MTA Security Fundamentals Exam 98-367

¡Supera tus tareas y exámenes ahora con Quizwiz!

The purpose of Microsoft Baseline Security Analyzer is to: A. List system vulnerabilities. B. Apply all current patches to a server. C. Set permissions to a default level. D. Correct a company's security state.

Answer : A

This question requires that you evaluate the underlined text to determine if it is correct. The first line of defense against attacks from the Internet is a software firewall. Select the correct answer if the underlined text does not make the statement correct. Select "No change is needed'' if the underlined text makes the statement correct. A. hardware firewall B. virus software C. radius server D. No change is needed

Answer : A

To implement WPA2 Enterprise, you would need a/an: A. RADIUS server B. SSL server C. WEP server D. VPN server

Answer : A

To keep third-party content providers from tracking your movements on the web, enable InPrivate Browsing. Select the correct answer if the underlined text does not make the statement correct. Select "No change is needed'' if the underlined text makes the statement correct. A. InPrivate Filtering B. SmartScreen Filter C. Compatibility Mode D. No change is needed

Answer : A

What is an example of non-propagating malicious code? A. A back door B. A hoax C. A Trojan horse D. A worm

Answer : A

When conducting a security audit the first step is to: A. Inventory the company's technology assets B. Install auditing software on your servers C. Set up the system logs to audit security events D. Set up a virus quarantine area

Answer : A

Which is the minimum requirement to create BitLocker-To-Go media on a client computer? A. Windows XP Professional Service Pack 3 B. Windows Vista Enterprise Edition C. Windows 7 Enterprise Edition D. Windows 2000 Professional Service Pack 4

Answer : A

Which provides the highest level of security in a firewall? A. Stateful inspection B. Outbound packet filters C. Stateless inspection D. Inbound packet filters

Answer : A

Windows Firewall is a built-in. host-based, stateless firewall. Select the correct answer if the underlined text does not make the statement correct. Select "No change is needed" if the underlined text makes the statement correct. A. Stateful B. Network layer C. Packet filter D. No change is needed

Answer : A

You are volunteering at an organization that gets a brand new web server. To make the server more secure, you should add a second administrator account. Select the correct answer if the underlined text does not make the statement correct. Select "No change is needed" if the underlined text makes the statement correct. A. Disable unused services B. Enable LM authentication C. Enable NTLM authentication D. No change is needed.

Answer : A

You create a web server for your school. When users visit your site, they get a certificate error that says your site is not trusted. What should you do to fix this problem? A. Install a certificate from a trusted Certificate Authority (CA). B. Use a digital signature. C. Generate a certificate request. D. Enable Public Keys on your website.

Answer : A

You need to limit the programs that can run on client computers to a specific list. Which technology should you implement? A. Windows Security Center B. Security Accounts Manager C. System Configuration Utility D. AppLocker group policies

Answer : A

You need to install a domain controller in a branch office. You also need to secure the information on the domain controller. You will be unable to physically secure the server. Which should you implement? A. Read-Only Domain Controller B. Point-to-Point Tunneling Protocol (PPTP) C. Layer 2 Tunneling Protocol (L2TP) D. Server Core Domain Controller

Answer : A Explanation: A read-only domain controller (RODC) is a new type of domain controller in the Windows Server 2008 operating system. With an RODC, organizations can easily deploy a domain controller in locations where physical security cannot be guaranteed. An RODC hosts read- only partitions of the Active Directory Domain Services (AD DS) database.

The purpose of a digital certificate is to verify that a: A. Public key belongs to a sender. B. Computer is virus-free. C. Private key belongs to a sender. D. Digital document is complete.

Answer : A Explanation: In cryptography, a public key certificate (also known as a digital certificate or identity certificate) is an electronic document that uses a digital signature to bind a public key with an identity.

Phishing is an attempt to: A. Obtain information by posing as a trustworthy entity. B. Limit access to e-mail systems by authorized users. C. Steal data through the use of network intrusion. D. Corrupt e-mail databases through the use of viruses.

Answer : A Explanation: Phishing is the act of attempting to acquire sensitive information such as usernames, passwords, and credit card details (and sometimes, indirectly, money) by masquerading as a trustworthy entity in an electronic communication.

