โ† All MCTS 70-640 Flashcard Decks

Risk Assessment & Management Flashcards

7 cards from real MCTS 70-640 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Risk Assessment & Management flashcards as text
  1. A penetration test reveals that an expired user account was used to authenticate to a file server three months after termination. Which AD control would have prevented this risk?

    Answer: Enabling automatic account expiration and monitoring via audit logs

    Setting the account expiration date at termination and monitoring audit events 4625/4768 ensures expired accounts cannot authenticate after the expiry date.

  2. Your organization wants to reduce the risk that a compromised read-only domain controller (RODC) exposes sensitive credentials. Which configuration should be applied?

    Answer: Add highly privileged accounts to the RODC's Password Replication Policy denied list

    Adding privileged accounts (e.g., Domain Admins) to the RODC's Denied List ensures their credentials are never cached on the potentially exposed RODC.

  3. A security assessment identifies that Group Policy is being applied to sensitive domain controller OUs without change control. Which AD feature provides a detective control for unauthorized GPO changes?

    Answer: Enabling Advanced Audit Policy for DS Access โ€” Audit Directory Service Changes

    Enabling 'Audit Directory Service Changes' generates event 5136 whenever a Group Policy object is modified, providing a detective control for unauthorized changes.

  4. Your risk register identifies Kerberos ticket-granting ticket (TGT) theft as a critical threat. Which mitigation reduces the lifespan of stolen TGTs?

    Answer: Decrease the maximum Kerberos ticket lifetime in the Default Domain Policy

    Reducing the maximum Kerberos ticket lifetime shortens the window during which a stolen TGT can be replayed by an attacker.

  5. A risk assessment reveals that domain users can create computer accounts in the default Computers container, potentially introducing unmanaged machines. Which setting removes this risk?

    Answer: Set the 'ms-DS-MachineAccountQuota' attribute to 0 on the domain object

    Setting ms-DS-MachineAccountQuota to 0 prevents non-privileged users from joining computers to the domain, eliminating the risk of unmanaged machine account creation.

  6. During risk analysis, you determine that a trust relationship with a partner domain increases your attack surface. Which trust configuration minimizes the risk while maintaining necessary access?

    Answer: Create a one-way external trust with SID filtering enabled

    A one-way external trust with SID filtering enabled limits access to only what is needed and prevents SID history-based privilege escalation from the partner domain.

  7. A compliance audit requires that all privileged AD changes be traceable to an individual. Which combination of controls satisfies this requirement?

    Answer: Enable Advanced Audit Policy for Audit Directory Service Changes and require individual named accounts for all admin tasks

    Combining directory service change auditing with named individual admin accounts ensures every privileged AD modification is logged with a specific identity.

Risk Assessment & Management Flashcards โ€” MCTS 70-640 Study Cards with Answers