โ† All 70-413 Exam Flashcard Decks

Regulatory Frameworks & Compliance Flashcards

7 cards from real 70-413 Exam practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Regulatory Frameworks & Compliance flashcards as text
  1. A healthcare organization must ensure that PHI stored on laptops is protected if a device is lost or stolen. Which Windows Server feature best satisfies this HIPAA requirement?

    Answer: BitLocker Drive Encryption

    BitLocker Drive Encryption protects data at rest by encrypting entire volumes, satisfying HIPAA's requirement to safeguard PHI on portable devices.

  2. Under PCI DSS, cardholder data must be encrypted in transit. Which Windows Server role provides certificate-based encryption to meet this requirement?

    Answer: Active Directory Certificate Services

    Active Directory Certificate Services (AD CS) issues digital certificates that enable TLS/SSL encryption for data in transit, satisfying PCI DSS transport encryption requirements.

  3. A SOX audit requires that changes to financial application servers be logged with before-and-after values. Which auditing subcategory should be enabled?

    Answer: Audit Object Access

    Audit Object Access tracks reads, writes, and modifications to files and registry keys, capturing before-and-after change details required for SOX compliance.

  4. An organization subject to FISMA must implement continuous monitoring. Which Windows Server component provides real-time security event collection across multiple servers?

    Answer: Windows Event Collector (WEF)

    Windows Event Forwarding (WEF) aggregates security events from multiple servers to a central collector, enabling the continuous monitoring required by FISMA.

  5. PCI DSS Requirement 6 mandates that systems are protected against known vulnerabilities. Which Windows Server feature automates patch deployment to meet this requirement?

    Answer: Windows Server Update Services (WSUS)

    WSUS centralizes and automates the deployment of Microsoft patches and updates, directly addressing PCI DSS Requirement 6 for vulnerability management.

  6. A legal firm must ensure that confidential documents cannot be printed or forwarded outside the organization. Which technology enforces these information rights?

    Answer: Active Directory Rights Management Services (AD RMS)

    AD RMS applies persistent usage policies to documents that travel with the file, preventing unauthorized printing, forwarding, or copying regardless of location.

  7. Under HIPAA's Security Rule, an organization must implement access controls so users only access the minimum necessary PHI. Which Group Policy setting enforces this principle on shared file servers?

    Answer: NTFS permissions combined with Access-Based Enumeration

    NTFS permissions restrict access to only authorized users, and Access-Based Enumeration hides folders the user cannot access, implementing least-privilege access to PHI.