Healthcare IT Network Security & Access Control Flashcards
7 cards from real CHISSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Healthcare IT Network Security & Access Control flashcards as text
Which network segmentation strategy is most commonly recommended to isolate medical devices from general hospital IT systems?
Answer: VLAN-based segmentation with strict ACLs
VLAN-based segmentation with strict access control lists allows medical devices to be logically isolated while still permitting controlled, monitored communication with clinical systems.
A hospital's EHR system must enforce the 'minimum necessary' access principle. Which access control model best supports this requirement?
Answer: Role-Based Access Control (RBAC)
RBAC assigns access rights based on clinical roles, ensuring each user only accesses information necessary for their specific job function, directly supporting the HIPAA minimum necessary standard.
Under NIST guidelines, what is the primary purpose of implementing 802.1X port-based authentication on a healthcare network?
Answer: To ensure only authenticated devices connect to network segments
802.1X port-based authentication prevents unauthorized devices from connecting to the network by requiring successful authentication before granting network access.
A healthcare organization wants to reduce the attack surface of its patient portal. Which principle should guide the configuration of the web application firewall?
Answer: Deny all traffic by default and allow only required application functions
A default-deny (whitelisting) approach minimizes attack surface by blocking all traffic except explicitly permitted application functions, reducing exposure to unknown threats.
Which authentication mechanism provides the strongest security for remote access to a healthcare organization's clinical systems?
Answer: Multi-factor authentication combining something you know and something you have
Multi-factor authentication requiring two different credential types (e.g., password plus a hardware token) significantly reduces the risk of unauthorized access even if one factor is compromised.
When deploying wireless networks in a healthcare facility, which protocol is considered minimum acceptable for securing patient data transmitted over Wi-Fi?
Answer: WPA2 with AES-CCMP
WPA2 with AES-CCMP is the minimum acceptable standard because WEP and original WPA have known cryptographic weaknesses that make them unsuitable for protecting ePHI.
A security analyst detects repeated failed login attempts against the hospital's VPN concentrator from external IP addresses. What is the BEST immediate response?
Answer: Implement account lockout policies and geo-IP blocking where feasible
Account lockout policies slow brute-force attacks while geo-IP blocking reduces attack surface from high-risk regions, balancing security with operational continuity.