Installing and Configuring Windows Server 2012 Exam Risk Assessment & Management 5 — Questions and Answers
Question 1: A Windows Server 2012 environment undergoes a vulnerability scan revealing 200 vulnerabilities. Which risk management approach should guide remediation prioritization?
- Fix all vulnerabilities alphabetically by CVE ID
- Prioritize by exploitability and potential business impact (Correct answer)
- Remediate newest vulnerabilities first regardless of severity
- Address only vulnerabilities reported in news media
Correct answer: Prioritize by exploitability and potential business impact
Risk-based remediation prioritizes vulnerabilities with the highest exploitability and greatest potential impact on business operations.
Question 2: Which Windows Server 2012 tool can generate a security baseline report comparing current settings against a known-good configuration to identify risk deviations?
- Microsoft Baseline Security Analyzer (MBSA) (Correct answer)
- Performance Monitor (PerfMon)
- Resource Monitor
- Disk Management Console
Correct answer: Microsoft Baseline Security Analyzer (MBSA)
Microsoft Baseline Security Analyzer scans for missing patches and misconfigurations by comparing settings against Microsoft security baselines.
Question 3: An administrator must ensure that critical Windows Server 2012 systems can recover quickly after an incident. Which metric defines how much data loss is acceptable in terms of time?
- Maximum Tolerable Downtime (MTD)
- Recovery Time Objective (RTO)
- Recovery Point Objective (RPO) (Correct answer)
- Mean Time to Repair (MTTR)
Correct answer: Recovery Point Objective (RPO)
Recovery Point Objective (RPO) defines the maximum age of data that must be recovered, representing the acceptable data loss window.
Question 4: During a risk assessment, a control that reduces the probability of a threat exploiting a vulnerability is classified as which type?
- Corrective control
- Preventive control (Correct answer)
- Detective control
- Recovery control
Correct answer: Preventive control
Preventive controls reduce the likelihood that a threat will successfully exploit a vulnerability before an incident occurs.
Question 5: A Windows Server 2012 administrator needs to demonstrate that security controls are operating effectively to management. Which process provides this ongoing assurance?
- Initial risk assessment
- Continuous monitoring and control testing (Correct answer)
- One-time penetration testing
- Annual policy review
Correct answer: Continuous monitoring and control testing
Continuous monitoring and periodic control testing provide ongoing evidence that security controls remain effective over time.
Question 6: Which Windows Server 2012 feature creates an isolated network zone for sensitive servers, reducing the blast radius of a security incident through network segmentation?
- Network Access Protection (NAP)
- Windows Firewall host-based isolation with IPsec (Correct answer)
- DNS round-robin load balancing
- DHCP scope segregation
Correct answer: Windows Firewall host-based isolation with IPsec
Windows Firewall with IPsec can enforce server and domain isolation, limiting lateral movement and containing breaches to specific network segments.
Question 7: An organization's risk appetite is described as 'conservative.' How should this influence security control selection for Windows Server 2012 deployments?
- Implement only mandatory compliance controls to minimize cost
- Implement robust, layered controls even when risk probability is low (Correct answer)
- Accept all risks below a high severity threshold
- Deploy controls only after a security incident occurs
Correct answer: Implement robust, layered controls even when risk probability is low
A conservative risk appetite means the organization prefers stronger controls and less tolerance for uncertainty, even for lower-probability risks.
A Windows Server 2012 environment undergoes a vulnerability scan revealing 200 vulnerabilities.
Which risk management approach should guide remediation prioritization?