Courseiva
hardMultiple ChoiceObjective-mapped

CCSP Practice Question: A large healthcare organization uses a hybrid…

A large healthcare organization uses a hybrid cloud environment with on-premises systems and Microsoft Azure. They store protected health information (PHI) in Azure Blob Storage and use Azure SQL Database for transactional data. The organization must comply with HIPAA and has implemented encryption at rest using Azure Storage Service Encryption and Transparent Data Encryption (TDE) for SQL. During a recent audit, the security team discovered that the organization does not have a formal process to identify and respond to security incidents that involve PHI. Additionally, the organization's backup strategy stores encrypted backups in a separate Azure region, but the backup encryption keys are managed by Azure and are not customer-controlled. The compliance officer is concerned about the ability to demonstrate HIPAA compliance in the event of an audit. Which of the following actions should the organization take FIRST to address the most critical gap?

⚠ Common exam trap

ISC2 often tests the distinction between proactive security controls (encryption, vulnerability assessment, data classification) and the mandatory reactive compliance process (incident response plan) required by regulations like HIPAA, leading candidates to prioritize technical fixes over procedural requirements.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Develop and implement a formal incident response plan that includes procedures for detecting, reporting, and responding to PHI breaches.

The most critical gap is the lack of a formal incident response plan for PHI breaches. HIPAA requires covered entities to have documented policies and procedures for detecting, reporting, and responding to security incidents involving ePHI. Without this plan, the organization cannot demonstrate compliance during an audit, regardless of encryption or backup controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Conduct a vulnerability assessment of all cloud resources to identify and remediate security weaknesses.

    Why it's wrong here

    Vulnerability assessments are good practice but not the first priority over incident response.

  • Develop and implement a formal incident response plan that includes procedures for detecting, reporting, and responding to PHI breaches.

    Why this is correct

    An incident response plan is a HIPAA requirement and addresses the identified gap.

  • Implement customer-managed keys (CMK) for all Azure backups to ensure the organization controls encryption keys.

    Why it's wrong here

    Key management is important but not the most critical compliance gap.

  • Implement a data classification policy to label all data assets according to sensitivity.

    Why it's wrong here

    Data classification is useful but does not directly address the lack of incident response.

Quick reference

Azure Blob Storage Tier Comparison

TierStorage CostRetrieval CostLatencyUse Case
HotHighestLowestImmediateActive data, frequent reads
CoolLowerHigherImmediateData accessed < once / month
ColdLower stillHigherImmediateData accessed < once / quarter
ArchiveLowestHighest + rehydration delayHoursLong-term compliance retention

About these practice questions

One of 964 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.