What is the standard or basic collection of NTFS permissions? A. Read and execute, read, write, full control, modify, list folder contents B. Change permissions, read permissions, write permissions C. Read attributes, list folder/read data, traverse folder/execute file D. Create files/write data, create folders/append data, take ownership

Answer : A Reference: http://technet.microsoft.com/en-us/library/bb727008.aspx

You create a new file in a folder that has inheritance enabled. By default, the new file: A. Takes the permissions of the parent folder B. Does not take any permissions C. Takes the permissions of other folders in the same directory D. Takes the permissions of other files in the same directory

Answer : A Reference: https://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en- us/acl_inherit_permissions.mspx?mfr=true

The Graphic Design Institute hires you to help them set up a server for their 20-person team. As a general practice of hardening the server, you start by performing which two tasks? (Choose two.) A. Disable the guest account. B. Rename the admin account. C. Remove the account lockout policy. D. Format partitions with FAT32.

Answer : A,B

You have a Windows 7 desktop computer, and you create a Standard User account for your roommate so that he can use the desktop from time to time. Your roommate has forgotten his password. Which two actions can you take to reset the password? (Choose two.) A. Use your password reset disk. B. Use your administrator account. C. Boot into Safe Mode with your roommate's account. D. From your roommate's account press CTRL+ALT+DELETE, and then click Change a password.

Answer : A,B

Which two security settings can be controlled by using group policy? (Choose two.) A. Password complexity B. Access to the Run... command C. Automatic file locking D. Encrypted access from a smart phone

Answer : A,B Reference: http://technet.microsoft.com/en-us/library/cc875814.aspx

What are three major attack vectors that a social engineering hacker may use? (Choose three.) A. Telephone B. Reverse social engineering C. Waste management D. Honey pot systems E. Firewall interface

Answer : A,B,C

What are three examples of two-factor authentication? (Choose three.) A. A fingerprint and a pattern B. A password and a smart card C. A username and a password D. A password and a pin number E. A pin number and a debit card

Answer : A,B,E Explanation: At minimum two-factor authentication requires two out of three regulatory-approved authentication variables such as: ✑ Something you know (like the PIN on your bank card or email password). ✑ Something you have (the physical bank card or a authenticator token). ✑ Something you are (biometrics like your finger print or iris pattern)

Which two characteristics should you recommend for a user's domain password? (Choose two.) A. Hard to guess B. Includes Unicode characters C. Easy to remember D. Easy to increment

Answer : A,C Reference: http://www.usewisdom.com/computer/passwords.html

The company that you work for wants to set up a secure network, but they do not have any servers. Which three security methods require the use of a server? (Choose three.) A. 802.1x B. WPA2 Personal C. WPA2 Enterprise D. RADIUS E. 802.11ac

Answer : A,C,D

Cookies impact security by enabling: (Choose two.) A. Storage of Web site passwords. B. Higher security Web site protections. C. Secure Sockets Layer (SSL). D. Web sites to track browsing habits.

Answer : A,D Reference: http://en.wikipedia.org/wiki/HTTP_cookie

Which three elements does HTTPS encrypt? (Choose three.) A. Browser cookies B. Server IP address C. Port numbers D. Website URL E. Login information

Answer : A,D,E Reference: http://stackoverflow.com/questions/499591/are-https-urls-encrypted

A brute force attack: A. Uses response filtering B. Tries all possible password variations C. Uses the strongest possible algorithms D. Targets all the ports

Answer : B

Keeping a server updated: A. Maximizes network efficiency B. Fixes security holes C. Speeds up folder access D. Synchronizes the server

Answer : B

To protect systems from buffer overflow errors, you can use: A. Antivirus software B. Data Execution Prevention C. A proxy server D. An Intruder Prevention System

Answer : B

Which enables access to all of the logged-in user's capabilities on a computer? A. Java applets B. ActiveX controls C. Active Server Pages (ASP) D. Microsoft Silverlight

Answer : B

Which password attack uses all possible alpha numeric combinations? A. Social engineering B. Brute force attack C. Dictionary attack D. Rainbow table attack

Answer : B

You need to grant a set of users write access to a file on a network share. You should add the users to: A. A security group B. The Authenticated Users group C. The Everyone group D. A distribution group

Answer : B

You want to make your computer resistant to online hackers and malicious software. What should you do? A. Configure a forward proxy. B. Install anti-virus software. C. Enable spam filtering. D. Turn on Windows Firewall.

