################################################################################
DOCUMENT         : MS_Exchange_2019_Mailbox_Server_STIG
VERSION          : 002.003.001.001
CHECKSUM         : 23ab969d46d7332e1831464e12c083ba0294ec92fe6ede610ec25421619147f9
MANUAL QUESTIONS : 15

IMPORTANT: Make sure to save the completed version of this file to: 
<SCC Install>/Resources/Content/Manual_Questions/Completed_Files

This file contains all of the non-automated STIG requirements found in the STIG.
Results from this file will be combined with automated checks in SCC to provide
complete STIG compliance results.

This file will be programmaticaly imported, so do not modify anything in this file
except for placing an '[X]' to select a Single answer, and entering text comments.

The list of questions is printed in order of severity, listing CAT I (High), then CAT II, etc..

################################################################################

QUESTION         : 1 of 15
TITLE            : CAT I, V-259686, SV-259686r961161, SRG-APP-000261
TEST_ACTION_ID   : ocil:navy.navwar.niwcatlantic.scc.sql.server:testaction:8101
QUESTION_ID      : ocil:navy.navwar.niwcatlantic.scc.sql.server:question:8101
RULE             : Exchange servers must have an approved DOD email-aware virus protection software installed.
QUESTION_TEXT    : Review the Email Domain Security Plan (EDSP).

Determine the antivirus strategy.

Verify the email-aware antivirus scanner product is Exchange 2019 compatible and DOD approved. 

If email servers are using an email-aware antivirus scanner product that is not DOD approved and Exchange 2019 compatible, this is a finding.

References:
CCI-001308
     ===========================================================================
     Select One of the following by entering an X in the brackets
     [ ] Finding
     [ ] Not a Finding
     [ ] Not Applicable
     [X] Not Reviewed
     Enter any comments : 

******************************* end of question 1 *******************************

QUESTION         : 2 of 15
TITLE            : CAT II, V-259659, SV-259659r960918, SRG-APP-000111
TEST_ACTION_ID   : ocil:navy.navwar.niwcatlantic.scc.sql.server:testaction:2901
QUESTION_ID      : ocil:navy.navwar.niwcatlantic.scc.sql.server:question:2901
RULE             : Exchange queue monitoring must be configured with threshold and action.
QUESTION_TEXT    : Note: If a third-party application is performing monitoring functions, the reviewer should verify the application is monitoring correctly and mark the vulnerability not applicable (NA).

Open the Exchange Management Shell and enter the following command:

perfmon
Get-MonitoringItemHelp -Identity <String> -Server <ServerIdParameter>

If no sets are defined or queues are not being monitored, this is a finding.

References:
CCI-000154
     ===========================================================================
     Select One of the following by entering an X in the brackets
     [ ] Finding
     [ ] Not a Finding
     [ ] Not Applicable
     [X] Not Reviewed
     Enter any comments : 

******************************* end of question 2 *******************************

QUESTION         : 3 of 15
TITLE            : CAT II, V-259660, SV-259660r960930, SRG-APP-000118
TEST_ACTION_ID   : ocil:navy.navwar.niwcatlantic.scc.sql.server:testaction:3101
QUESTION_ID      : ocil:navy.navwar.niwcatlantic.scc.sql.server:question:3101
RULE             : Exchange must protect audit data against unauthorized read access.
QUESTION_TEXT    : Review the Email Domain Security Plan (EDSP) or document that contains this information. 

Determine the authorized groups or users that should have "Read" access to the audit data.

By default, the logs are located on the application partition in \Program Files\Microsoft\Exchange Server\V15\Logging.

If any group or user has "Read" access to the audit data that is not documented in the EDSP, this is a finding.

References:
CCI-000162
     ===========================================================================
     Select One of the following by entering an X in the brackets
     [ ] Finding
     [ ] Not a Finding
     [ ] Not Applicable
     [X] Not Reviewed
     Enter any comments : 

******************************* end of question 3 *******************************

QUESTION         : 4 of 15
TITLE            : CAT II, V-259661, SV-259661r960933, SRG-APP-000119
TEST_ACTION_ID   : ocil:navy.navwar.niwcatlantic.scc.sql.server:testaction:3301
QUESTION_ID      : ocil:navy.navwar.niwcatlantic.scc.sql.server:question:3301
RULE             : Exchange must protect audit data against unauthorized access.
QUESTION_TEXT    : Review the Email Domain Security Plan (EDSP) or document that contains this information. 

Determine the authorized groups or users that should have access to the audit data.

