SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
MCTS: Configuring Windows Firewall And Network Access Protection
Start Test
Study First
Subjects
:
certifications
,
mcts
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. For NAP to work - a network component must enforce NAP by either allowing or denying network access. The following list describes the different NAP enforcement types you can use:
Win 7 - Win Vista - and Win XP SP3
compliant client computers
Remote Desktop Gateways (RD Gateway).
GPO settings in the Computer ConfigurationPoliciesWindows SettingsSecurity SettingsNetwork Access ProtectionNAP Client Configuration
2. IPsec enforcement requires a CA running Win Server ______ or ________ Certificate Services and NAP to support health certificates.
2008 (or Windows Server 2008 R2)
domain controller
Windows Firewall With Advanced Security
RD Gateway
3. When deploying NAP - plan to implement it in ______ mode first. This will allow you to identify and fix noncompliant computers before preventing them from connecting to your network.
SoHR
Connection request policy
Trusted Server Group
monitoring-only
4. ______ enforcement does not provide remediation.
RD Gateway
System Statement of Health Response (SSoHR)
logging
firewalls
5. Which NAP enforcement types do not require support from your network infrastructure?
SHA
System Statement of Health Response (SSoHR)
IPsec connection security - DHCP - and VPN enforcement do not require support from your network infrastructure.
worms
6. The ______ defines the level of network access clients get based on which health policy they match.
Network policy
compliant - noncompliant - and unauthenticated
logging
Windows Firewall With Advanced Security
7. Use the ______ snap-in to create an inbound firewall rule that allows a server application to receive incoming connections.
Request Policy
health policy server
Local IP Address
Windows Firewall With Advanced Security
8. The ______ enforcement type uses a computer running Win Server 2008 or Win Server 2008 R2 and the DHCP Server service that provides IP addresses to intranet clients.
DHCP servers
System health validators
per-IP address or a per-TCP/UDP port number
SHA
9. A health requirement policy is a combination of the following:
Enforcement Clients
Connection request policy - System health validators - Remediation server group - Health policy - Network policy
monitoring-only
A certification authority - A web application
10. If you use Remote Desktop to allow users to control their desktops from remote computers across the Internet - you can use the ______ enforcement type to block access unless the client computer passes a health check.
Win XP SP3 - Win Vista - Win 7 - Win Server 2008 - and Win Server 2008 R2.
RD Gateway
System Health Agents (SHAs)
Network policy
11. A ______ determines whether a request should be processed by NPS.
Request Policy
SHA
Trusted Server Group
Connection request policy
12. Use the ______ subnode to configure an HRA for IPsec NAP clients to use.
Remote Desktop Gateways (RD Gateway).
Enforcement Clients - User Interface Settings - Health Registration Settings
manually - domain controller
Trusted Server Group
13. The NAP health policy server combines the SoHRs from the multiple SHVs into a ______.
Health policy - health policies
System Statement of Health Response (SSoHR)
Local IP Address
System Statement of Health (SSoH)
14. After configuring the NPS server - you must configure client computers for NAP. The easiest way to do this is to use ______ node.
Remediation server group
worms
GPO settings in the Computer ConfigurationPoliciesWindows SettingsSecurity SettingsNetwork Access ProtectionNAP Client Configuration
remediation
15. NAP depends on a Win Server 2008 or Win Server 2008 R2 NAP health policy server - which acts as a ______ server - to evaluate the health of client computers.
RADIUS
Connection request policy - System health validators - Remediation server group - Health policy - Network policy
SHA
System Health Agents (SHAs) - System Health Validators (SHVs)
16. By default - Windows Firewall (as well as most other firewalls) ______.
17. In networking - ______ analyze communications and drop packets that haven't been specifically allowed.
SHA
firewalls
Network Policy And Access Services
802.1X access points
18. The ______ are the server components that analyze the SoH generated by the SHA and create an SoH Response (SoHR).
Enforcement Clients - User Interface Settings - Health Registration Settings
health state
Win 7 - Win Vista - and Win XP SP3
System Health Validators (SHVs)
19. Configure the ______ policy to provide customized text (and - optionally - an image) that users will see as part of the NAP client interface.
domain controller
firewalls
User Interface Settings
compliant - noncompliant
20. To install NAP - first install the ______ role - then select the Network Policy Server check box on the Select Role Services page.
logging
Network Policy And Access Services
meets health requirements
Enforcement Clients - User Interface Settings - Health Registration Settings
21. ______ allows you to verify that computers meet specific health requirements before granting them unlimited access to your internal network.
firewalls
do not filter
Network Policy And Access Services
Network Access Protection (NAP)
22. The Private profile must be ______ applied to a network. The Public profile applies any time a ______ is not available - and a network has not been configured as Private.
Testing - Monitoring - Limited access
firewalls
manually - domain controller
Remote Desktop Gateways (RD Gateway).
23. The ______ defines health requirements using SHV settings. Separate ______ must exist for both compliant and noncompliant clients.
domain controller
IPsec connection security
DHCP servers
Health policy - health policies
24. The NAP health policy server sends the SSoHR back to the NAP client through the NAP enforcement point. The NAP enforcement point can now connect a ______ computer to the network or connect a ______ computer to a remediation network.
