AXIS Quality Assurance & Compliance 2 — Questions and Answers
Question 1: Which regulation restricts the use of video surveillance equipment manufactured by certain Chinese companies in US federal government applications?
- GDPR Article 32
- NDAA Section 889 (Correct answer)
- HIPAA Security Rule
- FCC Part 15
Correct answer: NDAA Section 889
NDAA Section 889 prohibits US federal agencies from procuring video surveillance equipment from specific Chinese manufacturers including Hikvision and Dahua.
Question 2: When performing a post-installation quality check on an AXIS camera, which tool is best suited to verify that the device firmware is up to date and configured correctly?
- AXIS Site Designer
- AXIS Device Manager (Correct answer)
- AXIS Camera Station
- AXIS Companion
Correct answer: AXIS Device Manager
AXIS Device Manager is the purpose-built tool for managing firmware updates, device configuration, and compliance checks across multiple AXIS devices.
Question 3: What does the ONVIF standard primarily ensure in an IP video surveillance system?
- End-to-end video encryption
- Interoperability between devices from different manufacturers (Correct answer)
- Compliance with local data retention laws
- Physical security of network switches
Correct answer: Interoperability between devices from different manufacturers
ONVIF (Open Network Video Interface Forum) is an open standard that ensures interoperability and integration between IP-based security products from different vendors.
Question 4: During a system acceptance test, a customer finds that image quality degrades significantly at night. What is the most appropriate first compliance step?
- Issue a change order for higher-resolution cameras
- Compare recorded footage against the project specification's image quality requirements (Correct answer)
- Reboot all cameras and reconfigure motion detection
- Replace all lenses with varifocal alternatives
Correct answer: Compare recorded footage against the project specification's image quality requirements
The correct first step is to compare actual performance against the documented project specification to determine whether a compliance gap exists.
Question 5: Which cybersecurity practice is recommended by AXIS as part of hardening a deployed camera?
- Leaving default credentials to simplify technician access
- Disabling HTTPS to reduce processing overhead
- Changing default passwords and disabling unused services (Correct answer)
- Using HTTP instead of HTTPS for management traffic
Correct answer: Changing default passwords and disabling unused services
AXIS Hardening Guide recommends changing all default passwords and disabling unused network services and protocols to reduce the attack surface.
Question 6: A technician is installing cameras in a healthcare facility. Which regulation is most relevant to ensuring patient privacy in video recorded areas?
- PCI DSS
- HIPAA (Correct answer)
- SOX
- FERPA
Correct answer: HIPAA
HIPAA (Health Insurance Portability and Accountability Act) governs the privacy and security of protected health information, which includes video of patients in healthcare settings.
Question 7: What is the purpose of an AXIS signed firmware image?
- To speed up the firmware update process over slow networks
- To ensure the firmware has not been tampered with and originates from AXIS (Correct answer)
- To allow third-party developers to customize device behavior
- To enable remote firmware rollback without technician access
Correct answer: To ensure the firmware has not been tampered with and originates from AXIS
Signed firmware uses cryptographic signatures to verify authenticity and integrity, preventing the installation of modified or malicious firmware.
Which regulation restricts the use of video surveillance equipment manufactured by certain Chinese companies in US federal government applications?