New Year Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

HITRUST CCSFP - Certified CSF Practitioner 2025 Exam

Page: 3 / 5
Total 141 questions

When considering third-party reports for reliance, what must be included in the report? (Select all that apply)

A.

Description of scope

B.

Completed remediation for testing exceptions

C.

List of procedures performed

D.

Executive summary

E.

Conclusions reached for each test

All i1 Readiness Assessments undergo HITRUST Quality Assurance (QA) reviews.

A.

True

B.

False

The HITRUST QA reservation must be made by the External Assessor at least six months in advance of the submission date.

A.

True

B.

False

During HITRUST's QA phase of a Validated Assessment, HITRUST picks a sample of Control Objectives to review the assessor's validation and testing procedures.

A.

True

B.

False

Where in MyCSF can the CSF framework be browsed?

A.

Home

B.

Tasks

C.

Administration

D.

Reference Library

E.

Search

Which type of assessments must be performed to be eligible for certification? [0158]

A.

e1 Readiness Assessment

B.

an e1, i1 or an r2 Validated Assessment

C.

Customized Assessment

D.

Targeted Assessment

A sample of laptops is being selected to ensure AV software has been properly installed/configured. Where should the population be pulled from? [0173]

A.

The AV console, as it lists all laptops with AV installed

B.

The IT asset inventory, for capital assets only

C.

The IT asset inventory, for a list of all laptops

D.

The Risk Register, as it lists all firewalls with AV installed

An assessed entity is required to comply with six regulatory factors. Must the entity include all six regulatory factors in the scope of their assessment? [0088]

A.

Yes

B.

No

When creating a new r2 assessment you are required to use the latest version of the HITRUST CSF.

A.

True

B.

False

In which assessment(s) are you allowed to "carve out" third-party controls as not applicable? (Select all that apply) [0116]

A.

i1

B.

r2

C.

e1

D.

Interim