Courseiva
mediumMultiple Select

CAS-004 Practice Question: Which TWO of the following are essential elements…

Which TWO of the following are essential elements of an effective data governance framework?

⚠ Common exam trap

CAS-005 often tests the confusion between governance elements (classification, stewardship, policy) and technical controls (encryption, breach notification) — candidates must distinguish accountability structures from implementation controls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Data classification policies and procedures

Data classification policies and procedures (A) are essential because they define how data is categorized by sensitivity and value, which drives the controls, handling rules, and access decisions that the rest of the governance framework depends on. Assignment of data stewardship roles (C) is equally essential because governance requires clearly designated owners and stewards who are accountable for data quality, protection, and lifecycle management across business and IT domains. Together, classification and stewardship form the core of an effective framework by establishing both what must be protected and who is responsible for it. The other options do not belong: mandatory data localization (B) is a jurisdiction-specific regulatory constraint rather than a universal governance element, an automated breach notification system (D) is an incident-response control, and full-disk encryption on all endpoints (E) is a technical safeguard rather than a governance essential.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Data classification policies and procedures

    Why this is correct

    Data classification policies and procedures satisfy the framework's need to categorise information by sensitivity, enabling controls such as encryption, access restrictions and retention to be applied proportionately. Without classification, Microsoft Entra ID access policies and DLP rules cannot distinguish confidential data from public, so governance decisions lack the risk context they require.

  • ✗

    Mandatory data localization requirements

    Why it's wrong here

    Mandatory data localisation constrains where data may reside; governance frameworks define decision rights, stewardship and classification regardless of jurisdiction. It is tempting because residency rules are common in regulated sectors, and it would be correct where legislation demands data remain within national borders.

  • ✓

    Assignment of data stewardship roles

    Why this is correct

    Assigning data stewardship roles establishes named accountability for data quality, classification and policy adherence across business units. This satisfies the framework's need for ownership beyond central IT, ensuring decisions about access, retention and usage are enforced locally. Stewardship complements executive sponsorship by translating governance policy into operational practise.

  • ✗

    Automated breach notification system

    Why it's wrong here

    Automated breach notification is an incident-response capability triggered after a compromise; governance frameworks instead specify accountability, classification and lifecycle rules. It is tempting because notification duties appear in privacy regulation, and it would be correct for a question about meeting regulatory breach-reporting obligations.

  • ✗

    Implementation of full-disk encryption on all endpoints

    Why it's wrong here

    Full-disk encryption protects data at rest on endpoints; it defines no ownership, classification, retention or access-control policy, so it cannot constitute a governance element. It is tempting because encryption is a control that governance frameworks mandate, and it would be the right answer to a question about endpoint data-at-rest protection.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.