Administering Windows Server 2012 Regulatory Frameworks & Compliance 2 — Questions and Answers
Question 1: Under HIPAA, which Windows Server 2012 feature maintains an audit trail of who accessed files containing Protected Health Information (PHI)?
- BitLocker Drive Encryption
- Object Access Auditing via Group Policy (Correct answer)
- Network Load Balancing
- Windows Deployment Services
Correct answer: Object Access Auditing via Group Policy
Object Access Auditing in Group Policy records access to files and folders containing PHI, satisfying HIPAA audit control requirements.
Question 2: A compliance officer requires that all failed logon attempts be recorded centrally from multiple servers. Which Windows Server 2012 feature best fulfills this?
- Windows Firewall with Advanced Security
- Network Policy Server (NPS)
- Windows Event Forwarding (WEF) (Correct answer)
- DirectAccess
Correct answer: Windows Event Forwarding (WEF)
Windows Event Forwarding collects security events from multiple servers to a central collector, enabling centralized failed logon monitoring.
Question 3: SOX compliance requires that no single user can both create and approve financial transactions. This control principle is called:
- Least privilege
- Defense in depth
- Separation of duties (Correct answer)
- Need to know
Correct answer: Separation of duties
Separation of duties prevents a single individual from having enough access to commit and conceal fraud, a core SOX control requirement.
Question 4: Which Windows Server 2012 feature applies file access policies dynamically based on user department and data classification attributes for regulatory compliance?
- Encrypting File System (EFS)
- Dynamic Access Control (DAC) (Correct answer)
- BitLocker To Go
- Distributed File System (DFS)
Correct answer: Dynamic Access Control (DAC)
Dynamic Access Control uses claims-based policies that automatically enforce access based on user attributes and resource classification.
Question 5: A healthcare organization must encrypt data at rest on Windows Server 2012 file servers to comply with HIPAA. Which tool is most appropriate?
- IPsec
- SSL/TLS
- BitLocker Drive Encryption (Correct answer)
- PPTP VPN
Correct answer: BitLocker Drive Encryption
BitLocker Drive Encryption protects data at rest on server volumes, satisfying HIPAA requirements for encryption of stored PHI.
Question 6: Which Windows Server 2012 auditing subcategory tracks changes made to Active Directory objects and their attributes for compliance purposes?
- Audit Account Logon Events
- Audit Directory Service Changes (Correct answer)
- Audit Privilege Use
- Audit Process Tracking
Correct answer: Audit Directory Service Changes
Audit Directory Service Changes records modifications to AD objects and attributes, providing a compliance audit trail for directory changes.
Question 7: For compliance with NIST SP 800-53, an administrator must enforce an account lockout after five failed logon attempts. Where is this configured in Windows Server 2012?
- Local Security Policy > Security Options
- Account Lockout Policy under Password Policy in Group Policy
- Account Lockout Policy under Account Policies in Group Policy (Correct answer)
- Active Directory Users and Computers account properties
Correct answer: Account Lockout Policy under Account Policies in Group Policy
Account Lockout Policy under Account Policies in Group Policy sets the lockout threshold, duration, and reset counter for domain accounts.
Under HIPAA, which Windows Server 2012 feature maintains an audit trail of who accessed files containing Protected Health Information (PHI)?