Risk Assessment & Management Flashcards
7 cards from real Installing and Configuring Windows Server 2012 Exam practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Risk Assessment & Management flashcards as text
A Windows Server 2012 administrator discovers an unpatched vulnerability with a CVSS score of 9.8. Using risk-based patching, which action should be taken first?
Answer: Apply the patch immediately after testing in a lab environment
A CVSS score of 9.8 is critical; risk-based patching prioritizes immediate remediation after lab validation.
Which type of risk assessment relies on expert judgment and experience rather than numerical data to evaluate threats?
Answer: Qualitative
Qualitative risk assessment uses expert judgment and descriptive categories rather than precise numerical calculations.
An organization wants to reduce the likelihood of brute-force attacks on Windows Server 2012 domain accounts. Which Group Policy setting directly addresses this risk?
Answer: Account lockout threshold
Account lockout threshold locks accounts after a specified number of failed attempts, directly preventing brute-force attacks.
During a Business Impact Analysis (BIA), which metric defines the maximum tolerable downtime before business operations are severely impacted?
Answer: Maximum Tolerable Downtime (MTD)
Maximum Tolerable Downtime (MTD) defines the absolute maximum time a system can be offline before causing unacceptable business damage.
Which Windows Server 2012 feature enables administrators to apply fine-grained password policies to specific user groups, allowing different risk profiles?
Answer: Fine-Grained Password Policy (PSO)
Password Settings Objects (PSOs) allow different password policies for different user groups, supporting risk-tiered access control.
A threat model identifies that an insider threat poses the highest risk to a Windows Server 2012 environment. Which control BEST mitigates this specific risk?
Answer: Privileged Access Workstations (PAWs) with separation of duties
Privileged Access Workstations combined with separation of duties limit what insiders can access and do, directly countering insider threats.
When conducting a risk assessment for Windows Server 2012 infrastructure, what is the PRIMARY purpose of asset valuation?
Answer: To prioritize protection efforts based on asset importance to the business
Asset valuation in risk assessment determines which assets are most critical so that protective controls are prioritized accordingly.