ISC2 Certified Cloud Security Professional (CCSP) Practice Question

While working as the security operations manager for a cloud service provider that hosts an electronic health record (EHR) SaaS platform, you learn that an attacker has downloaded protected health information (PHI) belonging to a single hospital tenant. The master services agreement mandates breach notification within four hours, and the hospital is a HIPAA covered entity. To comply with accepted cloud-security communication practices, which outbound notification should you make first?

  • Release a public media statement acknowledging the breach and outlining remediation steps.

  • Notify the hospital's designated incident-response contact using the four-hour contractual breach-notification process.

  • Email all affected patients advising them to change passwords and monitor accounts for identity theft.

  • Submit an immediate breach report to the U.S. Department of Health and Human Services Office for Civil Rights (OCR).

ISC2 Certified Cloud Security Professional (CCSP)
Cloud Security Operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot