nerdexam
CompTIA

CAS-005 · Question #434

The information security manager at a 24-hour manufacturing facility is reviewing a contract for potential risks to the organization. The contract pertains to the support of printers and…

The correct answer is B. The lack of an NDA with the company that supports its devices. When external technicians are granted access to printers and multifunction devices that buffer or store sensitive documents, there’s a real risk they could view, copy, or exfiltrate data. Without a non-disclosure agreement in place, there is no contractual obligation preventing…

Submitted by priya_blr· Mar 6, 2026Governance, Risk, and Compliance

Question

The information security manager at a 24-hour manufacturing facility is reviewing a contract for potential risks to the organization. The contract pertains to the support of printers and multifunction devices during non-standard business hours. Which of the following will the security manager most likely identify as a risk?

Options

  • APrint configurations settings for locked print jobs
  • BThe lack of an NDA with the company that supports its devices
  • CThe lack of an MSA to govern other services provided by the service provider
  • DThe lack of chain of custody for devices prior to deployment at the company

How the community answered

(52 responses)
  • A
    2% (1)
  • B
    77% (40)
  • C
    13% (7)
  • D
    8% (4)

Explanation

When external technicians are granted access to printers and multifunction devices that buffer or store sensitive documents, there’s a real risk they could view, copy, or exfiltrate data. Without a non-disclosure agreement in place, there is no contractual obligation preventing them from disclosing or misusing any confidential information they encounter. This gap presents a clear confidentiality risk that the information security manager should remediate.

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice