Courseiva

CAS-005 · topic practice

Governance, Risk, and Compliance practice questions

Governance, Risk, and Compliance is 20% of SecurityX (CAS-005), covering policy hierarchy, risk frameworks, regulatory obligations, and audit evidence. Questions are scenario-based: you map controls to requirements, select metrics, and identify which artifacts prove compliance. Expect HIPAA, GDPR, and patch-management scenarios requiring you to choose the best evidence or ordering rather than recall definitions.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Governance, Risk, and Compliance

What the exam tests

What to know about Governance, Risk, and Compliance

You must map controls and artifacts to specific regulatory and policy requirements, then justify the best evidence. The single most important thing: know the policy hierarchy order and which document type is mandatory versus advisory, since ordering and evidence-selection questions depend on it.

Ordering the security policy hierarchy: policy, standards, baselines, procedures, and guidelines from highest to lowest authority.

Selecting audit evidence such as access control logs, RBAC matrices, and audit trails for ePHI under HIPAA.

Choosing patch metrics like mean time to remediate (MTTR) for critical vulnerabilities to gauge program speed.

Identifying GDPR data subject rights: access, erasure, portability, rectification, restriction, and objection.

Watch out for

Common Governance, Risk, and Compliance exam traps

  • ▸Confusing standards with guidelines: standards are mandatory and specific, guidelines are discretionary recommendations, so hierarchy questions hinge on that distinction.
  • ▸Treating GDPR data subject rights as optional best practices rather than enforceable obligations requiring demonstrable evidence.
  • ▸Picking raw patch counts or deployment totals instead of time-based remediation metrics when asked how quickly critical patches are applied.

Practice set

Governance, Risk, and Compliance questions

20 questions · select your answer, then reveal the explanation

A healthcare organization must comply with HIPAA. Which of the following is a key requirement for protecting electronic protected health information (ePHI)?

A security manager is selecting metrics to present to the board. Which two of the following are key risk indicators (KRIs) that would be most relevant for executive oversight? (Choose two.)

A security manager is developing key risk indicators (KRIs) for the organization's cybersecurity program. Which THREE of the following are examples of KRIs? (Select THREE.)

A security analyst is calculating the annualized loss expectancy (ALE) for a server that has an asset value of $100,000, an exposure factor (EF) of 0.5, and an annualized rate of occurrence (ARO) of 2. What is the ALE?

An organization is required to comply with PCI DSS. Which of the following is a mandatory requirement for protecting cardholder data?

A security architect is designing a data classification scheme. Which TWO of the following are commonly used classification levels? (Select TWO.)

A security manager is reviewing the company's security policy hierarchy. Which of the following correctly orders these documents from highest to lowest authority?

A security team is selecting key risk indicators (KRIs) for the organization's cybersecurity program. Which of the following is an example of a KRI that provides a leading indicator of risk?

A company is adopting the NIST Risk Management Framework (RMF). Which step in the RMF involves selecting security controls based on the risk assessment?

A security analyst is evaluating security metrics for the security program. Which TWO of the following are considered key performance indicators (KPIs) for measuring the effectiveness of a security program?

A security manager is reviewing the organization's security policy hierarchy. Which of the following correctly orders these documents from highest to lowest level of authority?

A security architect is designing a data classification scheme. Which classification level should be used for data that, if disclosed, could cause serious damage to the organization's reputation or financial standing?

A healthcare organization is implementing a vendor risk management program. Which THREE of the following should be included in the vendor risk assessment process? (Select THREE.)

A security analyst is defining key risk indicators (KRIs) for the security program. Which TWO of the following are examples of KRIs? (Select TWO.)

An organization is implementing a privacy program in accordance with GDPR. Which TWO of the following are data subject rights under GDPR? (Select TWO.)

A company is conducting a third-party risk assessment of a cloud service provider. Which TWO of the following are appropriate sources of evidence for evaluating the provider's security controls? (Select TWO.)

An organization is developing a security policy hierarchy. Which TWO of the following correctly represent the typical order from highest to lowest level in a policy framework? (Select TWO.)

A security manager is updating the organization's security policy framework. The manager needs to create a document that specifies the mandatory use of multi-factor authentication for all administrative access to critical systems. Which type of document is most appropriate?

A multinational retailer wants to standardize how it communicates third-party assurance results to its regulators and business partners. Leadership asks the GRC team to adopt an internationally recognized framework that lets an independent assessor issue a formal opinion on the design and operating effectiveness of the retailer's controls over a defined period. Which framework should the team adopt?

A security architect is designing a third-party risk management program for a cloud-first organization. The organization uses multiple SaaS providers for critical business functions. The architect must ensure that vendor risk is continuously monitored and that contractual protections are in place. Which TWO of the following are the MOST effective controls to achieve these goals? (Choose two.)

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Governance, Risk, and Compliance sessions

Start a Governance, Risk, and Compliance only practice session

Every question in these sessions is drawn from the Governance, Risk, and Compliance domain — nothing else.

Related practice questions

Related CAS-005 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CAS-005 exam test about Governance, Risk, and Compliance?
You must map controls and artifacts to specific regulatory and policy requirements, then justify the best evidence. The single most important thing: know the policy hierarchy order and which document type is mandatory versus advisory, since ordering and evidence-selection questions depend on it.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Governance, Risk, and Compliance questions in a focused session?
Yes — the session launcher on this page draws every question from the Governance, Risk, and Compliance domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CAS-005 topics?
Use the topic links above to move to related areas, or go back to the CAS-005 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CAS-005 exam covers. They are not copied from any real exam or dump site.