Administering Windows Server 2012 Regulatory Frameworks & Compliance 5 — Questions and Answers
Question 1: Fine-grained password policies in Windows Server 2012 that override the domain default policy are stored in which Active Directory object type?
- Group Policy Object (GPO)
- Password Settings Object (PSO) (Correct answer)
- Organizational Unit (OU)
- Site Link Object
Correct answer: Password Settings Object (PSO)
Password Settings Objects (PSOs) store fine-grained password and lockout policies that can be applied directly to users or global security groups.
Question 2: A NIST SP 800-171 compliance requirement mandates multi-factor authentication for privileged accounts. Which Windows Server 2012 feature enables PKI-based smart card MFA?
- Windows Hello
- Active Directory Certificate Services with smart card logon templates (Correct answer)
- Windows Biometric Framework
- Remote Assistance
Correct answer: Active Directory Certificate Services with smart card logon templates
AD CS can issue smart card logon certificates, enabling PKI-based MFA combining something you have (card) and something you know (PIN).
Question 3: For HIPAA compliance, which Windows Server 2012 feature automatically classifies files containing sensitive content like SSNs based on file content patterns?
- File Server Resource Manager with Data Classification Infrastructure (Correct answer)
- Encrypting File System
- Windows Search Service
- Offline Files
Correct answer: File Server Resource Manager with Data Classification Infrastructure
FSRM's Data Classification Infrastructure scans file content and applies classification properties, enabling automated policy-driven protection of sensitive data.
Question 4: Which Windows Server 2012 auditing category records when a user exercises sensitive privileges such as backing up files or loading a device driver?
- Audit Logon Events
- Audit Object Access
- Audit Privilege Use (Correct answer)
- Audit System Events
Correct answer: Audit Privilege Use
Audit Privilege Use records when sensitive user rights are exercised, helping detect abuse of privileged capabilities for compliance monitoring.
Question 5: Which Windows Server 2012 role enables federated identity across organizational boundaries so partner staff can access compliance portals without separate accounts?
- Active Directory Lightweight Directory Services (AD LDS)
- Active Directory Federation Services (AD FS) (Correct answer)
- Active Directory Rights Management Services (AD RMS)
- Active Directory Certificate Services (AD CS)
Correct answer: Active Directory Federation Services (AD FS)
AD FS enables federated SSO using claims-based identity, allowing partner organizations to authenticate with their own credentials across trust boundaries.
Question 6: The NIST Cybersecurity Framework 'Protect' function requires limiting system access to authorized hours. Which Windows Server 2012 AD setting enforces time-of-day logon restrictions?
- Account Expiration Date
- Logon Hours restriction in Active Directory user properties (Correct answer)
- Dynamic Access Control time conditions
- Windows Firewall time-based rules
Correct answer: Logon Hours restriction in Active Directory user properties
Logon Hours in Active Directory user properties restricts when an account can authenticate, limiting access to approved business hours.
Question 7: Which Windows Server 2012 feature exports Group Policy baselines in SCAP format for use with third-party compliance scanners to automate NIST benchmark assessments?
- Windows Server Update Services
- Microsoft Baseline Security Analyzer (MBSA)
- Security Compliance Manager (SCM) (Correct answer)
- Windows Assessment and Deployment Kit
Correct answer: Security Compliance Manager (SCM)
Security Compliance Manager can export security baselines in SCAP format, allowing automated compliance scanning against NIST or CIS benchmarks.
Fine-grained password policies in Windows Server 2012 that override the domain default policy are stored in which Active Directory object type?