Healthcare IT Network Security & Access Control Flashcards
7 cards from real CHISSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Healthcare IT Network Security & Access Control flashcards as text
A healthcare organization implements a Zero Trust Architecture (ZTA) for its clinical network. What is the foundational principle of this approach?
Answer: Never trust, always verify — authenticate and authorize every request regardless of network location
Zero Trust assumes no user or device is inherently trusted, requiring continuous verification of identity and authorization for every resource request regardless of network location.
Which protocol is specifically designed to provide centralized authentication, authorization, and accounting for network access in healthcare environments?
Answer: RADIUS (Remote Authentication Dial-In User Service)
RADIUS provides centralized AAA services for network access, enabling healthcare organizations to manage and audit who accesses the network, when, and with what privileges from a single point.
A CHISSP professional is reviewing firewall rules for a hospital network. Which rule represents a critical security misconfiguration?
Answer: Allow any-to-any traffic with logging enabled
An 'allow any-to-any' rule eliminates the security value of a firewall by permitting all traffic regardless of source, destination, or protocol, creating an open pathway for attackers.
What is the primary security benefit of implementing certificate-based authentication for healthcare system integrations using HL7 or FHIR APIs?
Answer: It provides strong mutual authentication, ensuring both parties are who they claim to be
Certificate-based authentication enables mutual TLS (mTLS), where both the client and server authenticate each other using digital certificates, preventing man-in-the-middle attacks and impersonation.
A hospital's security team wants to detect lateral movement by an attacker who has already compromised an internal workstation. Which tool is MOST effective for this purpose?
Answer: Security Information and Event Management (SIEM) system with behavioral analytics
A SIEM with behavioral analytics correlates logs across the network to detect anomalous internal traffic patterns indicative of lateral movement, which perimeter tools cannot see.
Which of the following BEST describes the purpose of network time protocol (NTP) security in a healthcare IT environment?
Answer: To synchronize clocks across systems, ensuring accurate and correlated security audit logs
Accurate, synchronized time across all systems ensures that security logs from different devices are correlated correctly, which is essential for forensic investigations and compliance audits.
A healthcare organization must ensure that a terminated employee's access to all clinical systems is revoked immediately upon termination. Which process BEST achieves this?
Answer: Integrating HR system termination workflows with automated identity lifecycle management to immediately disable all accounts
Automated integration between HR systems and identity management ensures immediate, comprehensive, and auditable access revocation across all systems simultaneously upon employment termination.