Administering Windows Server 2012 Risk Assessment & Management 5 — Questions and Answers
Question 1: A Windows Server 2012 administrator is tasked with building a risk treatment plan. Which of the following is NOT a recognized risk treatment option?
- Risk mitigation
- Risk transference
- Risk elimination (Correct answer)
- Risk acceptance
Correct answer: Risk elimination
Risk elimination is not a standard risk treatment option; the accepted options are mitigation, transference, acceptance, and avoidance.
Question 2: Your organization conducts a Delphi technique session to assess risk in its Windows Server 2012 environment. The Delphi technique is characterized by:
- Automated vulnerability scanning of all servers
- Iterative anonymous expert consensus gathering (Correct answer)
- Real-time penetration testing by ethical hackers
- Statistical analysis of historical incident data
Correct answer: Iterative anonymous expert consensus gathering
The Delphi technique uses multiple rounds of anonymous expert surveys to reach consensus on risk assessments without groupthink influence.
Question 3: A Windows Server 2012 domain controller stores the ntds.dit file. During a risk assessment, this file is identified as a critical asset. The ntds.dit file contains:
- IIS web application configurations
- All Active Directory user accounts, password hashes, and group memberships (Correct answer)
- DHCP scope and lease information
- Windows Server event log archives
Correct answer: All Active Directory user accounts, password hashes, and group memberships
The ntds.dit file is the Active Directory database containing all domain user accounts, password hashes, and group membership data.
Question 4: After implementing role-based access control (RBAC) on Windows Server 2012, some risk remains because administrators still have broad access within their roles. This remaining risk is called:
- Inherent risk
- Residual risk (Correct answer)
- Secondary risk
- Transferred risk
Correct answer: Residual risk
Residual risk is what remains after controls such as RBAC are implemented and represents risk that has not been fully eliminated.
Question 5: A risk assessment for a Windows Server 2012 environment uses a 5×5 risk matrix. If a threat has an Impact rating of 4 and a Likelihood rating of 3, the risk score is:
- 7
- 12 (Correct answer)
- 15
- 20
Correct answer: 12
In a standard risk matrix, Risk Score = Impact × Likelihood = 4 × 3 = 12.
Question 6: Management wants to avoid the risk of Windows Server 2012 reaching end-of-support status. Which action represents the risk avoidance strategy?
- Purchasing Extended Security Updates (ESU) from Microsoft
- Migrating all workloads to Windows Server 2019 before end-of-support (Correct answer)
- Documenting the risk and accepting it in writing
- Deploying a third-party security product to compensate
Correct answer: Migrating all workloads to Windows Server 2019 before end-of-support
Migrating to a supported OS version eliminates the end-of-support risk entirely, which is the definition of risk avoidance.
Question 7: Which Windows Server 2012 auditing category should be enabled to detect unauthorized privilege escalation attempts as part of a risk monitoring program?
- Object Access auditing
- Logon/Logoff auditing
- Privilege Use auditing (Correct answer)
- Detailed Tracking auditing
Correct answer: Privilege Use auditing
Privilege Use auditing records events when a user exercises a user right or privilege, enabling detection of unauthorized escalation attempts.
A Windows Server 2012 administrator is tasked with building a risk treatment plan.
Which of the following is NOT a recognized risk treatment option?