SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
MCTS: Configuring Windows Firewall And Network Access Protection
Start Test
Study First
Subjects
:
certifications
,
mcts
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Win Server 2008 and Win Server 2008 R2 include an SHV that corresponds to the SHA built into Windows ______.
An access control list (ACL) - A virtual local area network (VLAN)
requirement policies
Win 7 - Win Vista - and Win XP SP3
Connection request policy
2. ______ is the most effective way to configure firewall settings for all computers in a domain.
GPO settings in the Computer ConfigurationPoliciesWindows SettingsSecurity SettingsNetwork Access ProtectionNAP Client Configuration
Group Policy
per-IP address or a per-TCP/UDP port number
Health policy - health policies
3. The NAP health policy server uses its installed SHVs and the health requirement policies that you have configured to determine whether the NAP client ______.
Network policy
meets health requirements
Health policy - health policies
noncompliant - compliant
4. IPsec enforcement requires a CA running Win Server ______ or ________ Certificate Services and NAP to support health certificates.
2008 (or Windows Server 2008 R2)
802.1X - VPN - or DHCP
blocks any inbound traffic that hasn't been specifically allowed
drops
5. A group of servers that noncompliant clients can access is a ______.
requirement policies
System Health Agents (SHAs) - System Health Validators (SHVs)
Remediation server group
802.1X - VPN - or DHCP
6. For NAP to work - a network component must enforce NAP by either allowing or denying network access. The following list describes the different NAP enforcement types you can use:
netsh nap client show state
health policy server
Remote Desktop Gateways (RD Gateway).
Network Policy And Access Services
7. When deploying NAP - plan to implement it in ______ mode first. This will allow you to identify and fix noncompliant computers before preventing them from connecting to your network.
Enforcement Clients - User Interface Settings - Health Registration Settings
System Health Agents (SHAs) - System Health Validators (SHVs)
Network Policy And Access Services
monitoring-only
8. The NAP health policy server uses the ______ to determine the level of access the client computer should have and whether any remediation is necessary.
System Health Agents (SHAs)
Domain - Private - Public
Connection request policy
SoHR
9. NAP health validation takes place between two components:
System Health Agents (SHAs) - System Health Validators (SHVs)
Network Policy And Access Services
Trusted Server Group
logging
10. ______ enforcement does not provide remediation.
RD Gateway
System Statement of Health Response (SSoHR)
An access control list (ACL) - A virtual local area network (VLAN)
VPN servers
11. You need to create outbound firewall rules only when you configure outbound connections to be ______.
A certification authority - A web application
Win 7 - Win Vista - and Win XP SP3
Health policy - health policies
blocked by default
12. The Domain firewall profile applies whenever a computer can communicate with its ______.
network access
domain controller
logging
Connection request policy
13. By default - Windows Firewall (as well as most other firewalls) ______.
14. The NAP health policy server combines the SoHRs from the multiple SHVs into a ______.
health state
Group Policy
System Statement of Health Response (SSoHR)
VPN servers
15. Typically - a NAP deployment occurs in three phases:
compliant - noncompliant - and unauthenticated
scope
Network Access Protection (NAP)
Testing - Monitoring - Limited access
16. Installing the HRA role service configures the following:
domain controller
compliant - noncompliant - and unauthenticated
A certification authority - A web application
GPO settings in the Computer ConfigurationPoliciesWindows SettingsSecurity SettingsNetwork Access ProtectionNAP Client Configuration
17. Use the ______ snap-in to create an inbound firewall rule that allows a server application to receive incoming connections.
Windows Firewall With Advanced Security
Testing - Monitoring - Limited access
Trusted Server Group
System health validators
18. The ______ are the client components that create a Statement of Health (SoH) containing a description of the health of the client computer.
Win 7 - Win Vista - and Win XP SP3
Statement of Health Response (SoHR)
System Health Agents (SHAs)
compliant - noncompliant
19. The ______ type enforces NAP for remote access connections using a VPN server running Win Server 2008 or Win Server 2008 R2 and Routing and Remote Access.
VPN servers
drops
A certification authority - A web application
Statement of Health Response (SoHR)
20. In the case of _____ - automated software attacks computers across the Internet - gains elevated privileges - copies itself to the compromised computer - and then begins attacking other computers (typically at random).
RD Gateway
System Health Agents (SHAs)
System Statement of Health Response (SSoHR)
worms
21. If an application must accept incoming connections but the developers have not documented the communication ports that the application uses - you can use the ______ tool to identify which ports the application listens on.
Netstat
Win 7 - Win Vista - and Win XP SP3
System Statement of Health Response (SSoHR)
Windows Firewall With Advanced Security
22. ______ define which health checks a client must meet to be considered compliant.
System Health Validators (SHVs)
System health validators
Netstat
Group Policy
23. NAP depends on a Win Server 2008 or Win Server 2008 R2 NAP health policy server - which acts as a ______ server - to evaluate the health of client computers.
RADIUS
Windows Firewall With Advanced Security
Testing - Monitoring - Limited access
blocks any inbound traffic that hasn't been specifically allowed
24. Which versions of Windows can act as NAP clients?
Win XP SP3 - Win Vista - Win 7 - Win Server 2008 - and Win Server 2008 R2.
Group Policy
network access
health policy server
25. The Private profile must be ______ applied to a network. The Public profile applies any time a ______ is not available - and a network has not been configured as Private.
