← All 70-413 Exam Flashcard Decks

Regulatory Frameworks & Compliance Flashcards

7 cards from real 70-413 Exam practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Regulatory Frameworks & Compliance flashcards as text
  1. A federal agency deploying a cloud-hosted server infrastructure must obtain which authorization before processing government data under FedRAMP?

    Answer: Authority to Operate (ATO)

    FedRAMP requires cloud service providers to obtain an Authority to Operate (ATO) from a federal agency or a JAB Provisional ATO before processing federal data.

  2. An organization must restrict which users can install software on servers to comply with CIS Benchmark hardening standards. Which Group Policy setting achieves this most effectively?

    Answer: Configure Software Restriction Policies or AppLocker

    AppLocker (or Software Restriction Policies) allows administrators to define exactly which applications are permitted to run, blocking unauthorized software installation.

  3. A company undergoing an ISO 27001 audit must demonstrate a formal risk assessment process. Which Windows Server tool helps quantify risk by showing the effective permissions a user has?

    Answer: Effective Access tab in Advanced Security Settings

    The Effective Access tab in Advanced Security Settings shows the cumulative permissions a specific user or group has on an object, supporting ISO 27001 access rights review requirements.

  4. HIPAA requires covered entities to have a contingency plan, including data backup. Which Windows Server role provides automated, policy-driven backup to meet this requirement?

    Answer: Windows Server Backup

    Windows Server Backup provides scheduled, policy-driven backup of server data and system state, fulfilling HIPAA's contingency plan data backup requirement.

  5. Under PCI DSS Requirement 1, only authorized traffic may access the cardholder data environment. Which Windows Server feature enforces host-based traffic filtering at the server level?

    Answer: Windows Firewall with Advanced Security (WFAS)

    Windows Firewall with Advanced Security enforces inbound and outbound traffic rules at the host level, controlling which traffic can reach the cardholder data environment.

  6. An organization must prove to FISMA auditors that its servers are configured to a defined baseline. Which Windows Server tool compares current configuration against a Security Template?

    Answer: Security Configuration and Analysis snap-in

    The Security Configuration and Analysis snap-in imports a security template and compares it against the current system configuration, identifying deviations from the baseline.

  7. A SOX compliance officer requires that financial server administrator accounts have their password reset every 30 days. What is the most scalable way to enforce this using Active Directory?

    Answer: Apply a Fine-Grained Password Policy (PSO) with MaxPasswordAge=30 to the admin group

    A Fine-Grained Password Policy applied to the admin security group enforces the 30-day maximum without affecting password policies for all other domain users.