A merchant that completely outsources card data functions to a validated third party and never stores, processes, or transmits the data qualifies for SAQ A. The other questionnaires apply to environments with direct card data handling, standalone IP terminals, or validated point-to-point encryption solutions.

Exam trap

The trap here is selecting the most comprehensive questionnaire, SAQ D, out of caution when the merchant's fully outsourced model qualifies for the much simpler SAQ A.

34
MCQhard

A financial services firm operates a trading platform in which a 15-minute outage causes direct contractual penalties. The CISO must present a recommendation to the board on how to treat the residual risk of a ransomware event that could halt trading. The firm already has immutable offline backups and a tested recovery runbook. Which risk treatment action is MOST appropriate to recommend?

A.Transfer the risk by purchasing a cyber insurance policy that covers business interruption.
B.Mitigate the risk further by engineering automated failover and rehearsing recovery to meet the 15-minute recovery time objective.
C.Avoid the risk by shutting down the trading platform until ransomware can be fully eliminated.
D.Accept the residual risk because immutable backups and a tested runbook already exist.
AnswerB

Because the dominant residual exposure is time-to-recover against a hard 15-minute threshold, additional mitigation through automated failover and validated recovery exercises directly reduces the likelihood and impact of missing that objective. This aligns treatment with the actual risk driver, complements the existing backup controls, and gives the board measurable evidence that the residual risk now sits within appetite.

Why this answer

The scenario isolates recovery speed as the binding constraint, since backups and runbooks already exist. Further mitigation through automated failover and rehearsed recovery directly attacks the 15-minute recovery time objective, whereas insurance only offsets financial loss, acceptance contradicts the evident risk appetite, and avoidance would destroy the business line. Treatment should map to the specific residual risk driver rather than to generic control categories.

Exam trap

The trap here is reflexively choosing risk transfer through insurance whenever a large financial loss is mentioned, even when the scenario's real constraint is recovery time.

35
MCQmedium

During a policy gap analysis, it is discovered that the organization has a policy stating that sensitive data must be encrypted, but there are no procedures for implementing encryption on mobile devices. This is an example of a gap between:

A.Standards and guidelines
B.Policy and standards
C.Policy and guidelines
D.Policy and procedures
AnswerD

The encryption mandate exists as a stated policy, but no implementing procedures exist for mobile devices. The gap therefore lies between policy and procedures, since the documented requirement lacks the operational steps needed to enact it on that platform.

Why this answer

A policy states the mandatory 'what' (sensitive data must be encrypted), while procedures describe the step-by-step 'how' (how to enable encryption on mobile devices, which tools, who does it). The gap described is the absence of implementation procedures supporting an existing policy, so it is a policy-to-procedures gap.

Exam trap

The trap is treating 'standards' and 'procedures' as synonyms; the exam expects you to distinguish the mandatory technical requirement (standard) from the step-by-step implementation (procedure).

How to eliminate wrong answers

Option A is wrong because standards are specific mandatory requirements (for example, AES-256) and guidelines are recommendations; the question describes missing implementation steps, not missing technical standards. Option B is wrong because the policy exists and no specific standard is described as missing; the missing element is the procedural how-to. Option C is wrong because guidelines are advisory best practices, and the question is about the absence of mandatory implementation steps, which are procedures.

36
Multi-Selecthard

A security governance committee is reviewing the organization's risk register after a merger. The committee wants to apply risk treatment strategies that transfer or share risk with another party rather than reducing it internally. Which two actions represent risk transference? (Choose two.)

Select 2 answers
A.Deploying endpoint detection and response agents across all workstations to catch malicious activity earlier.
B.Diversifying the cloud provider portfolio so no single vendor outage halts all critical services.
C.Outsourcing the payment card processing function to a PCI DSS validated third-party service provider under contract.
D.Accepting the risk of a legacy application because remediation cost exceeds the potential loss.
E.Purchasing a cyber liability insurance policy that covers breach response costs and regulatory fines where insurable.
AnswersC, E

Contracting a validated service provider to handle card processing moves operational responsibility and much of the associated risk to that vendor. This is transference or sharing, since the provider assumes defined obligations and liabilities through the agreement, though the organization retains oversight and compliance accountability.

Why this answer

Risk transference shifts the financial or operational consequence to another party. Cyber insurance and outsourcing card processing to a validated provider both move risk to external entities through contracts or policies, whereas detection controls, acceptance, and diversification change or retain the risk internally.

Exam trap

The trap here is confusing risk reduction controls, such as deploying detection agents, with transference, which requires another party to absorb the consequence.

37
MCQmedium

A multinational retailer operates under GDPR for its EU customers and must demonstrate accountability to supervisory authorities. The Chief Privacy Officer wants a mechanism that documents, on an ongoing basis, which processing activities occur, what data categories are involved, and how long each is retained. Which GDPR instrument should the privacy team maintain to satisfy this requirement?

A.Standard Contractual Clauses (SCCs)
B.Binding Corporate Rules (BCRs)
C.Data Protection Impact Assessment (DPIA)
D.Records of Processing Activities (RoPA) under Article 30
AnswerD

The RoPA is the Article 30 accountability artifact that catalogues each processing activity, its purposes, data categories, recipients, retention periods, and security measures. It directly answers the regulator's need for a living register documenting what is processed and for how long. Because the retailer processes data at scale, maintaining this register is mandatory and serves as the documentary backbone for demonstrating GDPR accountability.

Why this answer

The Records of Processing Activities is the Article 30 accountability instrument that captures processing purposes, data categories, recipients, retention, and safeguards in one maintained register. A DPIA analyses a single high-risk activity, while SCCs and BCRs are cross-border transfer mechanisms. Only the RoPA provides the persistent, organization-wide documentation the retailer needs to show supervisory authorities how EU personal data is handled and retained.

Exam trap

The trap here is assuming any accountability document satisfies GDPR Article 30, when only the Records of Processing Activities provides the required ongoing inventory of processing purposes, data categories, and retention periods.

38
MCQeasy

An organization's security team has drafted a new acceptable use policy that defines how employees may handle company devices, email, and internet access. Before the policy is published and enforced, which action is most important to complete?

A.Translate the policy into every language spoken by employees before any review occurs
B.Archive the draft in the document management system with a version number
C.Publish the policy on the intranet and begin disciplinary enforcement immediately
D.Obtain review and formal approval from executive management and the appropriate governance body
AnswerD

Policies gain authority only when senior leadership formally approves them, which signals organizational commitment and provides the mandate for enforcement. Approval by executive management and the relevant governance body also ensures the policy aligns with business objectives and legal obligations, and it establishes accountability if disciplinary action is later required for violations, making this the essential step before publication.

Why this answer

Approval by executive management and the relevant governance body is what gives a policy its authority. Without that endorsement, the acceptable use policy is an unreviewed draft that cannot be enforced consistently, may conflict with legal or contractual obligations, and offers no defensible basis for disciplinary action. Distribution, translation, and version archiving are supporting activities that follow approval.

Exam trap

The trap here is focusing on distribution mechanics such as publishing or translating, when the policy's legitimacy depends on formal leadership approval before anything else.

39
MCQhard

An organization is implementing a privacy program based on privacy by design. Which principle requires that privacy controls be integrated into the system's default settings?

