Courseiva
easyMultiple SelectObjective-mapped

CAS-004 Practice Question: Which TWO of the following are examples of…

Which TWO of the following are examples of compensating controls for a security control deficiency?

⚠ Common exam trap

CompTIA often tests the distinction between compensating controls and risk acceptance or risk transfer, where candidates mistakenly select 'accepting the risk' or 'purchasing cyber insurance' as valid compensating controls because they confuse risk treatment strategies with alternative security measures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Increasing logging and monitoring.

Increasing logging and monitoring (A) is a compensating control because it does not prevent the security deficiency itself but instead provides enhanced visibility and detection capabilities to identify and respond to incidents that exploit the deficiency. For example, if a legacy system cannot support multifactor authentication, enabling verbose logging of authentication attempts and real-time alerting via a SIEM (e.g., Splunk or ELK) allows the security team to detect brute-force attacks or unauthorized access attempts, thereby compensating for the missing control. This aligns with the NIST SP 800-53 definition of compensating controls as alternative measures that reduce risk to an acceptable level without directly fixing the underlying flaw.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Increasing logging and monitoring.

    Why this is correct

    Enhanced monitoring can detect unauthorized activities that a deficient control might not prevent.

  • Implementing stricter access controls.

    Why this is correct

    Stricter access controls can compensate for weaknesses in other areas.

  • Accepting the risk.

    Why it's wrong here

    Risk acceptance is a risk treatment option, not a control.

  • Purchasing cyber insurance.

    Why it's wrong here

    Insurance transfers risk, but does not provide a security control.

  • Re-architecting the network.

    Why it's wrong here

    Re-architecting is a corrective control, but not necessarily compensating for a specific deficiency.

About these practice questions

This CAS-005 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.