Regulatory Frameworks & Compliance Flashcards
7 cards from real MCTS 70-640 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Regulatory Frameworks & Compliance flashcards as text
A security auditor needs to review which users have the 'Manage auditing and security log' right in your domain. Where is this right configured by default?
Answer: Default Domain Controllers Policy
The 'Manage auditing and security log' user right is defined in the Default Domain Controllers Policy GPO, which applies only to domain controllers.
Your organization is implementing AD RMS to comply with data classification requirements. Which AD RMS role service issues use licenses that allow users to consume protected content?
Answer: AD RMS Licensing
The AD RMS Licensing role service issues use licenses that grant authenticated users the rights to open and interact with RMS-protected content.
Which certificate template setting prevents a user from exporting their issued certificate's private key, meeting compliance requirements for non-exportable keys?
Answer: Do not allow private key to be exported = enabled in the Request Handling tab
In the certificate template's Request Handling tab, clearing 'Allow private key to be exported' ensures issued private keys cannot be exported from the machine.
An internal audit reveals that several service accounts have 'Password never expires' set, violating your compliance policy. Which PowerShell cmdlet would identify all such accounts in bulk?
Answer: Both A and B return the same results for user accounts
Both Get-ADUser with a PasswordNeverExpires filter and Search-ADAccount -PasswordNeverExpires identify user accounts where the password never expires.
For compliance with NIST SP 800-53, you must ensure that domain computers apply a minimum set of security settings regardless of their OU. Which approach is most appropriate?
Answer: Link a GPO at the domain level
Linking a baseline security GPO at the domain level ensures it applies to all computer objects in the domain regardless of which OU they reside in.
A compliance policy requires that the built-in Administrator account be renamed on all domain computers. Which Group Policy setting accomplishes this?
Answer: Security Options: Accounts: Rename administrator account
'Accounts: Rename administrator account' under Security Options directly renames the built-in Administrator account to the specified name on all machines where the GPO applies.
Your organization uses AD CS to issue certificates for compliance. Which CA type should be used for issuing certificates to external partners while keeping the root CA offline?
Answer: Standalone Subordinate CA
A Standalone Subordinate CA can issue certificates to external entities without AD integration, while the root CA remains offline for security.