โ† All Installing and Configuring Windows Server 2012 Exam Flashcard Decks

Regulatory Frameworks & Compliance Flashcards

7 cards from real Installing and Configuring Windows Server 2012 Exam practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Regulatory Frameworks & Compliance flashcards as text
  1. A compliance auditor asks you to demonstrate that privileged access is monitored on Windows Server 2012. Which audit subcategory should be enabled to track use of sensitive privileges?

    Answer: Audit Privilege Use

    Enabling 'Audit Privilege Use' records events whenever a user exercises a user right, satisfying privileged-access monitoring requirements.

  2. Your organization is subject to CJIS Security Policy and must enforce multi-factor authentication. Which Windows Server 2012 feature supports certificate-based smart card authentication?

    Answer: Active Directory Certificate Services (AD CS) with smart card enrollment

    AD CS issues smart card certificates, enabling PKI-based MFA which meets CJIS requirements for advanced authentication.

  3. Under DISA STIG guidance, the default Administrator account should be renamed. How do you enforce this across all domain computers using Windows Server 2012?

    Answer: Use a Group Policy setting under Security Options: 'Accounts: Rename administrator account'

    The 'Accounts: Rename administrator account' GPO setting pushes the rename to all computers in the linked scope.

  4. PCI DSS requirement 10 requires time synchronization across all systems. Which Windows Server 2012 service ensures consistent timestamps for audit logs?

    Answer: Windows Time Service (W32tm)

    Windows Time Service synchronizes clocks across domain members using the domain controller as the authoritative time source.

  5. A SOC 2 Type II audit requires evidence that access is revoked promptly when employees leave. Which process in Windows Server 2012 Active Directory directly addresses this?

    Answer: Disabling and then deleting user accounts per the offboarding procedure

    Disabling the account immediately blocks access, and subsequent deletion removes the account, fulfilling prompt access revocation.

  6. HIPAA's Technical Safeguards require automatic logoff of idle sessions. Which Windows Server 2012 Group Policy setting enforces this?

    Answer: Computer Configuration > Windows Settings > Security Settings > Local Policies > Security Options: 'Interactive logon: Machine inactivity limit'

    The 'Machine inactivity limit' security option locks the screen after a defined idle period, meeting HIPAA automatic logoff requirements.

  7. For FedRAMP compliance, you must ensure all remote administrative connections are encrypted. Which Windows Server 2012 feature should be used instead of Telnet or unencrypted RDP?

    Answer: RDP with Network Level Authentication (NLA) and TLS encryption enforced

    Enforcing NLA and TLS on RDP ensures credentials and sessions are encrypted, meeting FedRAMP encryption-in-transit requirements.