CompTIA SecurityX (CAS-005)
Bridge Certification – Advanced
Practice Question Bank V2.0 150
Multiple-Choice Questions |
Advanced/Hard Difficulty | For
Experienced Security
Professionals a well detailed one
written and graded
A+ upgraded
Domain 1: Governance, Risk, and Compliance (GRC)
Question 1
A global organization with operations in 15 countries is implementing a unified data
, 2
classification framework. The framework must align with GDPR, CCPA, PIPEDA, and China's PIPL.
Which approach best ensures compliance across jurisdictions while maintaining operational
efficiency?
A) Apply a single classification scheme based on the strictest regulatory requirement globally
B) Implement separate classification schemes for each jurisdiction with independent
management
C) Create a federated classification framework with core categories and jurisdictional overlays
D) Defer classification decisions to individual business units
-” detailed answer 100 % correct :-”C
Rationale: A federated framework with core categories and jurisdictional overlays provides
consistency while accommodating regional requirements. Option A creates unnecessary
overhead; Option B lacks consistency; Option D abdicates governance responsibility.
Question 2
An organization is preparing for a SOC 2 Type II audit. Which of the following is the primary
focus of this audit?
A) Financial controls and reporting accuracy
B) Operational effectiveness of security controls over a period of time
C) Compliance with international privacy regulations
D) Physical security of data center facilities
-” detailed answer 100 % correct :-”B
Rationale: SOC 2 Type II evaluates the operational effectiveness of security controls over a
period of time (typically 6-12 months). Type I is a point-in-time assessment. Financial controls
are SOC 1; privacy regulations are not the primary focus.
Question 3
A security architect is implementing NIST SP 800-53 controls for a federal agency. Which control
family addresses incident response planning and procedures?
A) AC (Access Control)
B) IR (Incident Response)
C) AU (Audit and Accountability)
D) SI (System and Information Integrity)
, 3
-” detailed answer 100 % correct :-”B
Rationale: IR (Incident Response) is the NIST SP 800-53 control family that addresses incident
response planning, training, testing, and handling. AC covers access control; AU covers audit; SI
covers integrity.
Question 4
Which of the following is the most significant challenge when implementing the NIST
Cybersecurity Framework (CSF) 2.0 in a global organization?
A) The framework's complexity and number of subcategories
B) Aligning the framework with existing regulatory requirements across multiple jurisdictions
C) The cost of implementing the framework
D) The lack of industry acceptance of the framework
-” detailed answer 100 % correct :-”B
Rationale: Aligning CSF 2.0 with multiple jurisdictional regulatory requirements is the most
significant challenge for global organizations. The framework is widely accepted; cost and
complexity are manageable with proper planning.
Question 5
An organization is implementing ISO 27001:2022. Which of the following is a new control added
in the 2022 version compared to the 2013 version?
A) Access control policy
B) Information security policy
C) Threat intelligence
D) Asset management
-” detailed answer 100 % correct :-”C
Rationale: Threat intelligence (Control 6.7) was added in ISO 27001:2022. Access control policy,
information security policy, and asset management were present in the 2013 version.
Question 6
A security architect is developing a business continuity plan (BCP) for a critical financial
application. Which of the following is the most important consideration when determining the
BCP strategy?
, 4
A) The cost of the BCP implementation
B) The alignment of RTO and RPO with business requirements and stakeholder expectations
C) The number of employees involved in the BCP
D) The location of the backup data center
-” detailed answer 100 % correct :-”B
Rationale: Alignment of RTO and RPO with business requirements is the most critical BCP
consideration. Cost, employee count, and location are secondary to meeting business needs.
Question 7
Which of the following is the primary purpose of a risk register in enterprise risk management?
A) To assign blame for security incidents
B) To document identified risks, their assessments, and mitigation status
C) To replace the need for risk assessments
D) To comply with insurance requirements
-” detailed answer 100 % correct :-”B
Rationale: A risk register documents identified risks, assessments, and mitigation status. It does
not assign blame, replace assessments, or serve primarily for insurance compliance.
Question 8
A multinational organization is implementing cross-border data transfer mechanisms to comply
with GDPR. Which of the following is a valid mechanism for transferring personal data from the
EU to a third country?
A) Standard Contractual Clauses (SCCs) with supplementary measures
B) Implicit consent from data subjects
C) Self-certification by the data recipient
D) Verbal agreement between the parties
-” detailed answer 100 % correct :-”A
Rationale: SCCs with supplementary measures are a valid GDPR transfer mechanism. Implicit
consent is insufficient; self-certification is not a valid mechanism; verbal agreements lack
enforceability.