nerdexam
CompTIA

CAS-005 · Question #511

An organization recently hired a third party to audit the information security controls present in the environment. After reviewing the audit findings, the Chief Information Security Officer (CISO)…

The correct answer is C. The previous network architecture contained controls that could be easily bypassed. The most likely reason for approving additional budget is that the audit revealed the existing network security controls could be easily bypassed. This justifies investing in a stronger, defense- in-depth network security strategy.

Submitted by haru.x· Mar 6, 2026Governance, Risk, and Compliance

Question

An organization recently hired a third party to audit the information security controls present in the environment. After reviewing the audit findings, the Chief Information Security Officer (CISO) approved the budget for an in-depth defense strategy for network security. Which of the following is the most likely reason the CISO approved the additional budget?

Options

  • AOther departments had unused budget, which was transferred to IT security.
  • BPotential customers increasingly asked for security compliance reports.
  • CThe previous network architecture contained controls that could be easily bypassed.
  • DThe auditor reported a low score on the PCI OSS self-assessment questionnaire.

How the community answered

(26 responses)
  • A
    12% (3)
  • B
    4% (1)
  • C
    77% (20)
  • D
    8% (2)

Explanation

The most likely reason for approving additional budget is that the audit revealed the existing network security controls could be easily bypassed. This justifies investing in a stronger, defense- in-depth network security strategy.

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice