SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
MCTS: Configuring Windows Firewall And Network Access Protection
Start Test
Study First
Subjects
:
certifications
,
mcts
,
it-skills
Instructions:
Answer
50
questions in
15 minutes
.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. 802.1X enforcement uses one of two methods to control which level of access compliant - noncompliant - and unauthenticated computers receive:
An access control list (ACL) - A virtual local area network (VLAN)
Testing - Monitoring - Limited access
worms
Network Policy And Access Services
2. The ______ defines the level of network access clients get based on which health policy they match.
per-IP address or a per-TCP/UDP port number
System Statement of Health (SSoH)
Network policy
System Health Agents (SHAs) - System Health Validators (SHVs)
3. Use the ______ snap-in to create an inbound firewall rule that allows a server application to receive incoming connections.
SoHR
communicate only with other
compliant - noncompliant
Windows Firewall With Advanced Security
4. A group of servers that noncompliant clients can access is a ______.
remediation
Connection request policy - System health validators - Remediation server group - Health policy - Network policy
Remediation server group
Remote Desktop Gateways (RD Gateway).
5. After configuring the NPS server - you must configure client computers for NAP. The easiest way to do this is to use ______ node.
Remediation server group
worms
Win XP SP3 - Win Vista - Win 7 - Win Server 2008 - and Win Server 2008 R2.
GPO settings in the Computer ConfigurationPoliciesWindows SettingsSecurity SettingsNetwork Access ProtectionNAP Client Configuration
6. Which versions of Windows can act as NAP clients?
2008 (or Windows Server 2008 R2)
A certification authority - A web application
Win XP SP3 - Win Vista - Win 7 - Win Server 2008 - and Win Server 2008 R2.
User Interface Settings
7. The 802.1X access point applies the ACL to the connection and ______ all packets that are not allowed by the ACL.
communicate only with other
Network Policy And Access Services
GPO settings in the Computer ConfigurationPoliciesWindows SettingsSecurity SettingsNetwork Access ProtectionNAP Client Configuration
drops
8. IPsec enforcement allows you to require health compliance on a ______ or a ______ basis.
RD Gateway
Remote Desktop Gateways (RD Gateway).
per-IP address or a per-TCP/UDP port number
firewalls
9. For NAP to work - a network component must enforce NAP by either allowing or denying network access. The following list describes the different NAP enforcement types you can use:
Network Access Protection (NAP)
Remote Desktop Gateways (RD Gateway).
compliant - noncompliant
Win 7 - Win Vista - and Win XP SP3
10. Win 7 - Win Vista - Win Server 2008 - Win Server 2008 R2 - and Win XP SP3 include an ______ that monitors Windows Security Center settings.
SHA
do not filter
health state
Windows Firewall With Advanced Security
11. You can configure client NAP settings using the three subnodes:
scope
Enforcement Clients - User Interface Settings - Health Registration Settings
Remediation server group
User Interface Settings
12. A health requirement policy is a combination of the following:
netsh nap client show state
RADIUS
compliant - noncompliant - and unauthenticated
Connection request policy - System health validators - Remediation server group - Health policy - Network policy
13. A ______ determines whether a request should be processed by NPS.
System Statement of Health Response (SSoHR)
Connection request policy
noncompliant - compliant
network access
14. In the case of _____ - automated software attacks computers across the Internet - gains elevated privileges - copies itself to the compromised computer - and then begins attacking other computers (typically at random).
Domain - Private - Public
compliant - noncompliant - and unauthenticated
worms
Windows Firewall With Advanced Security
15. With VPN server enforcement enabled - only ______ are granted unlimited network access.
compliant client computers
domain controller
requirement policies
DHCP servers
16. By default - all versions of Windows (including Win Srvr 2008 R2) ______ outbound traffic.
do not filter
manually - domain controller
Network Access Protection (NAP)
logging
17. To install HRA - first install the ______ role - then select the Network Policy Server check box on the Select Role Services page.
SHA
compliant - noncompliant
2008 (or Windows Server 2008 R2)
Network Policy And Access Services
18. One of the most powerful ways to increase computer security is to configure firewall ______.
Enforcement Clients
manually - domain controller
do not filter
scope
19. Each SHA on the NAP client validates its system health and generates an SoH. The NAP client combines the SoHs from multiple SHAs into a ______ - which includes version info for the NAP client and the set of SoHs for the installed SHAs.
Enforcement Clients - User Interface Settings - Health Registration Settings
System Statement of Health (SSoH)
RD Gateway
drops
20. The ______ enforcement type uses a computer running Win Server 2008 or Win Server 2008 R2 and the DHCP Server service that provides IP addresses to intranet clients.
Statement of Health Response (SoHR)
logging
drops
DHCP servers
21. NAP depends on a Win Server 2008 or Win Server 2008 R2 NAP health policy server - which acts as a ______ server - to evaluate the health of client computers.
Enforcement Clients
RADIUS
meets health requirements
compliant client computers
22. ______ define which health checks a client must meet to be considered compliant.
