Healthcare IT Network Security & Access Control Flashcards
7 cards from real CHISSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Healthcare IT Network Security & Access Control flashcards as text
A healthcare network administrator needs to monitor traffic between a biomedical device network and the clinical LAN. Which tool is MOST appropriate?
Answer: Network-based IDS (NIDS) with a span/mirror port on the inter-segment switch
A NIDS with a span port passively monitors traffic between segments without impacting device performance or availability, which is critical for time-sensitive biomedical devices.
Which of the following is a key security concern unique to legacy medical devices that cannot be patched or updated?
Answer: They often run outdated operating systems with unmitigated vulnerabilities
Many legacy medical devices run end-of-life operating systems (e.g., Windows XP) that cannot receive security patches, leaving known vulnerabilities permanently unmitigated.
What is the recommended compensating control for a medical device running an unsupported operating system that cannot be updated?
Answer: Isolate the device in a dedicated VLAN with strict firewall rules and enhanced monitoring
Network isolation with strict ACLs and enhanced monitoring compensates for an unpatched device by limiting its exposure and increasing visibility into any anomalous activity.
A hospital's Active Directory environment has a privileged account used by multiple IT administrators. Which practice violates least-privilege principles?
Answer: Using a shared 'Domain Admin' account for routine administrative tasks
Sharing a single Domain Admin account eliminates individual accountability, grants excessive privileges for routine tasks, and violates both least-privilege and non-repudiation principles.
Which technology allows a healthcare organization to verify the integrity of network devices and endpoints before granting them access to clinical resources?
Answer: Network Access Control (NAC)
NAC evaluates device health — patch status, antivirus, configuration compliance — before permitting connection, preventing non-compliant endpoints from accessing sensitive clinical resources.
In healthcare IT security, what does 'defense in depth' primarily refer to?
Answer: Layering multiple independent security controls so a failure in one does not compromise the entire system
Defense in depth layers multiple independent controls (firewalls, IDS, access control, encryption, monitoring) so that an attacker must defeat every layer, reducing the likelihood of a successful breach.
A nurse's workstation automatically logs out after 3 minutes of inactivity. Which security principle does this automatic timeout BEST enforce?
Answer: Session management and unauthorized access prevention
Automatic session timeout prevents unauthorized individuals from accessing a logged-in workstation left unattended, directly addressing the risk of session hijacking and unauthorized access.