MCTS 70-642 Regulatory Frameworks & Compliance 2 — Questions and Answers
Question 1: A healthcare organization must ensure that Windows Server 2008 file servers storing patient records comply with HIPAA. Which feature best enforces access control to protected health information?
- BitLocker Drive Encryption
- Active Directory Rights Management Services (AD RMS) (Correct answer)
- Windows Firewall with Advanced Security
- Network Access Protection (NAP)
Correct answer: Active Directory Rights Management Services (AD RMS)
AD RMS enforces persistent access controls on sensitive documents, ensuring only authorized users can view protected health information regardless of where the file is copied.
Question 2: Under PCI DSS requirements, cardholder data must be encrypted during transmission. Which Windows Server 2008 feature satisfies this requirement for internal network traffic?
- IPsec policies enforcing encryption between servers (Correct answer)
- NTFS file permissions on network shares
- Windows Firewall inbound rules
- DNS Security Extensions (DNSSEC)
Correct answer: IPsec policies enforcing encryption between servers
IPsec policies can enforce encryption of data in transit between servers on the internal network, directly satisfying PCI DSS Requirement 4 for protecting cardholder data over open networks.
Question 3: An auditor requires proof that privileged user access to domain controllers is logged. Which Windows Server 2008 audit policy category should be enabled?
- Audit Object Access
- Audit Privilege Use
- Audit Account Logon Events (Correct answer)
- Audit Policy Change
Correct answer: Audit Account Logon Events
Audit Account Logon Events records authentication events when domain accounts log on, providing the auditor with evidence of who accessed domain controllers.
Question 4: SOX compliance requires that changes to financial system configurations be tracked and approved. Which Windows Server 2008 feature supports this by recording configuration changes?
- Network Monitor
- Windows Server Backup
- Audit Policy Change audit category (Correct answer)
- Remote Desktop Services
Correct answer: Audit Policy Change audit category
Enabling the Audit Policy Change category logs modifications to audit policies, user rights, and trust relationships, providing a trail of configuration changes for SOX compliance.
Question 5: A company subject to FISMA must implement continuous monitoring of network connections. Which Windows Server 2008 role provides centralized logging of network access attempts?
- Active Directory Certificate Services
- Network Policy Server (NPS) (Correct answer)
- Windows Deployment Services
- Hyper-V
Correct answer: Network Policy Server (NPS)
Network Policy Server logs all network access requests and authentication attempts centrally, supporting FISMA's continuous monitoring requirement.
Question 6: Under GLBA, financial institutions must protect customer data. A Windows Server 2008 administrator wants to prevent data exfiltration via removable media. Which solution is most appropriate?
- Configure NAP health policies
- Use Group Policy to restrict removable storage device access (Correct answer)
- Enable Windows Firewall on all endpoints
- Deploy AD CS for certificate enrollment
Correct answer: Use Group Policy to restrict removable storage device access
Group Policy can restrict or block access to removable storage devices such as USB drives, preventing unauthorized data exfiltration as required by GLBA safeguards.
Question 7: An organization must comply with NIST SP 800-53 and ensure separation of duties for server administration. Which Active Directory feature best supports this requirement?
- Fine-Grained Password Policies
- Role-Based Access Control using security groups (Correct answer)
- Audit Logon Events policy
- Read-Only Domain Controllers (RODC)
Correct answer: Role-Based Access Control using security groups
Role-Based Access Control using security groups allows administrators to assign only the minimum necessary permissions to each role, enforcing separation of duties per NIST SP 800-53.
A healthcare organization must ensure that Windows Server 2008 file servers storing patient records comply with HIPAA.
Which feature best enforces access control to protected health information?