← All Installing and Configuring Windows Server 2012 Exam Flashcard Decks

Regulatory Frameworks & Compliance Flashcards

7 cards from real Installing and Configuring Windows Server 2012 Exam practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Regulatory Frameworks & Compliance flashcards as text
  1. Which Windows Server 2012 feature allows you to create a Just Enough Administration (JEA) model by restricting what cmdlets a delegated admin can run in PowerShell?

    Answer: PowerShell Constrained Language Mode via Group Policy AppLocker rules

    AppLocker can restrict PowerShell to Constrained Language Mode, limiting available cmdlets to only what is needed for a role.

  2. A compliance requirement mandates that all DNS queries from domain clients be logged for forensic purposes. Which Windows Server 2012 DNS feature supports this?

    Answer: DNS Debug Logging (DNS server diagnostic logging)

    DNS debug logging records all queries and responses to a log file, enabling forensic review of DNS activity.

  3. Under NIST 800-171, CUI must be protected with FIPS 140-2 validated encryption. How do you enable FIPS compliance mode in Windows Server 2012?

    Answer: Enable the 'System cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing' policy setting

    The FIPS policy setting in Security Options forces Windows components to use only FIPS 140-2 validated cryptographic modules.

  4. An auditor requires proof that your Windows Server 2012 servers have no unnecessary services running, per CIS Benchmark guidance. Which tool quickly identifies and disables unneeded roles and services?

    Answer: Security Configuration Wizard (SCW)

    SCW analyzes the server's role and disables services, ports, and features not required, aligning with CIS attack-surface reduction guidance.

  5. GDPR requires that personal data breaches be detected and reported within 72 hours. Which Windows Server 2012 component helps detect unauthorized data access in near real-time?

    Answer: File Server Resource Manager (FSRM) with file screen alerts

    FSRM file screens can trigger email alerts when unauthorized file types or access patterns are detected on file servers.

  6. Which Windows Server 2012 Active Directory feature lets you apply a stricter password policy to a subset of privileged users without changing the domain-wide Default Domain Policy?

    Answer: Fine-Grained Password Policies (Password Settings Objects)

    Fine-Grained Password Policies use Password Settings Objects (PSOs) linked to users or global security groups to apply different policies within the same domain.

  7. For compliance with US Executive Order 13556 on CUI, which Windows Server 2012 capability helps classify and label sensitive files stored on file servers?

    Answer: Dynamic Access Control (DAC) with File Classification Infrastructure (FCI)

    DAC with FCI automatically classifies files based on content or properties and can apply access policies based on those classifications.