フリー問題

Administering Windows Server (AZ-802) のフリー問題 16 / 20 問目

問題文

A file server holds highly sensitive data. Which pairing of an identity-side control and a data-side control addresses the risk of an attacker who has compromised an ordinary workstation?

選択肢

  1. Encrypt the server's volumes so that the data is unreadable if the disks are removed, and require a longer password for all domain users so that credentials are harder to guess.
  2. Move the share to a workgroup server that is not joined to the domain, so that domain credentials cannot be used against it and the compromised account has no path to the data.
  3. Prevent the reuse of privileged credentials on ordinary systems so that the attacker cannot escalate, and grant data access through group membership that is limited and reviewed so that the compromised account reaches only what it needs.
  4. Require the sensitive data to be accessed only through remote desktop sessions on the file server itself, so that the files never leave the server and cannot be copied to a workstation, and disable drive redirection and clipboard redirection in the session settings so that no copy path remains open to the client.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。