Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CompTIA CAS-005 Exam - Topic 4 Question 34 Discussion

A global organization is reviewing potential vendors to outsource a critical payroll function. Each vendor's plan includes using local resources in multiple regions to ensure compliance with all regulations. The organization's Chief Information Security Officer is conducting a risk assessment on the potential outsourcing vendors' subprocessors. Which of the following best explains the need for this risk assessment?
C) The responsibility of protecting PII remains with the organization.
A) Risk mitigations must be more comprehensive than the existing payroll provider.
B) Due care must be exercised during all procurement activities.
D) Specific regulatory requirements must be met in each jurisdiction.

CompTIA CAS-005 Exam - Topic 4 Question 34 Discussion

Actual exam question for CompTIA's CAS-005 exam
Question #: 34
Topic #: 4
[All CAS-005 Questions]

A global organization is reviewing potential vendors to outsource a critical payroll function. Each vendor's plan includes using local resources in multiple regions to ensure compliance with all regulations. The organization's Chief Information Security Officer is conducting a risk assessment on the potential outsourcing vendors' subprocessors. Which of the following best explains the need for this risk assessment?

Show Suggested Answer Hide Answer
Suggested Answer: C

Per SecurityX CAS-005 GRC principles, outsourcing a function does not transfer accountability for protecting personally identifiable information (PII). While subprocessors handle data, the originating organization remains responsible under most data protection laws and frameworks (e.g., GDPR, CCPA).

Due care in procurement (option B) is important, but it is a supporting concept, not the primary driver in this context.

Jurisdictional compliance (option D) is a requirement, but the underlying reason for risk assessment is that accountability for PII protection remains with the organization.


Contribute your Thoughts:

0/2000 characters

Currently there are no comments in this discussion, be the first to comment!


Save Cancel