Windows XP Pro Regulatory Frameworks & Compliance 4 — Questions and Answers
Question 1: Which Windows XP Pro tool generates a report of security configuration settings that can be submitted as evidence during a compliance audit?
- Secedit.exe /analyze (Correct answer)
- Msconfig.exe
- Sfc.exe /scannow
- Netstat.exe
Correct answer: Secedit.exe /analyze
Secedit.exe with the /analyze switch compares current settings to a template and generates a log suitable for compliance documentation.
Question 2: DISA STIG guidelines for Windows XP require disabling the Guest account. Where is this configured in Windows XP Pro?
- Local Users and Groups in Computer Management (Correct answer)
- Network Connections properties
- Internet Options security zones
- Device Manager
Correct answer: Local Users and Groups in Computer Management
The Guest account can be disabled in Local Users and Groups by right-clicking the account and selecting Properties to uncheck account status.
Question 3: A healthcare organization must comply with HIPAA's Minimum Necessary standard, ensuring users access only the PHI required for their job. Which Windows XP Pro feature best supports this?
- NTFS permissions scoped to specific folders per user role (Correct answer)
- Password complexity enforcement
- Windows Firewall inbound rules
- Remote Desktop restricted access
Correct answer: NTFS permissions scoped to specific folders per user role
Scoping NTFS permissions to specific folders per user role ensures each employee can access only the PHI relevant to their job function.
Question 4: To meet CIS Benchmark recommendations, an administrator must rename the default Administrator account on Windows XP Pro. Where is this setting configured via policy?
- Security Options: Rename administrator account in Local Security Policy (Correct answer)
- User Accounts in Control Panel
- Computer Management > Local Users
- Registry HKLM\SAM\Users
Correct answer: Security Options: Rename administrator account in Local Security Policy
The 'Accounts: Rename administrator account' option in Security Options allows renaming the built-in Administrator account via policy.
Question 5: Which compliance framework specifically addresses protecting federal government information systems and would apply to a Windows XP Pro workstation used in a US federal agency?
- FISMA (Federal Information Security Management Act) (Correct answer)
- PCI DSS
- HIPAA
- GLBA
Correct answer: FISMA (Federal Information Security Management Act)
FISMA mandates security controls for federal information systems, requiring agencies to follow NIST guidelines for systems like Windows XP Pro workstations.
Question 6: An administrator needs to ensure Windows XP Pro does not cache the credentials of the last logged-on user, as required by a security policy. Which setting controls this?
- Interactive logon: Do not display last user name (Correct answer)
- Account lockout threshold
- Password: Store passwords using reversible encryption
- Interactive logon: Number of previous logons to cache
Correct answer: Interactive logon: Do not display last user name
Enabling 'Do not display last user name' prevents the username from appearing on the logon screen, removing a potential information disclosure.
Question 7: A SOX-compliant organization requires separation of duties. Which Windows XP Pro configuration prevents a standard user from installing software that could bypass audit controls?
- Running users as limited (non-administrator) accounts (Correct answer)
- Disabling System Restore
- Enabling Windows Firewall
- Setting screen saver timeout to 5 minutes
Correct answer: Running users as limited (non-administrator) accounts
Standard limited user accounts cannot install software system-wide, preventing users from bypassing or disabling audit mechanisms.
Which Windows XP Pro tool generates a report of security configuration settings that can be submitted as evidence during a compliance audit?