SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
MCTS: Configuring Windows Firewall And Network Access Protection
Start Test
Study First
Subjects
:
certifications
,
mcts
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Use the ______ snap-in to create an inbound firewall rule that allows a server application to receive incoming connections.
Windows Firewall With Advanced Security
Group Policy
A certification authority - A web application
IPsec connection security - DHCP - and VPN enforcement do not require support from your network infrastructure.
2. The only time you would want to configure the scope using the ______ group is when the computer is configured with multiple IP addresses - and you do not want to accept connections on all IP addresses.
Netstat
Local IP Address
SoHR
meets health requirements
3. The Domain firewall profile applies whenever a computer can communicate with its ______.
GPO settings in the Computer ConfigurationPoliciesWindows SettingsSecurity SettingsNetwork Access ProtectionNAP Client Configuration
DHCP servers
Netstat
domain controller
4. IPsec enforcement allows you to require health compliance on a ______ or a ______ basis.
per-IP address or a per-TCP/UDP port number
Enforcement Clients - User Interface Settings - Health Registration Settings
remediation
DHCP servers
5. The NAP health policy server combines the SoHRs from the multiple SHVs into a ______.
802.1X - VPN - or DHCP
Domain - Private - Public
System Statement of Health Response (SSoHR)
Trusted Server Group
6. ______ allows you to verify that computers meet specific health requirements before granting them unlimited access to your internal network.
Network Access Protection (NAP)
2008 (or Windows Server 2008 R2)
scope
Remediation server group
7. Each SHA on the NAP client validates its system health and generates an SoH. The NAP client combines the SoHs from multiple SHAs into a ______ - which includes version info for the NAP client and the set of SoHs for the installed SHAs.
System Statement of Health Response (SSoHR)
System Statement of Health (SSoH)
Netstat
2008 (or Windows Server 2008 R2)
8. Each SHV produces a _____ - which can contain remediation instructions (such as the version number of an antivirus signature file) if the client doesn't meet that SHV's health requirements.
Request Policy
SHA
Statement of Health Response (SoHR)
System Statement of Health Response (SSoHR)
9. Use the ______ subnode to configure an HRA for IPsec NAP clients to use.
blocked by default
IPsec connection security
Trusted Server Group
Network policy
10. The NAP client sends the SSoH to the NAP ______ through the NAP enforcement point.
RADIUS
System Statement of Health (SSoH)
health policy server
Connection request policy - System health validators - Remediation server group - Health policy - Network policy
11. To install HRA - first install the ______ role - then select the Network Policy Server check box on the Select Role Services page.
802.1X - VPN - or DHCP
Network Policy And Access Services
A certification authority - A web application
Group Policy
12. A health requirement policy is a combination of the following:
Connection request policy - System health validators - Remediation server group - Health policy - Network policy
requirement policies
SoHR
Connection request policy
13. With 802.1X - compliant computers are granted full network access - and noncompliant computers are connected to a ______ network or completely prevented from connecting to the network.
remediation
compliant - noncompliant
meets health requirements
Trusted Server Group
14. The Private profile must be ______ applied to a network. The Public profile applies any time a ______ is not available - and a network has not been configured as Private.
Domain - Private - Public
blocks any inbound traffic that hasn't been specifically allowed
manually - domain controller
compliant - noncompliant
15. The ______ defines the level of network access clients get based on which health policy they match.
SHA
Network policy
DHCP servers
Win XP SP3 - Win Vista - Win 7 - Win Server 2008 - and Win Server 2008 R2.
16. If an application must accept incoming connections but the developers have not documented the communication ports that the application uses - you can use the ______ tool to identify which ports the application listens on.
compliant - noncompliant
Netstat
802.1X - VPN - or DHCP
SoHR
17. The firewall profiles are:
Domain - Private - Public
Network policy
manually - domain controller
scope
18. Which versions of Windows can act as NAP clients?
blocked by default
compliant - noncompliant
Win XP SP3 - Win Vista - Win 7 - Win Server 2008 - and Win Server 2008 R2.
scope
19. If a computer falls out of compliance after connecting to the 802.1X network - the 802.1X network access device can change the computer's ______.
Domain - Private - Public
network access
System Health Agents (SHAs) - System Health Validators (SHVs)
communicate only with other
20. You need to create outbound firewall rules only when you configure outbound connections to be ______.
VPN servers
requirement policies
blocked by default
Statement of Health Response (SoHR)
21. The NAP health policy server uses the ______ to determine the level of access the client computer should have and whether any remediation is necessary.
remediation
DHCP servers
SoHR
health state
22. You must enable one policy to configure clients to use this enforcement type.
System Statement of Health (SSoH)
requirement policies
netsh nap client show state
Enforcement Clients
23. In networking - ______ analyze communications and drop packets that haven't been specifically allowed.
2008 (or Windows Server 2008 R2)
compliant client computers
firewalls
compliant - noncompliant
24. With the DHCP servers enforcement type - only ______ computers receive an IP address that grants full network access; ______computers are granted an IP address with a subnet mask of 255.255.255.255 and no default gateway.
compliant - noncompliant
Statement of Health Response (SoHR)
SHA
Health policy - health policies
25. The 802.1X access point applies the ACL to the connection and ______ all packets that are not allowed by the ACL.
drops
Enforcement Clients - User Interface Settings - Health Registration Settings
Remediation server group
health policy server
26. Installing the HRA role service configures the following:
IPsec connection security - DHCP - and VPN enforcement do not require support from your network infrastructure.
