mediumMultiple ChoiceObjective-mapped
SSCP A risk analyst at a healthcare organization Practice Question
You are a risk analyst at a healthcare organization. The organization recently deployed a new electronic health records (EHR) system. During the first month of operation, the IT helpdesk received multiple reports from doctors that the system becomes unresponsive for 10-15 seconds several times a day. The EHR vendor attributes this to insufficient database connection pooling, but the organization's system administrator notes that the database server's CPU and memory utilization never exceed 30%. The organization has a risk management policy that requires any system with availability <99.5% to be treated as a high risk. Based on initial data, the system has been unavailable for about 0.1% of the time (excluding planned maintenance). However, doctors report that the brief unresponsiveness is causing frustration and potential misdiagnosis due to interrupted workflows. You need to recommend a risk treatment approach. What should you do?
⚠ Common exam trap
The trap here is that candidates focus on the 99.5% availability threshold and assume the risk is acceptable (Option A) or immediately high (Option C), without recognizing that the policy requires a risk assessment that includes impact analysis, and that the technical symptom (connection pooling) may not be resolved by hardware upgrades or load balancers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct a deeper analysis to quantify the impact of these brief outages on clinical workflows and patient safety, then reassess risk
The risk management policy defines high risk based on availability <99.5%, and the system currently shows 99.9% availability (0.1% unavailability). However, the brief 10-15 second unresponsiveness may still pose a clinical safety risk that is not captured by a simple uptime metric. A deeper analysis is required to quantify the actual impact on clinical workflows and patient safety before deciding on risk treatment, as the policy may need to consider functional availability rather than just binary uptime.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Accept the current risk because the system meets the 99.5% availability threshold
Why it's wrong here
Accepting without understanding the clinical impact may ignore patient safety risks.
- ✗
Reduce the risk by implementing a load balancer and additional application servers
Why it's wrong here
The issue is likely a software configuration problem (connection pooling), not capacity.
- ✗
Document the system as high risk and require immediate remediation, such as upgrading the database server hardware
Why it's wrong here
The availability metric is within acceptable range; hardware may not solve the issue.
- ✓
Conduct a deeper analysis to quantify the impact of these brief outages on clinical workflows and patient safety, then reassess risk
Why this is correct
A deeper analysis will clarify the true risk level before deciding on treatment.
Go deeper
Related to this question
About these practice questions
One of 920 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.