โ† All DIS Flashcard Decks

Network Security & Protocols Flashcards

7 cards from real DIS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Network Security & Protocols flashcards as text
  1. Which firewall rule configuration would BEST protect a PACS server while allowing authorized radiology workstations to retrieve images?

    Answer: Allow inbound DICOM traffic only from whitelisted radiology workstation IPs

    Whitelisting specific IP addresses of authorized workstations ensures only approved devices can initiate DICOM connections to the PACS server.

  2. A DIS technician discovers the imaging network has an open Telnet service on a modality workstation. What is the recommended remediation?

    Answer: Disable Telnet and replace with SSH for remote management

    Telnet transmits data including credentials in plaintext; SSH provides encrypted, authenticated remote management as its secure replacement.

  3. What is the purpose of network intrusion detection system (NIDS) placement on a medical imaging network?

    Answer: To monitor network traffic for suspicious patterns that may indicate an attack

    A NIDS passively monitors network traffic and generates alerts when it detects patterns matching known attack signatures or anomalies.

  4. Which authentication method provides the STRONGEST security for remote access to a PACS administrator console?

    Answer: Multi-factor authentication (MFA) combining password and hardware token

    MFA requires multiple verification factors, so even if a password is compromised, unauthorized access is still prevented by the second factor.

  5. An imaging facility wants to ensure that only authenticated NTP servers synchronize time on DICOM devices. Which protocol version addresses this?

    Answer: NTPv4 with symmetric key or autokey authentication

    NTPv4 supports symmetric key and autokey authentication mechanisms that verify the identity of time servers before accepting synchronization.

  6. What is the security implication of allowing unrestricted outbound internet access from a PACS server?

    Answer: Malware could exfiltrate PHI or receive command-and-control instructions

    Unrestricted outbound access gives malware on a compromised PACS server a channel to send PHI to external attackers or receive instructions.

  7. Which log source would BEST help a DIS specialist detect brute-force login attempts against a PACS server?

    Answer: Authentication logs showing repeated failed login attempts from a single IP

    Authentication logs capture failed login events; a high frequency of failures from one source is a classic indicator of brute-force activity.

Network Security & Protocols Flashcards โ€” DIS Study Cards with Answers