
CompTIASecurityX (CASP+)
Domain 1Objective 5
GRC Tools CAS-005 Practice Questions (Page 2)
Part of the Governance, risk, and compliance domain, which accounts for 20% of the CAS-005 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~13–22 in this domain), expect 1–2 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)
32questions here
7free pages
7concepts
20%of the exam
Questions 6–10
- 6
Which type of tool is specifically designed to track an organization's compliance status against multiple regulatory requirements?
Select an answer first - 7
What is the primary purpose of generating compliance reports for management?
Select an answer first - 8
What is the primary benefit of creating a control mapping matrix that links organizational processes to multiple regulatory frameworks?
Select an answer first - 9
A large e-commerce company must ensure that its payment processing systems remain PCI DSS compliant. The security team wants to automate the collection of evidence for required controls, such as firewall reviews and vulnerability scans. Which automation approach is most effective?
Select an answer first - 10
Why is continuous monitoring important for maintaining compliance?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CAS-005” is a trademark of its owner, used for identification only.