Microsoft Windows 98 Risk Assessment & Management 4 — Questions and Answers
Question 1: Which Windows 98 Control Panel applet should be reviewed during a risk assessment to verify that only necessary services and components are installed?
- Display
- Add/Remove Programs (Correct answer)
- Mouse
- Accessibility Options
Correct answer: Add/Remove Programs
Add/Remove Programs shows all installed applications and Windows components, allowing a risk assessor to identify and remove unnecessary software that increases attack surface.
Question 2: What risk does the Windows 98 'Briefcase' feature introduce if left unmanaged on a shared workstation?
- Increased disk fragmentation
- Unauthorized synchronization and potential data leakage of sensitive files to removable media (Correct answer)
- Slower network performance
- Registry corruption
Correct answer: Unauthorized synchronization and potential data leakage of sensitive files to removable media
Briefcase enables file synchronization with laptops or removable drives, risking uncontrolled transfer of sensitive data outside the organization.
Question 3: In Windows 98, which log file is MOST useful for a post-incident review of system startup failures and driver load errors?
- DETLOG.TXT
- BOOTLOG.TXT (Correct answer)
- SETUPLOG.TXT
- NETLOG.TXT
Correct answer: BOOTLOG.TXT
BOOTLOG.TXT records every driver and module load attempt during startup, making it essential for diagnosing boot-time failures in a post-incident review.
Question 4: A risk assessor finds Windows 98 installed on a machine used for online banking. What is the PRIMARY concern?
- Slow internet browsing speed
- No security updates have been released since 2006, leaving unpatched vulnerabilities exploitable (Correct answer)
- Poor screen resolution
- Incompatible keyboard drivers
Correct answer: No security updates have been released since 2006, leaving unpatched vulnerabilities exploitable
Microsoft ended support for Windows 98 in 2006, meaning known vulnerabilities discovered since then will never be patched, exposing financial transactions to exploitation.
Question 5: Which risk mitigation strategy is MOST effective for protecting sensitive data stored on a Windows 98 FAT32 partition?
- Relying on Windows 98 built-in FAT32 permissions
- Using third-party encryption software since FAT32 has no native file-level permissions (Correct answer)
- Setting a BIOS boot password only
- Compressing the partition with DriveSpace
Correct answer: Using third-party encryption software since FAT32 has no native file-level permissions
FAT32 provides no file-level access control, so third-party encryption is necessary to protect sensitive data from anyone with physical or boot-level access to the machine.
Question 6: What is the risk management implication of Windows 98's lack of native support for NTFS file system permissions?
- Slower file read speeds
- Inability to enforce granular user-level access controls on local files (Correct answer)
- Incompatibility with USB drives
- Higher disk fragmentation rates
Correct answer: Inability to enforce granular user-level access controls on local files
Without NTFS permission support, Windows 98 cannot restrict file access by user account, making it impossible to enforce least-privilege access control on the local machine.
Question 7: During a Windows 98 risk assessment, which finding would be classified as a CRITICAL vulnerability requiring immediate remediation?
- Desktop wallpaper set to default
- Guest account enabled with no password and File Sharing active (Correct answer)
- Screen saver set to 10-minute timeout
- Desktop icons arranged in default positions
Correct answer: Guest account enabled with no password and File Sharing active
A passwordless Guest account combined with active File Sharing allows any network user to access shared resources without any authentication, representing a critical access control failure.
Which Windows 98 Control Panel applet should be reviewed during a risk assessment to verify that only necessary services and components are installed?