Microsoft MCSE 2003 70-299 Web Demo
This webdemo is just a demo data, only for reference and learning, there is no other purposes
1.You work as a security administrator for Microsoft. The basic network and some configurations are as the following:
Today, you discover that unauthorized users intercepted data in sales
documents while the documents were transmitted over the WLAN. You need
to protect sales documents from being intercepted by unauthorized
users. What should you do?
A. Use the CMAK wizard to create an executable file that a user can use
to automatically create a remote access connection with customized
security settings.
B. A new VPN server will be available. And then, configure a Connection
Manager Administration Kit (CMAK) profile that connects sales users to
the VPN server.
C. choose to automatically use the current credentials.
D. provide credentials each time a connection is made.
Answer: B
2.You work as a security administrator for Microsoft. The basic network and some policies are as the following:
Now, the Lan Security IPSec policy applies to network traffic on both
network adapters in Server_One. You have to configure Server_One in
order to communicate on the test network without IPSec security.
Server_One must still use the Lan Security policy when it communicates
on the company network. What would you do to configure Server_One?
A. Exchange public keys and then separately generate the Main Mode master key keying material.
B. Configure ICF to permit ISAKMP for UDP port 500.
C. Configure IPSec to use certificates for authentication.
D. You could use the netsh IPSec to assign a constant IPSec policy,
which permits all traffic on the network adapter on the test network.
E. you could configure local IPSec policy. After that, you can use the
IP Security Policy Management Export Policies and Import Policies menu
commands to back up and restore IPSec policy.
Answer: D
3.You work as a security administrator for Microsoft. The basic network structure is as following:
In order to replicate data, you configure a new Windows Server 2003
computer named Server_Two in the theTwo.com forest. The database
administrator configures the database on Server_One to replicate to
Server_Two every night. Management reports that a competitor acquired
confidential customer data. You determine that the competitor
intercepted customer data as it replicated from Server_One to
Server_Two. You decide to use IPSec to protect customer data as it
replicates. You need to configure an IPSec policy to protect customer
data as it replicates. What should you do?
A. Using transport mode to protect host-to-host communications
B. Using IPSec to allow remote users to connect to an organization's private network across the Internet.
C. Encapsulating Security Payload with certificate-based authentication in tunnel mode would be available.
D. Establishing an IPSec connection to the IPSec gateway that provides access to the internal network.
Answer: C
4.Which of the following are valid reasons to enable LM authentication? (Choose all that apply.)
A. Users will access network resources using computers running Windows 95.
B. Users will access network resources using computers running Windows 98.
C. Users will access network resources using computers running Windows NT.
D. Users will access network resources using computers running Windows Me.
Answer: AB
5.You work as a security administrator for Microsoft. The basic network and some policies are as the following:
You want to do some work at home, using company??s resources.
Currently, you need to make sure that users can successfully establish
a VPN connection to Server_Three. How can you do that?
A. Provides certificate-based authentication for computers by using IP Security (IPSec) for network communications.
B. Provides both client and server authentication abilities to a computer account.
C. Allows the holder to act as a registration authority (RA) for Simple Certificate Enrollment Protocol (SCEP) requests.
D. You could add Server_Three computer account to the RAS and IAS Servers security group.
E. Used by a router when requested through SCEP from a certification
authority that holds a Certificate Enrollment Protocol (CEP) Encryption
certificate.
Answer: D
6.Which of the following passwords will not be stored in an LMHash?
A. tyia
B. imsitrjs5itr
C. passwordpassword
D. l%@3tty7&
Answer: C
7. Enabling account lockout accomplishes which of the following goals?
A. Makes it impossible to steal a user??s password.
B. Reduces the likelihood that a malicious attacker will use brute force techniques to discover a user??s password.
C. Eliminates the need for strong passwords.
D. Reduces Help desk costs.
Answer: B
8.Which of the following passwords is an example of a strong password?
A. tyia
B. imsitrjs5itr
C. passwordpassword
D. l%@3tty7&
Answer: D