802.1X - VPN - or DHCP
Connection request policy - System health validators - Remediation server group - Health policy - Network policy
manually - domain controller
DHCP servers
26. Typically - you apply an ACL to ______ computer connections and allow ______ computers to connect without an ACL (thus granting them unlimited network access).
netsh nap client show state
noncompliant - compliant
Network policy
SoHR
27. The ______ enforcement type requires clients to perform a NAP health check before they can receive a health certificate.
worms
IPsec connection security
2008 (or Windows Server 2008 R2)
Win 7 - Win Vista - and Win XP SP3
28. ______ allows you to verify that computers meet specific health requirements before granting them unlimited access to your internal network.
IPsec connection security - DHCP - and VPN enforcement do not require support from your network infrastructure.
Network Access Protection (NAP)
firewalls
drops
29. NAP is designed to connect hosts to different network resources depending on their current ______.
per-IP address or a per-TCP/UDP port number
IPsec connection security - DHCP - and VPN enforcement do not require support from your network infrastructure.
health state
communicate only with other
30. You must enable one policy to configure clients to use this enforcement type.
Enforcement Clients
domain controller
A certification authority - A web application
IPsec connection security
31. You can configure client NAP settings using the three subnodes:
scope
compliant client computers
Remediation server group
Enforcement Clients - User Interface Settings - Health Registration Settings
32. The NAP client sends the SSoH to the NAP ______ through the NAP enforcement point.
netsh nap client show state
compliant - noncompliant
Connection request policy
health policy server
33. A ______ determines whether a request should be processed by NPS.
Connection request policy
Connection request policy - System health validators - Remediation server group - Health policy - Network policy
health policy server
domain controller
34. The 802.1X access point applies the ACL to the connection and ______ all packets that are not allowed by the ACL.
communicate only with other
drops
Enforcement Clients - User Interface Settings - Health Registration Settings
health state
35. By default - all versions of Windows (including Win Srvr 2008 R2) ______ outbound traffic.
do not filter
Remote Desktop Gateways (RD Gateway).
netsh nap client show state
remediation
36. VLANs are identified using a VLAN identifier - which must be configured on the switch itself. You can then use NAP to specify in which VLAN the ______ computers are placed.
RD Gateway
An access control list (ACL) - A virtual local area network (VLAN)
VPN servers
compliant - noncompliant - and unauthenticated
37. To install HRA - first install the ______ role - then select the Network Policy Server check box on the Select Role Services page.
Network Policy And Access Services
Remote Desktop Gateways (RD Gateway).
Testing - Monitoring - Limited access
Statement of Health Response (SoHR)
38. The NAP health policy server sends the SSoHR back to the NAP client through the NAP enforcement point. The NAP enforcement point can now connect a ______ computer to the network or connect a ______ computer to a remediation network.
compliant - noncompliant
noncompliant - compliant
Network Access Protection (NAP)
Network Policy And Access Services
39. Health ______ determine which clients must meet health requirements - what those health requirements are - and what happens if a client cannot comply.
communicate only with other
requirement policies
Network Policy And Access Services
manually - domain controller
40. The only time you would want to configure the scope using the ______ group is when the computer is configured with multiple IP addresses - and you do not want to accept connections on all IP addresses.
SoHR
Remediation server group
Local IP Address
compliant - noncompliant
41. You can also use IPsec connection security to allow healthy computers to ______ healthy computers.
communicate only with other
Network policy
worms
manually - domain controller
42. IPsec enforcement allows you to require health compliance on a ______ or a ______ basis.
per-IP address or a per-TCP/UDP port number
RADIUS
802.1X access points
compliant - noncompliant
43. Win 7 - Win Vista - Win Server 2008 - Win Server 2008 R2 - and Win XP SP3 include an ______ that monitors Windows Security Center settings.
SHA
per-IP address or a per-TCP/UDP port number
netsh nap client show state
Connection request policy - System health validators - Remediation server group - Health policy - Network policy
44. The ______ defines health requirements using SHV settings. Separate ______ must exist for both compliant and noncompliant clients.
blocks any inbound traffic that hasn't been specifically allowed
Health policy - health policies
compliant - noncompliant
System Health Validators (SHVs)
45. The ______ enforcement type uses Ethernet switches or wireless access points that support 802.1X authentication.
logging
A certification authority - A web application
802.1X access points
Remote Desktop Gateways (RD Gateway).
46. 802.1X enforcement uses one of two methods to control which level of access compliant - noncompliant - and unauthenticated computers receive:
Netstat
Win 7 - Win Vista - and Win XP SP3
An access control list (ACL) - A virtual local area network (VLAN)
User Interface Settings
47. You can quickly verify a client's configuration by running the following command at a command prompt:
netsh nap client show state
Remediation server group
Enforcement Clients - User Interface Settings - Health Registration Settings
GPO settings in the Computer ConfigurationPoliciesWindows SettingsSecurity SettingsNetwork Access ProtectionNAP Client Configuration
48. Windows Firewall ______ identifies connections that Windows Firewall allows or blocks.
A certification authority - A web application
logging
DHCP servers
System Health Agents (SHAs)
49. Each SHA on the NAP client validates its system health and generates an SoH. The NAP client combines the SoHs from multiple SHAs into a ______ - which includes version info for the NAP client and the set of SoHs for the installed SHAs.
System Statement of Health (SSoH)
Remote Desktop Gateways (RD Gateway).
Network Policy And Access Services
blocked by default
50. With the DHCP servers enforcement type - only ______ computers receive an IP address that grants full network access; ______computers are granted an IP address with a subnet mask of 255.255.255.255 and no default gateway.
compliant - noncompliant
An access control list (ACL) - A virtual local area network (VLAN)
Remediation server group
2008 (or Windows Server 2008 R2)