You plan to standardize member servers with the Windows Server 2022 security baseline and regularly report deviations per server. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: Download the Microsoft Security Compliance Toolkit; in Group Policy Management, create a new GPO and use Import Settings to import the 'Windows Server 2022 – Member Server' baseline GPO backup from the toolkit, then link it to the MemberServers OU., Use Policy Analyzer (from the Microsoft Security Compliance Toolkit) to scan MemberServers against the imported baseline and export deviation reports..
Why this is the answer
To standardize member servers with a security baseline, the most effective method is to leverage the Microsoft Security Compliance Toolkit. This toolkit provides pre-configured security baselines as GPO backups. You download the toolkit, then in Group Policy Management, create a new GPO and use the "Import Settings" feature to import the specific "Windows Server 2022 – Member Server" baseline. Linking this GPO to the MemberServers OU applies the baseline settings. For reporting deviations, Policy Analyzer, also part of the Microsoft Security Compliance Toolkit, is the correct tool. It can scan systems against the imported baseline and generate reports detailing any configurations that deviate. Using the deprecated Security Compliance Manager is incorrect as it's no longer supported. Intune security baselines are primarily for cloud-managed devices and not directly applied to on-premises servers via Group Policy in this manner. Relying solely on Event Viewer security logs is inefficient and does not provide a comprehensive, automated way to identify baseline deviations.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed