CAS-004 Governance, Risk, and Compliance Practice Question
Which of the following is a key difference between compliance and security?
⚠ Common exam trap
CAS-005 often tests the misconception that compliance and security are equivalent or that one is strictly a subset of the other, when in reality compliance is a minimum baseline and security is the broader, continuous risk-reduction discipline.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Compliance typically represents a minimum bar, while security seeks best practice
Compliance frameworks (PCI DSS, HIPAA, ISO 27001) define a baseline set of controls an organization must satisfy to meet regulatory or contractual obligations — they establish a floor, not a ceiling. Security, by contrast, is an ongoing risk-management discipline that aims to reduce risk to an acceptable level using best practices, defense in depth, and continuous improvement. An organization can be fully compliant yet still be insecure because compliance scopes are narrow and point-in-time, whereas security must address the full threat landscape.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Compliance is voluntary, security is mandatory
Why it's wrong here
Compliance is frequently mandatory, imposed by regulators such as GDPR or HIPAA, while security is a voluntary organisational choice to manage risk. This option is tempting because some standards are voluntary, but the defining difference is that compliance targets external requirements, whereas security targets actual risk reduction.
- ✗
Compliance is proactive, security is reactive
Why it's wrong here
The relationship is inverted: compliance is typically reactive, responding to audits and regulatory deadlines, while security is proactive, hunting threats before incidents. This option is tempting because security teams do react to incidents, but that describes response, not the compliance-security distinction itself.
- ✗
Security only applies to technical controls, compliance to administrative
Why it's wrong here
Both compliance and security span technical and administrative controls; frameworks such as ISO 27001 and PCI DSS mandate technical measures, while security programmes include policies and training. This split is tempting because compliance often leans on documentation, but the real axis is obligation versus risk reduction.
- ✓
Compliance typically represents a minimum bar, while security seeks best practice
Why this is correct
Compliance maps to mandated frameworks and regulations, so meeting them satisfies an external minimum threshold. Security pursues defence against evolving threats beyond that floor, adopting controls and practices that exceed regulatory requirements because attackers are not bound by the same baseline.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.