Pass the HITRUST CSF Practitioner CCSFP Questions and answers with CertsForce

Viewing page 3 out of 5 pages
Viewing questions 21-30 out of questions
Questions # 21:

Which of the following does HITRUST certify?

Options:

A.

Products


B.

People


C.

Implemented Systems


D.

Facilities


E.

All of the above


Expert Solution
Questions # 22:

It is possible to test only privacy-related requirements to obtain a HITRUST privacy certification.

Options:

A.

True


B.

False


Expert Solution
Questions # 23:

The concept of HITRUST CSF risk levels was adapted from what security standard?

Options:

A.

ISO/IEC 27001


B.

ISO/IEC 27002


C.

COBIT 5


D.

NIST 800-53


Expert Solution
Questions # 24:

To place reliance on a point-in-time assessment report, the issue date must be within two years from the assessment fieldwork start date. [0078]

Options:

A.

True


B.

False


Expert Solution
Questions # 25:

Which of the following must be confirmed before inheriting requirement scores?

Options:

A.

The requirement Cross Version IDs (CVIDs) must match


B.

The requirement must be partially or fully inheritable


C.

The provider must have published the assessment for inheritance


D.

All of the above


Expert Solution
Questions # 26:

After completion of a Validated Assessment, all remediated CAPs can be removed from the final report.

Options:

A.

True


B.

False


Expert Solution
Questions # 27:

A hospital system based in both Texas and Massachusetts processes credit card data within its scoped environment. Management has asked that all relevant regulatory factors be included in the r2 assessment. Which of the following regulatory requirements should be selected? (Select all that apply) [0013]

Options:

A.

Texas Health and Safety Code


B.

State of Massachusetts Data Protection Act


C.

Singapore Personal Data Act


D.

State of Nevada Security of Personal Information Requirements


E.

PCI-DSS


Expert Solution
Questions # 28:

A validated assessment is only available to organizations after performing a readiness assessment. [0020]

Options:

A.

True


B.

False


Expert Solution
Questions # 29:

When partially inheriting a requirement statement score from an external cloud service provider, the weighting applied to the score is determined primarily by the assessed entity and the service provider. [0190]

Options:

A.

True


B.

False


Expert Solution
Questions # 30:

When an implementation gap is remediated, what is the minimum number of days the control must operate before retesting? [0130]

Options:

A.

Immediately


B.

30 Days


C.

60 Days


D.

90 Days


Expert Solution
Viewing page 3 out of 5 pages
Viewing questions 21-30 out of questions