A.Full functionality – positive-sum, not zero-sum
B.Privacy embedded into design
C.Privacy as the default setting
D.Proactive not reactive; preventative not remedial
AnswerC

Privacy as the default setting requires that systems automatically apply the strictest privacy protections without user intervention, so personal data is protected unless the individual opts otherwise. This directly satisfies the requirement that controls be integrated into default settings.

Why this answer

Privacy as the default setting is the privacy-by-design principle requiring that privacy protections be built into the system's default configuration, so users do not have to take action to protect their data. It means the most privacy-protective settings are on by default, and users must opt in to share more. This directly matches the question's wording about default settings.

Exam trap

The trap is mixing up the seven privacy-by-design principles; candidates often pick 'privacy embedded into design' when the question specifically mentions default settings.

How to eliminate wrong answers

Option A is wrong because full functionality (positive-sum) means privacy and functionality should not be traded off against each other; it does not address default settings. Option B is wrong because privacy embedded into design means privacy is considered from the start of system design, not specifically that defaults are privacy-protective. Option D is wrong because proactive not reactive means anticipating and preventing privacy issues before they occur, rather than remediating after; it does not describe default settings.

40
MCQeasy

A security manager is updating the organization's risk register. A new risk has been identified: a critical vendor may fail to provide timely security patches, potentially leading to a breach. The manager decides to purchase cyber insurance to cover potential financial losses from such a breach. Which risk treatment strategy does this represent?

A.Risk transference
B.Risk mitigation
C.Risk avoidance
D.Risk acceptance
AnswerA

Risk transference shifts the financial impact of a risk to a third party, typically through insurance or contracts. By purchasing cyber insurance, the organization transfers the potential financial losses from a breach to the insurer. This is a classic example of risk transference. The risk itself remains, but the financial burden is shared or shifted. This aligns with the scenario.

Why this answer

Purchasing cyber insurance transfers the financial impact of a potential breach to the insurer. Risk transference is the correct treatment because the organization is not reducing the likelihood or impact through controls, nor is it avoiding the risk or accepting it without action. Insurance is a common method of transferring financial risk associated with vendor failures.

Exam trap

The trap here is confusing risk transference with risk mitigation; insurance does not reduce the chance of a breach, it only transfers the financial consequences.

41
Multi-Selectmedium

A security manager is implementing a policy exception management process. Which TWO of the following are essential components of an effective exception management process?

Select 2 answers
A.A policy that all exceptions are denied
B.A defined expiration date for each exception
C.A formal request and approval workflow
D.Automatic approval for temporary workarounds
E.Immediate policy revision to eliminate the need for exceptions
AnswersB, C

Expiration dates enforce time-bound risk acceptance, ensuring exceptions are reviewed and renewed rather than persisting indefinitely. This directly satisfies the process requirement for periodic reassessment, preventing stale waivers from silently accumulating. Without expiry, exceptions become permanent policy bypasses, undermining governance and auditability across Microsoft Entra ID and other controlled environments.

Why this answer

An effective exception management process requires a formal request and approval workflow (C) so that each exception is documented, justified, risk-assessed, and authorized by the appropriate authority rather than granted informally. It also requires a defined expiration date for each exception (B), ensuring exceptions are temporary, time-bound, and reviewed or renewed before they become permanent policy gaps. Together, these components provide accountability and limit risk exposure.

Option A is wrong because blanket denial of all exceptions is impractical and prevents legitimate business needs from being addressed. Option D is wrong because automatic approval of temporary workarounds bypasses risk review and oversight. Option E is wrong because immediately revising policy to eliminate every exception is not always feasible and does not constitute an exception management process.

Exam trap

The trap is selecting options that sound efficient (automatic approval, immediate policy revision) but actually undermine the control and accountability that exception management is meant to provide.

42
MCQhard

An organization is implementing a privacy program to comply with GDPR. Which of the following BEST describes the concept of 'privacy by design' as it applies to a new customer relationship management (CRM) system?

A.Incorporating data minimization and access controls into the system architecture from the start.
B.Assigning a data protection officer to review system logs quarterly.
C.Adding a privacy notice to the CRM after deployment.
D.Conducting a privacy impact assessment (PIA) after the system is live.
AnswerA

Privacy by design embeds data minimisation and access controls into the CRM architecture from inception, rather than retrofitting them later. This satisfies GDPR's requirement that protection be built into processing systems and default settings before personal data is collected.

Why this answer

Privacy by design is a foundational GDPR principle (Article 25) requiring data protection to be embedded into systems and processes from the outset, not bolted on afterward. Option A captures this by integrating data minimization and access controls into the CRM's architecture during design, which is exactly what 'by design' means. This proactive approach reduces compliance risk and prevents costly retrofits.

Exam trap

CAS-005 often tests the misconception that privacy by design is about post-deployment activities like privacy notices or audits, rather than proactive architectural integration.

How to eliminate wrong answers

Option B is wrong because assigning a DPO to review logs quarterly is an operational oversight activity, not a design-time control embedded in the system architecture. Option C is wrong because adding a privacy notice after deployment is a reactive, cosmetic measure that does not embed privacy into the system's design. Option D is wrong because conducting a PIA after the system is live is too late — GDPR requires DPIAs before processing begins, especially for high-risk processing.

43
Multi-Selecthard

A security architect is designing a data classification scheme aligned with a new privacy regulation. Which THREE of the following are common data classification levels used in enterprise environments? (Select THREE.)

Select 3 answers
A.Public
B.Internal
C.Critical
D.Secret
E.Confidential
AnswersA, B, E

Public denotes information approved for unrestricted disclosure, carrying no confidentiality requirement. It satisfies the stem's requirement for a common classification level, forming the lowest tier of enterprise schemes and letting architects label marketing material, published policies and open datasets without unnecessary controls.

Why this answer

Common classification levels include public (no impact), internal (moderate impact), confidential (high impact), and restricted (very high impact). Secret is typically a government classification, not enterprise. Critical is not a standard classification level.

44
MCQhard

A multinational retailer must demonstrate compliance with the EU General Data Protection Regulation while also honoring local data-residency laws in a country where it operates. Legal counsel advises that a single global retention schedule cannot satisfy both regimes. Which governance artifact should the security manager produce to reconcile these competing obligations?

A.A records retention and residency matrix mapping each data category to jurisdictional requirements
B.An updated acceptable use policy signed by all employees who handle customer data
C.A business continuity plan that documents failover of the retailer's EU data centers
D.A data protection impact assessment covering the retailer's cross-border transfers
AnswerA

A retention and residency matrix ties each data category to the specific retention period and storage location mandated by every applicable jurisdiction, making conflicts explicit and resolvable. This is exactly the governance artifact needed when a single global schedule cannot satisfy GDPR and local residency law, because it allows differentiated handling per jurisdiction while preserving an auditable rationale.

Why this answer

Where global retention rules collide with local residency mandates, the organization needs a structured mapping of each data category to the retention period and permitted location required by every jurisdiction involved. A retention and residency matrix makes the conflicts visible and provides auditable, differentiated handling, whereas privacy assessments, use policies, and continuity plans address risk, behavior, and availability rather than reconciling legal obligations.

Exam trap

The trap here is treating any privacy-focused document, such as a DPIA, as the universal answer for multi-jurisdictional compliance, when the specific need is an artifact that maps obligations per data category and jurisdiction.

