โ† All 70-413 Exam Flashcard Decks

Regulatory Frameworks & Compliance Flashcards

7 cards from real 70-413 Exam practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Regulatory Frameworks & Compliance flashcards as text
  1. A company must implement network admission control to ensure only compliant (patched, AV-enabled) machines can access the internal network. Which Windows Server role provides this?

    Answer: Network Access Protection (NAP)

    Network Access Protection evaluates client health against defined policies and restricts or remediates non-compliant machines before granting full network access.

  2. Under GDPR, personal data must not be transferred outside the EU without adequate protections. When designing a Windows Server infrastructure with Azure integration, which feature controls data residency?

    Answer: Azure region selection and data residency policies

    Selecting specific Azure regions and applying data residency policies ensures personal data remains within EU boundaries, satisfying GDPR's data transfer restrictions.

  3. An auditor requires proof that privileged account usage on domain controllers is monitored. Which audit policy logs when a user exercises a user right such as 'Act as part of the operating system'?

    Answer: Audit Privilege Use

    Audit Privilege Use generates events when a user account exercises a user right, capturing privileged operations for compliance reporting on domain controller activity.

  4. CIS Controls require disabling unnecessary services on servers to reduce attack surface. Which Windows Server tool assesses which roles and services are needed and generates a security policy accordingly?

    Answer: Security Configuration Wizard (SCW)

    The Security Configuration Wizard guides administrators through role-based questions and generates a security policy that disables unneeded services and ports.

  5. PCI DSS requires that access to system components is assigned an individual ID so each user can be held accountable. What Active Directory practice directly supports this requirement?

    Answer: Assigning individual user accounts and prohibiting shared accounts

    Assigning unique individual accounts to every user ensures accountability and non-repudiation, which is a direct PCI DSS Requirement 8 mandate.

  6. A defense contractor must comply with CMMC (Cybersecurity Maturity Model Certification) Level 2, which maps to NIST SP 800-171. Which Windows Server capability addresses the requirement to limit unsuccessful logon attempts?

    Answer: Account Lockout Policy in Group Policy

    Account Lockout Policy settings (threshold, duration, and observation window) directly implement NIST SP 800-171 control 3.1.8 for limiting failed logon attempts.

  7. An ISO 27001-certified organization must perform regular internal audits of IT controls. Which Windows Server feature provides a detailed report of all Group Policy settings applied to a specific computer?

    Answer: Group Policy Management Console (GPMC) with Group Policy Results

    The Group Policy Results Wizard in GPMC generates an RSoP report showing every policy setting applied to a computer or user, providing evidence for ISO 27001 control audits.