Administering Windows Server 2012 Risk Assessment & Management 2 — Questions and Answers
Question 1: A security audit reveals that several Windows Server 2012 systems store sensitive data without BitLocker encryption. Which risk response strategy does enabling BitLocker represent?
- Risk acceptance
- Risk avoidance
- Risk mitigation (Correct answer)
- Risk transference
Correct answer: Risk mitigation
Enabling BitLocker reduces the impact of data theft by encrypting the data, which is a risk mitigation strategy.
Question 2: Your organization's Windows Server 2012 infrastructure undergoes a Business Impact Analysis (BIA). Which metric defines the maximum tolerable downtime before business operations are severely impacted?
- Recovery Point Objective (RPO)
- Mean Time Between Failures (MTBF)
- Maximum Tolerable Downtime (MTD) (Correct answer)
- Recovery Time Objective (RTO)
Correct answer: Maximum Tolerable Downtime (MTD)
MTD defines the absolute maximum time a business function can be unavailable before causing irreparable harm.
Question 3: During a risk assessment of Active Directory, you identify that a compromised domain admin account could affect all 500 servers. This scenario best illustrates which risk concept?
- Single point of failure (Correct answer)
- Residual risk
- Risk appetite
- Inherent risk
Correct answer: Single point of failure
A single domain admin account having unrestricted access to all servers represents a single point of failure in the security architecture.
Question 4: A Windows Server 2012 administrator uses the Security Configuration Wizard (SCW) to reduce the server attack surface. In risk terms, SCW primarily helps with:
- Transferring risk to a third party
- Reducing the threat landscape by disabling unneeded services (Correct answer)
- Calculating annualized loss expectancy
- Documenting residual risk for management acceptance
Correct answer: Reducing the threat landscape by disabling unneeded services
SCW reduces attack surface by disabling unnecessary roles, features, and services, thereby shrinking the threat landscape.
Question 5: Your risk register shows a vulnerability in Windows Server 2012 RDP with a CVSS score of 9.8. Which factor should most influence how quickly you remediate this?
- The number of servers in the domain
- The exploitability and impact reflected in the high CVSS score (Correct answer)
- Whether the vulnerability has a vendor patch
- The cost of the affected servers
Correct answer: The exploitability and impact reflected in the high CVSS score
A CVSS score of 9.8 indicates near-maximum exploitability and impact, making it the primary driver for urgent remediation priority.
Question 6: Management accepts the risk of not patching a low-severity Windows Server 2012 vulnerability due to potential application compatibility issues. What document should formally capture this decision?
- Change management request
- Risk acceptance statement signed by the data owner (Correct answer)
- Vulnerability scan report
- System security plan amendment
Correct answer: Risk acceptance statement signed by the data owner
A formal risk acceptance statement signed by the data owner documents accountability for the decision to accept known risk.
Question 7: When performing quantitative risk analysis for a Windows Server 2012 file server, you calculate an Asset Value of $200,000 and an Exposure Factor of 40%. What is the Single Loss Expectancy (SLE)?
- $40,000
- $80,000 (Correct answer)
- $120,000
- $200,000
Correct answer: $80,000
SLE = Asset Value × Exposure Factor = $200,000 × 0.40 = $80,000.
A security audit reveals that several Windows Server 2012 systems store sensitive data without BitLocker encryption.
Which risk response strategy does enabling BitLocker represent?