โ† All DIS Flashcard Decks

Cybersecurity & Risk Flashcards

7 cards from real DIS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Cybersecurity & Risk flashcards as text
  1. Which network segmentation approach is MOST effective at isolating imaging devices (CT, MRI) from the general hospital network?

    Answer: Implementing a VLAN dedicated to medical imaging equipment

    A dedicated VLAN for medical imaging equipment isolates these devices from general network traffic, reducing attack surface and lateral movement risk.

  2. A DIS practitioner discovers that a former employee's PACS credentials were never deactivated after termination. This violates which security practice?

    Answer: User account lifecycle management / offboarding procedures

    Proper offboarding procedures require immediate deactivation of system credentials when an employee leaves to prevent unauthorized access.

  3. Which term describes the maximum acceptable time that a digital imaging system can be offline following a disaster before causing unacceptable harm?

    Answer: Recovery Time Objective (RTO)

    The Recovery Time Objective (RTO) defines the maximum tolerable downtime before a system must be restored to prevent unacceptable operational impact.

  4. A social engineering attack where an attacker impersonates an IT technician to gain physical access to an imaging server room is called:

    Answer: Pretexting

    Pretexting involves creating a fabricated scenario (pretext) to manipulate individuals into granting access or revealing information.

  5. Which DICOM security profile provides both encryption and integrity protection for image data during transmission?

    Answer: DICOM Secure Transport Connection Profile (TLS)

    The DICOM Secure Transport Connection Profile using TLS provides both encryption and data integrity protection for DICOM communications over networks.

  6. An organization performs quarterly reviews of who has access to the PACS system and removes unnecessary permissions. This process is known as:

    Answer: User access review / recertification

    User access review (recertification) is a periodic process to validate that current access rights are still appropriate and remove unnecessary permissions.

  7. Which of the following BEST describes the concept of 'defense in depth' as applied to a digital imaging environment?

    Answer: Using multiple overlapping security controls so that failure of one does not compromise the system

    Defense in depth employs multiple layers of security controls so that if one layer fails, others continue to protect the system from compromise.