45
Multi-Selectmedium

An organization's security team is reviewing security metrics to present to the board. Which THREE of the following are commonly used Key Performance Indicators (KPIs) for a security program? (Select THREE.)

Select 3 answers
A.Patch compliance percentage
B.Mean time to respond (MTTR)
C.Number of firewalls deployed
D.Vulnerabilities by severity
E.Mean time to detect (MTTD)
AnswersA, B, E

Patch compliance percentage directly measures the proportion of assets carrying current security updates, giving the board a quantifiable view of vulnerability exposure reduction. It is a standard operational KPI because it tracks remediation effectiveness over time against a defined baseline, satisfying the stem's requirement for board-level security programme metrics.

Why this answer

Patch compliance percentage (A) is a valid KPI because it measures the proportion of systems that have current security patches applied within a defined SLA, directly reflecting vulnerability exposure reduction and the effectiveness of patch management. Mean time to respond (B) is a KPI that quantifies the average elapsed time from alert or incident identification to containment/remediation action, showing the operational efficiency of the incident response process. Mean time to detect (E) is a KPI measuring the average time between an actual compromise or event occurring and its detection, which gauges monitoring and detection capability maturity.

Number of firewalls deployed (C) is a raw inventory count, not a performance measure, so it is a metric rather than a KPI. Vulnerabilities by severity (D) is a point-in-time risk/volume metric describing the current state, not a performance indicator of the security program's effectiveness over time.

Exam trap

CAS-005 often tests the distinction between KPIs (outcome-oriented, tied to goals) and raw metrics or vanity counts (e.g., number of firewalls), causing candidates to select inventory counts as KPIs.

46
MCQhard

An organization is adopting the NIST Risk Management Framework (RMF). During which step would the security team select and implement security controls, and how does this map to the organization's governance structure?

A.Step 4: Assess — controls are evaluated for effectiveness.
B.Step 1: Prepare — the organization establishes risk management roles and responsibilities.
C.Step 5: Authorize — a senior official accepts the risk.
D.Step 2: Select and Step 3: Implement — controls are chosen based on risk assessment and integrated into the system.
AnswerD

Within the NIST RMF, Step 2 (Select) chooses controls from the risk assessment, and Step 3 (Implement) deploys them into the system. This mapping satisfies the stem's requirement to tie control selection and implementation to the organisation's governance structure.

Why this answer

In the NIST RMF, Step 2 (Select) is where controls are chosen based on the risk assessment and organizational risk tolerance, and Step 3 (Implement) is where those controls are deployed and integrated into the system and its environment of operation. Together they represent the control selection and implementation phase, which maps to governance through the policies, roles, and risk decisions established in Step 1 (Prepare).

Exam trap

The trap is conflating the RMF steps: candidates often pick Assess (Step 4) because it sounds like where controls are handled, but Assess only evaluates controls that were already selected and implemented in Steps 2 and 3.

How to eliminate wrong answers

Option A is wrong because Step 4 (Assess) evaluates whether the selected and implemented controls are effective — it does not select or implement them. Option B is wrong because Step 1 (Prepare) establishes the risk management context, roles, responsibilities, and governance structure, but does not choose or deploy controls. Option C is wrong because Step 5 (Authorize) is where a senior official makes a risk-based decision to authorize the system to operate, not where controls are selected or implemented.

47
MCQmedium

During a vendor risk assessment, a company receives a SOC 2 Type II report from a cloud service provider. What does this report primarily attest to?

A.The design and operating effectiveness of controls over a period of time
B.The vendor's financial stability
C.The vendor's compliance with privacy laws
D.The vendor's penetration test results
AnswerA

SOC 2 Type II evaluates control design and operating effectiveness across a defined audit period, unlike Type I which reports design at a single point in time. This satisfies the vendor assessment requirement for sustained control performance evidence.

Why this answer

SOC 2 Type II reports on the effectiveness of controls over a period of time.

48
MCQeasy

Under GDPR, which of the following is a data subject right that allows an individual to request that their personal data be erased?

A.Right to portability
B.Right to access
C.Right to erasure
D.Right to rectification
AnswerC

The right to erasure, or right to be forgotten, lets a data subject demand deletion of personal data where no overriding legal ground for retention applies. This directly satisfies the GDPR requirement for an individual to request erasure of their data.

Why this answer

The right to erasure (also known as the 'right to be forgotten') is explicitly defined in GDPR Article 17, allowing data subjects to request deletion of their personal data under certain conditions. This is a core data subject right alongside access, rectification, and portability. Option C directly names this right.

Exam trap

CAS-005 often tests the confusion among GDPR data subject rights, particularly mixing up erasure with portability or rectification, by using similar-sounding descriptions.

How to eliminate wrong answers

Option A is wrong because the right to portability (Article 20) allows data subjects to receive their personal data in a structured, commonly used, machine-readable format and transmit it to another controller. Option B is wrong because the right to access (Article 15) allows individuals to obtain confirmation of whether their data is being processed and access to that data. Option D is wrong because the right to rectification (Article 16) allows individuals to correct inaccurate or incomplete personal data.

49
Multi-Selecthard

A security architect is designing a new cloud-based system that must comply with the Payment Card Industry Data Security Standard (PCI DSS). The architect needs to ensure that cardholder data is protected both at rest and in transit. Which TWO of the following controls are required by PCI DSS to protect cardholder data in this scenario? (Choose two.)

Select 2 answers
A.Restrict physical access to cardholder data storage systems.
B.Render primary account numbers (PAN) unreadable anywhere they are stored.
C.Conduct quarterly external and internal vulnerability scans.
D.Implement a web application firewall (WAF) in front of all public-facing web servers.
E.Encrypt transmission of cardholder data across open, public networks.
AnswersB, E

PCI DSS Requirement 3 requires that stored cardholder data be rendered unreadable through encryption, truncation, tokenization, or hashing. This addresses data at rest and is essential for protecting stored PAN. The architect must ensure that any storage of cardholder data complies with this requirement to reduce the risk of compromise.

Why this answer

PCI DSS explicitly requires encrypting cardholder data during transmission over open, public networks (Requirement 4) and rendering stored PAN unreadable (Requirement 3). These two controls directly protect data in transit and at rest. WAF, physical access, and vulnerability scans are important but do not specifically fulfill the data protection requirements for those states.

Exam trap

The trap here is selecting general PCI DSS requirements like WAF or vulnerability scans, which are important but not the specific controls for protecting cardholder data at rest and in transit.

50
MCQeasy

Which key performance indicator (KPI) is most useful for measuring the effectiveness of an incident response process?

A.Patch compliance percentage
B.Vulnerabilities by severity
C.Number of security awareness training sessions
D.Mean time to respond (MTTR)
AnswerD

MTTR measures elapsed time from incident detection to containment or resolution, directly reflecting how quickly the response process actually works. It satisfies the stem's requirement for a KPI gauging incident response effectiveness, unlike volume or cost metrics.

Why this answer

Mean time to respond (MTTR) measures the average time taken to respond to and contain a security incident from detection. It directly reflects the efficiency and effectiveness of the incident response process, as lower MTTR indicates faster containment and reduced impact. Other metrics like patch compliance or vulnerabilities by severity are related to vulnerability management, not incident response effectiveness.

