Cybersecurity & Risk Flashcards
7 cards from real DIS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Cybersecurity & Risk flashcards as text
A DIS professional is asked to classify imaging data by sensitivity level. Which data classification level would apply to identifiable patient X-ray images?
Answer: Confidential / Protected Health Information
Identifiable patient imaging data constitutes Protected Health Information (PHI) under HIPAA and must be classified as confidential with strict access controls.
Which cryptographic method is BEST suited for encrypting large volumes of stored digital imaging files efficiently?
Answer: AES symmetric encryption
AES symmetric encryption is computationally efficient and widely used for encrypting large datasets such as imaging archives at rest.
An imaging center's risk assessment identifies that its PACS vendor no longer provides security updates. This is BEST described as:
Answer: End-of-life (EOL) software risk
End-of-life software risk occurs when a vendor discontinues support and patches, leaving known vulnerabilities permanently unaddressed.
Which security control is considered a PREVENTIVE control in the context of cybersecurity?
Answer: Firewall rule blocking unauthorized ports
A firewall blocking unauthorized ports prevents attacks from occurring, making it a preventive control rather than a detective or corrective one.
A medical imaging organization stores backups in the same building as the primary servers. Which risk does this create?
Answer: Single point of failure for site-level disasters
Co-located backups are vulnerable to the same site-level events (fire, flood, power failure) as primary systems, creating a single point of failure.
What does a penetration test (pen test) evaluate in an imaging IT environment?
Answer: How well the system resists real-world attack techniques
Penetration testing simulates real-world attacks against systems to identify exploitable vulnerabilities before malicious actors do.
In a risk treatment plan, choosing to purchase cyber liability insurance represents which risk response strategy?
Answer: Risk transfer
Purchasing insurance transfers the financial consequences of a risk event to a third party, representing the risk transfer strategy.