Administering Windows Server 2012 Risk Assessment & Management 4 — Questions and Answers
Question 1: Your Windows Server 2012 disaster recovery plan specifies an RPO of 4 hours. Which backup strategy best satisfies this requirement?
- Weekly full backups only
- Daily incremental backups with a 24-hour retention
- Backup jobs scheduled every 4 hours or less (Correct answer)
- Monthly full backups with daily differential backups
Correct answer: Backup jobs scheduled every 4 hours or less
An RPO of 4 hours requires backups to occur at least every 4 hours so no more than 4 hours of data can be lost in a disaster.
Question 2: A Windows Server 2012 administrator needs to classify servers by risk level. Which classification factor is MOST important for determining risk priority?
- Server hardware age
- Data sensitivity and business criticality (Correct answer)
- Number of users accessing the server
- Physical location of the server
Correct answer: Data sensitivity and business criticality
Data sensitivity and business criticality are the primary factors for risk classification because they determine potential impact of a breach.
Question 3: Management asks you to conduct a qualitative risk assessment for Windows Server 2012 systems. Which approach is characteristic of qualitative analysis?
- Calculating exact dollar values for SLE and ALE
- Using likelihood and impact ratings such as High, Medium, Low (Correct answer)
- Measuring MTBF and MTTR from historical data
- Determining exact asset values and exposure factors
Correct answer: Using likelihood and impact ratings such as High, Medium, Low
Qualitative risk analysis uses descriptive scales like High/Medium/Low for likelihood and impact rather than precise monetary values.
Question 4: After a risk assessment, you recommend purchasing cyber liability insurance to cover potential losses from a Windows Server 2012 data breach. This is an example of:
- Risk avoidance
- Risk mitigation
- Risk transference (Correct answer)
- Risk acceptance
Correct answer: Risk transference
Purchasing insurance transfers the financial consequences of a risk event to a third party (the insurer).
Question 5: A threat intelligence report indicates that a known threat actor is actively targeting Windows Server 2012 RDP vulnerabilities. In risk terms, this information affects which component of the risk equation?
- Vulnerability score
- Asset value
- Threat likelihood (probability) (Correct answer)
- Exposure factor
Correct answer: Threat likelihood (probability)
Active targeting by a known threat actor increases the probability that the vulnerability will be exploited, raising the threat likelihood.
Question 6: Which Windows Server 2012 feature would BEST help an administrator implement a risk-based patch management program by identifying missing security updates?
- Windows Deployment Services (WDS)
- Microsoft Baseline Security Analyzer (MBSA) (Correct answer)
- Active Directory Certificate Services (AD CS)
- Network Load Balancing (NLB)
Correct answer: Microsoft Baseline Security Analyzer (MBSA)
MBSA scans Windows systems and identifies missing security patches and misconfigurations, directly supporting risk-based patch prioritization.
Question 7: During a risk review, you find that a Windows Server 2012 web server has 15 open ports, most of which are unused. The BEST immediate risk reduction action is:
- Document the open ports in the risk register
- Disable or block all unnecessary open ports via Windows Firewall (Correct answer)
- Accept the risk because the server is behind a perimeter firewall
- Purchase an IDS to monitor all 15 ports
Correct answer: Disable or block all unnecessary open ports via Windows Firewall
Closing unnecessary ports directly reduces the attack surface and eliminates exposure from services that do not need to be accessible.
Your Windows Server 2012 disaster recovery plan specifies an RPO of 4 hours.
Which backup strategy best satisfies this requirement?