โ† All MCTS 70-640 Flashcard Decks

Risk Assessment & Management Flashcards

7 cards from real MCTS 70-640 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Risk Assessment & Management flashcards as text
  1. Your organization's security policy requires that service accounts used by IIS application pools have minimal privileges. Which AD account option best enforces this principle of least privilege?

    Answer: Use a Managed Service Account (MSA) scoped to a single server

    Managed Service Accounts (MSAs) are scoped to a single computer, have automatic password management, and provide least-privilege access for services.

  2. A security audit reveals that users in a branch office can modify the membership of the Domain Admins group. Which ACL permission on the group object must be revoked to mitigate this risk?

    Answer: Write Members permission on the group object

    The Write Members permission on the group object allows principals to add or remove members, and must be removed to prevent unauthorized elevation of privilege.

  3. An attacker performs a pass-the-hash attack using stolen NTLM hashes from a workstation. Which Windows Server 2008 feature most directly reduces the risk of credential theft from memory?

    Answer: Requiring Kerberos with Protected Users security group

    The Protected Users security group prevents members from using NTLM authentication and caches credentials, mitigating pass-the-hash attacks.

  4. During a risk assessment, you find that AD replication traffic between sites is unencrypted. Which setting mitigates the risk of replication data interception?

    Answer: Configure IPsec policies to encrypt LDAP replication traffic

    IPsec policies can encrypt AD replication traffic between domain controllers, protecting against network interception of directory data.

  5. A risk assessment identifies that users can enumerate all objects in Active Directory via anonymous LDAP queries. Which setting eliminates this risk?

    Answer: Set the 'dsHeuristics' attribute to disable anonymous LDAP operations

    Setting the dsHeuristics attribute (specifically bit 7) disables anonymous LDAP searches, preventing unauthenticated enumeration of directory objects.

  6. Your security team determines that the risk of a rogue domain controller joining the domain is high. Which AD feature can prevent unauthorized computers from becoming domain controllers?

    Answer: Using the 'Allow dcpromo only on pre-staged accounts' option via the Default Domain Controllers Policy

    Pre-staging DC computer accounts and requiring that dcpromo use existing accounts prevents unauthorized machines from being promoted to domain controllers.

  7. A risk review finds that domain users can read the password hint attribute of all other users in AD. Which approach mitigates this information disclosure risk?

    Answer: Apply a Deny Read ACE on the user password hint attribute for Authenticated Users

    Applying a Deny Read ACE on the ms-DS-Password-Hint attribute for Authenticated Users prevents other domain users from reading password hints.