Answer : B

Your password is 1Vu*cI!8sT. Which attack method is your password vulnerable to? A. Rainbow table B. Brute force C. Spidering D. Dictionary

Answer : B

A network sniffer is software or hardware that: A. Records user activity and transmits it to the server B. Captures and analyzes network communication C. Protects workstations from intrusions D. Catalogs network data to create a secure index

Answer : B Explanation: A network sniffer is a computer tool that captures network data in the form of low-level packets. Network sniffers can be used for technical troubleshooting and analyzing the communication.

A digitally signed e-mail message: A. Validates the recipient B. Validates the sender C. Is encrypted D. Is virus-free

Answer : B Explanation: By digitally signing a message, you apply your unique digital mark to the message. The digital signature includes your certificate and public key. This information proves to the recipient that you signed the contents of the message and not an imposter, and that the contents have not been altered in transit. Reference: http://office.microsoft.com/en-us/outlook-help/secure-messages-with-a-digital- signature-HP001230539.aspx

Setting a minimum password age restricts when users can: A. Request a password reset B. Change their passwords C. Log on by using their passwords D. Set their own password expiration

Answer : B Explanation: Configure the minimum password age to be more than 0 if you want Enforce password history to be effective. Without a minimum password age, users can cycle through passwords repeatedly until they get to an old favorite.

E-mail bombing attacks a specific entity by: A. Redirecting all e-mail to another entity B. Sending high volumes of e-mail C. Tracing e-mail to the destination address D. Triggering high levels of security alerts

Answer : B Explanation: In Internet usage, an email bomb is a form of net abuse consisting of sending huge volumes of email to an address in an attempt to overflow the mailbox or overwhelm the server where the email address is hosted in a denial-of-service attack.

An attorney hires you to increase the wireless network security for the law firm's office. The office has a very basic network, with just a modem and a router. Which of these security modes offers the highest security? A. WPA-Personal B. WEP C. WPA2-Personal D. WPA-Enterprise

Answer : C

Coho Winery wants to increase their web presence and hires you to set up a new web server. Coho already has servers for their business and would like to avoid purchasing a new one. Which server is best to use as a web server, considering the security and performance concerns? A. SQL Server B. File Server C. Domain Controller D. Application Server

Answer : C

Humongous Insurance is an online healthcare insurance company. During an annual security audit a security firm tests the strength of the company's password policy and suggests that Humongous Insurance implement password history policy. What is the likely reason that the security firm suggests this? A. Past passwords were easily cracked by the brute force method. B. Past passwords of users contained dictionary words. C. Previous password breaches involved use of past passwords. D. Past passwords lacked complexity and special characters.

Answer : C

The default password length for a Windows Server domain controller is: A. 0 B. 5 C. 7 D. 14

Answer : C

You are trying to connect to an FTP server on the Internet from a computer in a school lab. You cannot get a connection. You try on another computer with the same results. The computers in the lab are able to browse the Internet. You are able to connect to this FTP server from home. What could be blocking the connection to the server? A. A layer-2 switch B. A wireless access point C. A firewall D. A layer-2 hub

Answer : C

You sign up for an online bank account. Every 6 months, the bank requires you to change your password. You have changed your password 5 times in the past. Instead of coming up with a new password, you decide to use one of your past passwords, but the bank's password history prevents you on doing so. Select the correct answer if the underlined text does not make the statement correct Select "No change is needed" if the underlined text makes the statement correct. A. Minimum password age B. Maximum password duration C. Password complexity D. No change is needed.

Answer : D

Where should you lock up the backup tapes for your servers? A. The server room B. A filing cabinet C. The tape library D. An offsite fire safe

Answer : D Explanation: Backup tapes should be stored off site, preferably in a fire safe, so that the data is available should a fire, flood, or other disaster affect the location were the servers are.

The WPA2 PreShared Key (PSK) is created by using a passphrase (password) and salting it with the WPS PIN. Select the correct answer if the underlined text does not make the statement correct. Select "No change is needed" if the underlined text makes the statement correct. A. Service Set Identifier (SSID) B. Admin password C. WEP key D. No change is needed

Answer : A

The certificate of a secure public Web server on the Internet should be: A. Issued by a public certificate authority (CA) B. Signed by using a 4096-bit key C. Signed by using a 1024-bit key D. Issued by an enterprise certificate authority (CA)

Answer : A

A mail system administrator scans for viruses in incoming emails to increase the speed of mail processing. Select the correct answer if the underlined text does not make the statement correct. Select "No change is needed" if the underlined text makes the statement correct. A. Decrease the chances of a virus getting to a client machine B. Verify that the senders of the messages are legitimate C. Ensure that all links in the messages are trustworthy D. No change is needed.

