SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
MCTS: Configuring Windows Firewall And Network Access Protection
Start Test
Study First
Subjects
:
certifications
,
mcts
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. By default - all versions of Windows (including Win Srvr 2008 R2) ______ outbound traffic.
System health validators
SHA
do not filter
SoHR
2. Health ______ determine which clients must meet health requirements - what those health requirements are - and what happens if a client cannot comply.
health policy server
requirement policies
User Interface Settings
communicate only with other
3. The NAP health policy server uses its installed SHVs and the health requirement policies that you have configured to determine whether the NAP client ______.
meets health requirements
System Health Validators (SHVs)
compliant - noncompliant
communicate only with other
4. If an application must accept incoming connections but the developers have not documented the communication ports that the application uses - you can use the ______ tool to identify which ports the application listens on.
blocked by default
RD Gateway
Request Policy
Netstat
5. You can also use IPsec connection security to allow healthy computers to ______ healthy computers.
Group Policy
IPsec connection security
logging
communicate only with other
6. If a computer falls out of compliance after connecting to the 802.1X network - the 802.1X network access device can change the computer's ______.
network access
User Interface Settings
logging
SoHR
7. The ______ are the client components that create a Statement of Health (SoH) containing a description of the health of the client computer.
RADIUS
System Health Agents (SHAs)
logging
802.1X access points
8. Win 7 - Win Vista - Win Server 2008 - Win Server 2008 R2 - and Win XP SP3 include an ______ that monitors Windows Security Center settings.
SHA
Win XP SP3 - Win Vista - Win 7 - Win Server 2008 - and Win Server 2008 R2.
RADIUS
2008 (or Windows Server 2008 R2)
9. IPsec enforcement allows you to require health compliance on a ______ or a ______ basis.
per-IP address or a per-TCP/UDP port number
firewalls
A certification authority - A web application
Network policy
10. In the case of _____ - automated software attacks computers across the Internet - gains elevated privileges - copies itself to the compromised computer - and then begins attacking other computers (typically at random).
802.1X access points
Connection request policy - System health validators - Remediation server group - Health policy - Network policy
System Health Agents (SHAs)
worms
11. The NAP health policy server combines the SoHRs from the multiple SHVs into a ______.
System Statement of Health Response (SSoHR)
requirement policies
Network Policy And Access Services
An access control list (ACL) - A virtual local area network (VLAN)
12. Windows Firewall ______ identifies connections that Windows Firewall allows or blocks.
health state
logging
Win XP SP3 - Win Vista - Win 7 - Win Server 2008 - and Win Server 2008 R2.
Network Access Protection (NAP)
13. A group of servers that noncompliant clients can access is a ______.
Enforcement Clients
Remediation server group
RADIUS
System Health Agents (SHAs)
14. The NAP health policy server sends the SSoHR back to the NAP client through the NAP enforcement point. The NAP enforcement point can now connect a ______ computer to the network or connect a ______ computer to a remediation network.
RADIUS
RD Gateway
Network Policy And Access Services
compliant - noncompliant
15. The 802.1X access point applies the ACL to the connection and ______ all packets that are not allowed by the ACL.
SHA
Remediation server group
drops
System Health Agents (SHAs)
16. ______ is the most effective way to configure firewall settings for all computers in a domain.
Request Policy
Network policy
Group Policy
Remote Desktop Gateways (RD Gateway).
17. VLANs are identified using a VLAN identifier - which must be configured on the switch itself. You can then use NAP to specify in which VLAN the ______ computers are placed.
compliant - noncompliant - and unauthenticated
domain controller
SHA
Windows Firewall With Advanced Security
18. Each SHA on the NAP client validates its system health and generates an SoH. The NAP client combines the SoHs from multiple SHAs into a ______ - which includes version info for the NAP client and the set of SoHs for the installed SHAs.
SHA
RD Gateway
System Statement of Health (SSoH)
Network Access Protection (NAP)
19. ______ allows you to verify that computers meet specific health requirements before granting them unlimited access to your internal network.
Testing - Monitoring - Limited access
Network Policy And Access Services
An access control list (ACL) - A virtual local area network (VLAN)
Network Access Protection (NAP)
20. You must enable one policy to configure clients to use this enforcement type.
SoHR
DHCP servers
Enforcement Clients
Request Policy
21. A ______ determines whether a request should be processed by NPS.
GPO settings in the Computer ConfigurationPoliciesWindows SettingsSecurity SettingsNetwork Access ProtectionNAP Client Configuration
network access
Connection request policy
firewalls
22. After configuring the NPS server - you must configure client computers for NAP. The easiest way to do this is to use ______ node.
drops
compliant - noncompliant
Remote Desktop Gateways (RD Gateway).
GPO settings in the Computer ConfigurationPoliciesWindows SettingsSecurity SettingsNetwork Access ProtectionNAP Client Configuration
23. A health requirement policy is a combination of the following:
Trusted Server Group
Connection request policy - System health validators - Remediation server group - Health policy - Network policy
communicate only with other
Win XP SP3 - Win Vista - Win 7 - Win Server 2008 - and Win Server 2008 R2.
24. Use the ______ subnode to configure an HRA for IPsec NAP clients to use.
Trusted Server Group
logging
compliant - noncompliant - and unauthenticated
A certification authority - A web application
25. For NAP to work - a network component must enforce NAP by either allowing or denying network access. The following list describes the different NAP enforcement types you can use:
Netstat
Remote Desktop Gateways (RD Gateway).
compliant - noncompliant
remediation
26. One of the most powerful ways to increase computer security is to configure firewall ______.
scope
Enforcement Clients - User Interface Settings - Health Registration Settings
Network Policy And Access Services
A certification authority - A web application
27. Installing the HRA role service configures the following:
worms
A certification authority - A web application
System Health Agents (SHAs) - System Health Validators (SHVs)
Testing - Monitoring - Limited access
28. ______ define which health checks a client must meet to be considered compliant.
