New Year Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

HITRUST CCSFP - Certified CSF Practitioner 2025 Exam

Page: 4 / 5
Total 141 questions

For an r2 assessment, HITRUST requires a Corrective Action Plan (CAP) when the Control Reference required for certification scored a 70 or less, and Implementation scores less than 100%.

A.

True

B.

False

Who defines the scope of an assessment?

A.

Client Management

B.

The Assessor

C.

HITRUST

When performing r2 assessments, any added compliance factors should be considered before marking a requirement statement "N/A".

A.

True

B.

False

On an r2 assessment, the decision to require a CAP for a deficiency (gap) is determined at the Control Reference level and the Requirement Statement level.

A.

True

B.

False

Firewalls with identical configurations can be grouped for testing as one component.

A.

True

B.

False

When scoping an r2 assessment, selecting regulatory factors is required and may generate additional Requirement Statements in the assessment object.

A.

True

B.

False

For an r2 assessment, to obtain a Validated Report with Certification, each domain must score at least a 71 or higher.

A.

True

B.

False

After completion of a Validated Assessment, all remediated CAPs can be removed from the final report.

A.

True

B.

False

When testing, can you sample across a population of ungrouped primary components within an assessment's scope?

A.

Yes, across most of the components within scope

B.

No, you must test all components within scope

C.

Yes, across some of the components within scope

D.

Yes, a primary component sample can be produced using guidance from the scoring rubric

Which AI models can be evaluated using the A1 Security Assessment?

A.

Hodgkin-Huxley

B.

Predictive

C.

Back Propagation

D.

Generative

E.

Rule-Based