Answer : A

Account lockout policies are used to prevent which type of security attack? A. Brute force attacks B. Users sharing passwords C. Social engineering D. Passwords being reused immediately

Answer : A

Bridging is a process of sending packets from source to destination on OSI layer 3. Select the correct answer if the underlined text does not make the statement correct. Select "No change is needed" if the underlined text makes the statement correct. A. Routing B. Switching C. Repeating D. No change is needed.

Answer : A

How does the sender policy framework (SPF) aim to reduce spoofed email? A. It provides a list of IP address ranges for particular domains so senders can be verified. B. It includes an XML policy file with each email that confirms the validity of the message. C. It lists servers that may legitimately forward mail for a particular domain. D. It provides an encryption key so that authenticity of an email message can be validated

Answer : A

Humongous Insurance needs to set up a domain controller in a branch office. Unfortunately, the server cannot be sufficiently secured from access by employees in that office, so the company is installing a Primary Domain Controller. Select the correct answer if the underlined text does not make the statement correct. Select "No change is needed" if the underlined text makes the statement correct. A. Read-Only Domain Controller B. Backup Domain Controller C. Active Directory Server D. No change is needed.

Answer : A

Physically securing servers prevents: A. Theft B. Compromise of the certificate chain C. Man-in-the middle attacks D. Denial of Service attacks

Answer : A

Role separation improves server security by: A. Enforcing principle of least privilege. B. Installing applications on separate hard disks. C. Physically separating high security servers from other servers. D. Placing servers on separate VLANs.

Answer : A

The primary purpose of Network Access Protection (NAP) is to prevent: A. Loss of data from client computers on a network. B. Non-compliant systems from connecting to a network. C. Users on a network from installing software. D. Unauthorized users from accessing a network.

Answer : B Explanation: NAP enforces health policies by inspecting and assessing the health of client computers, restricting network access when client computers are noncompliant with health policy, and remediating noncompliant client computers to bring them into compliance with health policy before they are granted full network access. NAP enforces health policies on client computers that are attempting to connect to a network; NAP also provides ongoing health compliance enforcement while a client computer is connected to a network. Reference: http://technet.microsoft.com/en-us/library/cc754378(v=ws.10).aspx

Your company requires that users type a series of characters to access the wireless network. The series of characters must meet the following requirements: ✑ Contains more than 15 characters ✑ Contains at least one letter ✑ Contains at least one number ✑ Contains at least one symbol Which security technology meets these requirements? A. WEP B. WPA2 PSK C. WPA2 Enterprise D. MAC filtering

Answer : B Explanation: Pre-shared key mode (PSK, also known as Personal mode) is designed for home and small office networks that don't require the complexity of an 802.1X authentication server.[9] Each wireless network device encrypts the network traffic using a 256 bit key. This key may be entered either as a string of 64 hexadecimal digits, or as a passphrase of 8 to 63 printable ASCII characters

The purpose of User Account Control (UAC) is to: A. Encrypt the user's account B. Limit the privileges of software C. Secure your data from corruption D. Facilitate Internet filtering

Answer : B Explanation: User Account Control (UAC) is a technology and security infrastructure introduced with Microsoft's Windows machines. It aims to improve the security of Microsoft Windows by limiting application software to standard user privileges until an administrator authorizes an increase or elevation. In this way, only applications trusted by the user may receive administrative privileges, and malware should be kept from compromising the operating system.

Which of the following describes a VLAN? A. It connects multiple networks and routes data packets. B. It is a logical broadcast domain across physical subnets. C. It is a subnetwork that reveals a company's externally facing resources to the public network. D. It allows different network protocols to communicate between different network segments.

Answer : B Explanation: VLAN (Virtual Local Network) is a logically separate IP subnetwork which allow multiple IP networks and subnets to exist on the same-switched network. VLAN is a logical broadcast domain that can span multiple physical LAN segments. It is a modern way administrators configure switches into virtual local-area networks (VLANs) to improve network performance by separating large Layer 2 broadcast domains into smaller ones.

