Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CompTIA logo

CompTIASecurityX (CASP+)

Domain 1Objective 5

GRC Tools CAS-005 Practice Questions (Page 4)

Part of the Governance, risk, and compliance domain, which accounts for 20% of the CAS-005 exam. CompTIA does not publish an official question count, but from its 165-minute exam (~65–110 total, ~13–22 in this domain), expect 1–2 from this objective — we provide 32 practice questions to prepare you well beyond it. (estimate)

32questions here
7free pages
7concepts
20%of the exam

Questions 16–20

  1. 16expert · hard

    A government agency must collect and analyze data to demonstrate compliance with federal security regulations. The agency has a GRC tool that can collect data from various sources, but the data is often incomplete or inconsistent. The agency needs to ensure the data is reliable for compliance reporting. What is the most important step to improve data quality?

    Select an answer first
  2. 17foundation · easy

    Which data collection technique is most appropriate for verifying that security patches are applied to all systems?

    Select an answer first
  3. 18expert · hard

    A financial institution is required to continuously monitor its critical systems for compliance with PCI DSS. The security team has implemented a SIEM tool that collects logs from all systems. However, the SIEM generates a high volume of alerts, many of which are false positives. The team is overwhelmed and may miss genuine compliance issues. What is the best way to improve the effectiveness of continuous monitoring?

    Select an answer first
  4. 19application · medium

    A utility company must collect data from smart meters to prove compliance with energy consumption regulations. The data must be collected at regular intervals and analyzed for anomalies. Which data collection method is most appropriate?

    Select an answer first
  5. 20application · medium

    A healthcare organization must demonstrate compliance with HIPAA and ISO 27001 to external auditors. The compliance team manually maps each control to the corresponding framework requirement, but the mapping is inconsistent and outdated. Which approach best improves the accuracy and maintainability of the control-to-framework mapping?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CompTIA. “CAS-005” is a trademark of its owner, used for identification only.