MCTS 70-642 Risk Assessment & Management 5 — Questions and Answers
Question 1: A Windows Server 2008 security team is implementing a defense-in-depth strategy. Which risk management principle does this strategy reflect by using multiple overlapping layers of controls?
- Single point of control
- Diversity of defense
- Redundant risk acceptance
- Layered countermeasures (Correct answer)
Correct answer: Layered countermeasures
Defense-in-depth applies layered countermeasures so that if one control fails, subsequent layers continue to protect the asset.
Question 2: An administrator reviewing Windows Server 2008 security policy notices that the organization has not updated its risk assessment in two years. Which risk management best practice requires that risk assessments be revisited periodically or after major changes?
- Continuous monitoring (Correct answer)
- One-time assessment
- Residual risk logging
- Threat modeling freeze
Correct answer: Continuous monitoring
Continuous monitoring ensures that the risk posture remains current by regularly reassessing threats, vulnerabilities, and controls as the environment changes.
Question 3: A Windows Server 2008 network faces a risk from an unpatched vulnerability. Management decides to segment the vulnerable server into an isolated VLAN with strict firewall rules rather than patching. Which risk response strategy does this represent?
- Risk avoidance
- Risk acceptance
- Risk mitigation (Correct answer)
- Risk transfer
Correct answer: Risk mitigation
Implementing network segmentation and firewall rules reduces the exploitability of the vulnerability, which is a risk mitigation (reduction) strategy.
Question 4: During a Windows Server 2008 environment risk assessment, which document formally records identified risks, their likelihood, impact ratings, assigned owners, and planned responses?
- Security policy document
- Risk register (Correct answer)
- Change management log
- Incident response plan
Correct answer: Risk register
A risk register is the formal repository that catalogs all identified risks along with their attributes, ownership, and treatment plans.
Question 5: A Windows Server 2008 administrator is assessing the risk of a worm outbreak. The Exposure Factor (EF) for the file server is determined to be 75%. What does this value represent?
- The probability that the worm will infect the server
- The percentage of the asset's value that would be lost in a single incident (Correct answer)
- The annual frequency of worm outbreaks
- The cost to recover from the worm attack
Correct answer: The percentage of the asset's value that would be lost in a single incident
The Exposure Factor (EF) represents the proportion of an asset's value that would be lost or compromised in a single occurrence of a specific threat.
Question 6: An organization is evaluating third-party cloud services for Windows Server 2008 backup offloading. The risk manager is concerned about risks introduced by the vendor relationship itself. What type of risk does this represent?
- Internal operational risk
- Supply chain / third-party risk (Correct answer)
- Regulatory compliance risk
- Physical security risk
Correct answer: Supply chain / third-party risk
Third-party or supply chain risk arises when external vendors introduce vulnerabilities, compliance gaps, or reliability issues into the organization's risk profile.
Question 7: When a Windows Server 2008 security policy mandates that all risk treatment decisions must be formally approved and signed off by senior management, which governance principle is being enforced?
- Separation of duties
- Management accountability (Correct answer)
- Need-to-know access
- Mandatory access control
Correct answer: Management accountability
Management accountability ensures that executives formally own and are responsible for risk acceptance or treatment decisions rather than delegating them entirely to IT.
A Windows Server 2008 security team is implementing a defense-in-depth strategy.
Which risk management principle does this strategy reflect by using multiple overlapping layers of controls?