70-413 Exam Professional Standards & Competencies 2 — Questions and Answers
Question 1: When designing a server infrastructure for a regulated healthcare organization, which compliance framework most directly governs how protected health information (PHI) must be secured on Windows servers?
- PCI DSS
- HIPAA Security Rule (Correct answer)
- SOX Title II
- FISMA
Correct answer: HIPAA Security Rule
The HIPAA Security Rule mandates administrative, physical, and technical safeguards for electronic PHI on all covered entity systems.
Question 2: A server infrastructure architect is documenting a design decision. Which artifact best demonstrates professional due diligence by capturing the alternatives considered and the rationale for the chosen approach?
- Network topology diagram
- Architecture Decision Record (ADR) (Correct answer)
- Change advisory board ticket
- Service-level agreement
Correct answer: Architecture Decision Record (ADR)
An Architecture Decision Record (ADR) formally records the context, options evaluated, and justification, demonstrating professional accountability.
Question 3: During capacity planning for a new Hyper-V cluster, you discover that the proposed design will violate the organization's Acceptable Use Policy regarding shared storage encryption. What is the correct professional action?
- Deploy as designed and file a risk acceptance memo after go-live
- Escalate the conflict to the security team before finalizing the design (Correct answer)
- Implement a workaround that bypasses the policy quietly
- Proceed because Hyper-V handles encryption at the VM level automatically
Correct answer: Escalate the conflict to the security team before finalizing the design
Escalating policy conflicts before deployment is the professionally responsible action that protects both the organization and the engineer.
Question 4: Which principle requires that a Windows Server administrator only be granted the minimum permissions necessary to perform their job function?
- Separation of duties
- Defense in depth
- Principle of least privilege (Correct answer)
- Role-based trust
Correct answer: Principle of least privilege
The principle of least privilege limits access rights to only those resources and permissions explicitly required for the job role.
Question 5: An IT professional learns that a colleague has been sharing domain administrator credentials to avoid the approval process. What is the most appropriate first response?
- Ignore it since no breach has occurred yet
- Report the behavior through the organization's incident or ethics channel (Correct answer)
- Confront the colleague publicly in a team meeting
- Change the domain admin password without notifying anyone
Correct answer: Report the behavior through the organization's incident or ethics channel
Reporting through proper channels addresses the security risk and upholds professional ethics without causing unnecessary disruption.
Question 6: When preparing a disaster recovery design for a 70-413 scenario, which professional standard requires you to document the Maximum Tolerable Downtime (MTD) before selecting a recovery strategy?
- ISO 27001 asset classification
- Business Impact Analysis (BIA) (Correct answer)
- ITIL service catalog review
- NIST SP 800-53 control baseline
Correct answer: Business Impact Analysis (BIA)
A Business Impact Analysis (BIA) defines MTD and Recovery Time Objectives, which drive all subsequent DR strategy decisions.
Question 7: A server infrastructure plan is being reviewed by stakeholders who have conflicting requirements. What professional technique best resolves competing priorities while keeping all parties aligned?
- Let the project manager decide unilaterally
- Facilitate a requirements prioritization workshop using MoSCoW or similar method (Correct answer)
- Implement the most technically elegant solution regardless of stakeholder input
- Delay the project until consensus forms naturally
Correct answer: Facilitate a requirements prioritization workshop using MoSCoW or similar method
Structured prioritization techniques like MoSCoW give all stakeholders a voice and produce a documented, agreed-upon priority list.
When designing a server infrastructure for a regulated healthcare organization, which compliance framework most directly governs how protected health information (PHI) must be secured on Windows servers?