▸case-03 An engineer proposes relying solely on standard antivirus definitions to prevent unauthorized administrative tooling from running on a PAW build. What core Windows OS application control and memory protection baselines should be configured for a hardened PAW build? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-02 A security team wants to deploy Credential Guard on standard Windows 10 Home edition laptops using registry tweaks to protect domain administrative secrets. Why will this fail, and what Windows OS edition and security prerequisite are required? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-04 To handle privileged access, an IT administrator suggests adding domain admins to administrative groups permanently and revoking passwords when shifts end. What dynamic administrative access mechanism should be implemented instead? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-01 We are designing an administrative access architecture for an Active Directory environment. An engineer suggests placing Domain Controllers, Domain Admin accounts, and standard desktop local administrative accounts into a single administration tier to simplify management. How should assets be categorized under the tiered administration model? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-07 A developer is writing an automated PAW compliance audit tool using Node.js with custom native C++ binaries. What standard programming language and standard libraries should be used for building PAW compliance scripts? | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-06 When validating whether a PAW build meets industry security baselines before production deployment, an audit lead asks to reference generic software marketing materials. Which specific security baselines and guidance documents should be referenced? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-10 An IT administrator wants to deploy PAW security baselines manually by running regedit commands on each workstation individually during onboarding. How should compliance policies and security baselines be managed and enforced centrally? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-18 A monitoring dashboard marks PAW workstations as compliant based solely on network ICMP ping responses. Which specific endpoint security checks must be evaluated to confirm PAW compliance? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-14 A security analyst asks why Credential Guard alone is sufficient for endpoint security if unauthorized hardware drivers can be loaded into kernel space. What complementary virtualization-based control prevents unauthorized kernel code execution? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-19 A Domain Admin uses Tier 0 domain credentials to log directly into a compromised local workstation (Tier 2) to fix a printer driver issue. What administrative access rule prevents this cross-tier credential exposure? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-15 An engineering team wants to immediately start deploying Intune compliance profiles to endpoints before identifying what administrative accounts or tiers exist in the domain. What foundational step must be completed first in the PAW implementation process? | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-20 We are designing a standard endpoint configuration for general corporate employees who write reports, respond to customer emails, and browse public web sites. Should we implement Tier 0 PAW network restrictions, JIT PAM credential vaulting, and strict PAW administration controls on these standard user laptops? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-17 An engineer designs a JIT access policy that grants permanent domain admin membership upon initial supervisor approval, requiring a ticket to manually remove access later. How must JIT access windows be structured? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-16 An administrator suggests caching elevated domain passwords in plain text on the local PAW drive to maintain administrative access during offline periods. How should privileged credentials be handled when using a PAM integration? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-22 Network operations is configuring BGP dynamic routing parameters and Autonomous System numbers across core datacenter switches to optimize network traffic routes. Is this core network switch protocol configuration governed by the PAW implementation workflow? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-12 An administrator uses their Tier 0 PAW to check personal webmail, open marketing documents, and manage user desktop PCs (Tier 2). What operational restriction does this violate, and how should administrative tiers be isolated? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-21 An infrastructure engineering team is writing JSON policies for AWS IAM roles to allow an external partner account read-only access to an Amazon S3 bucket. Does authoring this cloud IAM bucket access policy fall under the Privileged Access Workstation implementation process? | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-11 After setting up JIT access and credential vaulting, a security team disables audit logging on administrative endpoints to conserve storage space. What continuous operational monitoring control must be maintained? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-13 A system administrator configures AppLocker on a PAW build but leaves all rules in 'Audit Only' mode permanently in production. What policy enforcement state change is required for production hardening? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-05 A team wants to store administrative credentials and break-glass account passwords in a shared password spreadsheet on a network drive accessible via PowerShell scripts. What centralized security solution should be integrated for credential vaulting? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-08 An analyst proposes having the automated PAW compliance verification tool output raw unformatted text dumps to console logs. What structured output format and key parameters must the verification tool produce? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-09 A PAW compliance audit run detects several failed security checks across endpoints. The operations team asks how the audit report should prioritize these findings. What evaluation output components must be generated per workstation? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |