CompTIA SecurityX (CASP+) CAS-
005 Certification Exam Practice
Question Bank Advanced-Level
Practice Questions for Security
Architects, Senior Security
Engineers, and Enterprise
Security Practitioners a well
detailed one written
and graded A+ upgraded
Domain 1: Governance, Risk, and Compliance (GRC) – 20% of Exam
, 2
Question 1
A multinational organization is implementing a new third-party risk management program.
Which of the following represents the MOST effective approach for continuous vendor risk
assessment?
A) Conduct annual on-site audits for all third-party vendors
B) Implement continuous monitoring using automated GRC tools with real-time threat
intelligence feeds
C) Require all vendors to complete a self-assessment questionnaire once per quarter
D) Rely on vendor-provided SOC 2 Type II reports exclusively
-” detailed answer 100 % correct :-”B
Rationale: Continuous monitoring using automated GRC tools with real-time threat intelligence
feeds provides ongoing visibility into vendor security posture rather than point-in-time
assessments. Annual audits (A) are insufficient for detecting emerging risks. Self-assessments (C)
are subjective and lack verification. SOC 2 reports (D) are valuable but represent only a snapshot
and should complement, not replace, continuous monitoring.
Question 2
A security architect is developing a threat model for a new cloud-native application. Which
threat modeling methodology is MOST appropriate for identifying trust boundary violations in a
microservices architecture?
A) PASTA
B) STRIDE
C) OCTAVE
D) TRIKE
-” detailed answer 100 % correct :-”B
Rationale: STRIDE (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service,
Elevation of Privilege) is specifically designed to identify threats across trust boundaries, making
it ideal for microservices architectures where numerous trust boundaries exist between
services. PASTA (A) is risk-centric and more suited for business-driven threat modeling. OCTAVE
(C) is operational-focused. TRIKE (D) uses a risk-based approach with threat trees.
, 3
Question 3
An organization must comply with both GDPR and CCPA requirements for data subject access
requests (DSARs). Which data governance control BEST enables efficient DSAR fulfillment?
A) Implementing data loss prevention (DLP) at network egress points
B) Maintaining an accurate data inventory with classification and data lineage mapping
C) Encrypting all personal data at rest using AES-256
D) Implementing role-based access control (RBAC) for data stores
-” detailed answer 100 % correct :-”B
Rationale: An accurate data inventory with classification and lineage mapping enables
organizations to locate, retrieve, and provide personal data efficiently in response to DSARs. DLP
(A) focuses on preventing data exfiltration. Encryption (C) protects data confidentiality but
doesn't aid in locating data. RBAC (D) controls access but doesn't provide the discovery
capabilities needed for DSAR compliance.
Question 4
A security program manager is creating a RACI matrix for incident response activities. In a RACI
matrix, what does the "A" represent?
A) Accountable
B) Assigned
C) Approved
D) Assessed
-” detailed answer 100 % correct :-”A
Rationale: In a RACI matrix, "A" represents Accountable—the person ultimately responsible for
ensuring the activity is completed correctly. "R" is Responsible (the doer), "C" is Consulted
(provides input), and "I" is Informed (kept updated).
Question 5
Which security framework is MOST appropriate for an organization seeking to align its IT service
management with business objectives while maintaining strong security governance?
A) NIST CSF
B) COBIT
, 4
C) ISO/IEC 27001
D) ITIL
-” detailed answer 100 % correct :-”B
Rationale: COBIT (Control Objectives for Information and Related Technologies) is specifically
designed to align IT governance with business objectives and includes comprehensive security
governance components. NIST CSF (A) is focused on cybersecurity risk management. ISO/IEC
27001 (C) is an information security management standard. ITIL (D) focuses on IT service
management rather than security governance.
Question 6
A financial institution is required to comply with PCI DSS for its payment processing systems.
Which requirement mandates that cardholder data environments maintain network
segmentation?
A) Requirement 1
B) Requirement 3
C) Requirement 6
D) Requirement 10
-” detailed answer 100 % correct :-”A
Rationale: PCI DSS Requirement 1 specifically addresses installing and maintaining network
security controls, including network segmentation to isolate the cardholder data environment
(CDE) from other networks. Requirement 3 (B) covers protecting stored cardholder data.
Requirement 6 (C) addresses secure development. Requirement 10 (D) covers logging and
monitoring.
Question 7
A security analyst is evaluating the risk of a new vendor relationship. The vendor will have
access to sensitive customer PII. Which risk assessment approach BEST quantifies the potential
financial impact of a data breach involving this vendor?
A) Qualitative risk assessment using a high/medium/low scale
B) Quantitative risk assessment calculating single loss expectancy (SLE) and annualized loss
expectancy (ALE)