mediumMultiple Choice
SSCP Practice Question: You work for a hospital that has recently…
You work for a hospital that has recently transitioned to an electronic health record (EHR) system. The system stores protected health information (PHI) and must comply with HIPAA. The hospital's security policy requires that all access to PHI be logged and that any unauthorized access be detected promptly. The IT department has implemented logging on the EHR system, but the security team is overwhelmed by the volume of logs and cannot review them in a timely manner. Additionally, there have been incidents where employees accessed patient records without a legitimate need, but these were only discovered months later during random audits. The hospital needs to improve its detection capabilities. Which of the following is the most effective solution?
⚠ Common exam trap
Many candidates think increasing log verbosity or retention improves detection, but without automated analysis, more data only worsens the signal-to-noise ratio and delays incident discovery.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy a Security Information and Event Management (SIEM) system with automated alerting.
A SIEM system aggregates logs from the EHR system and applies correlation rules to detect patterns indicative of unauthorized access, such as an employee viewing records outside their department or during off-hours. It generates real-time alerts, enabling the security team to respond promptly rather than relying on manual log review. This directly addresses the problem of being overwhelmed by log volume and delayed detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Deploy a Security Information and Event Management (SIEM) system with automated alerting.
Why this is correct
A SIEM correlates and analyses EHR log events centrally, applying automated alerting rules so unauthorised PHI access is flagged promptly rather than discovered months later. This directly addresses the stated constraint: the security team cannot manually review the log volume in a timely manner.
- ✗
Retain logs for a longer period to allow more thorough audits.
Why it's wrong here
Longer retention preserves evidence for later audits but does not surface unauthorised access promptly, leaving the detection delay unchanged. It is tempting because retention supports forensic investigation and compliance, and would be correct where historical review, not real-time detection, is the requirement.
- ✗
Assign additional staff to manually review logs on a daily basis.
Why it's wrong here
Adding manual reviewers scales human effort against log volume but still relies on people spotting anomalies, so detection remains slow and inconsistent. It is tempting because more staff directly addresses the overwhelmed team, and would be correct if the logs were already correlated and prioritised.
- ✗
Increase the verbosity of logging to capture more details.
Why it's wrong here
Increasing verbosity multiplies log volume, worsening the review backlog without identifying illegitimate access, so prompt detection does not improve. It is tempting because richer detail aids forensics, and would be correct when investigating a known incident rather than detecting unauthorised PHI access.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.