โ† All MCSE Flashcard Decks

70-298: Designing Network Security Flashcards

6 cards from real MCSE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 70-298: Designing Network Security flashcards as text
  1. Which certificate type is required for EFS recovery agents in a Windows Server 2003 PKI environment?

    Answer: EFS Recovery Agent certificate

    The EFS Recovery Agent certificate grants designated accounts the ability to decrypt EFS-protected files if the original encrypting user's key is lost.

  2. What is the function of an Enterprise Root CA in a Windows Server 2003 PKI hierarchy?

    Answer: Issues certificates to subordinate CAs and is the trust anchor for the entire PKI

    The Enterprise Root CA sits at the top of the PKI hierarchy and signs the certificates of subordinate CAs; it should be kept offline to protect the root private key.

  3. Which auditing category should be enabled to track failed logon attempts in Windows Server 2003?

    Answer: Audit account logon events

    Enabling 'Audit account logon events' with failure auditing records failed authentication attempts, helping detect brute-force or credential-stuffing attacks.

  4. What is the purpose of 802.1X authentication in a wired or wireless network security design?

    Answer: Requires devices to authenticate before gaining network access

    802.1X is a port-based network access control standard that requires clients to authenticate (typically via RADIUS) before being granted network access.

  5. Which Windows Server 2003 service acts as a RADIUS server to centralize network access authentication?

    Answer: Internet Authentication Service (IAS)

    Internet Authentication Service (IAS) is Microsoft's RADIUS server implementation that centralizes authentication, authorization, and accounting for network access.

  6. What security measure does Smart Card logon provide that standard password authentication does not?

    Answer: Two-factor authentication requiring physical possession of the card

    Smart card logon implements two-factor authentication by requiring both the physical smart card and a PIN, making credential theft much harder.