nerdexam
CompTIA

CS0-003 · Question #653

Hotspot Question A healthcare organization must develop an action plan based on the findings from a risk assessment. The action plan must consist of a recommended list of security controls…

The correct answer is PHI data was found within the development and test environments.: Require data deidentification; A large volume of ICMP traffic is detected from an external source to Server2.: Filter echo request replies; Unauthorized software was discovered on technician workstations.: Implement MDM solution; A large number of potentially malicious emails is reaching end-user and shared mailboxes.: Implement web content filter; The internet-facing web server allows access to internal data without requiring credentials.: Require user authentication; Sensitive materials were found on a fax machine in a common area.: Implement PIN to print. This hotspot question tests the ability to match specific security controls to corresponding risk findings identified during a healthcare organization's risk assessment, requiring knowledge of HIPAA, NIST, and general cybersecurity control frameworks.

Submitted by naveen.iyer· Mar 6, 2026Vulnerability Management

Question

Hotspot Question A healthcare organization must develop an action plan based on the findings from a risk assessment. The action plan must consist of a recommended list of security controls. INSTRUCTIONS Select the appropriate control to implement for each risk finding. Findings may be used only once. If at any time you would like to bring back the initial state of the simulation, please click the Reset All button. Answer:

Exhibit

CS0-003 question #653 exhibit

Answer Area

  • PHI data was found within the development and test environments.Require data deidentification
    Select controlImplement web content filterRequire data deidentificationFilter echo request repliesRequire user authenticationImplement IDS/IPSImplement SPFImplement MDM solutionImplement file integrity monitoringImplement PIN to printImplement email encryption
  • A large volume of ICMP traffic is detected from an external source to Server2.Filter echo request replies
    Select controlImplement web content filterRequire data deidentificationFilter echo request repliesRequire user authenticationImplement IDS/IPSImplement SPFImplement MDM solutionImplement file integrity monitoringImplement PIN to printImplement email encryption
  • Unauthorized software was discovered on technician workstations.Implement MDM solution
    Select controlImplement web content filterRequire data deidentificationFilter echo request repliesRequire user authenticationImplement IDS/IPSImplement SPFImplement MDM solutionImplement file integrity monitoringImplement PIN to printImplement email encryption
  • A large number of potentially malicious emails is reaching end-user and shared mailboxes.Implement web content filter
    Select controlImplement web content filterRequire data deidentificationFilter echo request repliesRequire user authenticationImplement IDS/IPSImplement SPFImplement MDM solutionImplement file integrity monitoringImplement PIN to printImplement email encryption
  • The internet-facing web server allows access to internal data without requiring credentials.Require user authentication
    Select controlImplement web content filterRequire data deidentificationFilter echo request repliesRequire user authenticationImplement IDS/IPSImplement SPFImplement MDM solutionImplement file integrity monitoringImplement PIN to printImplement email encryption
  • Sensitive materials were found on a fax machine in a common area.Implement PIN to print
    Select controlImplement web content filterRequire data deidentificationFilter echo request repliesRequire user authenticationImplement IDS/IPSImplement SPFImplement MDM solutionImplement file integrity monitoringImplement PIN to printImplement email encryption

Explanation

This hotspot question tests the ability to match specific security controls to corresponding risk findings identified during a healthcare organization's risk assessment, requiring knowledge of HIPAA, NIST, and general cybersecurity control frameworks.

Approach. The correct approach is to analyze each risk finding and map it to the most appropriate compensating or mitigating control. For example, if a finding indicates unencrypted data at rest, the control would be 'Implement data encryption'; if the finding is lack of access control, the control would be 'Implement Role-Based Access Control (RBAC)'; if the finding involves missing audit trails, the control is 'Enable audit logging and monitoring'; if the finding is weak authentication, the control is 'Implement Multi-Factor Authentication (MFA)'; and if the finding is lack of employee awareness, the control is 'Conduct security awareness training'. Each control directly addresses the root cause of its corresponding finding, which is the principle behind building an effective action plan from a risk assessment in regulated environments like healthcare.

Concept tested. Risk assessment action planning and security control selection - specifically the ability to align identified vulnerabilities or risk findings with the appropriate administrative, technical, or physical security controls as required by frameworks such as NIST SP 800-53, HIPAA Security Rule, and ISO 27001.

Reference. NIST SP 800-53 (Security and Privacy Controls), HIPAA Security Rule 45 CFR Part 164, CompTIA Security+ Domain 5 (Governance, Risk, and Compliance)

Topics

#risk assessment#security controls#remediation#data deidentification

Community Discussion

No community discussion yet for this question.

Full CS0-003 Practice