多项选择题Your company has 10 servers that run Windows Server 2008. The servers have Remote Desktop Protocol (RDP) enabled for server administration. RDP is configured to use default security settings. All administrators’ computers run Windows Vista. You need to ensure the RDP connections are as secure as possible.Which two actions should you perform? ()

A.Set the security layer for each server to the RDP Security Layer.
B.Configure the firewall on each server to block port 3389.
C.Acquire user certificates from the internal certification authority.
D.Configure each server to allow connections only to Remote Desktop client computers that use Network Level Authentication.


您可能感兴趣的试卷

你可能感兴趣的试题

3.单项选择题Your corporate network has a member server named RAS1 that runs Windows Server 2008. You configure RAS1 to use the Routing and Remote Access Services (RRAS). 󰙴The company s remote access policy allows members of the Domain Users group to dial in to RAS1. The company issues smart cards to all employees.  You need to ensure that smart card users are able to connect to RAS1 by using a dial-up connection.  What should you do?()

A.Install the Network Policy Server (NPS) on the RAS1 server.
B.Create a remote access policy that requires users to authenticate by using SPAP.
C.Create a remote access policy that requires users to authenticate by using EAP-TLS.
D.Create a remote access policy that requires users to authenticate by using MS-CHAP v2.

4.单项选择题Your company has an Active Directory forest. The corporate network uses DHCP to configure client computer IP addresses. The DHCP server has a DHCP client reservation for a portable computer named WKS1. You install a second DHCP server on the network. You need to ensure that WKS1 receives the DHCP reservation from the DHCP service. What should you do?()

A. Run the ipconfig /renew command on WKS1
B. Run the netsh add helper command on WKS1
C. Add the DHCP reservation for WKS1 to the second DHCP server
D. Add both DHCP servers to the RAS and IAS Servers group in the Active Directory domain

5.多项选择题Your company has a single Active Directory domain. All servers run Windows Server 2008. The company network has 10 servers that perform as Web servers. All confidential files are located on a server named  FSS1. The company security policy states that all confidential data must be transmitted in the most securemanner. When you monitor the network, you notice that the confidential files are stored on the FSS1 server are being transmitted over the network without encryption. You need to ensure taht encryption is always used when the confidential files on the FSS1 server are transmitted over the network. What are two possible ways to achieve this goal?()

A. Deactivate all LM and NTLM authentication methods on the FSS1 server
B. Use IIS to publish the confidentials files. activate SSL on the ISS server, and then open the files as a web folder.
C. Use IPSec encryption between the FSS1 server and the computers of the users who need to access the confidential files
D. Use the Server Message Block (SMB) signing between the FSS1 server and the computers of the users who want to access the confidential files.
E. Activate offline files for the confidential files that are stored on the FSS1 server. In the Folder Advanced.Properties dialog box, select the Encrypt contents to secure data option.

6.单项选择题Your company has two servers that run Windows Server 2008 R2 named Server2 and Server3.Both servers have the DNS Server server role installed.Server3 is configured to forward all DNS requests to Server2.You update a DNS record on Server2.You need to ensure that Server3 is able to immediately resolve the updated DNS record.What should you do?()

A. Run the dnscmd . /clearcache command on Server3.
B. Run the ipconfig /flushdns command on Server3.
C. Decrease the Time-to-Live (TTL) on the Start of Authority (SOA) record of na.contoso.com to 15 minutes.
D. Increase the Retry Interval value on the Start of Authority (SOA) record of na.contoso.com to 15 minutes.

7.单项选择题Your company has an Active Directory domain. A server named Server1 runs the Network Access Policy server role. You need to disable IPv6 for all connections except for the tunnel interface and the IPv6 Loopback interface. What should you do?()

A. Run the netsh ras ipv6 set command
B. Run the netsh interface ipv6 delete command
C. Run ipv6.exe and remove the IPv6 protocol
D. From the Local Area connection Properties, uncheck Internet Protocol Versions 6 (TCP/IPv6)

9.单项选择题Contoso Ltd. has a single Active Directory forest that has five domains. Each domain has two DNS servers.Each DNS server hosts Active Directory-integrated zones for all five domains. All domain controllers run Windows Server 2008 R2.Contoso acquires a company named Tailspin Toys. Tailspin Toys has a single Active Directory forest that contains a single domain.You need to configure the DNS system in the Contoso forest to provide name resolution for resources in both forests.What should you do?()