Connection request policy
logging
compliant - noncompliant
System health validators
29. Which NAP enforcement types do not require support from your network infrastructure?
firewalls
manually - domain controller
IPsec connection security - DHCP - and VPN enforcement do not require support from your network infrastructure.
Remote Desktop Gateways (RD Gateway).
30. The NAP health policy server uses the ______ to determine the level of access the client computer should have and whether any remediation is necessary.
Enforcement Clients - User Interface Settings - Health Registration Settings
Windows Firewall With Advanced Security
SoHR
domain controller
31. You can configure client NAP settings using the three subnodes:
Domain - Private - Public
Network Policy And Access Services
Enforcement Clients - User Interface Settings - Health Registration Settings
System Health Validators (SHVs)
32. The Private profile must be ______ applied to a network. The Public profile applies any time a ______ is not available - and a network has not been configured as Private.
RD Gateway
Win 7 - Win Vista - and Win XP SP3
manually - domain controller
scope
33. Which versions of Windows can act as NAP clients?
Win XP SP3 - Win Vista - Win 7 - Win Server 2008 - and Win Server 2008 R2.
Statement of Health Response (SoHR)
A certification authority - A web application
Health policy - health policies
34. NAP ______ allows you to identify noncompliant computers.
SHA
Win XP SP3 - Win Vista - Win 7 - Win Server 2008 - and Win Server 2008 R2.
GPO settings in the Computer ConfigurationPoliciesWindows SettingsSecurity SettingsNetwork Access ProtectionNAP Client Configuration
logging
35. Each SHV produces a _____ - which can contain remediation instructions (such as the version number of an antivirus signature file) if the client doesn't meet that SHV's health requirements.
network access
Statement of Health Response (SoHR)
IPsec connection security - DHCP - and VPN enforcement do not require support from your network infrastructure.
Netstat
36. The ______ defines health requirements using SHV settings. Separate ______ must exist for both compliant and noncompliant clients.
Network Access Protection (NAP)
Enforcement Clients - User Interface Settings - Health Registration Settings
Network Policy And Access Services
Health policy - health policies
37. With the DHCP servers enforcement type - only ______ computers receive an IP address that grants full network access; ______computers are granted an IP address with a subnet mask of 255.255.255.255 and no default gateway.
Win 7 - Win Vista - and Win XP SP3
compliant - noncompliant
Health policy - health policies
GPO settings in the Computer ConfigurationPoliciesWindows SettingsSecurity SettingsNetwork Access ProtectionNAP Client Configuration
38. NAP depends on a Win Server 2008 or Win Server 2008 R2 NAP health policy server - which acts as a ______ server - to evaluate the health of client computers.
RD Gateway
RADIUS
per-IP address or a per-TCP/UDP port number
802.1X access points
39. The only time you would want to configure the scope using the ______ group is when the computer is configured with multiple IP addresses - and you do not want to accept connections on all IP addresses.
Group Policy
Local IP Address
compliant - noncompliant - and unauthenticated
SoHR
40. Use the ______ snap-in to create an inbound firewall rule that allows a server application to receive incoming connections.
Testing - Monitoring - Limited access
network access
logging
Windows Firewall With Advanced Security
41. You need to create outbound firewall rules only when you configure outbound connections to be ______.
blocked by default
System Statement of Health Response (SSoHR)
requirement policies
Network Policy And Access Services
42. This installs the core NPS service - which is sufficient for using the Win Server 2008 computer as a RADIUS server for ______ - ______ - or ______ enforcement.
Enforcement Clients
remediation
802.1X - VPN - or DHCP
SoHR
43. You can quickly verify a client's configuration by running the following command at a command prompt:
netsh nap client show state
logging
Network policy
Domain - Private - Public
44. The ______ are the server components that analyze the SoH generated by the SHA and create an SoH Response (SoHR).
System Health Validators (SHVs)
802.1X access points
System Health Agents (SHAs)
health state
45. The ______ type enforces NAP for remote access connections using a VPN server running Win Server 2008 or Win Server 2008 R2 and Routing and Remote Access.
firewalls
RD Gateway
Statement of Health Response (SoHR)
VPN servers
46. Win Server 2008 and Win Server 2008 R2 include an SHV that corresponds to the SHA built into Windows ______.
Win 7 - Win Vista - and Win XP SP3
802.1X - VPN - or DHCP
User Interface Settings
netsh nap client show state
47. 802.1X enforcement uses one of two methods to control which level of access compliant - noncompliant - and unauthenticated computers receive:
communicate only with other
An access control list (ACL) - A virtual local area network (VLAN)
manually - domain controller
Group Policy
48. If you use Remote Desktop to allow users to control their desktops from remote computers across the Internet - you can use the ______ enforcement type to block access unless the client computer passes a health check.
RD Gateway
An access control list (ACL) - A virtual local area network (VLAN)
A certification authority - A web application
Domain - Private - Public
49. Typically - you apply an ACL to ______ computer connections and allow ______ computers to connect without an ACL (thus granting them unlimited network access).
Request Policy
VPN servers
noncompliant - compliant
RD Gateway
50. When deploying NAP - plan to implement it in ______ mode first. This will allow you to identify and fix noncompliant computers before preventing them from connecting to your network.
Connection request policy - System health validators - Remediation server group - Health policy - Network policy
monitoring-only
Local IP Address
A certification authority - A web application