/40

Cybersecurity Quiz

1. Which of the following cybersecurity objectives ensures that only authorized users can access specific data or resources?

2. Which of the following cybersecurity objectives is primarily focused on ensuring that data or communication is genuine and from a verified source?

3. Which is the correct order of the main steps in managing cybersecurity risk?

4. In the NIST SP 800-53 Risk Management Framework (SPDF), which of the following correctly represents the order of steps from organizational readiness to handling vulnerabilities?

5. Which of the following cybersecurity activity(ies) is/are conducted by the manufacturer?

6. What is the primary purpose of threat modeling in medical device cybersecurity management?

7. According to FDA post-market guidance, how should cybersecurity risks be assessed in medical devices?

8. What is the primary purpose of a data flow diagram in cybersecurity management?

9. In the context of FDA's Content of Premarket Submissions for Management of Cybersecurity in Medical Devices, what is an "asset"?

10. Which of the following are examples of physical assets in a cybersecurity context?

11. Which of the following are examples of information assets in cybersecurity?

12. What is an attack vector in cybersecurity?

13. Which of the following correctly lists the attack vector types defined in CVSS 3.1?

14. Which of the following is an example of a network attack vector according to CVSS 3.1?

15. Which of the following is an example of an adjacent network attack vector according to CVSS 3.1?

16. Which of the following is an example of a local attack vector according to CVSS 3.1?

17. Which of the following is an example of a physical attack vector according to CVSS 3.1?

18. What is the purpose of an MDS2 (Manufacturer Disclosure Statement for Medical Device Security) form?

19. What is the purpose of MS STRIDE in risk identification?

20. In the context of STRIDE Threat Mode, what does "Spoofing" refer to?

21. Which of the following is an example of Tampering with data in the STRIDE Threat Model?

22. Which of the following is an example of a repudiation threat in the STRIDE threat model?

23. Which of the following is NOT an example of information disclosure in a medical device according to STRIDE?

24. Which of the following is an example of a Denial of Service (DoS) attack on a medical device?

25. Which of the following is an example of elevation of privileges in a medical device according to STRIDE?

26. How does AAMI TIR57:2016 recommend evaluating risk in medical device cybersecurity?

27. What is the primary function of the MITRE system in cybersecurity?

28. Which of the following is an example of a mitigation strategy for preventing spoofing identity attacks?

29. Which of the following is an example of a mitigation strategy to prevent tampering with data?

30. Which of the following is an effective mitigation strategy to prevent repudiation in a medical device?

31. Which of the following is an effective mitigation strategy to prevent information disclosure in a medical device?

32. Which of the following is an effective mitigation strategy to defend against denial of service (DoS) attacks on a medical device?

33. Which of the following is an effective mitigation strategy to prevent elevation of privileges in a medical device?

34. What is vulnerability testing in cybersecurity?

35. What is a penetration test in cybersecurity?

36. What is fuzz testing in cybersecurity?

37. What is the primary goal of the FDA's post-market cybersecurity program for medical devices?

38. Which of the following are potential risks introduced by design changes?

39. In case of uncontrolled risk being identified, what will be the timeline to communicate with customer about the remediation plan?

40. What is the main purpose of becoming a member of an Information Sharing and Analysis Organization (ISAO)?

Your score is

0%