← All MCSE Flashcard Decks

MSCE Security Protocols & Compliance Standards Flashcards

7 cards from real MCSE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 MSCE Security Protocols & Compliance Standards flashcards as text
  1. A healthcare organization must comply with HIPAA Security Rule. Which of the following is classified as an 'Addressable' implementation specification rather than 'Required'?

    Answer: Automatic logoff

    Automatic logoff is an Addressable implementation specification under HIPAA, meaning organizations must implement it if reasonable and appropriate or document why not.

  2. Which Active Directory feature allows administrators to define fine-grained password policies for specific users or groups without affecting the Default Domain Policy?

    Answer: Password Settings Objects (PSOs)

    Password Settings Objects (PSOs) in Active Directory allow fine-grained password and lockout policies to be applied to specific users or groups, overriding the domain-level policy.

  3. A penetration test reveals that an attacker can relay NTLM authentication from one server to another to gain unauthorized access. Which mitigation directly prevents NTLM relay attacks?

    Answer: Enabling SMB signing on all servers

    SMB signing ensures that SMB packets are digitally signed, preventing an attacker from relaying captured NTLM authentication to another server.

  4. Under ISO/IEC 27001, which clause specifically requires organizations to determine the context of the organization and identify interested parties?

    Answer: Clause 4 — Context of the Organization

    ISO 27001 Clause 4 requires organizations to understand their internal and external context and identify the needs and expectations of interested parties.

  5. Which Windows Server role service provides a centralized policy engine for authenticating and authorizing network access based on RADIUS?

    Answer: Network Policy Server (NPS)

    Network Policy Server (NPS) is the Microsoft implementation of RADIUS, providing centralized authentication, authorization, and accounting for network access.

  6. An organization wants to ensure that keys used for encrypting sensitive data are never exposed in plaintext outside of a hardware boundary. Which Azure service fulfills this requirement?

    Answer: Azure Key Vault Managed HSM

    Azure Key Vault Managed HSM uses FIPS 140-2 Level 3 validated hardware security modules where private keys never leave the HSM boundary in plaintext.

  7. Which Kerberos delegation type allows a service to impersonate a user to any service in the domain, posing the highest security risk?

    Answer: Unconstrained Delegation

    Unconstrained Delegation allows a service to forward the user's TGT to any service in the domain, making it the most dangerous delegation type if the server is compromised.