Chapter 5 Lesson 1 Flashcards
0
Q
- You are in the process of developing a client security standard for your organization. You want to ensure that help desk staff are able to run programs using elevated privileges when connected through a remote assistance session to a computer where the user is logged on with an account that is not a member of the local administrators group. Which of the following Group Policy items should you configure to implement this standard?
A. User Account Control: Behavior Of The Elevation Prompt For Standard Users.
B. User Account Control: Behavior Of The Elevation Prompt For Administrators In
Admin Approval Mode.
C. User Account Control: Detect Application Installations And Prompt For Elevation.
D. User Account Control: Run All Administrators In Admin Approval Mode.
A
A
1
Q
1.You are developing a client security standard for your organization. Which of the follow- ing organizational characteristics would dictate that you use Software Restriction Policies to restrict application execution as opposed to AppLocker policies? (Choose all that apply. Each answer forms a complete solution.)
A. There are computers in the organization running Windows 7 Professional.
B. The Active Directory Domain Services forest is set to the Windows Server 2003
functional level.
C. Line of business applications are not digitally signed.
D. There are computers in the organization running Windows Vista Enterprise.
A
A and D
3
Q
3. You want to ensure that users change their passwords every 21 days and that users are locked out for 15 minutes if they enter an incorrect password three times in a 30-minute period. Which of the following Group Policy items must you configure to accomplish this goal? (Choose all that apply. Each answer forms part of a complete solution.) A. Account Lockout Duration B. Enforce Password History C. Maximum Password Age D. Minimum Password Age E. Account Lockout Threshold F. Reset Account Lockout Counter After
A
A, C, E, and F
4
Q
- Your organization has 200 desktop computers that have the Windows 7 Enterprise edition operating system installed. You want to ensure that users in your organiza- tion are able to write data only to removable USB flash storage devices that you have specially protected using BitLocker To Go. Users should not be able to con- figure BitLocker To Go on removable USB flash storage devices themselves or use encrypted BitLocker To Go devices from other organizations. Which of the following policies should you configure to accomplish this goal? (Choose all that apply. Each answer forms a complete solution.)
A. Configure Use Of Passwords For Removable Data Drives
B. Deny Write Access To Removable Drives Not Protected By BitLocker
C. Provide The Unique Identifiers For Your Organization
D. Control Use Of BitLocker On Removable Drives
A
B, C, and D
5
Q
5. The portable computers in your organization do not have TPM chips. You want to enable file and folder encryption on these computers but do not want to require users to start up using a USB flash device. Users are restricted so that they can write documents only to specific folders on the volume hosted on the portable computer’s internal hard disk. Which of the following encryption solutions can you implement to meet this goal? A. BitLocker B. BitLocker To Go C. IPsec D. Encrypting File System
A
D