I would first ask for clarification. Else I'd have to assume they were referring to Windows Server. Still, this is difficult to answer with zero context, such as the position being interviewed for. With that said, I'd go with the usual:
1. Ensure you have a strong password policy.
2. Utilize NTFS to secure files and folders.
3. Utilize GPOs to manage the domain environment.
4. Implement a maintenance window to ensure all patches/updates are installed.
5. Harden the OS (disable unnecessary services, disable Guest account, etc).
6. Ensure you have strong policies and procedures to make everything stick.