By default, the logs are located on the application partition in \Program Files\Microsoft\Exchange Server\V15\Logging.

If any group or user has modify privileges for the audit data that is not documented in the EDSP, this is a finding.

References:
CCI-000163
     ===========================================================================
     Select One of the following by entering an X in the brackets
     [ ] Finding
     [ ] Not a Finding
     [ ] Not Applicable
     [X] Not Reviewed
     Enter any comments : 

******************************* end of question 4 *******************************

QUESTION         : 5 of 15
TITLE            : CAT II, V-259662, SV-259662r960936, SRG-APP-000120
TEST_ACTION_ID   : ocil:navy.navwar.niwcatlantic.scc.sql.server:testaction:3501
QUESTION_ID      : ocil:navy.navwar.niwcatlantic.scc.sql.server:question:3501
RULE             : Exchange must protect audit data against unauthorized deletion.
QUESTION_TEXT    : Review the Email Domain Security Plan (EDSP) or document that contains this information.

Determine the authorized groups or users that should have "Delete" permissions for the audit data.

By default, the logs are located on the application partition in \Program Files\Microsoft\Exchange Server\V15\Logging.

If any group or user has "Delete" permissions for the audit data that is not documented in the EDSP, this is a finding.

References:
CCI-000164
     ===========================================================================
     Select One of the following by entering an X in the brackets
     [ ] Finding
     [ ] Not a Finding
     [ ] Not Applicable
     [X] Not Reviewed
     Enter any comments : 

******************************* end of question 5 *******************************

QUESTION         : 6 of 15
TITLE            : CAT II, V-259663, SV-259663r960948, SRG-APP-000125
TEST_ACTION_ID   : ocil:navy.navwar.niwcatlantic.scc.sql.server:testaction:3701
QUESTION_ID      : ocil:navy.navwar.niwcatlantic.scc.sql.server:question:3701
RULE             : Exchange audit data must be on separate partitions.
QUESTION_TEXT    : Review the Email Domain Security Plan (EDSP) or document that contains this information.

Determine the audit logs' assigned partition.

By default, the logs are located on the application partition in \Program Files\Microsoft\Exchange Server\V15\Logging.

If the log files are not on a separate partition from the application, this is a finding.

References:
CCI-001348
     ===========================================================================
     Select One of the following by entering an X in the brackets
     [ ] Finding
     [ ] Not a Finding
     [ ] Not Applicable
     [X] Not Reviewed
     Enter any comments : 

******************************* end of question 6 *******************************

QUESTION         : 7 of 15
TITLE            : CAT II, V-259669, SV-259669r961095, SRG-APP-000211
TEST_ACTION_ID   : ocil:navy.navwar.niwcatlantic.scc.sql.server:testaction:4901
QUESTION_ID      : ocil:navy.navwar.niwcatlantic.scc.sql.server:question:4901
RULE             : Exchange Mailbox databases must reside on a dedicated partition.
QUESTION_TEXT    : Review the Email Domain Security Plan (EDSP) or document that contains this information.

Determine the location where the Exchange Mailbox databases reside.

Open the Exchange Management Shell and enter the following command:

Get-MailboxDatabase | Select-Object -Property Name, Identity, EdbFilePath

Open Windows Explorer, navigate to the mailbox databases, and verify they are on a dedicated partition.

If the mailbox databases are not on a dedicated partition, this is a finding.

References:
CCI-001082
     ===========================================================================
     Select One of the following by entering an X in the brackets
     [ ] Finding
     [ ] Not a Finding
     [ ] Not Applicable
     [X] Not Reviewed
     Enter any comments : 

******************************* end of question 7 *******************************

QUESTION         : 8 of 15
TITLE            : CAT II, V-259672, SV-259672r961128, SRG-APP-000231
TEST_ACTION_ID   : ocil:navy.navwar.niwcatlantic.scc.sql.server:testaction:5501
QUESTION_ID      : ocil:navy.navwar.niwcatlantic.scc.sql.server:question:5501
RULE             : Exchange email forwarding must be restricted.
QUESTION_TEXT    : Review the Email Domain Security Plan (EDSP). 

Determine any accounts that have been authorized to have email auto-forwarded.

Note: If email auto-forwarding is not being used, this check is not applicable.

Open the Exchange Management Shell and enter the following commands:

Get-Mailbox | Select-Object -Property Name, Identity, Forward* 

Note: The asterisk (*) will grab both ForwardingAddress and ForwardingSMTPAddress.

If any user has a forwarding SMTP address and is not documented in the EDSP, this is a finding.