Exam trap

CAS-005 often tests the confusion between preventive metrics (like patch compliance) and response metrics (like MTTR), leading candidates to choose a vulnerability management metric.

How to eliminate wrong answers

Option A is wrong because patch compliance percentage measures how well systems are patched, which is a preventive control, not an incident response metric. Option B is wrong because vulnerabilities by severity is a risk assessment metric, not a measure of incident response effectiveness. Option C is wrong because the number of security awareness training sessions is a training metric, not an incident response KPI.

51
MCQmedium

An organization is using the FAIR model to quantify risk. Which of the following is a primary component of the FAIR taxonomy?

A.Inherent risk and residual risk
B.Annualized loss expectancy and single loss expectancy
C.Loss event frequency and loss magnitude
D.Threat event frequency and vulnerability
AnswerC

Loss event frequency and loss magnitude form FAIR's two top-level factors, splitting risk into how often a threat event occurs and how much it costs. This taxonomy directly satisfies the stem's quantification requirement, letting analysts model frequency and magnitude separately rather than relying on qualitative ratings.

Why this answer

The FAIR (Factor Analysis of Information Risk) taxonomy decomposes risk into two primary factors: Loss Event Frequency (LEF) — how often a loss event is expected to occur — and Loss Magnitude (LM) — how much loss each event would cause. These two top-level factors are then further decomposed (e.g., LEF into threat event frequency and vulnerability; LM into primary and secondary loss). LEF and LM are the canonical first-level components of the FAIR ontology.

Exam trap

CAS-005 often tests whether candidates can distinguish FAIR's structural taxonomy components (LEF, LM) from derived quantitative outputs (ALE, SLE) or generic risk terms (inherent vs. residual risk).

How to eliminate wrong answers

Option A is wrong because inherent risk and residual risk are general risk-management concepts (risk before and after controls), not primary components of the FAIR taxonomy — FAIR models them through control strength affecting LEF. Option B is wrong because ALE and SLE are quantitative outputs derived from FAIR analysis (SLE × ARO = ALE), not taxonomy components; they are results, not structural elements. Option D is wrong because threat event frequency and vulnerability are sub-components that feed into Loss Event Frequency, not the top-level primary components of the FAIR taxonomy.

52
MCQeasy

A financial institution must comply with the Sarbanes-Oxley Act (SOX). Which of the following is a primary focus of SOX compliance?

A.Security of credit card transactions
B.Privacy of health information
C.Protection of personally identifiable information (PII)
D.Accuracy and reliability of financial reporting
AnswerD

SOX mandates accurate, reliable financial reporting and internal controls over financial disclosure, directly satisfying the stem's regulatory constraint for a financial institution. Unlike frameworks centred on data privacy or payment card handling, SOX specifically governs the integrity of financial statements and the controls assuring their accuracy.

Why this answer

SOX is a U.S. federal law enacted in 2002 to protect investors by improving the accuracy and reliability of corporate financial disclosures. Its primary focus is ensuring that financial reporting is accurate, reliable, and subject to internal controls and independent audits. This directly aligns with option D.

Exam trap

CAS-005 often tests the confusion between compliance frameworks — candidates may associate SOX with financial data but incorrectly pick PII or PCI, forgetting that SOX is specifically about financial reporting accuracy and internal controls.

How to eliminate wrong answers

Option A is wrong because credit card transaction security is governed by PCI DSS, not SOX. Option B is wrong because health information privacy is the domain of HIPAA. Option C is wrong because PII protection is a broad privacy concern covered by laws like GDPR or CCPA, not the primary focus of SOX.

53
MCQmedium

A company is required to comply with PCI DSS. What is the primary purpose of conducting quarterly network vulnerability scans?

A.To ensure firewall rules are correctly configured
B.To verify encryption strength
C.To detect and remediate vulnerabilities in a timely manner
D.To monitor user access logs
AnswerC

Quarterly scanning satisfies PCI DSS Requirement 11.3.2 by identifying exploitable weaknesses in external and internal networks before attackers do, enabling remediation within the mandated timeframe. Continuous detection keeps the cardholder data environment compliant between annual penetration tests, directly addressing the standard's timely-remediation constraint.

Why this answer

The primary purpose of quarterly network vulnerability scans under PCI DSS is to detect and remediate vulnerabilities in a timely manner. PCI DSS Requirement 11.2 mandates quarterly internal and external vulnerability scans to identify security weaknesses and address them before they can be exploited. This proactive approach helps maintain a secure network environment.

Exam trap

CAS-005 often tests the confusion between vulnerability scanning and other security assessments like firewall audits or encryption validation, leading candidates to select a secondary benefit.

How to eliminate wrong answers

Option A is wrong because while firewall rule configuration is important, vulnerability scans are not primarily for verifying firewall rules; that is typically done through configuration reviews or penetration testing. Option B is wrong because verifying encryption strength is not the main goal of vulnerability scans; encryption is assessed through other means like cryptographic audits. Option D is wrong because monitoring user access logs is a detective control, not the purpose of vulnerability scans.

54
Multi-Selectmedium

A risk manager is applying the FAIR model to quantify a risk. Which TWO of the following are primary components used in FAIR analysis? (Select TWO.)

Select 2 answers
A.Loss Magnitude (LM)
B.Single Loss Expectancy (SLE)
C.Annual Loss Expectancy (ALE)
D.Loss Event Frequency (LEF)
E.Annualized Rate of Occurrence (ARO)
AnswersA, D

Loss Magnitude quantifies the financial impact of a single loss event across primary and secondary forms. It is a primary FAIR factor, paired with Loss Event Frequency to derive annualised risk exposure in the model.

Why this answer

FAIR model decomposes risk into Loss Event Frequency (LEF) and Loss Magnitude (LM). Single Loss Expectancy (SLE) and Annualized Rate of Occurrence (ARO) are used in quantitative risk analysis (e.g., ALE), but not primary FAIR components. Exposure Factor (EF) is part of SLE calculation.

Annual Loss Expectancy (ALE) is a result, not a component.

55
Multi-Selecthard

An organization is implementing a vendor risk management program and is reviewing a contract that includes a right-to-audit clause. Which THREE of the following are common elements that should be verified during such an audit? (Select THREE.)

Select 3 answers
A.Employee satisfaction surveys
B.Vendor's financial stability
C.Access control mechanisms
D.Incident response procedures
E.Data encryption practices
AnswersC, D, E

Access control mechanisms are a core control area verified under right-to-audit clauses, confirming that only authorised identities reach vendor systems and data. Auditors examine authentication, authorisation and privileged access management to validate the vendor's safeguards against unauthorised entry.

Why this answer

Option C (Access control mechanisms) is correct because a right-to-audit review must verify that the vendor enforces least privilege, authentication, and authorization controls to protect the organization's data from unauthorized access. Option D (Incident response procedures) is correct because the audit should confirm the vendor has documented detection, containment, eradication, and notification processes, including breach notification timelines, to meet contractual and regulatory obligations. Option E (Data encryption practices) is correct because auditors must verify encryption in transit and at rest, key management, and algorithm standards to ensure data confidentiality and integrity.