The manager of a coffee shop hires you to securely set up WiFi in the shop. To keep computer users from seeing each other, what should you use with an access point? A. Client bridge mode B. Client isolation mode C. MAC address filtering D. Client mode

Answer : B Explanation: Wireless Client Isolation is a unique security feature for wireless networks. When Client Isolation is enabled any and all devices connected to the wireless LAN will be unable to talk to each other.

To prevent users from copying data to removable media, you should: A. Lock the computer cases B. Apply a group policy C. Disable copy and paste D. Store media in a locked room

Answer : B Reference: http://blogs.technet.com/b/askds/archive/2008/08/25/removable-storage-group- policy-and-windows-server-2008-and-windows-vista.aspx

Basic security questions used to reset a password are susceptible to: A. Hashing B. Social engineering C. Network sniffing D. Trojan horses

Answer : B Reference: http://en.wikipedia.org/wiki/Self-service_password_reset

Which type of firewall allows for inspection of all characteristics of a packet? A. NAT B. Stateful C. Stateless D. Windows Defender

Answer : B Reference: http://en.wikipedia.org/wiki/Stateful_firewall

Before you deploy Network Access Protection (NAP), you must install: A. Internet Information Server (IIS) B. Network Policy Server (NPS) C. Active Directory Federation Services D. Windows Update Service

Answer : B Reference: http://technet.microsoft.com/en-us/library/bb681008.aspx

Shredding documents helps prevent: A. Man-in-the-middle attacks B. Social engineering C. File corruption D. Remote code execution E. Social networking

Answer : B Reference: http://technet.microsoft.com/en-us/library/cc875841.aspx

The primary method of authentication in an SSL connection is passwords. To answer, choose the option "No change is needed" if the underlined text is correct. If the underlined text is not correct, choose the correct answer. A. No change is needed B. Certificates C. IPsec D. Biometrics

Answer : B Reference: https://www.geocerts.com/ssl/understanding_authentication

What are two attributes that an email message may contain that should cause a user to question whether the message is a phishing attempt? (Choose two.) A. An image contained in the message B. Spelling and grammar errors C. Threats of losing service D. Use of bold and italics

Answer : B,C Reference: http://www.microsoft.com/security/online-privacy/phishing-symptoms.aspx

Which two are included in an enterprise antivirus program? (Choose two.) A. Attack surface scanning B. On-demand scanning C. Packet scanning D. Scheduled scanning

Answer : B,D

You are an intern and are working remotely. You need a solution that meets the following requirements: ✑ Allows you to access data on the company network securely ✑ Gives you the same privileges and access as if you were in the office What are two connection methods you could use? (Choose two.) A. Forward Proxy B. Virtual Private Network (VPN) C. Remote Access Service (RAS) D. Roaming Profiles

Answer : B,D

A user who receives a large number of emails selling prescription medicine is probably receiving pharming mail. Select the correct answer if the underlined text does not make the statement correct. Select "No change is needed" if the underlined text makes the statement correct. A. Malware B. Spoofed mail C. Spam D. No change is needed.

Answer : C

Passwords that contain recognizable words are vulnerable to a: A. Denial of Service attack B. Hashing attack C. Dictionary attack D. Replay attack

Answer : C Explanation: A dictionary attack is a method of breaking into a password-protected computer or server by systematically entering every word in a dictionary as a password. A dictionary attack can also be used in an attempt to find the key necessary to decrypt an encrypted message or document. Dictionary attacks work because many computer users and businesses insist on using ordinary words as passwords. Dictionary attacks are rarely successful against systems that employ multiple-word phrases, and unsuccessful against systems that employ random combinations of uppercase and lowercase letters mixed up with numerals. Reference: http://searchsecurity.techtarget.com/definition/dictionary-attack

What is a service set identifier (SSID)? A. A wireless encryption standard B. The wireless LAN transmission type C. The broadcast name of an access point D. A wireless security protocol

Answer : C Explanation: SSID (service set identifier) is a function performed by an Access Point that transmits its name so that wireless stations searching for a network connection can 'discover' it. It's what allows your wireless adapter's client manager program or Windows built-in wireless software to give you a list of the Access Points in range.

Which technology enables you to filter communications between a program and the Internet? A. RADIUS server B. Antivirus software C. Software firewall D. BitLocker To Go

Answer : C Explanation: There are two types of firewalls the Hardware Firewall and the Software Firewall. A Software Firewall is a software program and a Hardware Firewall is a piece of hardware. Both have the same objective of filtering communications over a system.

You have two servers that run Windows Server. All drives on both servers are formatted by using NTFS. You move a file from one server to the other server. The file's permissions in the new location will: A. Enable full access to the everyone group B. Restrict access to the Administrators group C. Inherit the destination folder's permissions D. Retain the original folder's permissions

Answer : C Explanation: You can modify how Windows Explorer handles permissions when objects are copied or moved to another NTFS volume. When you copy or move an object to another volume, the object inherits the permissions of its new folder.

What does NAT do? A. It encrypts and authenticates IP packets. B. It provides caching and reduces network traffic. C. It translates public IP addresses to private addresses and vice versa. D. It analyzes incoming and outgoing traffic packets.

Answer : C Reference: http://en.wikipedia.org/wiki/Network_address_translation

You would implement a wireless intrusion prevention system to: A. Prevent wireless interference B. Detect wireless packet theft C. Prevent rogue wireless access points D. Enforce SSID broadcasting

Answer : C Reference: http://en.wikipedia.org/wiki/Wireless_intrusion_prevention_system

E-mail spoofing: A. Forwards e-mail messages to all contacts B. Copies e-mail messages sent from a specific user C. Obscures the true e-mail sender D. Modifies e-mail routing logs

Answer : C Reference: http://www.microsoft.com/mscorp/safety/technologies/senderid/technology.mspx

Dumpster diving refers to a physical threat that a hacker might use to look for information about a computer network. Select the correct answer if the underlined text does not make the statement correct. Select "No change is needed" if the underlined text makes the statement correct. A. Phishing B. Malware C. Reverse Social engineering D. No change is needed

Answer : D

Many Internet sites that you visit require a user name and password. How should you secure these passwords? A. Save them to a text file B. Enable session caching C. Configure the browser to save passwords D. Save them to an encrypted file E. Reuse the same password

Answer : D

The Active Directory controls, enforces, and assigns security policies and access rights for all users. Select the correct answer if the underlined text does not make the statement correct. Select "No change is needed" if the underlined text makes the statement correct. A. NTFS permissions B. User Account Control C. Registry D. No change is needed

Answer : D

The Windows Firewall protects computers from unauthorized network connections. Select the correct answer if the underlined text does not make the statement correct. Select "No change is needed'' if the underlined text makes the statement correct. A. Email viruses B. Phishing scams C. Unencrypted network access D. No change is needed

Answer : D

The client computers on your network are stable and do not need any new features. Which is a benefit of applying operating system updates to these clients? A. Keep the software licensed B. Keep the server ports available C. Update the hardware firewall D. Close existing vulnerabilities

Answer : D

What does implementing Windows Server Update Services (WSUS) allow a company to manage? A. Shared private encryption key updates B. Updates to Group Policy Objects C. Active Directory server replication D. Windows updates for workstations and servers

Answer : D

What is a common method for password collection? A. Email attachments B. Back door intrusions C. SQL Injection D. Network sniffers

Answer : D

Which enables you to change the permissions on a folder? A. Take ownership B. Extended attributes C. Auditing D. Modify

Answer : D

You are an intern at Wide World Importers and help manage 1000 workstations. All the workstations are members of an Active Domain. You need to push out an internal certificate to Internet Explorer on all workstations. What is the quickest method to do this? A. Local policy B. Logon script C. Windows Update D. Group policy

Answer : D

You are trying to establish communications between a client computer and a server. The server is not responding. You confirm that both the client and the server have network connectivity. Which should you check next? A. Microsoft Update B. Data Execution Prevention C. Windows Firewall D. Active Directory Domains and Trusts

Answer : D

Network Access Protection (NAP) enables administrators to control access to network resources based on a computer's: A. Encryption level B. Warranty C. Physical location D. Configuration

Answer : D Explanation: Network Access Protection (NAP) is a new set of operating system components included with the Windows Server 2008 and Windows Vista operating systems that provides a platform to help ensure that client computers on a private network meet administrator-defined requirements for system health. NAP policies define the required configuration and update status for a client computers operating system and critical software. For example, computers might be required to have antivirus software with the latest signatures installed, current operating system updates installed, and a host- based firewall enabled. By enforcing compliance with health requirements, NAP can help network administrators mitigate some of the risk caused by improperly configured client computers that might be exposed to viruses and other malicious software.

