SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
MCTS: Configuring Windows Firewall And Network Access Protection
Start Test
Study First
Subjects
:
certifications
,
mcts
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Use the ______ subnode to configure cryptographic settings for NAP clients (the default settings are typically fine).
Network Policy And Access Services
health policy server
System Statement of Health (SSoH)
Request Policy
2. You must enable one policy to configure clients to use this enforcement type.
Remediation server group
requirement policies
Enforcement Clients
health policy server
3. Health ______ determine which clients must meet health requirements - what those health requirements are - and what happens if a client cannot comply.
communicate only with other
per-IP address or a per-TCP/UDP port number
requirement policies
IPsec connection security
4. By default - Windows Firewall (as well as most other firewalls) ______.
5. To install NAP - first install the ______ role - then select the Network Policy Server check box on the Select Role Services page.
Enforcement Clients - User Interface Settings - Health Registration Settings
Local IP Address
Network Policy And Access Services
SHA
6. With the DHCP servers enforcement type - only ______ computers receive an IP address that grants full network access; ______computers are granted an IP address with a subnet mask of 255.255.255.255 and no default gateway.
noncompliant - compliant
Enforcement Clients - User Interface Settings - Health Registration Settings
compliant - noncompliant
IPsec connection security - DHCP - and VPN enforcement do not require support from your network infrastructure.
7. If an application must accept incoming connections but the developers have not documented the communication ports that the application uses - you can use the ______ tool to identify which ports the application listens on.
communicate only with other
2008 (or Windows Server 2008 R2)
Netstat
Connection request policy - System health validators - Remediation server group - Health policy - Network policy
8. Each SHV produces a _____ - which can contain remediation instructions (such as the version number of an antivirus signature file) if the client doesn't meet that SHV's health requirements.
Statement of Health Response (SoHR)
Win 7 - Win Vista - and Win XP SP3
per-IP address or a per-TCP/UDP port number
requirement policies
9. The ______ enforcement type uses Ethernet switches or wireless access points that support 802.1X authentication.
Connection request policy
network access
Network Access Protection (NAP)
802.1X access points
10. The ______ type enforces NAP for remote access connections using a VPN server running Win Server 2008 or Win Server 2008 R2 and Routing and Remote Access.
domain controller
network access
worms
VPN servers
11. In networking - ______ analyze communications and drop packets that haven't been specifically allowed.
noncompliant - compliant
firewalls
System Statement of Health (SSoH)
SHA
12. 802.1X enforcement uses one of two methods to control which level of access compliant - noncompliant - and unauthenticated computers receive:
User Interface Settings
System Health Agents (SHAs)
An access control list (ACL) - A virtual local area network (VLAN)
logging
13. A group of servers that noncompliant clients can access is a ______.
RD Gateway
Network Policy And Access Services
RD Gateway
Remediation server group
14. The ______ enforcement type uses a computer running Win Server 2008 or Win Server 2008 R2 and the DHCP Server service that provides IP addresses to intranet clients.
System Health Agents (SHAs) - System Health Validators (SHVs)
DHCP servers
communicate only with other
System health validators
15. Configure the ______ policy to provide customized text (and - optionally - an image) that users will see as part of the NAP client interface.
Network policy
System Health Agents (SHAs) - System Health Validators (SHVs)
User Interface Settings
Win 7 - Win Vista - and Win XP SP3
16. The Private profile must be ______ applied to a network. The Public profile applies any time a ______ is not available - and a network has not been configured as Private.
Enforcement Clients
IPsec connection security - DHCP - and VPN enforcement do not require support from your network infrastructure.
VPN servers
manually - domain controller
17. For NAP to work - a network component must enforce NAP by either allowing or denying network access. The following list describes the different NAP enforcement types you can use:
User Interface Settings
communicate only with other
Remote Desktop Gateways (RD Gateway).
Enforcement Clients
18. One of the most powerful ways to increase computer security is to configure firewall ______.
RD Gateway
remediation
SoHR
scope
19. If a computer falls out of compliance after connecting to the 802.1X network - the 802.1X network access device can change the computer's ______.
scope
An access control list (ACL) - A virtual local area network (VLAN)
firewalls
network access
20. When deploying NAP - plan to implement it in ______ mode first. This will allow you to identify and fix noncompliant computers before preventing them from connecting to your network.
monitoring-only
Win XP SP3 - Win Vista - Win 7 - Win Server 2008 - and Win Server 2008 R2.
Netstat
Local IP Address
21. By default - all versions of Windows (including Win Srvr 2008 R2) ______ outbound traffic.
do not filter
Health policy - health policies
noncompliant - compliant
System health validators
22. Typically - a NAP deployment occurs in three phases:
Win 7 - Win Vista - and Win XP SP3
Testing - Monitoring - Limited access
communicate only with other
Statement of Health Response (SoHR)
23. The NAP health policy server sends the SSoHR back to the NAP client through the NAP enforcement point. The NAP enforcement point can now connect a ______ computer to the network or connect a ______ computer to a remediation network.
compliant - noncompliant
network access
firewalls
802.1X - VPN - or DHCP
24. NAP ______ allows you to identify noncompliant computers.
System health validators
logging
Network Access Protection (NAP)
network access
25. In the case of _____ - automated software attacks computers across the Internet - gains elevated privileges - copies itself to the compromised computer - and then begins attacking other computers (typically at random).
Win XP SP3 - Win Vista - Win 7 - Win Server 2008 - and Win Server 2008 R2.
System Health Agents (SHAs) - System Health Validators (SHVs)
Windows Firewall With Advanced Security
worms
26. The only time you would want to configure the scope using the ______ group is when the computer is configured with multiple IP addresses - and you do not want to accept connections on all IP addresses.