A certification authority - A web application
System Statement of Health Response (SSoHR)
System Health Agents (SHAs) - System Health Validators (SHVs)
27. By default - all versions of Windows (including Win Srvr 2008 R2) ______ outbound traffic.
RD Gateway
RADIUS
do not filter
Trusted Server Group
28. ______ define which health checks a client must meet to be considered compliant.
Connection request policy
System health validators
Network Access Protection (NAP)
RD Gateway
29. If you use Remote Desktop to allow users to control their desktops from remote computers across the Internet - you can use the ______ enforcement type to block access unless the client computer passes a health check.
scope
RD Gateway
compliant client computers
meets health requirements
30. In the case of _____ - automated software attacks computers across the Internet - gains elevated privileges - copies itself to the compromised computer - and then begins attacking other computers (typically at random).
noncompliant - compliant
worms
Testing - Monitoring - Limited access
logging
31. VLANs are identified using a VLAN identifier - which must be configured on the switch itself. You can then use NAP to specify in which VLAN the ______ computers are placed.
GPO settings in the Computer ConfigurationPoliciesWindows SettingsSecurity SettingsNetwork Access ProtectionNAP Client Configuration
compliant - noncompliant
compliant - noncompliant - and unauthenticated
scope
32. Typically - a NAP deployment occurs in three phases:
Domain - Private - Public
Netstat
meets health requirements
Testing - Monitoring - Limited access
33. NAP health validation takes place between two components:
System Health Agents (SHAs) - System Health Validators (SHVs)
do not filter
domain controller
Network Policy And Access Services
34. The ______ enforcement type requires clients to perform a NAP health check before they can receive a health certificate.
compliant - noncompliant
IPsec connection security
blocked by default
health state
35. ______ is the most effective way to configure firewall settings for all computers in a domain.
System Health Agents (SHAs)
Group Policy
compliant client computers
Local IP Address
36. The NAP health policy server uses its installed SHVs and the health requirement policies that you have configured to determine whether the NAP client ______.
meets health requirements
VPN servers
Remediation server group
RD Gateway
37. Typically - you apply an ACL to ______ computer connections and allow ______ computers to connect without an ACL (thus granting them unlimited network access).
SoHR
manually - domain controller
netsh nap client show state
noncompliant - compliant
38. IPsec enforcement requires a CA running Win Server ______ or ________ Certificate Services and NAP to support health certificates.
Connection request policy - System health validators - Remediation server group - Health policy - Network policy
A certification authority - A web application
netsh nap client show state
2008 (or Windows Server 2008 R2)
39. The ______ enforcement type uses Ethernet switches or wireless access points that support 802.1X authentication.
DHCP servers
blocks any inbound traffic that hasn't been specifically allowed
802.1X access points
netsh nap client show state
40. Configure the ______ policy to provide customized text (and - optionally - an image) that users will see as part of the NAP client interface.
compliant - noncompliant
Windows Firewall With Advanced Security
User Interface Settings
Remediation server group
41. When deploying NAP - plan to implement it in ______ mode first. This will allow you to identify and fix noncompliant computers before preventing them from connecting to your network.
Health policy - health policies
requirement policies
firewalls
monitoring-only
42. Which NAP enforcement types do not require support from your network infrastructure?
firewalls
logging
Remote Desktop Gateways (RD Gateway).
IPsec connection security - DHCP - and VPN enforcement do not require support from your network infrastructure.
43. This installs the core NPS service - which is sufficient for using the Win Server 2008 computer as a RADIUS server for ______ - ______ - or ______ enforcement.
System Health Validators (SHVs)
SoHR
802.1X - VPN - or DHCP
Win XP SP3 - Win Vista - Win 7 - Win Server 2008 - and Win Server 2008 R2.
44. You can quickly verify a client's configuration by running the following command at a command prompt:
netsh nap client show state
Win 7 - Win Vista - and Win XP SP3
SoHR
SHA
45. One of the most powerful ways to increase computer security is to configure firewall ______.
Testing - Monitoring - Limited access
do not filter
Request Policy
scope
46. The ______ are the client components that create a Statement of Health (SoH) containing a description of the health of the client computer.
Local IP Address
SoHR
System Health Agents (SHAs)
Connection request policy
47. With VPN server enforcement enabled - only ______ are granted unlimited network access.
System Health Agents (SHAs) - System Health Validators (SHVs)
SHA
compliant - noncompliant - and unauthenticated
compliant client computers
48. NAP depends on a Win Server 2008 or Win Server 2008 R2 NAP health policy server - which acts as a ______ server - to evaluate the health of client computers.
System Statement of Health (SSoH)
communicate only with other
RADIUS
scope
49. You can configure client NAP settings using the three subnodes:
scope
do not filter
Windows Firewall With Advanced Security
Enforcement Clients - User Interface Settings - Health Registration Settings
50. Health ______ determine which clients must meet health requirements - what those health requirements are - and what happens if a client cannot comply.
System Statement of Health Response (SSoHR)
requirement policies
An access control list (ACL) - A virtual local area network (VLAN)
SHA