nerdexam
CompTIA

CAS-003 · Question #551

A pharmacy gives its clients online access to their records and the ability to review bills and make payments. A new SSL vulnerability on a special platform was discovered, allowing an attacker to…

The correct answer is A. Cardholder data C. Personal health information. A pharmacy's online payment and health records portal exposes cardholder data and personal health information when an SSL vulnerability allows an attacker to intercept encrypted traffic.

Risk Management

Question

A pharmacy gives its clients online access to their records and the ability to review bills and make payments. A new SSL vulnerability on a special platform was discovered, allowing an attacker to capture the data between the end user and the web server providing these services. After invest the new vulnerability, it was determined that the web services providing are being impacted by this new threat. Which of the following data types a MOST likely at risk of exposure based on this new threat? (Select TWO)

Options

  • ACardholder data
  • Bintellectual property
  • CPersonal health information
  • DEmployee records
  • ECorporate financial data

How the community answered

(21 responses)
  • A
    76% (16)
  • B
    14% (3)
  • D
    5% (1)
  • E
    5% (1)

Why each option

A pharmacy's online payment and health records portal exposes cardholder data and personal health information when an SSL vulnerability allows an attacker to intercept encrypted traffic.

ACardholder dataCorrect

The pharmacy accepts online payments, meaning cardholder data including card numbers and verification values is transmitted between the client browser and the web server and is directly captured by an attacker exploiting the SSL interception vulnerability.

Bintellectual property

Intellectual property such as proprietary formulas or trade secrets is not transmitted through a client-facing pharmacy billing and records web portal.

CPersonal health informationCorrect

Patient prescription and medical record data accessed through the pharmacy portal constitutes personal health information protected under HIPAA, and this PHI is transmitted over the vulnerable SSL channel, making it directly at risk of interception and exposure.

DEmployee records

Employee records are internal HR data that are not exposed through the pharmacy's client-facing online services.

ECorporate financial data

Corporate financial data refers to internal business accounting information, not the client payment transactions processed through the pharmacy's web portal.

Concept tested: Data classification risk in SSL/TLS interception attacks

Source: https://www.hhs.gov/hipaa/for-professionals/security/guidance/index.html

Topics

#SSL/TLS vulnerability#PHI#cardholder data#data classification

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice