10 exam-style questions with answers and explanations, straight from our 1,030-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.
The C)HISSP exam has 100 questions and runs 2 hours.
These 10 free C)HISSP questions are organized by exam domain, so you can see how each part of the Certified Healthcare Information Systems Security Practitioner blueprint is tested. Reveal the answer and explanation under each question.
Domain 1: Intro to the Healthcare Industry
Question 1
Ransomware is spreading from nursing-station workstations on a ward network. Infusion pumps on the same network are still delivering prescribed treatment. Disconnecting the entire ward would remove central alarm monitoring before alternative monitoring could be arranged. IT can isolate the affected workstations without interrupting the pumps. How should the incident commander begin containment?
Show answer & explanation
Correct answer: C - Isolate the affected workstations and coordinate downtime procedures with nursing staff.
Question 2
After two hospitals merge their laboratory feeds, results begin appearing in the wrong patient charts. Each hospital historically assigned medical record numbers independently, but the receiving system matches records using the number alone. The affected feed has been paused. Which correction addresses the identification defect before processing resumes?
Show answer & explanation
Correct answer: B - Match each local record number within its issuing facility's namespace before mapping to the enterprise patient record.
Domain 2: Regulatory Environment
Question 3
A verified cardiologist at another practice requests a patient's recent electrocardiogram and medication history for ongoing treatment. No special confidentiality law or agreed restriction applies. Which response accurately applies HIPAA to the request?
Show answer & explanation
Correct answer: A - Send the requested records securely for treatment without requiring the patient's authorization.
Question 4
For an approved health-services research project, a hospital prepares a dataset that retains full admission and discharge dates and five-digit ZIP codes. Every direct identifier prohibited in a HIPAA limited data set has been removed. The researchers need the retained fields for their analysis. Which release arrangement preserves those fields without misclassifying the data?
Show answer & explanation
Correct answer: C - Release it as a limited data set under a data use agreement; it remains PHI.
Domain 3: Healthcare Privacy & Security Policies
Question 5
A clinician enters a password and a six-digit authenticator-app code into a convincing imitation of the hospital login page. The attacker immediately relays both to the real site and obtains a valid session. Which authentication change specifically defeats this real-time credential-relay mechanism?
Show answer & explanation
Correct answer: C - Replace manually entered codes with FIDO2 security keys using WebAuthn.
Domain 4: Information Governance & Risk Management
Question 6
An electronic health record recovery exercise produces this log:
Outage begins: 10:00.
Service restored and clinically validated: 11:10.
Latest recoverable committed transaction: 09:40; nothing later is recoverable.
The approved recovery time objective is two hours and the recovery point objective is 15 minutes. What should the exercise report recommend?
Show answer & explanation
Correct answer: A - Improve recoverable data currency; the recovery time objective was met, but the recovery point objective was missed.
Question 7
A hospital estimates that a particular archive outage costs $240,000 per occurrence and occurs, on average, once every four years. A resilience service costing $25,000 annually would reduce the frequency to once every 12 years without changing the loss per occurrence. Mandatory safeguards and patient-safety requirements are satisfied with or without the service. Considering only the stated annualized financial effects, which recommendation follows?
Show answer & explanation
Correct answer: A - Purchase the service; its expected net financial benefit is $15,000 per year.
Domain 5: Information Governance & Risk Assessment
Question 8
A vulnerability review identifies a CVSS v3.1 base score of 9.8 on a network-isolated research workstation containing no patient data, and a score of 7.5 on an internet-facing patient portal. A current threat advisory confirms exploitation of the portal flaw at other organizations. Neither local system shows evidence of compromise, and both patches are equally straightforward to deploy. Which prioritization is justified?
Show answer & explanation
Correct answer: B - Patch the portal first; its exposure and the exploitation evidence outweigh the difference in base scores.
Domain 6: Third-Party Risk Management
Question 9
A cloud company will retain a hospital's encrypted patient-record backups for seven years. The hospital alone controls the decryption keys, and the company cannot read the records. The company argues that it therefore needs no business associate agreement. Under HIPAA, how should this relationship be classified?
Show answer & explanation
Correct answer: D - A business associate relationship, because the company maintains electronic PHI for the hospital.
Question 10
"The opinion is unmodified, so the whole service is covered," says a procurement manager reviewing a prospective billing vendor's SOC 2 Type 2 report. The report, however, expressly excludes controls at the subcontractor storing the patient-data backups. What additional due diligence addresses the actual gap?
Show answer & explanation
Correct answer: D - Assess the backup subcontractor's relevant controls and the billing vendor's oversight of that subcontractor.
That's 10 of 1,030
The full bank has 1,020 more C)HISSP questions with explanations.