Network Policy And Access Services
drops
Local IP Address
health state
27. The 802.1X access point applies the ACL to the connection and ______ all packets that are not allowed by the ACL.
drops
Health policy - health policies
Network Policy And Access Services
compliant - noncompliant
28. With 802.1X - compliant computers are granted full network access - and noncompliant computers are connected to a ______ network or completely prevented from connecting to the network.
RD Gateway
blocks any inbound traffic that hasn't been specifically allowed
remediation
meets health requirements
29. The NAP health policy server combines the SoHRs from the multiple SHVs into a ______.
Health policy - health policies
IPsec connection security
Trusted Server Group
System Statement of Health Response (SSoHR)
30. ______ enforcement does not provide remediation.
meets health requirements
RD Gateway
System Health Agents (SHAs) - System Health Validators (SHVs)
An access control list (ACL) - A virtual local area network (VLAN)
31. With VPN server enforcement enabled - only ______ are granted unlimited network access.
compliant - noncompliant
Connection request policy - System health validators - Remediation server group - Health policy - Network policy
Win XP SP3 - Win Vista - Win 7 - Win Server 2008 - and Win Server 2008 R2.
compliant client computers
32. The NAP health policy server uses its installed SHVs and the health requirement policies that you have configured to determine whether the NAP client ______.
RADIUS
compliant - noncompliant - and unauthenticated
meets health requirements
Remote Desktop Gateways (RD Gateway).
33. Win 7 - Win Vista - Win Server 2008 - Win Server 2008 R2 - and Win XP SP3 include an ______ that monitors Windows Security Center settings.
System Statement of Health (SSoH)
Remediation server group
SHA
System Statement of Health Response (SSoHR)
34. IPsec enforcement requires a CA running Win Server ______ or ________ Certificate Services and NAP to support health certificates.
domain controller
Connection request policy - System health validators - Remediation server group - Health policy - Network policy
Group Policy
2008 (or Windows Server 2008 R2)
35. Use the ______ subnode to configure an HRA for IPsec NAP clients to use.
Testing - Monitoring - Limited access
Trusted Server Group
Win XP SP3 - Win Vista - Win 7 - Win Server 2008 - and Win Server 2008 R2.
Netstat
36. The ______ are the client components that create a Statement of Health (SoH) containing a description of the health of the client computer.
compliant client computers
GPO settings in the Computer ConfigurationPoliciesWindows SettingsSecurity SettingsNetwork Access ProtectionNAP Client Configuration
System Health Agents (SHAs)
RD Gateway
37. ______ define which health checks a client must meet to be considered compliant.
System health validators
compliant - noncompliant
logging
System Statement of Health Response (SSoHR)
38. Each SHA on the NAP client validates its system health and generates an SoH. The NAP client combines the SoHs from multiple SHAs into a ______ - which includes version info for the NAP client and the set of SoHs for the installed SHAs.
System Statement of Health (SSoH)
Win 7 - Win Vista - and Win XP SP3
Statement of Health Response (SoHR)
2008 (or Windows Server 2008 R2)
39. The ______ enforcement type requires clients to perform a NAP health check before they can receive a health certificate.
Remediation server group
meets health requirements
SoHR
IPsec connection security
40. NAP health validation takes place between two components:
System Health Agents (SHAs) - System Health Validators (SHVs)
802.1X - VPN - or DHCP
Enforcement Clients
GPO settings in the Computer ConfigurationPoliciesWindows SettingsSecurity SettingsNetwork Access ProtectionNAP Client Configuration
41. Which NAP enforcement types do not require support from your network infrastructure?
VPN servers
netsh nap client show state
compliant - noncompliant
IPsec connection security - DHCP - and VPN enforcement do not require support from your network infrastructure.
42. Installing the HRA role service configures the following:
An access control list (ACL) - A virtual local area network (VLAN)
A certification authority - A web application
Testing - Monitoring - Limited access
Network policy
43. You need to create outbound firewall rules only when you configure outbound connections to be ______.
802.1X access points
scope
blocked by default
compliant - noncompliant
44. Which versions of Windows can act as NAP clients?
Win XP SP3 - Win Vista - Win 7 - Win Server 2008 - and Win Server 2008 R2.
RD Gateway
logging
802.1X access points
45. IPsec enforcement allows you to require health compliance on a ______ or a ______ basis.
per-IP address or a per-TCP/UDP port number
compliant - noncompliant
System Health Agents (SHAs)
drops
46. After configuring the NPS server - you must configure client computers for NAP. The easiest way to do this is to use ______ node.
GPO settings in the Computer ConfigurationPoliciesWindows SettingsSecurity SettingsNetwork Access ProtectionNAP Client Configuration
domain controller
Testing - Monitoring - Limited access
Win 7 - Win Vista - and Win XP SP3
47. To install HRA - first install the ______ role - then select the Network Policy Server check box on the Select Role Services page.
Network Policy And Access Services
logging
A certification authority - A web application
blocked by default
48. Use the ______ snap-in to create an inbound firewall rule that allows a server application to receive incoming connections.
Local IP Address
compliant - noncompliant - and unauthenticated
health state
Windows Firewall With Advanced Security
49. You can also use IPsec connection security to allow healthy computers to ______ healthy computers.
network access
communicate only with other
noncompliant - compliant
SoHR
50. A ______ determines whether a request should be processed by NPS.
System Statement of Health (SSoH)
netsh nap client show state
Connection request policy
Enforcement Clients - User Interface Settings - Health Registration Settings