
CompTIASecurityX (CASP+)
Domain 1Objective 10
Compliance Strategies CAS-005 Practice Questions (Page 2)
Part of the Governance, risk, and compliance domain, which accounts for 20% of the CAS-005 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~13–22 in this domain), expect 1–2 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
5concepts
20%of the exam
Questions 6–10
- 6
An organization is implementing an ISMS and has decided to use ISO/IEC 27001. The organization has a mature security program but lacks a formal risk management process. Which of the following is the most appropriate first step in implementing the ISMS?
Select an answer first - 7
A company has implemented an ISMS aligned with ISO/IEC 27001. During an internal audit, the auditor notes that the company has not defined a process for regularly reviewing and updating the risk treatment plan. Which ISO/IEC 27001 requirement is being violated?
Select an answer first - 8
A global financial services company processes credit card payments and is subject to both PCI DSS and local data protection regulations. The company is considering using a cloud provider to host its payment processing system. Which of the following is the most important consideration for maintaining compliance?
Select an answer first - 9
Which of the following is a key requirement of PCI DSS for maintaining a secure network?
Select an answer first - 10
A company is implementing PCI DSS controls and needs to ensure that only authorized personnel can access cardholder data. Which of the following is a PCI DSS requirement that directly addresses this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CAS-005” is a trademark of its owner, used for identification only.