Option A (Employee satisfaction surveys) is not a security or compliance control relevant to vendor risk, and Option B (Vendor's financial stability) is a business viability concern typically assessed during due diligence rather than a right-to-audit control review.

Exam trap

CAS-005 often tests the distinction between security-focused audit elements and broader business or HR factors, tempting candidates to select financial stability or employee satisfaction as part of a right-to-audit, which are typically outside the scope of information security audits.

56
MCQhard

A security analyst calculates the annualized loss expectancy (ALE) for a server. The single loss expectancy (SLE) is $50,000, and the annualized rate of occurrence (ARO) is 0.2. What is the ALE?

A.$50,200
B.$2,500
C.$10,000
D.$250,000
AnswerC

ALE is calculated by multiplying single loss expectancy by annualised rate of occurrence: $50,000 × 0.2 = $10,000. This quantifies the expected annual loss from the risk, matching the stem's supplied SLE and ARO values.

Why this answer

The annualized loss expectancy (ALE) is calculated by multiplying the single loss expectancy (SLE) by the annualized rate of occurrence (ARO). Here, SLE = $50,000 and ARO = 0.2, so ALE = $50,000 * 0.2 = $10,000. This represents the expected monetary loss per year from the risk.

Exam trap

CAS-005 often tests the confusion between the ALE formula and other combinations like SLE + ARO or SLE / ARO, leading candidates to pick a mathematically incorrect option.

How to eliminate wrong answers

Option A is wrong because $50,200 is the sum of SLE and ARO, not the product; ALE is not calculated by addition. Option B is wrong because $2,500 is SLE divided by 20 (or ARO multiplied by 0.05), which is not the correct formula. Option D is wrong because $250,000 is SLE multiplied by 5 (or SLE divided by 0.2), which incorrectly uses the reciprocal of ARO.

57
MCQmedium

A multinational financial services firm is aligning its enterprise risk management program with the NIST Risk Management Framework (RMF). The Chief Risk Officer wants to ensure that risk response decisions are formally authorized before changes are made to production systems. Which RMF step is responsible for providing that authorization?

A.Assess security controls
B.Categorize the system
C.Monitor security controls
D.Authorize the system
AnswerD

The Authorize step is where a senior official reviews the security assessment results, the plan of action and milestones, and the continuous monitoring strategy, then formally accepts the residual risk and grants an authorization to operate. This directly satisfies the Chief Risk Officer's requirement that risk decisions be authorized before production changes are made, because the authorization decision is documented and tied to explicit risk acceptance.

Why this answer

Authorization is the RMF step where an authorizing official formally accepts residual risk and permits the system to operate. It follows categorization, control selection, implementation, and assessment, and it is the point at which risk decisions become official. Continuous monitoring then sustains that authorization over time.

Because the CRO requires formal risk acceptance before production changes, the Authorize step is the correct fit.

Exam trap

The trap here is confusing the assessment of controls with the formal acceptance of residual risk, which occurs only at the authorization decision.

58
MCQmedium

A hospital is preparing for a compliance audit and must demonstrate that it has implemented administrative safeguards required by the HIPAA Security Rule. Which activity best provides this evidence?

A.Publishing a notice of privacy practices on the hospital website
B.Installing biometric access readers at the data center entrance
C.Maintaining a current inventory of all electronic protected health information systems and the results of periodic risk analyses
D.Enabling full-disk encryption on all clinical workstations
AnswerC

The HIPAA Security Rule requires covered entities to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information. Documented system inventories and periodic risk analysis results are core administrative safeguards and provide direct audit evidence. This activity demonstrates that the hospital has identified where ePHI resides and has evaluated risks, which is exactly what an auditor expects to see.

Why this answer

Administrative safeguards under the HIPAA Security Rule include risk analysis, risk management, workforce security, and access management. A documented inventory of ePHI systems and periodic risk analysis results directly demonstrate that the hospital has assessed risks and identified where ePHI is stored and processed. The other choices are physical, technical, or Privacy Rule activities that do not provide the specific administrative evidence the auditor seeks.

Exam trap

The trap here is selecting any security control as evidence of administrative safeguards, when the auditor specifically requires documentation of risk analysis and governance activities.

59
MCQhard

An organization's security policy defines that all sensitive data must be encrypted. However, a business unit has a legacy application that cannot support encryption without a major rewrite. The risk owner decides to accept the risk. This is an example of which risk treatment strategy?

A.Risk acceptance
B.Risk mitigation
C.Risk transfer
D.Risk avoidance
AnswerA

Accepting the risk means the risk owner acknowledges the legacy application's exposure and proceeds without encryption, absorbing potential loss. This matches risk acceptance rather than mitigation, transfer or avoidance, satisfying the stem's decision to tolerate the identified risk.

Why this answer

Risk acceptance is the correct answer because the risk owner has decided to acknowledge the risk and continue operating without implementing additional controls. The legacy application cannot support encryption without a major rewrite, so the organization chooses to accept the risk rather than mitigate, transfer, or avoid it. This aligns with the definition of risk acceptance as a risk treatment strategy where no action is taken to reduce the risk, and the organization retains the potential consequences.

Exam trap

The trap here is confusing risk acceptance with risk mitigation when a compensating control is mentioned, or assuming that any decision to not encrypt automatically means acceptance, while ignoring that the risk owner's formal acceptance is the key differentiator.

How to eliminate wrong answers

Option B is wrong because risk mitigation involves implementing controls to reduce the risk, such as encryption, which is not possible here without a rewrite. Option C is wrong because risk transfer shifts the risk to a third party, typically through insurance or outsourcing, which is not mentioned. Option D is wrong because risk avoidance would mean discontinuing the activity or application entirely to eliminate the risk, which is not the case here.

60
Multi-Selecthard

During a compliance audit for PCI DSS, the auditor identifies that cardholder data is stored beyond the required retention period. The organization wants to implement proper data lifecycle management. Which THREE of the following should the organization include in its data retention policy? (Select THREE.)

Select 3 answers
A.Encryption requirements for data in transit
B.Retention schedules for each data classification level
C.Process for legal hold to suspend deletion
D.Data classification scheme definitions
E.Secure disposal methods for data at end of life
AnswersB, C, E

Retention schedules per classification level directly satisfy PCI DSS's requirement to define and enforce how long cardholder data is kept. Mapping each classification to a defined retention period ensures data is disposed of once its purpose expires, preventing the indefinite storage the audit identified.

Why this answer

Option B is correct because a data retention policy must define explicit retention schedules for each data classification level, ensuring cardholder data is not stored beyond the PCI DSS-required period and is deleted when no longer needed. Option C is correct because a legal hold process is essential to suspend scheduled deletion when data is subject to litigation, regulatory investigation, or e-discovery obligations, preventing spoliation while still enforcing lifecycle management. Option E is correct because secure disposal methods (such as NIST SP 800-88 media sanitization, cryptographic erasure, or physical destruction) must be specified for data at end of life to ensure cardholder data cannot be recovered after retention expires.

Option A does not belong because encryption for data in transit is a transmission-security control, not a retention lifecycle element. Option D does not belong because the data classification scheme itself is a prerequisite input to the policy, not a retention-specific requirement being asked for here.

Exam trap

CAS-005 often tests whether candidates can distinguish retention policy content (schedules, legal hold, disposal) from adjacent policies like encryption and classification definitions, which are inputs rather than retention-policy components.

