Risk Assessment & Management Flashcards
7 cards from real MCTS 70-640 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Risk Assessment & Management flashcards as text
Your organization's risk policy requires separation of duties between AD schema modifications and day-to-day domain administration. Which built-in group assignment enforces this?
Answer: Keep Schema Admins empty and add members only when schema changes are needed
Keeping Schema Admins empty by default and adding members only during planned changes enforces separation of duties and minimizes the risk window for schema modifications.
A risk assessment identifies that BitLocker recovery keys stored in AD can be read by all Domain Admins. Which control limits access to only the security team?
Answer: Configure a DACL on the computer object to grant Read to the security group and deny all others
Configuring a DACL on computer objects to grant Read on ms-FVE-RecoveryInformation only to a specific security group restricts who can retrieve BitLocker recovery keys from AD.
An assessment finds that users in the organization can read the dial-in properties of user accounts, potentially revealing remote access configurations. How should this be mitigated?
Answer: Remove the Read permission on the msNPAllowDialin attribute for Authenticated Users
Removing Read permission on msNPAllowDialin for Authenticated Users prevents regular users from enumerating remote access configuration of other accounts.
During a risk review, you discover that the SYSVOL share permissions allow domain users to write GPO templates. Which risk does this create and how should it be remediated?
Answer: Risk of malicious script injection into logon scripts; fix by removing Write permission for non-admin users on SYSVOL
Writable SYSVOL permissions for domain users allow injection of malicious scripts into logon/startup scripts; Write access should be restricted to Group Policy creators and admins.
A risk scenario involves an insider threat where a help desk technician resets passwords for executives and uses the credentials. Which AD control provides a detective control for this behavior?
Answer: Audit account management events to log password reset actions with the initiator's identity
Auditing account management events (event 4723/4724) records who reset a password, providing a detective control to identify insider abuse of password reset privileges.
Your disaster recovery risk assessment requires that the AD database can be restored if all domain controllers fail simultaneously. Which backup strategy satisfies this requirement?
Answer: Perform System State backups of at least one domain controller regularly and store offline
Regular System State backups (which include the AD database, SYSVOL, registry, and boot files) stored offline allow full AD recovery if all domain controllers are lost.
A risk assessment finds that LDAP traffic between applications and domain controllers is unsigned, allowing man-in-the-middle injection of forged LDAP responses. Which Group Policy setting mitigates this?
Answer: Set 'Domain controller: LDAP server signing requirements' to 'Require signing'
Setting 'Domain controller: LDAP server signing requirements' to 'Require signing' forces clients to sign all LDAP traffic, preventing man-in-the-middle tampering.