MCTS 70-642 Risk Assessment & Management 3 — Questions and Answers
Question 1: A Windows Server 2008 network security team is conducting a Business Impact Analysis (BIA). Which metric defines the maximum tolerable downtime before a system outage causes irreparable business harm?
- Recovery Time Objective (RTO)
- Recovery Point Objective (RPO)
- Maximum Tolerable Downtime (MTD) (Correct answer)
- Mean Time Between Failures (MTBF)
Correct answer: Maximum Tolerable Downtime (MTD)
Maximum Tolerable Downtime (MTD) is the longest time a business process can be unavailable before the organization suffers catastrophic harm.
Question 2: An administrator is reviewing Windows Server 2008 logs and notices repeated failed authentication attempts from multiple IP addresses targeting the same account. According to risk management principles, which threat category does this most likely represent?
- Unintentional insider threat
- Structured external attack (Correct answer)
- Natural disaster risk
- Unstructured external threat
Correct answer: Structured external attack
Coordinated brute-force attempts from multiple IPs indicate a structured external attack with deliberate planning and resources behind it.
Question 3: When assessing risk for a Windows Server 2008 DNS server, which vulnerability assessment technique passively examines network traffic without sending probe packets to targets?
- Active scanning
- Passive scanning (Correct answer)
- Penetration testing
- Fuzz testing
Correct answer: Passive scanning
Passive scanning analyzes existing network traffic and logs to identify vulnerabilities without generating traffic that could alert targets or disrupt services.
Question 4: A security manager wants to assess risk to Windows Server 2008 infrastructure using a method that relies on expert judgment and descriptive categories like High, Medium, and Low rather than specific numbers. Which approach is being used?
- Quantitative risk assessment
- Qualitative risk assessment (Correct answer)
- Monte Carlo simulation
- Factor Analysis of Information Risk (FAIR)
Correct answer: Qualitative risk assessment
Qualitative risk assessment uses subjective categories and expert opinion rather than precise financial figures to rank and prioritize risks.
Question 5: After deploying security patches on a Windows Server 2008 environment, some vulnerability risk still remains because no patch fully eliminates all attack vectors. What is this remaining risk called?
- Inherent risk
- Residual risk (Correct answer)
- Secondary risk
- Transferred risk
Correct answer: Residual risk
Residual risk is the risk that remains after all controls and countermeasures have been applied to reduce the original inherent risk.
Question 6: A Windows Server 2008 administrator is asked to identify which assets are most critical to business operations as the first step in a formal risk assessment. What is this initial inventory step called?
- Threat identification
- Vulnerability scanning
- Asset identification (Correct answer)
- Control gap analysis
Correct answer: Asset identification
Asset identification is the foundational first step in risk assessment, cataloging all hardware, software, and data assets and their business value.
Question 7: During a Windows Server 2008 network risk assessment, the team uses the DREAD model to score threats. What does the 'D' in DREAD stand for?
- Detection
- Damage potential (Correct answer)
- Defense capability
- Data exposure
Correct answer: Damage potential
In the DREAD model (Damage, Reproducibility, Exploitability, Affected users, Discoverability), 'D' stands for Damage potential — the severity of harm if exploited.
A Windows Server 2008 network security team is conducting a Business Impact Analysis (BIA).
Which metric defines the maximum tolerable downtime before a system outage causes irreparable business harm?