Windows XP Pro Regulatory Frameworks & Compliance 2 — Questions and Answers
Question 1: Under HIPAA, which Windows XP Pro feature helps ensure that ePHI stored locally is protected if a laptop is stolen?
- Encrypting File System (EFS) (Correct answer)
- NTFS permissions only
- Windows Firewall
- Disk Quotas
Correct answer: Encrypting File System (EFS)
EFS encrypts files on NTFS volumes so that stolen hardware cannot expose protected health information without the proper credentials.
Question 2: Sarbanes-Oxley (SOX) Section 404 requires organizations to maintain internal controls over financial reporting. Which Windows XP Pro audit policy directly supports this?
- Audit object access (Correct answer)
- Audit system events
- Audit privilege use
- Audit process tracking
Correct answer: Audit object access
Auditing object access logs who reads or modifies files, supporting SOX requirements to track access to financial data.
Question 3: A company must comply with PCI DSS and needs to ensure Windows XP Pro workstations never store cardholder data in browser caches. Which setting achieves this?
- Configure Internet Explorer to delete temporary files on browser close (Correct answer)
- Enable Windows Firewall
- Set NTFS permissions on the Temp folder
- Enable Audit Account Logon Events
Correct answer: Configure Internet Explorer to delete temporary files on browser close
Configuring IE to delete temporary Internet files on exit prevents cached cardholder data from persisting on the workstation.
Question 4: GLBA (Gramm-Leach-Bliley Act) requires financial institutions to safeguard customer data. Which Windows XP Pro Group Policy setting limits who can log on locally to financial workstations?
- Allow log on locally user right (Correct answer)
- Audit logon events policy
- Password complexity requirement
- Account lockout threshold
Correct answer: Allow log on locally user right
The 'Allow log on locally' user right in Group Policy restricts which users can interactively log on to a workstation.
Question 5: Which Windows XP Pro tool would an auditor use to verify that security policy settings match a documented compliance baseline across multiple machines?
- Security Configuration and Analysis snap-in (Correct answer)
- Device Manager
- System Information (msinfo32)
- Network Connections
Correct answer: Security Configuration and Analysis snap-in
The Security Configuration and Analysis snap-in compares current settings to a security template, identifying deviations from a compliance baseline.
Question 6: FERPA requires educational institutions to protect student records. Which Windows XP Pro feature lets administrators restrict access to student data folders to only authorized staff?
- NTFS discretionary access control lists (DACLs) (Correct answer)
- Shared folder permissions alone
- Internet Connection Firewall
- System Restore
Correct answer: NTFS discretionary access control lists (DACLs)
NTFS DACLs provide granular, user-level access control to folders and files, ensuring only authorized staff can access student records.
Question 7: A compliance officer needs a record of all failed logon attempts on a Windows XP Pro machine over the past 30 days. Which log file contains this information?
- Security log in Event Viewer (Correct answer)
- Application log in Event Viewer
- System log in Event Viewer
- Dr. Watson log
Correct answer: Security log in Event Viewer
Windows XP Pro records failed logon attempts as audit failure events in the Security log, viewable through Event Viewer.
Under HIPAA, which Windows XP Pro feature helps ensure that ePHI stored locally is protected if a laptop is stolen?