Installing and Configuring Windows Server 2012 Exam Risk Assessment & Management 2 — Questions and Answers
Question 1: A security administrator needs to quantify the potential financial loss from a server failure. Which metric represents the estimated monetary loss from a single occurrence of a risk event?
- Annualized Loss Expectancy (ALE)
- Single Loss Expectancy (SLE) (Correct answer)
- Annualized Rate of Occurrence (ARO)
- Return on Security Investment (ROSI)
Correct answer: Single Loss Expectancy (SLE)
Single Loss Expectancy (SLE) represents the monetary loss expected from a single occurrence of a specific risk event.
Question 2: During a Windows Server 2012 risk assessment, which type of control is a firewall primarily classified as?
- Corrective
- Detective
- Preventive (Correct answer)
- Compensating
Correct answer: Preventive
A firewall is a preventive control because it blocks threats before they can compromise a system.
Question 3: An organization calculates that a data breach has a 20% chance of occurring each year and would cost $500,000. What is the Annualized Loss Expectancy (ALE)?
- $100,000 (Correct answer)
- $500,000
- $250,000
- $1,000,000
Correct answer: $100,000
ALE = SLE × ARO = $500,000 × 0.20 = $100,000.
Question 4: Which Windows Server 2012 feature helps organizations identify and classify sensitive data to support risk management decisions?
- Dynamic Access Control (DAC) (Correct answer)
- BitLocker Drive Encryption
- Network Policy Server (NPS)
- Windows Firewall with Advanced Security
Correct answer: Dynamic Access Control (DAC)
Dynamic Access Control allows administrators to classify and label data, enabling risk-based access decisions.
Question 5: A company accepts a risk because the cost of mitigation exceeds the potential loss. Which risk response strategy is being used?
- Risk avoidance
- Risk transference
- Risk acceptance (Correct answer)
- Risk mitigation
Correct answer: Risk acceptance
Risk acceptance means acknowledging a risk and choosing not to act when mitigation costs outweigh potential losses.
Question 6: Which Windows Server 2012 audit policy category should be enabled to detect unauthorized privilege escalation attempts?
- Account Management
- Privilege Use (Correct answer)
- Object Access
- Policy Change
Correct answer: Privilege Use
The Privilege Use audit category tracks when users exercise sensitive privileges, helping detect escalation attempts.
Question 7: An administrator is performing a qualitative risk assessment. Which approach is most appropriate for this method?
- Calculating exact financial figures for each risk
- Using a probability and impact matrix with descriptive scales (Correct answer)
- Running Monte Carlo simulations on loss data
- Applying actuarial tables to predict risk frequency
Correct answer: Using a probability and impact matrix with descriptive scales
Qualitative risk assessment uses descriptive scales (low/medium/high) plotted on a probability and impact matrix rather than exact financial values.
A security administrator needs to quantify the potential financial loss from a server failure.
Which metric represents the estimated monetary loss from a single occurrence of a risk event?