Network Security & Protocols Flashcards
7 cards from real DIS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Network Security & Protocols flashcards as text
Which HIPAA Security Rule safeguard directly applies to encrypting ePHI transmitted over a hospital imaging network?
Answer: Technical safeguard: Transmission Security (§164.312(e))
The Transmission Security technical safeguard requires encryption or equivalent protection for ePHI transmitted over electronic networks.
A hospital implements certificate-based mutual TLS (mTLS) for DICOM connections. What security property does this add beyond server-only TLS?
Answer: Both the server and client authenticate each other using digital certificates
Mutual TLS requires both parties to present valid certificates, ensuring that only authenticated, authorized devices can establish DICOM connections.
What is the role of a Certificate Authority (CA) in securing DICOM network communications?
Answer: It issues and validates digital certificates that establish trust between DICOM entities
A CA signs digital certificates that bind a public key to an entity's identity, allowing DICOM systems to verify they are communicating with legitimate partners.
Which attack exploits vulnerabilities in the DNS system to redirect imaging workstation queries for the PACS hostname to a malicious server?
Answer: DNS poisoning (cache poisoning)
DNS cache poisoning corrupts DNS resolver caches with fraudulent records, redirecting legitimate domain queries to attacker-controlled IP addresses.
A DIS specialist wants to verify that a PACS server's TLS certificate has not been revoked. Which protocol is used for real-time certificate status checking?
Answer: OCSP (Online Certificate Status Protocol)
OCSP allows a client to query a CA's responder in real time to determine whether a specific certificate is currently valid or has been revoked.
Which security mechanism prevents replay attacks on DICOM TLS sessions?
Answer: TLS session nonces and sequence numbers that make each handshake unique
TLS uses random nonces in each handshake and sequence numbers in records, ensuring that captured session data cannot be replayed to impersonate a valid session.
A hospital's imaging network shows periodic high-volume UDP traffic to external IPs from a modality workstation. What type of security incident does this MOST likely indicate?
Answer: The workstation may be participating in a DDoS amplification attack or is infected with malware phoning home
Unexpected high-volume UDP traffic to external addresses is a common indicator of DDoS botnet participation or malware beaconing to command-and-control servers.