Name:     ID: 
 
    Email: 

70-290-MNE-Ch14

Multiple Choice
Identify the letter of the choice that best completes the statement or answers the question.
 

 1. 

Windows Server 2003 ____ processes require a user to submit a valid user name and password combination to gain access to desktop systems or domain environments.
a.
encryption
c.
authentication
b.
security
d.
access control
 

 2. 

____ literally controls which users, groups, and computers can access resources, along with the level of access granted.
a.
Encryption
c.
Authentication
b.
Security
d.
Access control
 

 3. 

If a user only needs to be able to read a file and not make changes, they should be granted no more than the ____ permission to that file.
a.
Read
c.
Modify
b.
Write
d.
Execute
 

 4. 

The concept of only granting users the lowest level of resource access they require is known as ____.
a.
access restriction
c.
low level access
b.
the principle of least privilege
d.
the principle of resource restriction
 

 5. 

In Windows Server 2003, the ability to encrypt confidential files is provided by ____.
a.
the Encryption Access
c.
Access control
b.
the Encrypting File System
d.
the File Security System
 

 6. 

____ is an open-standard security protocol used to encrypt the contents of packets sent across a TCP/IP network.
a.
NTFS
c.
IPSec
b.
EFS
d.
TCPIPSec
 

 7. 

When implemented between network clients and servers, IPSec is running in ____ mode, and can fully secure communications sessions across a network.
a.
open
c.
tunnel
b.
secure
d.
transport
 

 8. 

____ mode is when IPSec is used in such a way that data is secured between two pre-defined endpoints only.
a.
Open
c.
Tunnel
b.
Secure
d.
Transport
 

 9. 

An administrator can analyze policy settings by using the ____ command line utility.
a.
SECEDIT
c.
ANALPOL
b.
GPUPDATE
d.
SECPOL
 

 10. 

In the Microsoft world, updates are released as ____ as soon as a security flaw or other issue is identified and corrected.
a.
service packs
c.
hot fixes
b.
system updates
d.
bug fixes
 

 11. 

Service packs and hot fixes can be downloaded and installed via ____.
a.
email
c.
Microsoft executables
b.
Windows Updates
d.
network proxy
 

 12. 

The Security Configuration Manager tools consist of ____ core components.
a.
2
c.
6
b.
4
d.
8
 

 13. 

____ help(s) ensure that a consistent security setting can be applied to multiple machines and be easily maintained.
a.
Security templates
b.
The Security Configuration and Analysis tool
c.
Security settings in Group Policy objects
d.
The SECEDIT command-line tool
 

 14. 

A computer running ____ can take advantage of security template configurations and deployments.
a.
Windows ME
c.
Windows NT
b.
Windows 98
d.
Windows 2000
 

 15. 

When Windows Server 2003 is installed, the default security settings applied to the computer are stored in a template called ____.
a.
Security Install.exe
c.
Security Setup.inf
b.
Setup Security.inf
d.
Default Security.exe
 

 16. 

The purpose of the ____ template is to provide a single file in which all of the original computer security settings are stored.
a.
factory
c.
default
b.
incremental
d.
analysis
 

 17. 

The ____ template weakens the default security to allow legacy applications to run under Windows Server 2003.
a.
Securews.inf
c.
Hisecws.inf
b.
Compatws.inf
d.
Iesacls.inf
 

 18. 

The ____ template contains settings to lock down Internet Explorer security settings.
a.
Hisecws.inf
c.
Iesacls.inf
b.
Rootsec.inf
d.
Compatws.inf
 

 19. 

The ____ template should only be incrementally applied to domain controllers, which must be running Windows 2000 or Windows Server 2003.
a.
Securews.inf
c.
Rootsec.inf
b.
Compatws.inf
d.
Hisecdc.inf
 

 20. 

The ____ template is used in reapplying security permissions to resources on the system drive that have been changed in one way or another.
a.
Hisecws.inf
c.
Iesacls.inf
b.
Rootsec.inf
d.
Compatws.inf
 

 21. 

To apply a security template to a local machine, open the Local Security Settings MMC snap-in by running ____.
a.
GPUPDATE.EXE
c.
SECTEMP.MMC
b.
SECPOL.MSC
d.
SECTEMP.EXE
 

 22. 

____ security settings are refreshed any time the machine is rebooted.
a.
Local Policy
c.
Group Policy
b.
Initial System
d.
Incremental
 

 23. 

Even if there have been no changes to Group Policy, the security settings are refreshed every ____.
a.
30 minutes
c.
8 hours
b.
90 minutes
d.
16 hours
 

 24. 

The ____ snap-in allows administrators to compare current system settings to a previously configured security template.
a.
Security Configuration and Analysis
c.
Security Templates
b.
Group Policy Object Editor MMC
d.
Local Security Policy
 

 25. 

____, along with the Task Scheduler, can ensure that every computer in the workgroup maintains consistent security policy settings.
a.
GPUPDATE
c.
SECSCHEDULE
b.
SECEDIT
d.
SECPOLICY
 

 26. 

The SECEDIT command uses ____ main switches.
a.
2
c.
6
b.
5
d.
8
 

 27. 

The ____ SECEDIT switch configures a system with database and template settings.
a.
/analyze
c.
/dbsettings
b.
/configure
d.
/validate
 

 28. 

The ____ SECEDIT switch examines database settings and compares them to a computer configuration.
a.
/configure
c.
/compare
b.
/validate
d.
/analyze
 

 29. 

The ____ SECEDIT switch creates a template that can be used to return to previous security settings in the event that settings are changed.
a.
/InitialSettings
c.
/GenerateRollback
b.
/compare
d.
/validate
 

 30. 

____ helps detect potential threats, increases user accountability, and provides evidence of security breaches if or when they occur.
a.
Monitoring
c.
Accounting
b.
Auditing
d.
Securing
 

 31. 

____ specific resources, such as printer and file shares, can tell you how often users are accessing them.
a.
Monitoring
c.
Accounting
b.
Auditing
d.
Securing
 

 32. 

Which of the following is first in the order in which Group Policy settings are applied?
a.
Organizational Unit
c.
Domain
b.
Local
d.
Site
 

 33. 

Which of the following comes last in the order in which Group Policy settings are applied?
a.
Organizational Unit
c.
Domain
b.
Local
d.
Site
 

 34. 

____ includes determining the computers for which auditing should be configured, what objects need to be audited, the type of events to audit, and whether to audit the successes, failures, or both.
a.
Monitoring
c.
Planning
b.
Accounting
d.
Securing
 

 35. 

By default, the security log shows events that occurred on the ____.
a.
remote host
c.
domain controller
b.
local computer
d.
monitored computer
 



 
Submit          Reset Help