โ† All MCTS 70-640 Flashcard Decks

Regulatory Frameworks & Compliance Flashcards

7 cards from real MCTS 70-640 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Regulatory Frameworks & Compliance flashcards as text
  1. Your organization must comply with SOX requirements and needs to ensure that all privileged AD account activity is logged. Which audit policy subcategory should you enable?

    Answer: Audit Privilege Use

    Audit Privilege Use tracks when a user exercises a user right, which is required to log privileged account activity for SOX compliance.

  2. A compliance officer requires that all domain controllers retain security event logs for at least 90 days without overwriting. Which Group Policy setting controls this?

    Answer: Retention method for security log

    The 'Retention method for security log' policy set to 'Do not overwrite events' ensures logs are preserved until manually cleared.

  3. Under HIPAA compliance, your AD environment must enforce automatic workstation lockout after a period of inactivity. Which GPO setting accomplishes this?

    Answer: Interactive logon: Machine inactivity limit

    'Interactive logon: Machine inactivity limit' is the Windows Server 2008 security policy that locks the workstation after a set idle period.

  4. Which Windows Server 2008 feature allows you to apply different password complexity and length requirements to specific AD security groups rather than the entire domain?

    Answer: Password Settings Objects (PSOs)

    Password Settings Objects (PSOs) implement fine-grained password policies, allowing different password requirements for specific users or groups.

  5. For PCI-DSS compliance, an administrator must ensure that service accounts cannot be used for interactive logon. Which setting should be applied?

    Answer: Deny log on locally

    'Deny log on locally' user right prevents the specified accounts from interactively logging on to any machine where the GPO applies.

  6. A regulatory audit finds that your domain lacks a legal warning banner before logon. Which Group Policy setting displays a logon message to users?

    Answer: Both A and C together

    Both 'Interactive logon: Message title for users attempting to log on' (caption) and the corresponding text setting must be configured together to display a legal banner.

  7. Your security policy mandates that cached credentials must be disabled on laptops to meet compliance requirements. Which Group Policy setting should be configured to 0?

    Answer: Interactive logon: Number of previous logons to cache

    Setting 'Interactive logon: Number of previous logons to cache' to 0 prevents Windows from caching domain credentials locally.