← All MCSE Flashcard Decks

70-299: Implementing Network Security Flashcards

6 cards from real MCSE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 70-299: Implementing Network Security flashcards as text
  1. Which port must be open in a firewall for Kerberos authentication to function across a firewall?

    Answer: 88 (TCP and UDP)

    Kerberos uses port 88 on both TCP and UDP; this port must be accessible between clients and domain controllers for authentication to succeed across firewalls.

  2. What is the purpose of the Resultant Set of Policy (RSoP) tool in Windows Server 2003?

    Answer: Displays the effective Group Policy settings applied to a user or computer

    RSoP shows the net result of all GPOs applied to a user or computer, factoring in inheritance, filtering, and precedence, useful for troubleshooting policy application.

  3. Which security option prevents a system from being shut down without logging on first?

    Answer: Allow system to be shut down without having to log on — Disabled

    Disabling the 'Allow system to be shut down without having to log on' option requires authentication before the shutdown option becomes available.

  4. What is the MOST secure way to store the backup of a CA's private key?

    Answer: Hardware Security Module (HSM) or encrypted offline media stored in a secure vault

    CA private keys should be protected by an HSM or stored on encrypted offline media in a physically secured location, as compromise of the CA key compromises the entire PKI.

  5. Which Windows Server 2003 log file records successful and failed security events as configured by audit policy?

    Answer: Security log in Event Viewer

    The Security log in Event Viewer records audit events such as logon successes and failures, object access, and privilege use as configured by local or group policy.

  6. What does enabling 'Digitally sign communications (always)' for SMB in Windows Server 2003 prevent?

    Answer: Man-in-the-middle attacks that modify SMB traffic in transit

    SMB signing ensures that each SMB packet is digitally signed by the sender, preventing attackers from intercepting and modifying file-sharing traffic (man-in-the-middle attacks).