Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

HITRUST CCSFP Exam - Topic 5 Question 13 Discussion

Actual exam question for HITRUST's CCSFP exam
Question #: 13
Topic #: 5
[All CCSFP Questions]

A sample of laptops is being selected to ensure AV software has been properly installed/configured. Where should the population be pulled from? [0173]

Show Suggested Answer Hide Answer
Suggested Answer: C

When testing implementation, the population must include the full set of in-scope assets, not just a subset filtered by existing controls.

AV console (A) only shows devices with AV installed; it would exclude noncompliant assets.

IT asset inventory (C) provides the complete list of laptops, making it the proper source for random sample selection.

Risk register (D) lists risks, not devices.

Capital assets only (B) not comprehensive for all laptops.

Extract Reference (HITRUST Assessment Sampling Guidance, CCSFP [0173]):

Sampling must be based on the complete population from the IT asset inventory; reliance on control-based systems (e.g., AV console) introduces bias.


Contribute your Thoughts:

0/2000 characters
Mindy
18 days ago
I disagree, A is more accurate since it focuses on AV.
upvoted 0 times
...
Mitsue
23 days ago
C is the best choice, it covers all laptops.
upvoted 0 times
...
Cristina
1 month ago
The Risk Register seems off to me; I don't recall it being the right source for checking AV installations. It’s more about firewalls, I think.
upvoted 0 times
...
Jame
1 month ago
I practiced a similar question, and I feel like the IT asset inventory is definitely the way to go, but I wonder if capital assets only is too limiting.
upvoted 0 times
...
Carmen
2 months ago
I'm not too sure, but I remember something about the AV console being useful for checking installations. Could that be an option?
upvoted 0 times
...
Annamae
2 months ago
I think the population should come from the IT asset inventory since it should have a complete list of all laptops, right?
upvoted 0 times
...

Save Cancel