Big 11.11 Sale - Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70dumps

CCSFP Questions and Answers

Question # 6

Where is an Offline Assessment initiated?

A.

From the assessment object

B.

From the MyCSF landing page

C.

Via the HITRUST Support Desk

D.

From the HITRUST Analytics Page

Full Access
Question # 7

Vulnerability testing should never be performed on client systems by an external assessor.

A.

True

B.

False

Full Access
Question # 8

Documents placed in the document repository can be accessed across multiple assessment objects. [0113]

A.

False

B.

True

Full Access
Question # 9

Control Reference scores are averaged to determine Domain scores.

A.

True

B.

False

Full Access
Question # 10

After completion of a Validated Assessment, all remediated CAPs can be removed from the final report.

A.

True

B.

False

Full Access
Question # 11

What can the Illustrative Procedures be used for? (Select all that apply)

A.

Consistency in testing between the Assessed Entity and the External Assessor

B.

Implementation testing guidance

C.

Optional procedures

D.

The basis for an assessor test plan

Full Access
Question # 12

How large would the sample size be for a manual control with a population of 56 unique items?

A.

5

B.

8

C.

6

D.

25

E.

56

Full Access
Question # 13

An assessed entity is required to comply with six regulatory factors. Must the entity include all six regulatory factors in the scope of their assessment? [0088]

A.

Yes

B.

No

Full Access
Question # 14

Gaps with required CAPs must be remediated within six months.

A.

True

B.

False

Full Access
Question # 15

When an implementation gap is remediated, what is the minimum number of days the control must operate before retesting? [0130]

A.

Immediately

B.

30 Days

C.

60 Days

D.

90 Days

Full Access
Question # 16

For an r2 assessment, what is the minimum number of days an organization should wait before a new or updated Policy and/or Procedure can be reconsidered for testing?

A.

Immediately

B.

30 Days

C.

60 Days

D.

90 Days

Full Access
Question # 17

Does the HITRUST CSF encompass all requirements from the authoritative sources mapped to an assessment object?

A.

Yes

B.

No

Full Access
Question # 18

A readiness assessment report provides the highest level of assurance. [0019]

A.

True

B.

False

Full Access
Question # 19

Requirement Statement scores are averaged to determine Control Reference and Domain scores.

A.

True

B.

False

Full Access
Question # 20

When are HITRUST Assurance Advisories (HAA) posted? [0167]

A.

There is no formal schedule for issuing Assurance Advisories

B.

Annually

C.

Quarterly

D.

Monthly

Full Access
Question # 21

When generating a test plan the assessor must only use the Illustrative Procedures provided within the tool. [0054]

A.

True

B.

False

Full Access
Question # 22

Control Objectives are a statement of the desired result or purpose to be achieved by implementing control procedures into a particular process.

A.

True

B.

False

Full Access
Question # 23

How would you score implemented coverage for one system if two of four evaluative elements were in place?

A.

50

B.

25

C.

75

D.

0

Full Access
Question # 24

A validated assessment is only available to organizations after performing a readiness assessment. [0020]

A.

True

B.

False

Full Access
Question # 25

Should a company always select the most current version of the CSF framework? [0163]

A.

No, the tool will select the version

B.

Yes

C.

No, the assessor should select the version

D.

No, a company can select any active version of the framework that best fits their needs

Full Access
Question # 26

Which of the following are appropriate types of inheritance within MyCSF? (Select all that apply) [0061]

A.

Cross Organizational

B.

Bi-lateral

C.

Internal

D.

External

Full Access
Question # 27

If most of the evaluative elements associated with a requirement statement do not apply to an assessed entity’s control environment, the requirement statement can be marked "N/A".

A.

True

B.

False

Full Access
Question # 28

Which assessment type allows users to select any HITRUST authoritative source?

A.

Readiness Assessment

B.

Validated Assessment

C.

r2 Assessment

D.

e1 Assessment

E.

None of the above

Full Access
Question # 29

Using only the information from the chart and question below, please answer:

This assessment will be able to achieve certification. [0192]

A.

True

B.

False

Full Access
Question # 30

In which assessment(s) are you allowed to "carve out" third-party controls as not applicable? (Select all that apply) [0116]

A.

i1

B.

r2

C.

e1

D.

Interim

Full Access
Question # 31

On an r2 assessment, HITRUST requires evidence to be linked to all maturity levels that score above 25% for Policy and Procedure, and over 0% for Implementation, Measured, and Managed.

A.

True

B.

False

Full Access
Question # 32

If an organization requires an assessment with the highest level of assurance, which assessment type should they choose?

A.

i1 Validated

B.

i1 Readiness

C.

r2 Validated

D.

e1 Validated with RDS enabled

Full Access
Question # 33

When creating different scenarios for an assessment where the scope has yet to be fully defined, which option allows you to see the difference in Requirement Statement counts without updating the object itself? [0181]

A.

Applicable Controls

B.

Preview Changes

C.

Preview Profile

D.

Create Assessment

Full Access
Question # 34

A control that is not documented cannot be measured. [0126]

A.

True

B.

False

Full Access
Question # 35

When considering third-party reports for reliance, what must be included in the report? (Select all that apply)

A.

Description of scope

B.

Completed remediation for testing exceptions

C.

List of procedures performed

D.

Executive summary

E.

Conclusions reached for each test

Full Access
Question # 36

An e1, i1, or r2 validated assessment must be performed by an approved HITRUST assessor.

A.

True

B.

False

Full Access
Question # 37

An organization has identified a number of components needed for an assessment. These components cover systems/applications for customers in the states of Massachusetts and Nevada. Assuming management wants corresponding regulatory factors to be included in their assessment, which regulatory factors would apply?

(Select all that apply)

A.

State of Massachusetts Data Protection Act

B.

CMS Minimum Security Requirements (High)

C.

State of Nevada Security of Personal Information Requirements

D.

Texas Health and Safety Code

E.

Subject to De-ID Requirements

Full Access
Question # 38

Under which version of the CSF did the framework go industry agnostic and HIPAA became its own regulatory factor?

A.

v9.2

B.

v9.3

C.

v9.0

D.

v9.4

E.

v9.1

Full Access
Question # 39

When creating a new r2 assessment you are required to use the latest version of the HITRUST CSF.

A.

True

B.

False

Full Access
Question # 40

Is the HITRUST CSF a replacement standard for HIPAA or NIST 800-53?

A.

Yes

B.

No

Full Access
Question # 41

An r2 certification is good for how many years?

A.

Two years provided an interim assessment is performed, all CAPs have been remediated, and all N/As discharged

B.

Two years provided an interim assessment is performed and interim requirements are met

C.

Two years regardless

D.

Until there has been a significant change in the in-scope environment

Full Access
Question # 42

A sample of laptops is being selected to ensure AV software has been properly installed/configured. Where should the population be pulled from? [0173]

A.

The AV console, as it lists all laptops with AV installed

B.

The IT asset inventory, for capital assets only

C.

The IT asset inventory, for a list of all laptops

D.

The Risk Register, as it lists all firewalls with AV installed

Full Access