01 Flashcards
_____________ is the process for targeted system or network information gathering. It involves active connections and directed queries of systems and networks in support of CNO initiatives
Enumeration
In a Server vs workstation the core files and architectures are essentially the same T/F?
T
A _______ is optimized to provides application services and shared resources
Server OS
A ______ is optimized for interactive desktop response time
Workstation OS
In a ______, each system is considered standalone with regards to authentication and system security principles
Workgroup
In a _______ each system shares common configurations, resources, and security principles. A centralized data base known as ___________, maintains this information. Once set-up the server becomes a ______________
Domain
Active Directory
domain controller
Domain servers running server OS’s without a active directory is called?
member servers
member servers maintain their own local SAM T/F?
True
Each ________ is a collection of information used by the system for determining access and privileges
User Account
___________ are unique accounts that provide the account identifier information for services
Service accounts
___________ are used to provide the account identifier for all processes executed on behalf of the user.
User Accounts
What is each part of a SID component?
S-1-5-21-776561741-162531612-682003330-500
S: Indictates its a SID
1: Revision level/ version number
5: authority value (windows)
long ass number: system or domain identifier rng
500: RID, individual for every account
What are the Accounts/Account Types for each of these SIDS?
S-1-5-18
S-1-5-19
S-1-5-20
S-1-5-[4a]-500
S-1-5-[4a]-501
local system, service account
local service, service account
network service, service account
administrator, user account
guest, user account
What makes up a Access token?
User SID
Group SID
Privileges
Together, the access token and the _____________ form the primary ______________
object’s permissions, security context
When bob is logged in he is the administrator group and is using the admin token all the time T/F?
F
A ________ is the ability of an account to perform a particular system related system operation such as shutting down the system, backing up/restoring files, changing system time, taking ownership of a file
privilege
The ____________ establishes privileges and account rights for users,
local security policy
What is considered privileges?
Allow logon locally
Allow logon over the network
Allow backup and restore
Allow Shutdown
Allow logon as a service
Allow system time to be changed
Allow backup and restore
Allow Shutdown
Allow system time to be changed
__________ contains information that deals with logon abilities. However, account rights differ from privileges in that they are not included as part of the access token T/F?
Account rights
T
Which of these are considered account rights?
Allow logon locally
Allow logon over the network
Allow backup and restore
Allow Shutdown
Allow logon as a service
Allow system time to be changed
Allow logon locally
Allow logon over the network
Allow logon as a service