A. Configure client computers in the Contoso forest to use the Tailspin Toys DNS server as the alternate DNS server.
B. Create a new conditional forwarder and store it in Active Directory. Replicate the new conditional forwarder to all DNS servers in the Contoso forest.
C. Create a new application directory partition in the Contoso forest. Enlist the directory partition for all DNS servers.
D. Create a new host (A) record in the GlobalNames folder on one of the DNS servers in the Contoso forest. Configure the host (A) record by using the Tailspin Toys domain name and the IP address of the DNS server in the Tailspin Toys forest.

10.单项选择题Your company has deployed Network Access Protection (NAP).You configure secure wireless access to the network by using 802.1X authentication from any access point. You need to ensure that all client computers that access the network are evaluated by NAP.  What should you do?()

A.Configure all access points as RADIUS clients to the Remediation Servers.
B.Configure all access points as RADIUS clients to the Network Policy Server (NPS).
C.Create a Network Policy that defines Remote Access Server as a network connection method.
D.Create a Network Policy that specifies EAP-TLS as the only available authentication method.

最新试题

You perform a security audit of a server named DC1. You install the Microsoft Network Monitor 3.0 application on DC1.You plan to capture all the LDAP traffic that comes to and goes from the server between 20:00 and 07:00 the next day and save it to the E:\data.cap file. You create a scheduled task. You add a new Start a program action to the task.You need to add the application name and the application arguments to the new action.What should you do?()

题型:单项选择题

Your company has a server named Printer1 that runs Windows Server 2008 R2. Printer1 has the Print and Document Services server role installed.You need to reduce the number of events registered in the system log on Printer1. What should you do?()

题型:单项选择题

Your company has a main office and a branch office. The branch office has three servers that run a Server Core installation of Windows Server 2008 R2. The servers are named Server1, Server2, and Server3. You want to configure the Event Logs subscription on Server1 to collect events from Server2 and Server3. You discover that you cannot create a subscription on Server1 from another computer. You need to configure a subscription on Server1.Which two actions should you perform?() 

题型:多项选择题

You have a server that runs Windows Server 2008. you create a new quota template. you apply quotas to 100 folders by using the quota template. you nede to modify the quota settings for al 100 folders. You must achive this goal by using the minimum amount of administrative effort. What should you do()?  

题型:单项选择题

Your company has an Active Directory domain that has two domain controllers named DC1 and DC2.You prepare both servers to support event subscriptions. On DC1, you create a new default subscription for DC2. You need to review system events for DC2.Which event log should you select?()

题型:单项选择题

Your company has a network that has 100 servers. You install a new server that runs Windows Server 2008 R2. The server has the Web Server (IIS) server role installed. After a week, you discover that the Reliability Monitor has no data, and that the Systems Stability chart has never been updated.You need to configure the server to collect the Reliability Monitor data.What should you do?()

题型:单项选择题

You perform a security audit on a server named Server1. You install the Microsoft Network Monitor 3.0 application on Server1.  You find that only some of the captured frames display host mnemonic names in the Source column and the Destination column. All other frames display IP addresses. You need to display mnemonic host names instead of IP addresses for all the frames.What should you do?()

题型:单项选择题

You have a server that runs Windows Server 2008. You need to configure the server as a VPN server. What should you installed on the server()?  

题型:单项选择题

Your company has a network that has 100 servers. A server named Server1 is configured as a file server. Server1 is connected to a SAN and has 15 logical drives. You want to automatically run a data archiving script if the free space on any of the logical drives is below 30 percent. You need to automate the script execution.You create a new Data Collector Set. What should you do next?()

题型:单项选择题

You perform a security audit of a server named CRM1. You want to build a list of all DNS requests that are initiated by the server. You install the Microsoft Network Monitor 3.0 application on CRM1. You capture all local traffic on CRM1 for 24 hours. You save the capture file as data.cap. You find that the size of the file is more than 1 GB. You need to create a file named DNSdata.cap from the existing capture file that contains only DNS-related data.What should you do? ()

题型:单项选择题