misc Flashcards
what is the difference between universal and global groups
universal groups can give user permissions to any resource in the forest while global groups can only give users user permissions to a resource in the same domain
universal groups can contain other universal groups, global groups and user objects while global groups can only contain other global groups and user objects
what are the foundational principles of trusted cloud
privacy, security, compliance
what are the requirements of trustworthy computing
hardware must be reliable
software must be reliable
service components must be dependable
what are the goals of trustworthy computing
security, privacy, business integrity
what are the means of delivery of trustworthy computing
security by design and by default
privacy
transparency
availability and manageability
what are the commitments to security microsoft made and examples of each
isolation and resilience
quality
updates
access control and authentication
isolation and resilience: firewall, cpu isolation, object access control
quality: secure coding practices during deployment, thorough bug testing and automated testing tools
updates: consistent updates
access control and authentication: providing access control to objects and using passwords/pki
what are the security by default in a domain domain controller
encryption
file policies
file permissions
server management and monitoring
logging/auditing
file sharing requirements and protocol
protocol: smb
requirements: enable “file and print sharing (smb-in)” and port 445 must be open
difference between efs and bitlocker
efs using symmetric while bitlocker uses asymmetric
efs encrypts on a file level while bitlocker encrypts the whole hard drive
what is fine grained password policy ?
Fine-Grained Password Policies (FGPP) allow you to create multiple password policies for specific users or groups
precautions to take when working with windows registry
do not copy from 1 windows machine to another
only change as a last resort
regularly backup
delegate a specific group of administrators that can edit registry