nerdexam
CompTIA

CAS-005 · Question #279

During a periodic internal audit, a company identifies a few new, critical security controls that are missing. The company has a mature risk management program in place, and the following requirements

Sign in or unlock CAS-005 to reveal the answer and full explanation for question #279. The question stem and answer options stay visible for context.

Submitted by helene.fr· Mar 6, 2026Governance, Risk, and Compliance

Question

During a periodic internal audit, a company identifies a few new, critical security controls that are missing. The company has a mature risk management program in place, and the following requirements must be met:

  • The stakeholders should be able to see all the risks.
  • The risks need to have someone accountable for them.

Which of the following actions should the GRC analyst take next?

Options

  • AAdd the risk to the risk register and assign the owner and severity.
  • BChange the risk appetite and assign an owner to it.
  • CMitigate the risk and change the status to accepted.
  • DReview the risk to decide whether to accept or reject it.

Unlock CAS-005 to see the answer

You've previewed enough free CAS-005 questions. Unlock CAS-005 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Full CAS-005 Practice