Courseiva
mediumMultiple ChoiceObjective-mapped

SSCP A risk analyst at a healthcare organization Practice Question

You are a risk analyst at a healthcare organization. The organization recently deployed a new electronic health records (EHR) system. During the first month of operation, the IT helpdesk received multiple reports from doctors that the system becomes unresponsive for 10-15 seconds several times a day. The EHR vendor attributes this to insufficient database connection pooling, but the organization's system administrator notes that the database server's CPU and memory utilization never exceed 30%. The organization has a risk management policy that requires any system with availability <99.5% to be treated as a high risk. Based on initial data, the system has been unavailable for about 0.1% of the time (excluding planned maintenance). However, doctors report that the brief unresponsiveness is causing frustration and potential misdiagnosis due to interrupted workflows. You need to recommend a risk treatment approach. What should you do?

⚠ Common exam trap

The trap here is that candidates focus on the 99.5% availability threshold and assume the risk is acceptable (Option A) or immediately high (Option C), without recognizing that the policy requires a risk assessment that includes impact analysis, and that the technical symptom (connection pooling) may not be resolved by hardware upgrades or load balancers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Conduct a deeper analysis to quantify the impact of these brief outages on clinical workflows and patient safety, then reassess risk

The risk management policy defines high risk based on availability <99.5%, and the system currently shows 99.9% availability (0.1% unavailability). However, the brief 10-15 second unresponsiveness may still pose a clinical safety risk that is not captured by a simple uptime metric. A deeper analysis is required to quantify the actual impact on clinical workflows and patient safety before deciding on risk treatment, as the policy may need to consider functional availability rather than just binary uptime.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Accept the current risk because the system meets the 99.5% availability threshold

    Why it's wrong here

    Accepting without understanding the clinical impact may ignore patient safety risks.

  • Reduce the risk by implementing a load balancer and additional application servers

    Why it's wrong here

    The issue is likely a software configuration problem (connection pooling), not capacity.

  • Document the system as high risk and require immediate remediation, such as upgrading the database server hardware

    Why it's wrong here

    The availability metric is within acceptable range; hardware may not solve the issue.

  • Conduct a deeper analysis to quantify the impact of these brief outages on clinical workflows and patient safety, then reassess risk

    Why this is correct

    A deeper analysis will clarify the true risk level before deciding on treatment.

About these practice questions

One of 920 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.