Domain 5: Governance — Don't Skip This
Domain 5 is a meaningful chunk of the exam. Most students skip it because it's "boring" — then lose a swathe of questions they could have gotten right with two days of focused study.
> Domain weightings are set by CompTIA and change with each exam version — confirm the current objectives at comptia.org.
Why People Skip It
It's not technical. No firewalls, no attacks, no labs. It's policies, risk management, compliance, and governance. But it's a sizable share of your score — a big block of questions. Skipping it is like leaving marks on the table.
Key Topics
Risk Management
- Risk assessment: qualitative vs. quantitative
- Risk responses: accept, avoid, transfer, mitigate
- Risk register and risk matrix
- ALE = SLE × ARO (know this formula)
Compliance and Regulations
- GDPR, HIPAA, PCI-DSS, SOX — know what each regulates
- Data sovereignty and privacy considerations
- Legal vs. regulatory vs. contractual obligations
Policies and Frameworks
- Acceptable use policy, password policy, incident response policy
- NIST CSF, ISO 27001, CIS Controls — know what each framework covers
- Change management and change advisory boards
Security Awareness
- Phishing simulations and training programs
- Insider threat programs
- User behaviour analytics
Study Tips
Make a comparison table for the frameworks and regulations — name, what it covers, who it applies to. For risk management, practice the ALE calculation: Annual Loss Expectancy = Single Loss Expectancy × Annual Rate of Occurrence.