70-413 Exam Professional Standards & Competencies 3 — Questions and Answers
Question 1: Which of the following best describes 'separation of duties' in a Windows Server environment?
- Splitting network traffic across multiple NICs for redundancy
- Ensuring no single person can complete a sensitive task without another person's involvement (Correct answer)
- Assigning separate GPOs to workstations and servers
- Configuring distinct VLAN segments for each server role
Correct answer: Ensuring no single person can complete a sensitive task without another person's involvement
Separation of duties requires that critical processes involve multiple individuals, reducing the risk of fraud or error by a single administrator.
Question 2: A company must retain server event logs for seven years due to financial audit regulations. Which competency area does designing this retention architecture fall under?
- Capacity planning
- Compliance and regulatory adherence (Correct answer)
- High-availability engineering
- Change management
Correct answer: Compliance and regulatory adherence
Designing log retention to meet audit timelines is a core competency within compliance and regulatory adherence for infrastructure architects.
Question 3: During a post-incident review (PIR) of a server outage, the team discovers the root cause was an undocumented manual change. Which professional process, if followed, would most likely have prevented this?
- Implementing RAID on all production servers
- Enforcing a formal change management process requiring pre-approval and documentation (Correct answer)
- Increasing the number of monitoring agents
- Running weekly vulnerability scans
Correct answer: Enforcing a formal change management process requiring pre-approval and documentation
A formal change management process requires documentation and approval before any production change, creating an audit trail that prevents undocumented modifications.
Question 4: An architect is asked to recommend a server deployment in a new country where data sovereignty laws prohibit transferring personal data outside national borders. Which professional responsibility is most relevant?
- Optimizing WAN latency between data centers
- Understanding and complying with local data residency and privacy regulations (Correct answer)
- Selecting the most cost-effective hypervisor platform
- Designing for maximum VM consolidation ratios
Correct answer: Understanding and complying with local data residency and privacy regulations
Data sovereignty laws are legal requirements that architects must understand and design for when deploying infrastructure across jurisdictions.
Question 5: A junior engineer proposes skipping documentation to meet a tight deployment deadline. As the senior architect, what is the most professionally responsible response?
- Agree, since documentation can be written retroactively after deployment
- Reject the proposal and advocate for adequate time to produce essential documentation (Correct answer)
- Delegate documentation to the junior engineer to complete after hours
- Skip infrastructure diagrams but keep the runbook
Correct answer: Reject the proposal and advocate for adequate time to produce essential documentation
Professional standards require adequate documentation as part of delivery; skipping it creates long-term operational and security risks that outweigh short-term schedule gains.
Question 6: Which professional certification body publishes the 'Code of Ethics and Professional Conduct' that many IT infrastructure professionals are expected to follow?
- IEEE Computer Society
- Project Management Institute (PMI)
- ISC² (Correct answer)
- CompTIA
Correct answer: ISC²
ISC² publishes a widely recognized Code of Ethics that certified professionals, including CISSPs, are required to uphold.
Question 7: When a server infrastructure design includes third-party cloud services, which professional artifact formally defines each party's responsibilities for availability, security, and support?
- Statement of Work (SOW)
- Memorandum of Understanding (MOU)
- Service Level Agreement (SLA) and shared responsibility matrix (Correct answer)
- RACI chart
Correct answer: Service Level Agreement (SLA) and shared responsibility matrix
An SLA combined with a shared responsibility matrix formally delineates what the cloud provider and customer each own for uptime, security, and incident response.
Which of the following best describes 'separation of duties' in a Windows Server environment?