70-298 Exam
Designing Security for a MS Windows Server 2003 Network
- 科目編號:70-298
- 科目名稱:Designing Security for a MS Windows Server 2003 Network
- 考題數目:12 Q&As
- 更新日期:2009-6-3
- 價 格 :
¥ 89.00¥ 65.00
購買 Testinside 考題大師 70-298 認證題庫 : 70-298
免費下載 70-298 認證考題 Demo
下載 70-298 PDF版認證考試題庫
下載 70-298 軟件版認證考試題庫
選擇 Testinside 70-298 題庫
70-298 考試是 Microsoft 公司的 Designing Security for a MS Windows Server 2003 Network 認證考試官方代號,TestInside 的 70-298 權威考試題庫軟件是 Microsoft 認證廠商的授權產品,TestInside 絕對保證第一次參加 70-298 考試的考生即可順利通過,否則承諾全額退款!
Designing Security for a MS Windows Server 2003 Network 認證作為全球IT領域專家 Microsoft 熱門認證之一,是許多大中IT企業選擇人才標準的必備條件。 如果你正在準備 70-298 考試,為 Microsoft Designing Security for a MS Windows Server 2003 Network認證做最後衝刺,又苦於沒有絕對權威的考試真題模擬, TestInside 希望能助你成
1、Testinside考題大師70-298試題都是考試原題的完美組合,覆蓋率95%以上,答案由多位專業資深講師原版破解得出,正確率100%,只要您使用本站的考試題庫參加70-298 考試,我們保證您一次輕鬆通過考試;
2、售後服務第一!我們相信要想在當今時代取得成功,必須為廣大用戶提供全套的周到細緻的全程優質售後服務,只有客戶滿意了,我們才能發展。客戶至上是我們Testinside考題大師的一貫宗旨;
3、Testinside實行「一次不過全額退款」承諾。如果您購買我們70-298的考題,只要不是首次通過,憑蓋有PROMETRIC或VUE考試中心鋼印的考試成績單,我們將退還您購買70-298考題大師的全部費用,絕對保證您的利益不受到任何的損失;
4、本站70-298題庫根據70-298考試的變化動態更新,在廠家考題每次發生變化後,我們承諾2天內更新70-298題庫。確保70-298考題的覆蓋率始終都在95%以上;我們提供2種 70-298 考題大師版本供你選擇。
5、軟件版本70-298 考試題庫
優點:具有學習模式,測試模式,線上自動升級
缺點:僅限固定電腦使用,不可打印為文本,只能PC閱讀
6、PDF 格式70-298 考試題庫
優點:不需下載安裝軟件,方便用戶打印和攜帶,但也帶來了可隨意制的弊端,因此我們提醒用戶不得隨意公開或出售本站的70-298題庫,一經發現立即取消其升級資格,且不予退款。
缺點:不具備測試模式,通過查看 Testinside.cn網站及查收我們的更新E-MAIL獲取更新信息。
TestInside 的優勢
70-298 試題的質量和價值
TestInside 模擬測試題具有最高的專業技術含量,只供具有相關專業知識的專家和學者學習和研究之用。
100% 保證您通過 70-298 的考試
如果你使用 TestInside 模擬測試,我們將保證你的第一次參加考試即取得成功,否則,我們將全額退款!
試用後再購買
TestInside 提供每種產品免費測試。在您決定購買之前,請檢測聯接,可能存在的問題及試題質量和適用性。
TestInside認證考試題庫網專業提供Microsoft 70-298 最新題庫下載,完全覆蓋 70-298 考試原題。
部分 70-298 認證考試題庫
Exam : Microsoft 70-298
Title : Designing Security for a MS Windows Server 2003 Network
Case 1, Lucerne Publishing
Overview
Lucerne Publishing is an industry leader in publishing technology textbooks, e-books, and magazines.
Physical Locations
The company has three offices, as shown in the Physical Locations and Connectivity exhibit.
The company's main office is in New York, and it has branch offices in Denver and Dallas. The company's employees and departments are distributed as shown in the following table
Business Processes
The IT staff in the New York office uses client computers to remotely administer all Lucerne Publishing servers and domain controllers.
Employees use their company client computers to access archived published books and archived accounting information through an internal Web site that runs IIS 6.0.
Directory Services
The company's network consists of a single Active Directory domain named lucernepublishing.com. All servers run Windows Server 2003, Enterprise Edition. Administration of Active Directory is centralized in New York.
Denver and Dallas user and computer accounts are located in their respective child OUs, as shown in the Organizational Unit Hierarchy exhibit.
The NYAdmins, ProductionAdmins, EditorialAdmins, and DevelopmentAdmins global user groups have full control of their respective organizational units (OUs). These global groups are located in their respective OUs.
Network Infrastructure
All client computers run Windows XP Professional.
The domain contains a public key infrastructure (PKI). The company uses an internal subordinate enterprise certification authority (CA) to issue certificates to users and computers.
