Courseiva
hardMultiple Choice

CAS-004 Practice Question: A regional healthcare provider with 2,000…

A regional healthcare provider with 2,000 employees recently acquired a smaller clinic that uses a legacy electronic health record (EHR) system. The provider's security team performed a risk assessment and identified that the legacy system does not support encryption at rest, lacks role-based access controls (RBAC), and stores administrative credentials in plaintext. The system is scheduled to be decommissioned in 18 months, but it must remain operational to support patient care during the transition. The provider is subject to HIPAA and state breach notification laws. The CEO wants to avoid any disruption to patient services but also minimize regulatory risk. Which of the following is the BEST course of action?

⚠ Common exam trap

CompTIA often tests the concept that compensating controls are a valid risk treatment option when a vulnerability cannot be immediately remediated, and candidates mistakenly choose risk acceptance (Option C) without realizing that HIPAA requires active safeguards, not just documentation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement compensating controls such as network segmentation, storage-level encryption, and strict access monitoring.

The best course of action because it allows the legacy EHR system to remain operational for patient care while reducing regulatory risk. Compensating controls like network segmentation isolate the vulnerable system, storage-level encryption (e.g., BitLocker or LUKS) protects data at rest, and strict access monitoring (e.g., SIEM with real-time alerts) mitigates the lack of RBAC and plaintext credentials. This approach balances the CEO's requirement for no disruption with HIPAA's security rule requirements for reasonable safeguards.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Accelerate the migration timeline to replace the legacy system within 6 months.

    Why it's wrong here

    Compressing migration to six months risks clinical disruption the CEO explicitly ruled out, and the legacy system must still operate during transition. Accelerated replacement suits scenarios where the vendor withdraws support or a critical patch cannot be applied, not where residual controls can mitigate risk for a defined 18-month window.

  • ✗

    Immediately disconnect the legacy system from the network and use manual processes.

    Why it's wrong here

    Severing network connectivity halts the patient care the CEO requires, and manual processes cannot substitute for an EHR handling clinical records. Disconnection suits systems with no operational dependency or imminent active compromise; this legacy EHR must remain available, so compensating controls rather than isolation are needed.

  • ✗

    Accept the residual risk and document it in the risk register.

    Why it's wrong here

    Documenting the plaintext administrative credentials and absent encryption as accepted residual risk leaves HIPAA-regulated ePHI exposed to breach notification duties without compensating controls. Risk acceptance suits low-likelihood, low-impact findings within appetite; here the identified weaknesses demand interim mitigation until decommissioning.

  • ✓

    Implement compensating controls such as network segmentation, storage-level encryption, and strict access monitoring.

    Why this is correct

    Compensating controls address the legacy system's missing encryption, RBAC and plaintext credentials without disrupting patient care during the 18-month transition. Network segmentation, storage-level encryption and access monitoring reduce HIPAA and breach-notification exposure while the system remains operational.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.