← All Installing and Configuring Windows Server 2012 Exam Flashcard Decks

Risk Assessment & Management Flashcards

7 cards from real Installing and Configuring Windows Server 2012 Exam practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Risk Assessment & Management flashcards as text
  1. A security administrator needs to quantify the potential financial loss from a server failure. Which metric represents the estimated monetary loss from a single occurrence of a risk event?

    Answer: Single Loss Expectancy (SLE)

    Single Loss Expectancy (SLE) represents the monetary loss expected from a single occurrence of a specific risk event.

  2. During a Windows Server 2012 risk assessment, which type of control is a firewall primarily classified as?

    Answer: Preventive

    A firewall is a preventive control because it blocks threats before they can compromise a system.

  3. An organization calculates that a data breach has a 20% chance of occurring each year and would cost $500,000. What is the Annualized Loss Expectancy (ALE)?

    Answer: $100,000

    ALE = SLE × ARO = $500,000 × 0.20 = $100,000.

  4. Which Windows Server 2012 feature helps organizations identify and classify sensitive data to support risk management decisions?

    Answer: Dynamic Access Control (DAC)

    Dynamic Access Control allows administrators to classify and label data, enabling risk-based access decisions.

  5. A company accepts a risk because the cost of mitigation exceeds the potential loss. Which risk response strategy is being used?

    Answer: Risk acceptance

    Risk acceptance means acknowledging a risk and choosing not to act when mitigation costs outweigh potential losses.

  6. Which Windows Server 2012 audit policy category should be enabled to detect unauthorized privilege escalation attempts?

    Answer: Privilege Use

    The Privilege Use audit category tracks when users exercise sensitive privileges, helping detect escalation attempts.

  7. An administrator is performing a qualitative risk assessment. Which approach is most appropriate for this method?

    Answer: Using a probability and impact matrix with descriptive scales

    Qualitative risk assessment uses descriptive scales (low/medium/high) plotted on a probability and impact matrix rather than exact financial values.