Each branch office has a wireless network that supports desktop and portable client computers. The wireless network infrastructure in each branch office contains an Internet Authentication Service (IAS) server and wireless access points that support IEEE 802.1x, RADIUS, and Wired Equivalent Privacy (WEP).
Problem Statements
The following business problems must be considered:
Members of the EditorialAdmins group and unauthorized users as members to this group. Members of this group must be restricted to only authorized users.
Editors connect to a shared folder named Edits on a member server named Server5. When they attempt to encrypt data located in Edits, they receive an error message stating that they cannot encrypt data.
Editors need to encrypt data remotely on Server5.
Some users in the Dallas office changed the location of their My Documents folders to shared folders on servers that do not back up their My Documents data. As a result, data was lost. The Dallas My Documents folders need to be moved to a server that backs up user data. Users in the Dallas office must be prevented from changing the location of their My Documents folder in the future.
Chief Information Officer
Security is Lucerne Publishing's primary concern. We must improve security on client computers, servers, and domain controllers by implementing a secure password policy. For legal reasons, we need a logon message that tells users that access to servers in the development department is restricted to only authorized users.
System Administrator
Each department needs different security patches. We need to test security patches prior to deploying them. After they are tested, the patches need to be deployed automatically to servers in each department. As we deploy the patches, we need to limit the network bandwidth used to obtain security patches.
Chief Security Officer
We need to automatically track when administrators modify user rights on a server or on a domain controller and when they modify local security account manager objects on servers.
We must implement the most secure method for authenticating Denver and Dallas users that access the wireless networks.
We need to protect data as it is sent between the wireless client computers and the wireless access points. Client computers need to automatically obtain wireless network access security settings.
Written Security Policy
The Lucerne Publishing written security policy includes the following requirements.
Passwords must contain at least seven characters and must not contain all or part of the user's account name. Passwords must contain uppercase and lowercase letters and numbers. The minimum password age must be 10 days, and the maximum password age must be 45 days.
Access to data on servers in the production department must be logged.
A standard set of security settings must be deployed to all servers in the development, editorial, and production departments. These settings must be configured and managed from a central location.
Servers in the domain must be routinely examined for missing security patches and service packs and to ascertain if any unnecessary services are running.
Services on domain controllers must be controlled from a central location. Which services start automatically and which administrators have permission to stop and start services must be centrally managed.
The IIS server must be routinely examined for missing IIS Security patches.
Users of the Web site and the files they download must be tracked. This data must be stored in a Microsoft SQL Server database.
Vendors and consultants who use Windows 95 or Windows 98 client computers must have the Active Directory Client Extensions software installed to be able to authenticate to domain controllers on the company's network.
Questions
1. You need to design a method to configure the servers in the development department to meet the requirements of the chief information officer. What should you do?
A. Use error reporting on all servers in the development department to report errors for a custom application.
B. Configure all servers in the development department so that they do not require the CTRL+ALT+DELETE keys be pressed in order to log on interactively to the server.
C. Create a Group Policy object (GPO) and link it to the development department's Servers OU. Configure the GPO with an interactive logon policy to display a message for users who attempt to log on.
D. Configure the screen saver on all servers in the development department to require a password.
Answer: C
2. You need to design a strategy to ensure that all servers are in compliance with the business requirements for maintaining security patches. What should you do?
A. Log on to a domain controller and run the Resultant Set of Policy wizard in planning mode on the domain.
B. Log on to each server and run Security Configuration and Analysis to analyze the security settings by using a custom security template.
C. Create a logon script to run the secedit command to analyze all servers in the domain.
D. Run the Microsoft Baseline Security Analyzer (MBSA) on a server to scan for Windows vulnerabilities on all servers in the domain.
Answer: D
3. You need to design a method to monitor the security configuration of the IIS server to meet the requirements in the written security policy. What should you do?
A. Log on to a domain controller and run the Resultant Set of Policy wizard in planning mode on the IIS server computer account.
B. Run the Microsoft Baseline Security Analyzer (MBSA) on the IIS server and scan for vulnerabilities in Windows and IIS checks.
C. Run Security Configuration and Analysis to analyze the IIS server's security settings by using a custom security template.
D. On the IIS server, run the gpresult command from a command prompt and analyze the output.
Answer: B
4. You need to design a certificate distribution method that meets the requirements of the chief security officer. Your solution must require the minimum amount of user effort. What should you do?
To answer, move the appropriate actions from the list of actions to the answer area, and arrange them in the appropriate order.
Answer:
5. You need to design a method to log changes that are made to servers and domain controllers. You also need to track when administrators modify local security account manager objects on servers. What should you do?
A. Enable failure audit for privilege use and object access on all servers and domain controllers.
B. Enable success audit for policy change and account management on all servers and domain controllers.
C. Enable success audit for process tracking and logon events on all servers and domain controllers.
D. Enable failure audit for system events and directory service access on all servers and domain controllers.
Answer: B
