MS-09-P1 Microsoft Endpoint Security Flashcards
Scrambles computer information
Encryption
Used to encrypt (scramble) and decrypt (unscramble) data
Keys
Utilizes many available algorithms and methods
Symmetric (shared key) and asymmetric (public/private key)
Pre installed in windows 10 and provides disk encryption method for OS, uses key lengths of 128 and 256, provides pre-boot protection, network unlock, GUI and Powershell managment
BitLocker
used for bitlocker key protection
TPM - Trusted Platform Module
A microcontroller embedded in the system and generates cryptographic keys
TPM - Trust Platform Module
An application that allows restricting multiple apps with a single rule. helps administrators control which apps and files users can run, including executable files, scripts, dynamic-link libraries (DLLs),and others.
AppLocker
Is a policy used to identify applications
Application Identify
T or F: Policy should be set to automatic for any AppLocker usage
True
.exe
Executable
.msi, .msp, .mst
Windows Installer
.ps1, .bat, .cmd, .vbs, .js
Script
Make sure files function properly
AppLocker Default Rules
Uses the app’s digital signature for identification
Publisher
Uses the app’s location in the file system for identification
Path