SY0-701 Question 469
Single answerExternal: Regulatory , Examinations , AssessmentA regional healthcare provider is preparing for an external review after a recent expansion into a new state. Leadership has asked the security manager to determine which activity will best demonstrate that the organization is meeting legally mandated security and privacy requirements for patient data before regulators arrive. Which of the following should the security manager prioritize?
- A
Conducting a regulatory compliance assessment against applicable healthcare and state privacy requirements
- B
Scheduling an internal red-team exercise to simulate an advanced ransomware attack
- C
Performing a vulnerability scan of all Internet-facing systems
- D
Reviewing security awareness training completion rates for all employees
Show answer and explanation
Correct answer: A
Explanation
The best answer is conducting a regulatory compliance assessment because the scenario centers on an external regulatory examination and the need to show adherence to legally mandated requirements. In Security+ terms, an external assessment for regulatory purposes focuses on measuring the organization's controls and processes against applicable laws, regulations, and standards. For a healthcare entity, this commonly includes HIPAA requirements and potentially additional state privacy or breach notification obligations. A compliance assessment typically reviews policies, procedures, risk analyses, technical safeguards, audit logs, training records, vendor management, and remediation evidence. By contrast, activities like red-team testing, vulnerability scanning, and training reviews are valuable supporting controls but do not, on their own, provide the structured, requirement-by-requirement validation needed for an external examination. Relevant best practices include maintaining documented control mappings, evidence of periodic risk analysis, and remediation records consistent with regulatory expectations such as those described by the HIPAA Security Rule and HHS guidance.
- A. Correct.
Correct. A regulatory compliance assessment is specifically intended to evaluate whether the organization meets required external legal, regulatory, and contractual obligations. In this scenario, the concern is demonstrating compliance with mandated security and privacy requirements before an external regulatory review. For a healthcare provider, this would include mapping implemented controls, policies, and evidence to applicable requirements such as HIPAA Security Rule and relevant state privacy laws.
- B. Incorrect.
Incorrect. A red-team exercise can help evaluate detection and response capabilities, but it does not directly demonstrate whether the organization satisfies specific regulatory obligations. It is a useful security validation activity, yet it is not the primary method for preparing for an external regulatory examination focused on compliance evidence and control alignment.
- C. Incorrect.
Incorrect. Vulnerability scanning is an important technical security practice and may support compliance efforts, but by itself it does not establish that the organization is meeting the full set of legal and privacy requirements. Regulators typically expect broader evidence, including administrative, technical, and physical safeguards, policies, risk analysis, and remediation tracking.
- D. Incorrect.
Incorrect. Security awareness training is often required or strongly expected under many frameworks, and completion metrics may be requested during an examination. However, training records alone provide only a narrow view of compliance and are not sufficient as the primary activity for validating overall adherence to regulatory requirements.