CPHIMS CPHIMS Technology and IT Infrastructure 4 — Questions and Answers
Question 1: A health system wants to prevent unauthorized USB devices from connecting to clinical workstations. Which control BEST addresses this risk?
- Full-disk encryption on workstations
- Endpoint device control software (Correct answer)
- Network intrusion detection system
- Role-based access control in the EHR
Correct answer: Endpoint device control software
Endpoint device control software enforces policies that allow, block, or restrict USB and other removable media on workstations.
Question 2: Which protocol does SNMP use to collect performance metrics from network devices in a healthcare environment?
- TCP port 443
- UDP port 161 (Correct answer)
- TCP port 22
- UDP port 53
Correct answer: UDP port 161
SNMP (Simple Network Management Protocol) uses UDP port 161 for polling and receiving management data from network devices.
Question 3: A hospital deploys a content delivery network (CDN) for its patient education portal. What is the PRIMARY benefit?
- Increased data encryption strength
- Reduced server load and improved page load times for distributed users (Correct answer)
- Compliance with HIPAA storage requirements
- Centralized audit log collection
Correct answer: Reduced server load and improved page load times for distributed users
A CDN caches content at geographically distributed edge nodes, reducing latency and origin server load for end users.
Question 4: In the context of healthcare IT disaster recovery, what is a 'warm site'?
- A fully operational duplicate data center ready for immediate failover
- A partially configured backup site that requires some setup time before use (Correct answer)
- A remote storage location for backup tapes only
- A cloud-based virtual environment with no pre-staged hardware
Correct answer: A partially configured backup site that requires some setup time before use
A warm site has pre-installed hardware and partial configuration, requiring additional setup (hours to days) before it can support operations.
Question 5: Which technology allows a healthcare application to authenticate users through a trusted third-party identity provider without sharing passwords?
- RADIUS
- LDAP directory sync
- SAML-based federated identity (Correct answer)
- CHAP authentication
Correct answer: SAML-based federated identity
SAML (Security Assertion Markup Language) enables federated single sign-on by passing authentication assertions between an identity provider and service provider.
Question 6: A hospital's network monitoring tool alerts that packet loss has reached 15% on a critical segment. What is the MOST likely clinical impact?
- Slower backup jobs overnight
- Degraded real-time applications such as VoIP and telemedicine (Correct answer)
- Increased storage consumption on file servers
- Expired SSL certificates on web servers
Correct answer: Degraded real-time applications such as VoIP and telemedicine
High packet loss severely degrades real-time, latency-sensitive applications like VoIP nurse call systems and telemedicine video.
Question 7: What is the role of a certificate authority (CA) in a healthcare organization's public key infrastructure (PKI)?
- Stores encrypted copies of user passwords
- Issues and revokes digital certificates that verify identities (Correct answer)
- Routes encrypted traffic between network segments
- Manages symmetric encryption keys for database storage
Correct answer: Issues and revokes digital certificates that verify identities
A CA is a trusted entity that issues digital certificates binding a public key to an identity, enabling verification and secure communications.
A health system wants to prevent unauthorized USB devices from connecting to clinical workstations.
Which control BEST addresses this risk?