โ† All MCTS 70-640 Flashcard Decks

Regulatory Frameworks & Compliance Flashcards

7 cards from real MCTS 70-640 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Regulatory Frameworks & Compliance flashcards as text
  1. A security auditor needs to review which users have the 'Manage auditing and security log' right in your domain. Where is this right configured by default?

    Answer: Default Domain Controllers Policy

    The 'Manage auditing and security log' user right is defined in the Default Domain Controllers Policy GPO, which applies only to domain controllers.

  2. Your organization is implementing AD RMS to comply with data classification requirements. Which AD RMS role service issues use licenses that allow users to consume protected content?

    Answer: AD RMS Licensing

    The AD RMS Licensing role service issues use licenses that grant authenticated users the rights to open and interact with RMS-protected content.

  3. Which certificate template setting prevents a user from exporting their issued certificate's private key, meeting compliance requirements for non-exportable keys?

    Answer: Do not allow private key to be exported = enabled in the Request Handling tab

    In the certificate template's Request Handling tab, clearing 'Allow private key to be exported' ensures issued private keys cannot be exported from the machine.

  4. An internal audit reveals that several service accounts have 'Password never expires' set, violating your compliance policy. Which PowerShell cmdlet would identify all such accounts in bulk?

    Answer: Both A and B return the same results for user accounts

    Both Get-ADUser with a PasswordNeverExpires filter and Search-ADAccount -PasswordNeverExpires identify user accounts where the password never expires.

  5. For compliance with NIST SP 800-53, you must ensure that domain computers apply a minimum set of security settings regardless of their OU. Which approach is most appropriate?

    Answer: Link a GPO at the domain level

    Linking a baseline security GPO at the domain level ensures it applies to all computer objects in the domain regardless of which OU they reside in.

  6. A compliance policy requires that the built-in Administrator account be renamed on all domain computers. Which Group Policy setting accomplishes this?

    Answer: Security Options: Accounts: Rename administrator account

    'Accounts: Rename administrator account' under Security Options directly renames the built-in Administrator account to the specified name on all machines where the GPO applies.

  7. Your organization uses AD CS to issue certificates for compliance. Which CA type should be used for issuing certificates to external partners while keeping the root CA offline?

    Answer: Standalone Subordinate CA

    A Standalone Subordinate CA can issue certificates to external entities without AD integration, while the root CA remains offline for security.

Regulatory Frameworks & Compliance Flashcards โ€” MCTS 70-640 Study Cards with Answers