Risk Assessment & Management Flashcards
7 cards from real Installing and Configuring Windows Server 2012 Exam practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Risk Assessment & Management flashcards as text
A Windows Server 2012 environment undergoes a vulnerability scan revealing 200 vulnerabilities. Which risk management approach should guide remediation prioritization?
Answer: Prioritize by exploitability and potential business impact
Risk-based remediation prioritizes vulnerabilities with the highest exploitability and greatest potential impact on business operations.
Which Windows Server 2012 tool can generate a security baseline report comparing current settings against a known-good configuration to identify risk deviations?
Answer: Microsoft Baseline Security Analyzer (MBSA)
Microsoft Baseline Security Analyzer scans for missing patches and misconfigurations by comparing settings against Microsoft security baselines.
An administrator must ensure that critical Windows Server 2012 systems can recover quickly after an incident. Which metric defines how much data loss is acceptable in terms of time?
Answer: Recovery Point Objective (RPO)
Recovery Point Objective (RPO) defines the maximum age of data that must be recovered, representing the acceptable data loss window.
During a risk assessment, a control that reduces the probability of a threat exploiting a vulnerability is classified as which type?
Answer: Preventive control
Preventive controls reduce the likelihood that a threat will successfully exploit a vulnerability before an incident occurs.
A Windows Server 2012 administrator needs to demonstrate that security controls are operating effectively to management. Which process provides this ongoing assurance?
Answer: Continuous monitoring and control testing
Continuous monitoring and periodic control testing provide ongoing evidence that security controls remain effective over time.
Which Windows Server 2012 feature creates an isolated network zone for sensitive servers, reducing the blast radius of a security incident through network segmentation?
Answer: Windows Firewall host-based isolation with IPsec
Windows Firewall with IPsec can enforce server and domain isolation, limiting lateral movement and containing breaches to specific network segments.
An organization's risk appetite is described as 'conservative.' How should this influence security control selection for Windows Server 2012 deployments?
Answer: Implement robust, layered controls even when risk probability is low
A conservative risk appetite means the organization prefers stronger controls and less tolerance for uncertainty, even for lower-probability risks.