Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: ecus65

HITRUST CCSFP - Certified CSF Practitioner 2025 Exam

Page: 1 / 5
Total 141 questions

Measured and Managed Maturity Levels can be scored for some, but not all, requirements in an r2 assessment object.

A.

True

B.

False

An i1 Control Reference that scores a 37 would yield what result?

A.

Required CAP

B.

HITRUST Certification

C.

Risk Acceptance

D.

No Gap

E.

Function Gap

A pharmacy that accepts Medicare/Medicaid and also takes credit cards should include which regulatory factors in their assessment?

A.

FISMA

B.

FTC Red Flags Rule

C.

PCI-DSS

D.

FedRAMP

E.

CMS (Centers for Medicare and Medicaid Services) Minimum Security Requirements (High)

For the maturity levels "Measured" and "Managed," any score above 50% requires the following supporting documentation. (Select all that apply)

A.

Organizational scoping factors

B.

Processes used to manage the risk of identified control deficiencies

C.

Reports used to document control environment monitoring

D.

Individuals responsible for measuring the control environment

The A1 Security Assessment requirements can only be added to the r2 assessment type.

A.

True

B.

False

To perform a rapid assessment, the assessment and/or insights report must each contain more than 60 requirements.

A.

True

B.

False

Would the certification threshold be met in an e1 assessment if all Requirement Statements had Implemented scored at 50%?

A.

Yes

B.

No

TION NO: 133 [Assessment Types and Process]

What type of scoping boundary includes the relevant IT platforms and supporting infrastructure used by one or more business units? [0155]

A.

Follow-the-data

B.

Enclave-focused

C.

Shared IT services

D.

Enterprise

On an r2 assessment, HITRUST requires evidence to be linked to all maturity levels that score above 25% for Policy and Procedure, and over 0% for Implementation, Measured, and Managed.

A.

True

B.

False

Which assessment type is the most tailorable to an organization's risk profile?

A.

i1

B.

r2

C.

Interim

D.

e1

E.

Bridge