61
MCQmedium

A security team is evaluating the effectiveness of their patching program. Which metric would best indicate how quickly the organization applies critical patches?

A.Number of unpatched systems
B.Patch compliance percentage
C.Mean time to patch
D.Vulnerabilities by severity
AnswerC

Mean time to patch measures the average elapsed duration between patch release and deployment across systems, directly quantifying remediation speed. It isolates the time dimension of the patching programme, unlike coverage or count metrics, which describe breadth rather than how quickly critical patches are applied.

Why this answer

Mean time to patch measures the average time taken from the release of a patch to its application on systems. It directly indicates how quickly the organization applies critical patches, as a lower mean time to patch signifies a faster patching process. Other metrics like patch compliance percentage show the proportion of systems patched but not the speed.

Exam trap

CAS-005 often tests the confusion between metrics that measure patching coverage (like patch compliance percentage) and those that measure patching speed (like mean time to patch).

How to eliminate wrong answers

Option A is wrong because the number of unpatched systems indicates the current state but not the speed of patching. Option B is wrong because patch compliance percentage measures the extent of patching, not the time taken. Option D is wrong because vulnerabilities by severity is a risk metric, not a measure of patching speed.

62
MCQmedium

A financial institution is evaluating a cloud service provider for hosting customer data. During the due diligence process, which report would best help the institution assess the provider's control environment and compliance with SOC 2?

A.SOC 2 Type II report
B.ISO 27001 certificate
C.Penetration test report
D.Vulnerability scan results
AnswerA

A SOC 2 Type II report covers the design and operating effectiveness of controls over a review period, giving evidence that the provider's control environment actually functioned. Type I only assesses design at a point in time, so it cannot demonstrate sustained SOC 2 compliance during due diligence.

Why this answer

A SOC 2 Type II report is the correct choice because it provides an independent auditor's opinion on the design AND operating effectiveness of a service provider's controls over a period of time (typically 3-12 months). This directly addresses the financial institution's need to assess the provider's control environment and SOC 2 compliance. Type II is specifically designed for vendor due diligence where evidence of sustained control operation is required.

Exam trap

CAS-005 often tests the distinction between SOC 2 Type I (design at a point in time) and Type II (operating effectiveness over time), and candidates frequently pick ISO 27001 or a pentest report as equivalent evidence when the question specifically asks about SOC 2 compliance.

How to eliminate wrong answers

Option B is wrong because an ISO 27001 certificate attests to an ISMS framework and certification, not to SOC 2 Trust Services Criteria, and it does not provide the detailed control testing evidence a SOC 2 Type II report contains. Option C is wrong because a penetration test report is a point-in-time technical assessment of exploitable vulnerabilities, not an attestation of the control environment or SOC 2 compliance. Option D is wrong because vulnerability scan results are raw technical findings from automated scanners and provide no auditor opinion on control design or operating effectiveness.

63
MCQmedium

An organization is reviewing its third-party risk management process. Which of the following clauses should be included in contracts with critical vendors to ensure ongoing visibility into their security posture?

A.Non-disclosure agreement (NDA)
B.Service-level agreement (SLA) for uptime
C.Right-to-audit clause
D.Data processing agreement (DPA)
AnswerC

A right-to-audit clause contractually grants the organisation the ability to inspect a critical vendor's security controls and evidence on demand, satisfying the requirement for ongoing visibility into their security posture rather than relying on one-off assurances.

Why this answer

A right-to-audit clause contractually grants the organization the ability to inspect, assess, and verify a vendor's security controls, policies, and practices — either directly or via a qualified third party. This is the mechanism that provides ongoing visibility into the vendor's security posture beyond initial due diligence. Without it, the organization has no legal standing to demand evidence of security compliance during the contract term.

Exam trap

The trap is conflating legal/privacy documents (NDA, DPA) or performance documents (SLA) with the specific contractual mechanism that grants inspection and verification rights — the right-to-audit clause.

How to eliminate wrong answers

Option A is wrong because an NDA only protects confidentiality of shared information; it does not grant any right to inspect or audit the vendor's security environment. Option B is wrong because an SLA for uptime addresses availability commitments and remedies, not security posture visibility or control verification. Option D is wrong because a DPA governs how personal data is processed and protected under privacy law (e.g., GDPR), but it does not by itself grant audit rights or ongoing security assessment access.

64
MCQmedium

A security analyst is calculating the annualized loss expectancy (ALE) for a server that processes credit card data. The server has a $100,000 asset value, and the exposure factor for a security breach is 0.4. Historical data shows that such breaches occur twice per year. What is the ALE?

A.$100,000
B.$40,000
C.$80,000
D.$200,000
AnswerC

SLE equals asset value multiplied by exposure factor: $100,000 × 0.4 = $40,000. ALE equals SLE multiplied by annualised rate of occurrence: $40,000 × 2 = $80,000. This matches the calculated annualised loss expectancy for the credit card server.

Why this answer

ALE is calculated as Single Loss Expectancy (SLE) multiplied by Annualized Rate of Occurrence (ARO). SLE = Asset Value × Exposure Factor = $100,000 × 0.4 = $40,000. ARO = 2 occurrences per year.

Therefore ALE = $40,000 × 2 = $80,000.

Exam trap

CAS-005 often tests whether candidates confuse SLE with ALE or forget to multiply by ARO; the trap is stopping at $40,000 or using the full asset value.

How to eliminate wrong answers

Option A is wrong because $100,000 is the asset value, not the ALE; it ignores both the exposure factor and the frequency. Option B is wrong because $40,000 is the SLE (the loss per single incident), not the annualized figure. Option D is wrong because $200,000 would result from multiplying the full asset value by 2 without applying the 0.4 exposure factor, which overstates the loss.

65
MCQhard

A company is considering adopting the NIST Risk Management Framework (RMF). Which of the following steps is unique to NIST RMF compared to ISO 27005?

A.System categorization
B.Risk identification
C.Risk treatment
D.Risk assessment
AnswerA

System categorisation, assigning impact levels (low, moderate, high) based on confidentiality, integrity and availability, is a distinctive early step in the NIST RMF. ISO 27005 addresses risk assessment and treatment without mandating this formal categorisation phase, making it the unique element.

Why this answer

System categorization is a step unique to the NIST RMF (Step 1: Categorize) that uses FIPS 199 to classify information systems by impact level (Low, Moderate, High). ISO 27005 focuses on risk management processes — risk identification, assessment, and treatment — but does not include a formal system categorization step as part of its framework. This makes system categorization the correct differentiator.

Exam trap

CAS-005 often tests framework-specific terminology, and candidates may incorrectly assume that risk assessment or treatment is unique to NIST RMF when these are shared with ISO 27005; the unique step is system categorization via FIPS 199.

How to eliminate wrong answers

Option B is wrong because risk identification is a core component of both NIST RMF (within Step 2/3) and ISO 27005, so it is not unique to NIST RMF. Option C is wrong because risk treatment is explicitly covered in ISO 27005 as well as NIST RMF, so it is not unique. Option D is wrong because risk assessment is a shared element of both frameworks, appearing in NIST RMF Step 2 and ISO 27005's risk assessment process.

