Administering Windows Server 2012 Regulatory Frameworks & Compliance 3 — Questions and Answers
Question 1: PCI DSS Requirement 3 mandates protection of stored cardholder data. Which Windows Server 2012 feature best satisfies this for local disk storage?
- Windows Defender
- Network Access Protection
- BitLocker Drive Encryption (Correct answer)
- Windows Resource Monitor
Correct answer: BitLocker Drive Encryption
BitLocker Drive Encryption encrypts entire volumes, protecting stored cardholder data if a server is physically compromised.
Question 2: For PCI DSS compliance, which remote access protocol should be DISABLED on Windows Server 2012 because it transmits credentials in cleartext?
- HTTPS
- SNMPv3
- Telnet (Correct answer)
- SFTP
Correct answer: Telnet
Telnet transmits all data including credentials in cleartext and violates PCI DSS Requirement 2.2.7, which mandates encrypted administration.
Question 3: An administrator deploys Active Directory Rights Management Services (AD RMS) to protect sensitive documents. Which compliance requirement does this primarily address?
- Physical security controls
- Information rights management and data loss prevention (Correct answer)
- Network segmentation
- Patch management
Correct answer: Information rights management and data loss prevention
AD RMS applies persistent usage policies to documents, preventing unauthorized access or redistribution even after files leave the organization.
Question 4: Which Windows Server 2012 Certificate Services configuration is required to issue S/MIME certificates for encrypted email compliance?
- Online Responder role service
- Certificate Enrollment Web Service only
- Active Directory Certificate Services with an Enterprise CA (Correct answer)
- Network Device Enrollment Service (NDES)
Correct answer: Active Directory Certificate Services with an Enterprise CA
An Enterprise CA integrated with AD can auto-enroll S/MIME certificates to users from templates, enabling compliant encrypted email.
Question 5: For FERPA compliance, an educational institution wants file-level access control on student records stored on a Windows Server 2012 file share. Which feature enforces this?
- NTFS permissions and Access Control Lists (Correct answer)
- BitLocker Network Unlock
- Windows Server Backup
- BranchCache
Correct answer: NTFS permissions and Access Control Lists
NTFS permissions and ACLs control exactly which user accounts and groups can read, write, or modify files containing student records.
Question 6: When configuring IPsec for PCI DSS network isolation between cardholder data systems on Windows Server 2012, which console is used to create Connection Security Rules?
- Network Policy Server
- Windows Firewall with Advanced Security (Correct answer)
- Routing and Remote Access
- Active Directory Sites and Services
Correct answer: Windows Firewall with Advanced Security
Windows Firewall with Advanced Security includes Connection Security Rules that configure IPsec authentication and encryption between hosts.
Question 7: A compliance audit requires proof that servers are kept current with security patches. Which Windows Server 2012 role provides centralized patch compliance reporting?
- Active Directory Federation Services
- Windows Server Update Services (WSUS) (Correct answer)
- Remote Desktop Services
- Volume Activation Services
Correct answer: Windows Server Update Services (WSUS)
WSUS provides centralized patch management and compliance reporting showing which computers have or have not installed required updates.
PCI DSS Requirement 3 mandates protection of stored cardholder data.
Which Windows Server 2012 feature best satisfies this for local disk storage?