Only ones that affect the network surface footprint, so none here as it's on a private VLAN.
I assume that "private VLAN" means it isn't exposed to potential external attack.
b) They won't download anything wrong. There's no route to the internet for this machine.
c) They won't visit any web sites. There's no browser on the machine. This is a core profile windows server installation.
Don't assume that we don't know what we're doing. We have 500ish Windows Server machines floating around.
It's good that you've managed to perfect the hiring process to the point you have zero risk of internal fraud or malice.
Nowhere!
What does that have to do with security updates and reboots?
Nothing!
Patching servers is just good practice. As is designing a system that can handle rebooting individual servers without user-facing downtime.