CompTIA
CAS-005 · Question #279
During a periodic internal audit, a company identifies a few new, critical security controls that are missing. The company has a mature risk management program in place, and the following requirements
Sign in or unlock CAS-005 to reveal the answer and full explanation for question #279. The question stem and answer options stay visible for context.
Submitted by helene.fr· Mar 6, 2026Governance, Risk, and Compliance
Question
During a periodic internal audit, a company identifies a few new, critical security controls that are missing. The company has a mature risk management program in place, and the following requirements must be met:
- The stakeholders should be able to see all the risks.
- The risks need to have someone accountable for them.
Which of the following actions should the GRC analyst take next?
Options
- AAdd the risk to the risk register and assign the owner and severity.
- BChange the risk appetite and assign an owner to it.
- CMitigate the risk and change the status to accepted.
- DReview the risk to decide whether to accept or reject it.
Unlock CAS-005 to see the answer
You've previewed enough free CAS-005 questions. Unlock CAS-005 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.