Windows XP Pro Risk Assessment & Management 5 — Questions and Answers
Question 1: A Windows XP Pro machine is found to have Remote Registry service enabled. What specific risk does this introduce?
- Increased print spooler errors
- Remote attackers can read or modify the registry over the network (Correct answer)
- Loss of Internet Explorer settings
- Slower boot performance
Correct answer: Remote attackers can read or modify the registry over the network
The Remote Registry service allows authorized (and potentially unauthorized) users to connect to and manipulate registry keys remotely, enabling configuration tampering or information gathering.
Question 2: Which Windows XP Pro policy setting reduces the risk of an attacker using cached domain credentials on a stolen laptop?
- Increase the number of cached logons
- Set 'Interactive logon: Number of previous logons to cache' to 0 (Correct answer)
- Enable Fast User Switching
- Disable NTLM authentication
Correct answer: Set 'Interactive logon: Number of previous logons to cache' to 0
Setting cached logons to 0 prevents Windows XP from storing domain credential hashes locally, so a stolen laptop cannot be used to authenticate as a domain user offline.
Question 3: During a Windows XP Pro risk assessment, you discover the local Administrator account has a blank password. What NTLM behavior does Windows XP apply in this case?
- It blocks all logons for that account
- It restricts blank-password accounts to console logon only by default (Correct answer)
- It automatically sets a random password
- It disables the account permanently
Correct answer: It restricts blank-password accounts to console logon only by default
By default, Windows XP restricts accounts with blank passwords to local console logon only, blocking network authentication to reduce the risk of remote exploitation.
Question 4: A risk management plan identifies that the cost of a control exceeds the potential loss it prevents. What is the CORRECT decision?
- Implement the control anyway for compliance
- Accept the risk and skip the control (Correct answer)
- Transfer the risk to a vendor
- Eliminate the asset entirely
Correct answer: Accept the risk and skip the control
When control cost exceeds potential loss, the economically rational decision is to accept the risk, since spending more than the expected loss is not cost-effective.
Question 5: Which Windows XP Pro feature should be evaluated during a risk assessment to ensure data confidentiality when files are sent to a shared network printer?
- Print Spooler encryption setting
- IPSec policy for the network segment (Correct answer)
- NTFS compression on the spool folder
- Printer pooling configuration
Correct answer: IPSec policy for the network segment
IPSec can encrypt traffic between the Windows XP Pro workstation and the print server, preventing eavesdropping on print data crossing the network.
Question 6: A Windows XP Pro risk assessment flags that users share a single local account. Which risk does this MOST directly create?
- Disk quota enforcement failure
- Inability to attribute actions to specific individuals (non-repudiation failure) (Correct answer)
- Slower system performance
- Automatic screen resolution changes
Correct answer: Inability to attribute actions to specific individuals (non-repudiation failure)
Shared accounts destroy individual accountability; audit logs cannot identify which person performed a specific action, breaking non-repudiation.
Question 7: Which Windows XP Pro Security Center component provides real-time risk visibility into the three key protection areas: firewall, automatic updates, and virus protection?
- Task Manager
- Windows Security Center (Correct answer)
- Local Security Policy
- Computer Management console
Correct answer: Windows Security Center
Windows Security Center (introduced in XP SP2) monitors and displays the status of the firewall, Automatic Updates, and antivirus software in a single dashboard.
A Windows XP Pro machine is found to have Remote Registry service enabled.
What specific risk does this introduce?