Creating MD5 hash for files is an example of ensuring what? A. Confidentiality B. Availability C. Least privilege D. Integrity

Answer : D Explanation: The MD5 message-digest algorithm is a widely used cryptographic hash function producing a 128-bit (16-byte) hash value, typically expressed in text format as a 32 digit hexadecimal number. MD5 has been utilized in a wide variety of cryptographic applications, and is also commonly used to verify data integrity.

Password history policies are used to prevent: A. Brute force attacks B. Users from sharing passwords C. Social engineering D. Passwords from being reused immediately

Answer : D Explanation: This security setting determines the number of unique new passwords that have to be associated with a user account before an old password can be reused. The value must be between 0 and 24 passwords. This policy enables administrators to enhance security by ensuring that old passwords are not reused continually. Reference: http://technet.microsoft.com/en-us/library/cc758950(v=ws.10).aspx

Windows Server Update Services (WSUS) is a tool that: A. Updates data stored in Windows servers B. Manages the services that run on a server C. Updates licensing for Windows servers D. Manages updates for Microsoft software

Answer : D Explanation: Windows Server Update Services (WSUS) enables information technology administrators to deploy the latest Microsoft product updates to computers that are running the Windows operating system. By using WSUS, administrators can fully manage the distribution of updates that are released through Microsoft Update to computers in their network. Reference: http://technet.microsoft.com/en-us/windowsserver/bb332157.aspx

What is the primary advantage of using Active Directory Integrated Zones? A. Zone encryption B. Password protection C. Non-repudiation D. Secure replication

Answer : D Reference: http://books.google.com/books?id=CXy- 2LBZCVgC&pg=PA201&dq=%22Active+Directory+Integrated+Zones%22,+Secure+replicat ion&hl=en&sa=X&ei=9s92U-v1KI- zyASjzILIDg&ved=0CE0Q6AEwAQ#v=onepage&q=%22Active%20Directory%20Integrated %20Zones%22%2C%20Secure%20replication&f=false

Which is a special folder permission? A. Read B. Modify C. Write D. Delete

Answer : D Reference: http://support.microsoft.com/kb/308419

You are an intern at Litware, Inc. Your manager asks you to make password guess attempts harder by limiting login attempts on company computers. What should you do? A. Enforce password sniffing. B. Enforce password history. C. Make password complexity requirements higher. D. Implement account lockout policy.

Answer : D Reference: http://technet.microsoft.com/en-us/library/dd277400.aspx

In Internet Explorer 8, the InPrivate Browsing feature prevents: A. Unauthorized private data input. B. Unencrypted communication between the client computer and the server. C. User credentials from being sent over the Internet. D. Any session data from being stored on the computer.

Answer : D Reference: http://windows.microsoft.com/en-us/windows/what-is-inprivate-browsing

You suspect a user's computer is infected by a virus. What should you do first? A. Restart the computer in safe mode B. Replace the computer's hard disk drive C. Disconnect the computer from the network D. Install antivirus software on the computer

Answer : D (or C - debatable)

You need to prevent unauthorized users from reading a specific file on a portable computer if the portable computer is stolen. What should you implement? A. File-level permissions B. Advanced Encryption Standard (AES) C. Folder-level permissions D. Distributed File System (DFS) E. BitLocker

Answer : E Reference: http://4sysops.com/archives/seven-reasons-why-you-need-bitlocker-hard-drive- encryption-for-your-whole-organization/

Which attack listens to network traffic of a computer resource? A. Resource gathering B. Denial of service C. ARP poisoning D. Eavesdropping E. Logic bomb

D


Conjuntos de estudio relacionados

Marieb Anatomy + Physiology Chapter 2: Chemistry

View Set

Drugs Affecting the Autonomic Nervous System

View Set

Chapter 41 - Listening Guide Quiz 32: Berlioz: Symphonie fantastique, V

View Set

Med Surg: Chapter 53: Nursing Management: Patients With Burn Injury: PREPU

View Set

EDIT: 8th World History 2nd 9 Weeks Exam

View Set

Tension pneumothorax- medical emergency

View Set

Chapter 46: Management of Patients with Gastric and Duodenal Disorders

View Set