Installing and Configuring Windows Server 2012 Exam Risk Assessment & Management 3 — Questions and Answers
Question 1: When configuring Windows Server 2012 for a high-security environment, which Group Policy setting reduces attack surface by disabling unnecessary services based on risk assessment findings?
- Security Configuration Wizard (SCW) baseline (Correct answer)
- Windows Update automatic installation
- Remote Desktop Services role
- Internet Explorer Enhanced Security Configuration
Correct answer: Security Configuration Wizard (SCW) baseline
The Security Configuration Wizard generates role-based security policies that disable unnecessary services identified during risk assessment.
Question 2: A residual risk remains after implementing security controls. What is the recommended next step if the residual risk exceeds the organization's risk tolerance?
- Document and accept the residual risk
- Remove all existing controls and start over
- Implement additional controls or transfer the risk (Correct answer)
- Ignore residual risk as it is expected
Correct answer: Implement additional controls or transfer the risk
If residual risk exceeds tolerance, additional controls should be applied or the risk transferred (e.g., through insurance) until it falls within acceptable limits.
Question 3: Which Windows Server 2012 component provides centralized logging to support risk monitoring and incident detection across multiple servers?
- Windows Server Update Services (WSUS)
- Windows Event Forwarding (WEF) (Correct answer)
- Remote Server Administration Tools (RSAT)
- Server Manager Dashboard
Correct answer: Windows Event Forwarding (WEF)
Windows Event Forwarding centralizes event logs from multiple servers to a collector, enabling centralized risk monitoring.
Question 4: During a risk assessment, a threat agent's capability and motivation are evaluated. What risk component do these factors directly influence?
- Vulnerability
- Impact
- Threat likelihood (Correct answer)
- Control effectiveness
Correct answer: Threat likelihood
Threat likelihood is determined by the capability and motivation of a threat agent to exploit a vulnerability.
Question 5: An organization purchases cyber insurance to cover losses from ransomware attacks on Windows servers. Which risk strategy does this represent?
- Risk avoidance
- Risk mitigation
- Risk transference (Correct answer)
- Risk acceptance
Correct answer: Risk transference
Purchasing cyber insurance transfers the financial impact of a risk to a third party (the insurer).
Question 6: Which Windows Server 2012 feature allows administrators to enforce least privilege by granting temporary elevated access only when needed, reducing standing risk?
- User Account Control (UAC) (Correct answer)
- Protected Users security group
- Just Enough Administration (JEA)
- Managed Service Accounts
Correct answer: User Account Control (UAC)
User Account Control prompts for elevation only when needed, enforcing least privilege and reducing the risk of persistent elevated sessions.
Question 7: A risk register is a key output of the risk assessment process. Which information is NOT typically included in a risk register?
- Risk description and category
- Risk owner and response plan
- Vendor financial statements (Correct answer)
- Likelihood and impact ratings
Correct answer: Vendor financial statements
A risk register documents risks, their attributes, owners, and responses—vendor financial statements are not part of this document.
When configuring Windows Server 2012 for a high-security environment, which Group Policy setting reduces attack surface by disabling unnecessary services based on risk assessment findings?