โ† All 70-413 Exam Flashcard Decks

Regulatory Frameworks & Compliance Flashcards

7 cards from real 70-413 Exam practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Regulatory Frameworks & Compliance flashcards as text
  1. A PCI DSS audit requires that all default vendor passwords be changed before production deployment. Which Windows Server feature can enforce password complexity at deployment time?

    Answer: Fine-Grained Password Policies

    Fine-Grained Password Policies (PSOs) allow granular password complexity and length requirements per user or group, ensuring non-default passwords for all service accounts.

  2. FISMA requires systems be categorized as Low, Moderate, or High impact. When designing server infrastructure, which document maps these impact levels to specific security controls?

    Answer: NIST SP 800-53

    NIST SP 800-53 provides the catalog of security and privacy controls that correspond to FISMA Low, Moderate, and High impact categorizations.

  3. A company must prove to auditors that no single administrator can both approve and implement firewall changes (separation of duties). Which Active Directory feature best enforces this?

    Answer: Role-Based Access Control via delegated OUs

    Delegating specific permissions to separate OUs enforces Role-Based Access Control, ensuring approval and implementation roles are assigned to different administrative groups.

  4. Under GDPR, an EU customer's personal data must be deleted upon request. Which Windows Server capability helps locate all instances of that data across file servers?

    Answer: File Classification Infrastructure (FCI)

    File Classification Infrastructure automatically classifies files by content using classification rules, enabling administrators to locate and act on all files containing specific personal data.

  5. SOX requires that audit logs cannot be altered by the accounts being audited. Which Windows Server configuration prevents even administrators from deleting security logs?

    Answer: Forward logs to a dedicated write-once log collector with restricted permissions

    Forwarding logs to a centralized server where the audited administrators lack delete permissions ensures log integrity, a core SOX audit trail requirement.

  6. A healthcare IT infrastructure must implement automatic workstation lockout after inactivity to comply with HIPAA's physical safeguards. Which GPO setting enforces this?

    Answer: User Configuration > Administrative Templates > Control Panel > Personalization > Screen Saver timeout with password

    The Screen Saver timeout with 'Password protect the screen saver' setting enforces automatic lockout after inactivity, satisfying HIPAA's workstation security requirements.

  7. PCI DSS Requirement 10 mandates tracking all access to network resources and cardholder data. Which Windows Server audit policy category captures successful and failed network logons?

    Answer: Audit Account Logon Events

    Audit Account Logon Events logs authentication attempts processed by domain controllers, capturing all network logon successes and failures as required by PCI DSS Requirement 10.