802.1X access points
compliant - noncompliant
drops
blocked by default
25. 802.1X enforcement uses one of two methods to control which level of access compliant - noncompliant - and unauthenticated computers receive:
An access control list (ACL) - A virtual local area network (VLAN)
compliant - noncompliant
blocks any inbound traffic that hasn't been specifically allowed
System Statement of Health Response (SSoHR)
26. One of the most powerful ways to increase computer security is to configure firewall ______.
VPN servers
System Health Agents (SHAs)
scope
DHCP servers
27. By default - all versions of Windows (including Win Srvr 2008 R2) ______ outbound traffic.
compliant client computers
do not filter
RADIUS
Remediation server group
28. ______ define which health checks a client must meet to be considered compliant.
noncompliant - compliant
Windows Firewall With Advanced Security
Connection request policy
System health validators
29. You can configure client NAP settings using the three subnodes:
requirement policies
Enforcement Clients - User Interface Settings - Health Registration Settings
compliant - noncompliant - and unauthenticated
firewalls
30. Which versions of Windows can act as NAP clients?
System Health Agents (SHAs) - System Health Validators (SHVs)
monitoring-only
Win XP SP3 - Win Vista - Win 7 - Win Server 2008 - and Win Server 2008 R2.
Connection request policy - System health validators - Remediation server group - Health policy - Network policy
31. Win Server 2008 and Win Server 2008 R2 include an SHV that corresponds to the SHA built into Windows ______.
Win 7 - Win Vista - and Win XP SP3
drops
scope
do not filter
32. Each SHA on the NAP client validates its system health and generates an SoH. The NAP client combines the SoHs from multiple SHAs into a ______ - which includes version info for the NAP client and the set of SoHs for the installed SHAs.
Network Policy And Access Services
Statement of Health Response (SoHR)
System Statement of Health (SSoH)
network access
33. The ______ are the client components that create a Statement of Health (SoH) containing a description of the health of the client computer.
System Health Agents (SHAs) - System Health Validators (SHVs)
noncompliant - compliant
System Health Agents (SHAs)
Health policy - health policies
34. Installing the HRA role service configures the following:
compliant client computers
logging
A certification authority - A web application
netsh nap client show state
35. The NAP health policy server uses its installed SHVs and the health requirement policies that you have configured to determine whether the NAP client ______.
meets health requirements
netsh nap client show state
monitoring-only
scope
36. With 802.1X - compliant computers are granted full network access - and noncompliant computers are connected to a ______ network or completely prevented from connecting to the network.
remediation
do not filter
scope
Testing - Monitoring - Limited access
37. You must enable one policy to configure clients to use this enforcement type.
Netstat
logging
Enforcement Clients
logging
38. The ______ enforcement type uses Ethernet switches or wireless access points that support 802.1X authentication.
User Interface Settings
802.1X access points
meets health requirements
compliant - noncompliant - and unauthenticated
39. The Domain firewall profile applies whenever a computer can communicate with its ______.
Local IP Address
domain controller
noncompliant - compliant
Testing - Monitoring - Limited access
40. You can also use IPsec connection security to allow healthy computers to ______ healthy computers.
System health validators
remediation
firewalls
communicate only with other
41. A group of servers that noncompliant clients can access is a ______.
do not filter
System health validators
Remediation server group
Connection request policy - System health validators - Remediation server group - Health policy - Network policy
42. You can quickly verify a client's configuration by running the following command at a command prompt:
Statement of Health Response (SoHR)
A certification authority - A web application
RD Gateway
netsh nap client show state
43. VLANs are identified using a VLAN identifier - which must be configured on the switch itself. You can then use NAP to specify in which VLAN the ______ computers are placed.
Enforcement Clients
health state
Testing - Monitoring - Limited access
compliant - noncompliant - and unauthenticated
44. NAP ______ allows you to identify noncompliant computers.
blocked by default
logging
noncompliant - compliant
communicate only with other
45. Each SHV produces a _____ - which can contain remediation instructions (such as the version number of an antivirus signature file) if the client doesn't meet that SHV's health requirements.
Statement of Health Response (SoHR)
An access control list (ACL) - A virtual local area network (VLAN)
compliant - noncompliant
System Health Validators (SHVs)
46. Windows Firewall ______ identifies connections that Windows Firewall allows or blocks.
DHCP servers
802.1X access points
System health validators
logging
47. Health ______ determine which clients must meet health requirements - what those health requirements are - and what happens if a client cannot comply.
User Interface Settings
RD Gateway
requirement policies
compliant - noncompliant - and unauthenticated
48. The ______ enforcement type requires clients to perform a NAP health check before they can receive a health certificate.
IPsec connection security
System Health Agents (SHAs) - System Health Validators (SHVs)
per-IP address or a per-TCP/UDP port number
firewalls
49. You need to create outbound firewall rules only when you configure outbound connections to be ______.
network access
blocked by default
compliant - noncompliant
blocks any inbound traffic that hasn't been specifically allowed
50. With VPN server enforcement enabled - only ______ are granted unlimited network access.
Group Policy
compliant client computers
health state
do not filter