Regulatory Frameworks & Compliance Flashcards
7 cards from real MCTS 70-640 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Regulatory Frameworks & Compliance flashcards as text
An auditor requires proof that no unauthorized changes were made to Group Policy Objects. Which tool generates a report comparing current GPO settings against a baseline?
Answer: Security Configuration and Analysis snap-in
The Security Configuration and Analysis snap-in compares current system security settings against a saved baseline (.inf template) and highlights discrepancies.
For FISMA compliance, all AD objects must have their changes tracked. Which audit policy must be enabled to log changes to AD object attributes?
Answer: Audit Directory Service Changes
Audit Directory Service Changes logs when attributes of AD objects are modified, created, moved, or deleted, meeting FISMA change-tracking requirements.
A compliance framework requires that all domain user accounts be set to expire after 90 days of inactivity. Which AD Users and Computers attribute controls account expiration?
Answer: Account expires
The 'Account expires' attribute sets a hard expiration date on the account, after which it cannot be used to authenticate.
Which Windows Server 2008 R2 AD DS tool helps you identify stale user and computer accounts that have not logged in within a specified number of days for compliance cleanup?
Answer: dsquery
The 'dsquery user -inactive ' command identifies accounts that have not logged on within the specified number of weeks.
Your organization's compliance policy requires Kerberos tickets to expire within 8 hours. Where in Group Policy do you configure the maximum lifetime for a service ticket?
Answer: Computer Configuration > Windows Settings > Security Settings > Account Policies > Kerberos Policy
Kerberos ticket lifetime settings are found under Account Policies > Kerberos Policy in the Computer Configuration section of Group Policy.
A compliance requirement states that failed logon attempts must be limited to 5 before lockout. After investigation, accounts are locking out after only 3 failures. What is the most likely cause?
Answer: A fine-grained password policy with stricter settings is applied to the affected group
Fine-grained password policies (PSOs) applied to a user's group take precedence over the Default Domain Policy if the PSO has a lower precedence value (higher priority).
For SOX IT controls, you must demonstrate segregation of duties by preventing members of the 'Finance Admins' group from modifying AD group membership for 'Auditors'. How do you accomplish this?
Answer: Both B and C achieve the same result through the same mechanism
Delegation of Control and manually setting a Deny ACE on the group object accomplish the same thing — both apply a Deny permission to the specific AD object.