70-299: Implementing Network Security Flashcards
6 cards from real MCSE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 70-299: Implementing Network Security flashcards as text
Which command is used to apply a security template to a Windows Server 2003 system from the command line?
Answer: secedit /configure /db temp.sdb /cfg hisecws.inf
The secedit command with the /configure switch applies a security template (.inf file) to the local system using a specified security database.
What is the effect of setting the LAN Manager Authentication Level to 'Send NTLMv2 response only. Refuse LM & NTLM'?
Answer: Forces all authentication to use NTLMv2, blocking weaker LM and NTLM protocols
This setting maximizes NTLM security by refusing the weaker LM and NTLMv1 authentication protocols, requiring all clients to use NTLMv2.
Which tool can be used to test IPSec policy on a Windows Server 2003 computer and see active security associations?
Answer: ipseccmd show sas
The ipseccmd show sas command displays active IPSec security associations, allowing administrators to verify that IPSec is negotiating correctly.
What does enabling 'Restrict CD-ROM access to locally logged-on user only' accomplish in Windows Server 2003?
Answer: Prevents network users from accessing the local CD-ROM drive
This security setting ensures that only the user physically logged on at the console can access the CD-ROM, preventing remote users from reading sensitive media.
Which Windows Server 2003 built-in group has the ability to manage security policy settings without being a member of Administrators?
Answer: Server Operators
Server Operators can perform tasks like managing shared resources, starting and stopping services, and backing up/restoring files on domain controllers.
What is the purpose of enabling 'Do not store LAN Manager hash value on next password change' in Windows Server 2003?
Answer: Prevents the weak LM hash from being stored in the SAM database
Disabling LM hash storage prevents the weak LAN Manager password hash from being saved, making offline password cracking attacks against the SAM database much harder.