← All 70-413 Exam Flashcard Decks

Risk Assessment & Management Flashcards

7 cards from real 70-413 Exam practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Risk Assessment & Management flashcards as text
  1. You are designing a Windows Server 2012 R2 deployment for a healthcare organization. HIPAA requires you to implement safeguards proportionate to identified risks. Which process does HIPAA mandate as the starting point?

    Answer: Risk analysis

    HIPAA Security Rule requires covered entities to conduct a formal risk analysis as the foundational step before implementing security safeguards.

  2. An organization discovers that a third-party vendor with access to its network has poor security practices. Which risk management response involves requiring the vendor to meet specific security standards contractually?

    Answer: Risk transference via contract SLA and security requirements

    Contractually requiring vendors to meet security standards transfers some responsibility and risk to the third party through legally binding terms.

  3. Which Windows Server feature allows administrators to track changes to security-sensitive files and registry keys, supporting the 'detective control' risk management strategy?

    Answer: File and Registry Auditing via Group Policy

    File and registry auditing configured through Group Policy logs changes to sensitive objects, enabling detection of unauthorized modifications.

  4. A risk assessment reveals that a single administrator account is used by multiple IT staff members. What type of risk does this shared account create?

    Answer: Repudiation risk — inability to attribute actions to specific individuals

    Shared accounts eliminate non-repudiation because actions cannot be attributed to a specific individual, creating significant accountability and audit gaps.

  5. In risk management, what is the relationship between 'threat,' 'vulnerability,' and 'risk'?

    Answer: Risk = Threat × Vulnerability × Asset Value

    Risk is a function of the threat exploiting a vulnerability against an asset, commonly expressed as Risk = Threat × Vulnerability × Asset Value.

  6. A company uses Hyper-V and wants to ensure that if a VM is compromised, the attacker cannot access the host OS. Which risk mitigation approach BEST addresses VM-to-host attack paths?

    Answer: Apply principle of least privilege to VM admin roles and disable unnecessary Hyper-V integration services

    Limiting VM admin privileges and disabling unnecessary integration services reduces the attack surface available for VM-to-host escape attempts.

  7. During a risk assessment, you find that the Recovery Time Objective (RTO) for a critical server is 4 hours, but the current disaster recovery plan requires 12 hours to restore. What risk does this gap represent?

    Answer: An availability risk — the business cannot meet its recovery commitment

    A gap between RTO and actual recovery time represents an availability risk — the organization cannot restore services within the business-required timeframe.