Risk Assessment & Management Flashcards
7 cards from real Installing and Configuring Windows Server 2012 Exam practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Assessment & Management flashcards as text
When configuring Windows Server 2012 for a high-security environment, which Group Policy setting reduces attack surface by disabling unnecessary services based on risk assessment findings?
Answer: Security Configuration Wizard (SCW) baseline
The Security Configuration Wizard generates role-based security policies that disable unnecessary services identified during risk assessment.
A residual risk remains after implementing security controls. What is the recommended next step if the residual risk exceeds the organization's risk tolerance?
Answer: Implement additional controls or transfer the risk
If residual risk exceeds tolerance, additional controls should be applied or the risk transferred (e.g., through insurance) until it falls within acceptable limits.
Which Windows Server 2012 component provides centralized logging to support risk monitoring and incident detection across multiple servers?
Answer: Windows Event Forwarding (WEF)
Windows Event Forwarding centralizes event logs from multiple servers to a collector, enabling centralized risk monitoring.
During a risk assessment, a threat agent's capability and motivation are evaluated. What risk component do these factors directly influence?
Answer: Threat likelihood
Threat likelihood is determined by the capability and motivation of a threat agent to exploit a vulnerability.
An organization purchases cyber insurance to cover losses from ransomware attacks on Windows servers. Which risk strategy does this represent?
Answer: Risk transference
Purchasing cyber insurance transfers the financial impact of a risk to a third party (the insurer).
Which Windows Server 2012 feature allows administrators to enforce least privilege by granting temporary elevated access only when needed, reducing standing risk?
Answer: User Account Control (UAC)
User Account Control prompts for elevation only when needed, enforcing least privilege and reducing the risk of persistent elevated sessions.
A risk register is a key output of the risk assessment process. Which information is NOT typically included in a risk register?
Answer: Vendor financial statements
A risk register documents risks, their attributes, owners, and responses—vendor financial statements are not part of this document.