Note: If no remote SMTP domain matching the mail-enabled user or contact that allows forwarding is configured for users identified with a forwarding address, this function will not work properly.

References:
CCI-001199
     ===========================================================================
     Select One of the following by entering an X in the brackets
     [ ] Finding
     [ ] Not a Finding
     [ ] Not Applicable
     [X] Not Reviewed
     Enter any comments : 

******************************* end of question 8 *******************************

QUESTION         : 9 of 15
TITLE            : CAT II, V-259673, SV-259673r961128, SRG-APP-000231
TEST_ACTION_ID   : ocil:navy.navwar.niwcatlantic.scc.sql.server:testaction:5701
QUESTION_ID      : ocil:navy.navwar.niwcatlantic.scc.sql.server:question:5701
RULE             : Exchange email-forwarding SMTP domains must be restricted.
QUESTION_TEXT    : Review the Email Domain Security Plan (EDSP) or document that contains this information.

Determine any accounts that have been authorized to have email auto-forwarded.

Note: If email auto-forwarding is not being used, this check is not applicable (NA).

Open the Exchange Management Shell and enter the following commands:

Get-RemoteDomain | Select Name, Identity, DomainName, AutoForwardEnabled |Format-List

If any domain for a user forwarding SMTP address is not documented in the EDSP, this is a finding.

Note: If no remote SMTP domain matching the mail-enabled user or contact that allows forwarding is configured for users identified with a forwarding address, this function will not work properly.

References:
CCI-001199
     ===========================================================================
     Select One of the following by entering an X in the brackets
     [ ] Finding
     [ ] Not a Finding
     [ ] Not Applicable
     [X] Not Reviewed
     Enter any comments : 

******************************* end of question 9 *******************************

QUESTION         : 10 of 15
TITLE            : CAT II, V-259698, SV-259698r961353, SRG-APP-000340
TEST_ACTION_ID   : ocil:navy.navwar.niwcatlantic.scc.sql.server:testaction:10301
QUESTION_ID      : ocil:navy.navwar.niwcatlantic.scc.sql.server:question:10301
RULE             : Role-Based Access Control must be defined for privileged and nonprivileged users.
QUESTION_TEXT    : Review the Email Domain Security Plan (EDSP) to verify which users should be in each built-in RBAC management role group. 

If this is not found, this is a finding.

References:
CCI-002235
     ===========================================================================
     Select One of the following by entering an X in the brackets
     [ ] Finding
     [ ] Not a Finding
     [ ] Not Applicable
     [X] Not Reviewed
     Enter any comments : 

******************************* end of question 10 *******************************

QUESTION         : 11 of 15
TITLE            : CAT II, V-259699, SV-259699r1015278, SRG-APP-000378
TEST_ACTION_ID   : ocil:navy.navwar.niwcatlantic.scc.sql.server:testaction:10501
QUESTION_ID      : ocil:navy.navwar.niwcatlantic.scc.sql.server:question:10501
RULE             : The Exchange application directory must be protected from unauthorized access.
QUESTION_TEXT    : Review the Email Domain Security Plan (EDSP) or document that contains this information.

Determine the authorized groups and users that have access to the Exchange application directories.

Verify the access permissions on the directory match the access permissions listed in the EDSP.

If any group or user has different access permissions, this is a finding.

Note: The default installation directory is \Program Files\Microsoft\Exchange Server\V15.

References:
CCI-003980
CCI-001812
     ===========================================================================
     Select One of the following by entering an X in the brackets
     [ ] Finding
     [ ] Not a Finding
     [ ] Not Applicable
     [X] Not Reviewed
     Enter any comments : 

******************************* end of question 11 *******************************

QUESTION         : 12 of 15
TITLE            : CAT II, V-259700, SV-259700r961461, SRG-APP-000380
TEST_ACTION_ID   : ocil:navy.navwar.niwcatlantic.scc.sql.server:testaction:10701
QUESTION_ID      : ocil:navy.navwar.niwcatlantic.scc.sql.server:question:10701
RULE             : An Exchange software baseline copy must exist.
QUESTION_TEXT    : Review the Email Domain Security Plan (EDSP) or document that contains this information.

Determine the software baseline.

Review the application software baseline procedures and implementation artifacts.

Note the list of files and directories included in the baseline procedure for completeness.

If an email software copy exists to serve as a baseline and is available for comparison during scanning efforts, this is not a finding.

