Pass the HITRUST CSF Practitioner CCSFP Questions and answers with CertsForce

Viewing page 2 out of 5 pages
Viewing questions 11-20 out of questions
Questions # 11:

How large would the sample size be for a manual control with a population of 56 unique items?

Options:

A.

5


B.

8


C.

6


D.

25


E.

56


Expert Solution
Questions # 12:

An organization has identified a number of components needed for an assessment. These components cover systems/applications for customers in the states of Massachusetts and Nevada. Assuming management wants corresponding regulatory factors to be included in their assessment, which regulatory factors would apply?

(Select all that apply)

Options:

A.

State of Massachusetts Data Protection Act


B.

CMS Minimum Security Requirements (High)


C.

State of Nevada Security of Personal Information Requirements


D.

Texas Health and Safety Code


E.

Subject to De-ID Requirements


Expert Solution
Questions # 13:

On an r2 assessment, the decision to require a CAP for a deficiency (gap) is determined at the Control Reference level and the Requirement Statement level.

Options:

A.

True


B.

False


Expert Solution
Questions # 14:

An Interim Assessment must be completed in how many months after r2 certification is achieved? [0023]

Options:

A.

6 months


B.

12 months


C.

18 months


D.

24 months


Expert Solution
Questions # 15:

Which assessment type is the most tailorable to an organization's risk profile?

Options:

A.

i1


B.

r2


C.

Interim


D.

e1


E.

Bridge


Expert Solution
Questions # 16:

When performing r2 assessments, any added compliance factors should be considered before marking a requirement statement "N/A".

Options:

A.

True


B.

False


Expert Solution
Questions # 17:

Which type of assessments must be performed to be eligible for certification? [0158]

Options:

A.

e1 Readiness Assessment


B.

an e1, i1 or an r2 Validated Assessment


C.

Customized Assessment


D.

Targeted Assessment


Expert Solution
Questions # 18:

If the client and the External Assessor disagree on assessment scope, HITRUST will determine the final scope. [0027]

Options:

A.

True


B.

False


Expert Solution
Questions # 19:

Pre-populated default maturity level scores cannot be changed across an assessment object.

Options:

A.

True


B.

False


Expert Solution
Questions # 20:

For the External Assessor QA process, the individual who acts as the Quality Assurance Reviewer for an assessor organization can also be the Engagement Executive.

Options:

A.

True


B.

False


Expert Solution
Viewing page 2 out of 5 pages
Viewing questions 11-20 out of questions