
CompTIASecurityX (CASP+)
Domain 1Objective 10
Compliance Strategies CAS-005 Practice Questions (Page 5)
Part of the Governance, risk, and compliance domain, which accounts for 20% of the CAS-005 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~13–22 in this domain), expect 1–2 from this objective — we provide 25 practice questions to prepare you well beyond it. (estimate)
25questions here
5free pages
5concepts
20%of the exam
Questions 21–25
- 21
A large e-commerce company is preparing for its annual PCI DSS assessment. The company has a complex network with multiple business units, and the cardholder data environment (CDE) is not clearly defined. The security team is concerned about the scope of the assessment. Which of the following is the most effective way to reduce the PCI DSS scope?
Select an answer first - 22
A company is implementing an ISMS and wants to use a standard that provides a comprehensive set of security controls that can be selected based on the organization's risk assessment. Which of the following standards is most appropriate?
Select an answer first - 23
Which of the following is a key requirement of ISO/IEC 27001 for maintaining an ISMS?
Select an answer first - 24
Which of the following best describes the primary purpose of the PCI DSS?
Select an answer first - 25
A financial services company is expanding its operations to accept credit card payments. The compliance officer is concerned about meeting both PCI DSS and industry-specific regulations such as GLBA. Which of the following is the most effective approach to align security practices with these requirements?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CAS-005
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CAS-005” is a trademark of its owner, used for identification only.