References:
CCI-001813
     ===========================================================================
     Select One of the following by entering an X in the brackets
     [ ] Finding
     [ ] Not a Finding
     [ ] Not Applicable
     [X] Not Reviewed
     Enter any comments : 

******************************* end of question 12 *******************************

QUESTION         : 13 of 15
TITLE            : CAT II, V-259701, SV-259701r1015279, SRG-APP-000381
TEST_ACTION_ID   : ocil:navy.navwar.niwcatlantic.scc.sql.server:testaction:10901
QUESTION_ID      : ocil:navy.navwar.niwcatlantic.scc.sql.server:question:10901
RULE             : Exchange software must be monitored for unauthorized changes.
QUESTION_TEXT    : Review the Email Domain Security Plan (EDSP).

Determine whether the site monitors system files (e.g., *.exe, *.bat, *.com, *.cmd, and *.dll) on servers for unauthorized changes against a baseline on a weekly basis.

If software files are not monitored for unauthorized changes, this is a finding.

Note: An approved and properly configured solution will contain both a list of baselines that includes all system file locations and a file comparison task that is scheduled to run at least weekly.

References:
CCI-003938
CCI-001814
     ===========================================================================
     Select One of the following by entering an X in the brackets
     [ ] Finding
     [ ] Not a Finding
     [ ] Not Applicable
     [X] Not Reviewed
     Enter any comments : 

******************************* end of question 13 *******************************

QUESTION         : 14 of 15
TITLE            : CAT II, V-259702, SV-259702r961470, SRG-APP-000383
TEST_ACTION_ID   : ocil:navy.navwar.niwcatlantic.scc.sql.server:testaction:11101
QUESTION_ID      : ocil:navy.navwar.niwcatlantic.scc.sql.server:question:11101
RULE             : Exchange services must be documented, and unnecessary services must be removed or disabled.
QUESTION_TEXT    : Review the Email Domain Security Plan (EDSP).

Note: Required services will vary among organizations depending on the role of the individual system. Organizations will develop their own list of services, which will be documented and justified with the information system security officer (ISSO). The site's list will be provided for any security review. Services that are common to multiple systems can be addressed in one document. Exceptions for individual systems should be identified separately by system.

Open a Windows PowerShell and enter the following command:

Get-Service | Where-Object {$_.status -eq 'running'}

Note: The command returns a list of installed services and the status of that service.

If the services required are not documented in the EDSP, this is a finding.

If any undocumented or unnecessary services are running, this is a finding.

References:
CCI-001762
     ===========================================================================
     Select One of the following by entering an X in the brackets
     [ ] Finding
     [ ] Not a Finding
     [ ] Not Applicable
     [X] Not Reviewed
     Enter any comments : 

******************************* end of question 14 *******************************

QUESTION         : 15 of 15
TITLE            : CAT II, V-259709, SV-259709r961620, SRG-APP-000435
TEST_ACTION_ID   : ocil:navy.navwar.niwcatlantic.scc.sql.server:testaction:12501
QUESTION_ID      : ocil:navy.navwar.niwcatlantic.scc.sql.server:question:12501
RULE             : Exchange must provide mailbox databases in a highly available and redundant configuration.
QUESTION_TEXT    : Review the Email Domain Security Plan (EDSP).

Determine if a Database Availability Group exists.
From Exchange Admin Center:
1. In the pane on the left, navigate to "servers". 
2. In the pane on the right, navigate to the "database availability groups" tab.
3. Verify a database availability group is configured with member servers.

If two or more member servers are not listed, this is a finding.

From Exchange PowerShell, run the following cmdlet:

Get-DatabaseAvailabilityGroup

If no DatabaseAvailabilityGroup is listed or a Database Availability Group is listed but has no member servers, this is a finding.

Determine if the Exchange Mailbox databases are using redundancy.
From Exchange Admin Center:
1. In the pane on the left, navigate to "servers".
2. In the pane on the right, navigate to the "databases" tab.
3. For each database, check the column "SERVERS WITH COPIES".

Unless specified in the EDSP, if the "SERVERS WITH COPIES" column does not have two or more servers listed, this is a finding.

From Exchange PowerShell, run the following cmdlet:

Get-MailboxDatabaseCopyStatus -Identity <DatabaseName>

Unless specified in the EDSP, if the output of this cmdlet does not show more than one copy, this is a finding.

References:
CCI-002385
     ===========================================================================
     Select One of the following by entering an X in the brackets
     [ ] Finding
     [ ] Not a Finding
     [ ] Not Applicable
     [X] Not Reviewed
     Enter any comments : 

******************************* end of question 15 *******************************