66
MCQmedium

A financial services firm's third-party risk team is onboarding a new SaaS payroll provider. The provider refuses to share its internal audit reports but will allow the firm to send its own assessor on-site to inspect the provider's controls. Which risk assessment method should the firm use to obtain assurance in this situation?

A.Review of the provider's SOC 2 Type I report
B.Acceptance of the provider's ISO/IEC 27001 certificate as sufficient evidence
C.On-site assessment performed by the firm's own assessors
D.Self-assessment questionnaire completed by the provider's security team
AnswerC

The provider has blocked access to internal audit reports but explicitly permits the firm to send assessors on-site. A direct on-site assessment lets the firm independently inspect the provider's controls, interview staff, and review evidence first-hand, generating the assurance the questionnaire or report-based approaches could not deliver under these constraints.

Why this answer

Because the provider withholds internal audit reports yet allows assessors on-site, the only method that yields independently verified, first-hand evidence of control effectiveness is a direct on-site assessment. Self-assessments and certifications provide weaker, provider-controlled evidence, and the SOC 2 report is unavailable by the provider's own refusal, leaving the on-site inspection as the reliable path.

Exam trap

The trap here is assuming that any recognized artifact such as a SOC 2 report or ISO certificate automatically satisfies third-party assurance needs, when the actual constraint is what evidence the provider will permit access to.

67
MCQmedium

A security analyst calculates the annual loss expectancy (ALE) for a critical asset. The single loss expectancy (SLE) is $50,000, and the annualized rate of occurrence (ARO) is 0.2. What is the annual loss expectancy?

A.$0
B.$10,000
C.$50,200
D.$250,000
AnswerB

Multiplying the single loss expectancy of $50,000 by the annualised rate of occurrence of 0.2 yields $10,000, satisfying the stem's quantitative risk calculation. This figure represents the expected yearly financial loss from the asset, enabling cost-benefit comparison against proposed security controls.

Why this answer

Annualized Loss Expectancy is calculated as ALE = SLE × ARO. With SLE = $50,000 and ARO = 0.2 (meaning the loss event is expected 0.2 times per year, i.e., once every five years), ALE = 50,000 × 0.2 = $10,000. This represents the expected yearly financial loss from the risk and is used to justify whether a control costing less than $10,000 per year is worth implementing.

Exam trap

CAS-005 often tests whether candidates remember ALE = SLE × ARO rather than adding, dividing, or inverting the operands — the distractors are deliberately built from those arithmetic mistakes.

How to eliminate wrong answers

Option A is wrong because $0 would only result if either SLE or ARO were zero — neither is, so there is a non-zero expected annual loss. Option C is wrong because $50,200 results from adding SLE and ARO (50,000 + 0.2) instead of multiplying them, which is a formula error. Option D is wrong because $250,000 results from dividing SLE by ARO (50,000 ÷ 0.2) instead of multiplying, another formula inversion.

68
MCQeasy

A newly hired CISO is reviewing the organization's risk register and finds that a legacy payment application carries a high inherent risk rating, but after accounting for the web application firewall, tokenization, and quarterly penetration testing already in place, the rating drops substantially. Which risk concept explains the difference between these two ratings?

A.Inherent risk
B.Residual risk
C.Control risk
D.Risk appetite
AnswerB

Residual risk is what remains after existing controls are applied to an inherent risk. The firewall, tokenization, and recurring penetration tests reduce the likelihood and impact of exploitation, so the lower rating reflects residual risk. The scenario explicitly describes inherent risk dropping once current controls are considered, which is the definition of residual risk.

Why this answer

The high rating represents inherent risk, the exposure before safeguards are considered. Once the firewall, tokenization, and recurring penetration tests are factored in, the remaining exposure is residual risk. Risk appetite is a tolerance threshold, inherent risk is the pre-control baseline, and control risk concerns control failure rather than the net exposure level.

Exam trap

The trap here is conflating residual risk with risk appetite, since both involve deciding whether an exposure is acceptable, when only residual risk measures what remains after controls are applied.

69
MCQmedium

A security manager is reviewing Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs) for the security program. Which of the following is an example of a KRI?

A.Mean time to detect (MTTD) security incidents
B.Number of critical vulnerabilities exceeding the risk appetite threshold
C.Percentage of systems patched within 30 days
D.Number of security incidents per month
AnswerB

A KRI signals exposure against a defined risk appetite, not operational throughput. Critical vulnerabilities breaching that threshold indicate the security posture has moved beyond acceptable tolerance, prompting escalation. KPIs, by contrast, measure performance such as patch coverage or mean time to remediate, so this metric is the risk indicator.

Why this answer

A Key Risk Indicator (KRI) measures risk exposure and whether it is approaching or exceeding the organization's risk appetite — the number of critical vulnerabilities exceeding the risk appetite threshold is a direct measure of unacceptable risk exposure. KRIs are forward-looking indicators that signal when risk levels are becoming dangerous.

Exam trap

The trap is that many security metrics (MTTD, patch rate, incident count) sound risk-related but are actually KPIs measuring process performance; only metrics tied to risk appetite thresholds qualify as KRIs.

How to eliminate wrong answers

Option A is wrong because Mean Time to Detect (MTTD) is a performance metric measuring how quickly the security team detects incidents, which is a KPI about operational efficiency, not a risk exposure indicator. Option C is wrong because the percentage of systems patched within 30 days is a KPI measuring the effectiveness and timeliness of the patching process, not a measure of risk threshold breach. Option D is wrong because the number of security incidents per month is a lagging performance/volume metric (a KPI) describing incident frequency, not a forward-looking indicator of risk appetite breach.

70
Multi-Selectmedium

A financial services company is conducting a risk assessment for a new online banking platform. The risk team must prioritize identified risks. Which TWO of the following factors are most critical in determining the priority for risk treatment? (Choose two.)

Select 2 answers
A.Number of open vulnerabilities
B.Vendor's market share
C.Potential impact on business objectives
D.Cost of the security control
E.Likelihood of occurrence
AnswersC, E

Impact measures the severity of consequences if a risk materializes, including financial loss, reputational damage, and regulatory penalties. For an online banking platform, impact directly ties to customer trust and compliance. Prioritizing risks with high impact ensures that treatment addresses threats that could severely disrupt operations or violate regulations, aligning security efforts with business resilience.

Why this answer

Risk prioritization hinges on assessing the likelihood of a risk event and its potential impact on business objectives. These two factors form the basis of risk scoring (e.g., risk = likelihood × impact) and guide where to focus treatment efforts. Cost, vendor market share, and vulnerability counts are secondary or irrelevant to determining which risks are most urgent for the online banking platform.

Exam trap

The trap here is focusing on the number of vulnerabilities or control cost as prioritization factors, when the core of risk prioritization is the combination of likelihood and business impact.

71
MCQmedium

An organization has identified a vulnerability in a legacy system that cannot be patched. The system is critical for operations, and the cost of mitigating the vulnerability exceeds the potential loss. Which risk treatment option is most appropriate?

A.Risk acceptance
B.Risk avoidance
C.Risk mitigation
D.Risk transfer
AnswerA

Acceptance fits because the legacy system cannot be patched, remains operationally critical, and the mitigation cost exceeds the potential loss. Retaining the residual risk formally, with documented sign-off and monitoring, is the proportionate treatment rather than transfer, avoidance or further mitigation.

