hardMultiple ChoiceObjective-mapped
CCSP Practice Question: A large healthcare organization uses a hybrid…
A large healthcare organization uses a hybrid cloud environment with on-premises systems and Microsoft Azure. They store protected health information (PHI) in Azure Blob Storage and use Azure SQL Database for transactional data. The organization must comply with HIPAA and has implemented encryption at rest using Azure Storage Service Encryption and Transparent Data Encryption (TDE) for SQL. During a recent audit, the security team discovered that the organization does not have a formal process to identify and respond to security incidents that involve PHI. Additionally, the organization's backup strategy stores encrypted backups in a separate Azure region, but the backup encryption keys are managed by Azure and are not customer-controlled. The compliance officer is concerned about the ability to demonstrate HIPAA compliance in the event of an audit. Which of the following actions should the organization take FIRST to address the most critical gap?
⚠ Common exam trap
ISC2 often tests the distinction between proactive security controls (encryption, vulnerability assessment, data classification) and the mandatory reactive compliance process (incident response plan) required by regulations like HIPAA, leading candidates to prioritize technical fixes over procedural requirements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Develop and implement a formal incident response plan that includes procedures for detecting, reporting, and responding to PHI breaches.
The most critical gap is the lack of a formal incident response plan for PHI breaches. HIPAA requires covered entities to have documented policies and procedures for detecting, reporting, and responding to security incidents involving ePHI. Without this plan, the organization cannot demonstrate compliance during an audit, regardless of encryption or backup controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Conduct a vulnerability assessment of all cloud resources to identify and remediate security weaknesses.
Why it's wrong here
Vulnerability assessments are good practice but not the first priority over incident response.
- ✓
Develop and implement a formal incident response plan that includes procedures for detecting, reporting, and responding to PHI breaches.
Why this is correct
An incident response plan is a HIPAA requirement and addresses the identified gap.
- ✗
Implement customer-managed keys (CMK) for all Azure backups to ensure the organization controls encryption keys.
Why it's wrong here
Key management is important but not the most critical compliance gap.
- ✗
Implement a data classification policy to label all data assets according to sensitivity.
Why it's wrong here
Data classification is useful but does not directly address the lack of incident response.
Quick reference
Azure Blob Storage Tier Comparison
| Tier | Storage Cost | Retrieval Cost | Latency | Use Case |
|---|---|---|---|---|
| Hot | Highest | Lowest | Immediate | Active data, frequent reads |
| Cool | Lower | Higher | Immediate | Data accessed < once / month |
| Cold | Lower still | Higher | Immediate | Data accessed < once / quarter |
| Archive | Lowest | Highest + rehydration delay | Hours | Long-term compliance retention |
Go deeper
Related to this question
About these practice questions
One of 964 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.