Installing and Configuring Windows Server 2012 Exam Risk Assessment & Management 4 — Questions and Answers
Question 1: A Windows Server 2012 administrator discovers an unpatched vulnerability with a CVSS score of 9.8. Using risk-based patching, which action should be taken first?
- Schedule the patch for the next quarterly maintenance window
- Apply the patch immediately after testing in a lab environment (Correct answer)
- Document the vulnerability and accept the risk
- Wait for vendor confirmation before patching
Correct answer: Apply the patch immediately after testing in a lab environment
A CVSS score of 9.8 is critical; risk-based patching prioritizes immediate remediation after lab validation.
Question 2: Which type of risk assessment relies on expert judgment and experience rather than numerical data to evaluate threats?
- Quantitative
- Qualitative (Correct answer)
- Hybrid
- Statistical
Correct answer: Qualitative
Qualitative risk assessment uses expert judgment and descriptive categories rather than precise numerical calculations.
Question 3: An organization wants to reduce the likelihood of brute-force attacks on Windows Server 2012 domain accounts. Which Group Policy setting directly addresses this risk?
- Minimum password length
- Account lockout threshold (Correct answer)
- Password history enforcement
- Maximum password age
Correct answer: Account lockout threshold
Account lockout threshold locks accounts after a specified number of failed attempts, directly preventing brute-force attacks.
Question 4: During a Business Impact Analysis (BIA), which metric defines the maximum tolerable downtime before business operations are severely impacted?
- Recovery Time Objective (RTO)
- Recovery Point Objective (RPO)
- Maximum Tolerable Downtime (MTD) (Correct answer)
- Mean Time Between Failures (MTBF)
Correct answer: Maximum Tolerable Downtime (MTD)
Maximum Tolerable Downtime (MTD) defines the absolute maximum time a system can be offline before causing unacceptable business damage.
Question 5: Which Windows Server 2012 feature enables administrators to apply fine-grained password policies to specific user groups, allowing different risk profiles?
- Default Domain Policy GPO
- Fine-Grained Password Policy (PSO) (Correct answer)
- Local Security Policy
- Security Configuration Wizard
Correct answer: Fine-Grained Password Policy (PSO)
Password Settings Objects (PSOs) allow different password policies for different user groups, supporting risk-tiered access control.
Question 6: A threat model identifies that an insider threat poses the highest risk to a Windows Server 2012 environment. Which control BEST mitigates this specific risk?
- Perimeter firewall with deep packet inspection
- Privileged Access Workstations (PAWs) with separation of duties (Correct answer)
- Antivirus software on all workstations
- DDoS protection services
Correct answer: Privileged Access Workstations (PAWs) with separation of duties
Privileged Access Workstations combined with separation of duties limit what insiders can access and do, directly countering insider threats.
Question 7: When conducting a risk assessment for Windows Server 2012 infrastructure, what is the PRIMARY purpose of asset valuation?
- To determine hardware replacement costs for budgeting
- To prioritize protection efforts based on asset importance to the business (Correct answer)
- To comply with financial reporting requirements
- To calculate depreciation schedules for IT assets
Correct answer: To prioritize protection efforts based on asset importance to the business
Asset valuation in risk assessment determines which assets are most critical so that protective controls are prioritized accordingly.
A Windows Server 2012 administrator discovers an unpatched vulnerability with a CVSS score of 9.8.
Using risk-based patching, which action should be taken first?