System health validators
meets health requirements
2008 (or Windows Server 2008 R2)
manually - domain controller
23. Each SHV produces a _____ - which can contain remediation instructions (such as the version number of an antivirus signature file) if the client doesn't meet that SHV's health requirements.
remediation
per-IP address or a per-TCP/UDP port number
Enforcement Clients
Statement of Health Response (SoHR)
24. Typically - you apply an ACL to ______ computer connections and allow ______ computers to connect without an ACL (thus granting them unlimited network access).
compliant - noncompliant
Enforcement Clients
noncompliant - compliant
Network Policy And Access Services
25. You must enable one policy to configure clients to use this enforcement type.
Enforcement Clients
firewalls
compliant client computers
Group Policy
26. NAP health validation takes place between two components:
Network policy
Group Policy
per-IP address or a per-TCP/UDP port number
System Health Agents (SHAs) - System Health Validators (SHVs)
27. You need to create outbound firewall rules only when you configure outbound connections to be ______.
System Health Agents (SHAs) - System Health Validators (SHVs)
RADIUS
blocks any inbound traffic that hasn't been specifically allowed
blocked by default
28. In networking - ______ analyze communications and drop packets that haven't been specifically allowed.
do not filter
Domain - Private - Public
firewalls
SoHR
29. The ______ defines health requirements using SHV settings. Separate ______ must exist for both compliant and noncompliant clients.
Health policy - health policies
Group Policy
worms
Network Policy And Access Services
30. The ______ enforcement type requires clients to perform a NAP health check before they can receive a health certificate.
Connection request policy
IPsec connection security
worms
Win XP SP3 - Win Vista - Win 7 - Win Server 2008 - and Win Server 2008 R2.
31. Use the ______ subnode to configure cryptographic settings for NAP clients (the default settings are typically fine).
Request Policy
drops
health state
health policy server
32. The firewall profiles are:
IPsec connection security - DHCP - and VPN enforcement do not require support from your network infrastructure.
System Health Validators (SHVs)
Domain - Private - Public
RD Gateway
33. Health ______ determine which clients must meet health requirements - what those health requirements are - and what happens if a client cannot comply.
requirement policies
compliant client computers
System Statement of Health Response (SSoHR)
manually - domain controller
34. Win Server 2008 and Win Server 2008 R2 include an SHV that corresponds to the SHA built into Windows ______.
meets health requirements
logging
compliant - noncompliant
Win 7 - Win Vista - and Win XP SP3
35. The only time you would want to configure the scope using the ______ group is when the computer is configured with multiple IP addresses - and you do not want to accept connections on all IP addresses.
per-IP address or a per-TCP/UDP port number
IPsec connection security
System Statement of Health Response (SSoHR)
Local IP Address
36. Configure the ______ policy to provide customized text (and - optionally - an image) that users will see as part of the NAP client interface.
RD Gateway
User Interface Settings
health policy server
Domain - Private - Public
37. The NAP health policy server combines the SoHRs from the multiple SHVs into a ______.
System Statement of Health Response (SSoHR)
IPsec connection security
health policy server
Enforcement Clients
38. VLANs are identified using a VLAN identifier - which must be configured on the switch itself. You can then use NAP to specify in which VLAN the ______ computers are placed.
health policy server
compliant - noncompliant - and unauthenticated
Trusted Server Group
Connection request policy - System health validators - Remediation server group - Health policy - Network policy
39. The ______ type enforces NAP for remote access connections using a VPN server running Win Server 2008 or Win Server 2008 R2 and Routing and Remote Access.
802.1X access points
VPN servers
RD Gateway
Local IP Address
40. This installs the core NPS service - which is sufficient for using the Win Server 2008 computer as a RADIUS server for ______ - ______ - or ______ enforcement.
Group Policy
802.1X - VPN - or DHCP
Windows Firewall With Advanced Security
802.1X access points
41. Windows Firewall ______ identifies connections that Windows Firewall allows or blocks.
Domain - Private - Public
logging
compliant client computers
scope
42. The ______ are the server components that analyze the SoH generated by the SHA and create an SoH Response (SoHR).
drops
meets health requirements
System Health Validators (SHVs)
manually - domain controller
43. The ______ enforcement type uses Ethernet switches or wireless access points that support 802.1X authentication.
802.1X access points
Enforcement Clients - User Interface Settings - Health Registration Settings
Testing - Monitoring - Limited access
firewalls
44. The NAP health policy server uses its installed SHVs and the health requirement policies that you have configured to determine whether the NAP client ______.
Connection request policy
Network Access Protection (NAP)
Connection request policy - System health validators - Remediation server group - Health policy - Network policy
meets health requirements
45. ______ enforcement does not provide remediation.
Local IP Address
RD Gateway
scope
2008 (or Windows Server 2008 R2)
46. The NAP health policy server sends the SSoHR back to the NAP client through the NAP enforcement point. The NAP enforcement point can now connect a ______ computer to the network or connect a ______ computer to a remediation network.
A certification authority - A web application
scope
noncompliant - compliant
compliant - noncompliant
47. To install NAP - first install the ______ role - then select the Network Policy Server check box on the Select Role Services page.
noncompliant - compliant
Network Policy And Access Services
Request Policy
DHCP servers
48. The NAP client sends the SSoH to the NAP ______ through the NAP enforcement point.
health policy server
scope
RD Gateway
Remediation server group
49. IPsec enforcement requires a CA running Win Server ______ or ________ Certificate Services and NAP to support health certificates.
compliant - noncompliant - and unauthenticated
2008 (or Windows Server 2008 R2)
RD Gateway
System Statement of Health (SSoH)
50. When deploying NAP - plan to implement it in ______ mode first. This will allow you to identify and fix noncompliant computers before preventing them from connecting to your network.
monitoring-only
RD Gateway
Request Policy
network access