MCTS 70-642 Risk Assessment & Management 4 — Questions and Answers
Question 1: A Windows Server 2008 administrator is implementing a risk management framework and needs to determine how often a specific threat event is expected to occur within a 12-month period. Which term describes this metric?
- Exposure Factor (EF)
- Annualized Rate of Occurrence (ARO) (Correct answer)
- Single Loss Expectancy (SLE)
- Asset Value (AV)
Correct answer: Annualized Rate of Occurrence (ARO)
ARO is the estimated frequency, expressed as a decimal or integer, that a specific threat is expected to occur within one year.
Question 2: When hardening a Windows Server 2008 DHCP server, an administrator applies the principle of least privilege to service accounts. Which risk management concept does this control directly address?
- Threat likelihood reduction
- Vulnerability reduction (Correct answer)
- Asset value protection
- Impact reduction
Correct answer: Vulnerability reduction
Least privilege reduces the attack surface by limiting what a compromised account can do, directly reducing system vulnerability to privilege escalation.
Question 3: A risk assessment for a Windows Server 2008 environment identifies that a database server holds data valued at $200,000, and a fire could destroy 40% of it. What is the Single Loss Expectancy (SLE)?
- $200,000
- $80,000 (Correct answer)
- $40,000
- $120,000
Correct answer: $80,000
SLE = Asset Value × Exposure Factor = $200,000 × 0.40 = $80,000.
Question 4: An organization has completed a risk assessment for its Windows Server 2008 infrastructure and documented all findings. The next step in the risk management lifecycle is to select and implement appropriate safeguards. Which phase does this represent?
- Risk identification
- Risk analysis
- Risk mitigation (Correct answer)
- Risk monitoring
Correct answer: Risk mitigation
Risk mitigation is the phase where selected controls and countermeasures are implemented to reduce identified risks to acceptable levels.
Question 5: A Windows Server 2008 administrator is evaluating security controls and distinguishes between controls that detect incidents after they occur versus those that prevent them. Which control type detects but does not prevent security events?
- Preventive control
- Detective control (Correct answer)
- Corrective control
- Deterrent control
Correct answer: Detective control
Detective controls, such as audit logs and intrusion detection systems, identify and alert on security events but do not stop them from occurring.
Question 6: During a Windows Server 2008 network security assessment, a penetration tester is given no prior knowledge of the target environment before attempting to exploit systems. What type of penetration test is this?
- White box test
- Gray box test
- Black box test (Correct answer)
- Crystal box test
Correct answer: Black box test
A black box penetration test simulates an external attacker with no inside knowledge, testing defenses from a pure outsider perspective.
Question 7: When developing a risk management policy for Windows Server 2008 infrastructure, management sets the maximum level of risk the organization is willing to accept without implementing additional controls. What is this threshold called?
- Risk appetite (Correct answer)
- Risk tolerance
- Risk capacity
- Risk posture
Correct answer: Risk appetite
Risk appetite is the amount and type of risk an organization is willing to accept in pursuit of its objectives before action is deemed necessary.
A Windows Server 2008 administrator is implementing a risk management framework and needs to determine how often a specific threat event is expected to occur within a 12-month period.
Which term describes this metric?