← All 70-413 Exam Flashcard Decks

Network Access Services Flashcards

7 cards from real 70-413 Exam practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Network Access Services flashcards as text
  1. Which NAP enforcement method requires clients to obtain a health certificate from the Health Registration Authority before being permitted to communicate with protected resources using IPsec?

    Answer: IPsec enforcement

    IPsec NAP enforcement requires compliant clients to possess a health certificate issued by the HRA; protected servers accept IPsec connections only from clients presenting a valid health certificate.

  2. What is the role of the Health Registration Authority (HRA) in a NAP with IPsec enforcement deployment?

    Answer: To validate client health statements and issue health certificates to compliant clients

    The HRA is an IIS-based component that receives health statements from NAP clients, forwards them to NPS for validation, and issues health certificates to clients that pass health checks.

  3. What is the primary function of a System Health Validator (SHV) in a NAP infrastructure?

    Answer: To define the specific health requirements that NAP client computers must meet

    An SHV is a plug-in component on NPS that defines and evaluates health requirements—such as firewall status, update level, or antivirus state—that a NAP client must satisfy to be deemed compliant.

  4. Which NAP enforcement method restricts non-compliant clients by assigning them a limited DHCP scope that only allows access to remediation servers?

    Answer: DHCP enforcement

    DHCP NAP enforcement integrates with the DHCP server to assign non-compliant clients a restricted IP configuration with limited routes, preventing access to production resources while allowing remediation.

  5. What is the primary function of Web Application Proxy (WAP) when deployed in Windows Server 2012 R2?

    Answer: To publish internal web applications to external users and support AD FS pre-authentication

    Web Application Proxy is a Remote Access role service that reverse-proxies internal web and application server URLs to external users, and can pre-authenticate requests using AD FS before passing them to back-end servers.

  6. When a NAP client is determined non-compliant and placed in a restricted network, what can the client typically do to restore full access?

    Answer: Connect to remediation servers to download updates and correct its health state

    The restricted network is designed to allow non-compliant clients access to remediation servers where they can download patches, update antivirus definitions, or change settings to achieve compliance.

  7. Which authentication method must be configured on RRAS to support smart card authentication for remote VPN users?

    Answer: EAP-TLS using certificate-based authentication with smart card support

    EAP-TLS supports certificate-based authentication, including smart cards, by using the certificate stored on the smart card for TLS mutual authentication between the client and the VPN server.