Why this answer

Risk acceptance is the appropriate treatment when a vulnerability cannot be mitigated (legacy system, no patch available), the system is critical to operations (so avoidance is not feasible), and the cost of mitigation exceeds the potential loss. The organization formally acknowledges the residual risk and documents the decision, often with compensating controls and management sign-off. This is a deliberate, documented business decision rather than neglect.

Exam trap

CAS-005 often tests the confusion between risk acceptance and risk avoidance when a system is critical — candidates must recognize that acceptance is chosen when the system must remain operational and mitigation is infeasible or cost-prohibitive, whereas avoidance requires eliminating the activity entirely.

How to eliminate wrong answers

Option B is wrong because risk avoidance means eliminating the activity or system that introduces the risk — but the system is critical for operations, so shutting it down is not viable. Option C is wrong because risk mitigation means applying controls to reduce the likelihood or impact of the vulnerability — but the question states the system cannot be patched and mitigation cost exceeds potential loss, so mitigation is not the most appropriate choice. Option D is wrong because risk transfer shifts the financial impact to a third party (e.g., cyber insurance or outsourcing), but transfer does not address the underlying unpatched vulnerability and is typically used alongside acceptance, not as the primary treatment when the cost-benefit analysis favors acceptance.

72
MCQmedium

A security compliance officer is mapping the organization's controls to the NIST Cybersecurity Framework (CSF) 2.0. The officer needs to ensure that the organization's governance and risk management processes are adequately covered. Which CSF 2.0 function primarily addresses the development and implementation of cybersecurity policies, procedures, and risk management strategies?

A.Detect (DE)
B.Govern (GV)
C.Identify (ID)
D.Protect (PR)
AnswerB

The Govern function, new in CSF 2.0, focuses on establishing and monitoring cybersecurity strategy, policies, and risk management. It ensures that governance structures are in place to support the other functions. This directly addresses the development and implementation of policies and procedures for managing risk.

Why this answer

CSF 2.0 introduced the Govern function to emphasize cybersecurity governance and risk management. It encompasses organizational context, risk management strategy, roles and responsibilities, and policy. This function ensures that cybersecurity is integrated into enterprise risk management, making it the correct choice for policy and procedure development.

Exam trap

The trap here is selecting Identify because it also deals with risk, but Govern specifically covers policy and strategy development.

73
MCQeasy

Which risk management framework is specifically designed for U.S. federal agencies and includes a six-step process: Categorize, Select, Implement, Assess, Authorize, and Monitor?

A.ISO 27005
B.COBIT
C.NIST RMF
D.FAIR
AnswerC

NIST RMF is the U.S. federal framework built on the six-step lifecycle: Categorize, Select, Implement, Assess, Authorize and Monitor. It satisfies the stem's requirement for a federal-specific process, unlike ISO 31000 or COSO ERM, which lack this mandated authorisation step and U.S. federal alignment.

Why this answer

The NIST Risk Management Framework (RMF) is the framework specifically designed for U.S. federal agencies and is defined by NIST SP 800-37. It prescribes exactly the six-step process named in the question: Categorize, Select, Implement, Assess, Authorize, and Monitor. This lifecycle aligns with FISMA requirements for federal information systems.

Exam trap

CAS-005 often tests whether candidates can distinguish NIST RMF's six-step federal authorization process from ISO 27005's risk management process and COBIT's governance domains — all three involve 'risk' but only NIST RMF has the Categorize/Select/Implement/Assess/Authorize/Monitor sequence.

How to eliminate wrong answers

Option A is wrong because ISO/IEC 27005 is an international information security risk management guideline that describes the risk management process (identification, analysis, evaluation, treatment) but does not define a six-step Categorize/Select/Implement/Assess/Authorize/Monitor workflow and is not U.S. federal-specific. Option B is wrong because COBIT is an IT governance and management framework from ISACA focused on aligning IT with business objectives across five domains — it is not a federal risk authorization process. Option D is wrong because FAIR (Factor Analysis of Information Risk) is a quantitative risk analysis methodology for measuring cyber risk in financial terms, not a six-step authorization framework.

74
Multi-Selecthard

A financial services firm is selecting a cloud provider to host regulated customer data. The vendor risk team wants contractual language that lets the firm independently verify the provider's security posture over time rather than relying only on the provider's self-reported questionnaires. (Choose two.)

Select 2 answers
A.A clause requiring the provider to deliver current SOC 2 Type II reports at least annually
B.A limitation-of-liability cap tied to twelve months of fees
C.A service level agreement specifying 99.99% uptime credits
D.A most-favored-nation pricing clause
E.A right-to-audit clause permitting on-site inspections and evidence collection
AnswersA, E

Requiring current SOC 2 Type II reports gives the firm an independent auditor's opinion on the design and operating effectiveness of the provider's controls over a period of time. Delivering them annually ensures the assurance stays valid rather than relying on a one-time snapshot. This directly supports ongoing, third-party-verified visibility into the provider's security posture and complements other contractual safeguards.

Why this answer

Ongoing independent visibility into a provider's security posture requires contractual rights that produce evidence rather than self-reporting. A right-to-audit establishes the legal ability to inspect and test controls, and a requirement for current SOC 2 Type II reports supplies recurring auditor-attested evidence of control effectiveness. Uptime SLAs, liability caps, and pricing clauses govern availability, financial exposure, and cost, none of which verify how the provider actually secures regulated data.

Exam trap

The trap here is treating any vendor contract term as security assurance, when only provisions that grant inspection rights or recurring independent audit evidence actually verify the provider's controls.

75
Multi-Selectmedium

A security officer is reviewing continuous compliance monitoring tools. Which TWO of the following are primary benefits of implementing such tools? (Select TWO.)

Select 2 answers
A.Guarantees 100% compliance with all regulations
B.Provides real-time visibility into compliance posture
C.Reduces the need for periodic audits by enabling ongoing tracking
D.Replaces the need for a risk management framework
E.Eliminates all security risks
AnswersB, C

Continuous compliance monitoring continuously assesses controls against frameworks, so drift and misconfigurations surface immediately rather than at periodic audits. This satisfies the stem's requirement for a primary benefit: real-time visibility into compliance posture, enabling prompt remediation before gaps escalate into reportable findings.

Why this answer

Option B is correct because continuous compliance monitoring tools continuously collect and analyze telemetry from systems, configurations, and controls, giving organizations real-time (or near-real-time) visibility into their current compliance posture rather than a point-in-time snapshot. Option C is correct because this ongoing tracking allows deviations and drift to be detected as they occur, reducing reliance on infrequent periodic audits and enabling faster remediation. Option A is incorrect because no tool can guarantee 100% compliance with all regulations; compliance depends on people, processes, and legal interpretation, and monitoring only provides evidence and alerts.

Option D is incorrect because a risk management framework (such as NIST RMF or ISO 31000) is a governance and process structure that tools support but cannot replace. Option E is incorrect because no tool can eliminate all security risks; monitoring reduces and manages risk but residual risk always remains.

Exam trap

The trap here is the absolutist language — 'guarantees 100% compliance,' 'replaces the framework,' 'eliminates all risks' — CAS-005 often tests whether candidates recognize that no security tool provides absolute guarantees.

Page 1 of 2 · 143 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Casp Grc questions.