Server Admin I Unit 8.6 Security Options Flashcards

1
Q

Security Options

A

Subset of Group Policy that governs rules for security on computer.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Security Options Settings Categories (4)

A
  1. Accounts
  2. Devices
  3. Interactive Logon
  4. Network Security
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Best Practices: Security Options: Accounts (3)

A
  1. Disable Administrator & Guest account.
  2. Rename accounts if unable to disable using the “Rename Administrator Account” or “Rename Guest Account” policies.
  3. Enable “Limit local account use of blank passwords to console logon only” policy.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Best Practices: Security Options: Interactive Logon (6)

A
  1. Disable: Display user information when session is locked.
  2. Enable: Do not display last user name.
  3. Disable: Do not require CTRL-ALT-DEL.
  4. Use: Message text for users attempting to log on.
  5. Enable: Prompt user to change password before expiration.
  6. Enable: Require Smart Card.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Best Practices: Security Options: Network Security (2)

A
  1. Enable: Force log off when logon hours expire.

2. Disable: Allow system to be shut down without having to log on.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

User Account Control

A

UAC; System that insures that actions which affect the system configuration are approved by users with the necessary rights to perform those actions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How to enable User Account Control

A

Enable “Run all adminstrators in Admin Approval Mode”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How many access tokens do Administrators get?

A

2; One Standard and One Administrator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

User Account Control Settings in Control Panel (4)

A
  1. Always Notify
  2. Notify me only when programs try to make changes to my computer.
  3. Notify me when programs try to make changes to my computer ( do not dim the desktop).
  4. Never Notify
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Secure Desktop

A

System that pauses all programs and darkens screen while displaying prompt for credentials or prompt for consent.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How long will Secure Desktop display on screen?

A

150 seconds, after 150 seconds the prompt for consent/credentials is automatically denied.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Never Notify UAC Setting Rules(2)

A
  1. If logged on as Admin, all actions are executed without UAC prompts or Secure Desktop.
  2. If logged on as a standard user, all actions requiring priviledge elevation are automatically denied.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Group Policy Equivalant for : Always Notify

A
  1. Behavior of the elevation prompt for administrators in Admin Approval Mode is set to : Prompt for consent on the secure desktop.
  2. User Account Control: Switch to the secure desktop when prompting for elevation is : Enabled.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Group Policy Equivalent for : Notify me only when programs try to make changes to my computer.

A
  1. Behavior of the elevation prompt for administrators in Admin Approval Mode is set to: Prompt for consent from non-Windows binaries.
  2. User Account Control: Switch to secure desktop when prompting for elevation is : Enabled.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Group Policy Equivalent for: Notify me only when programs try to make changes to my computer.(do not dim desktop)

A
  1. Behavior of the elevation prompt for administrators in Admin Approval Mode is set to: Prompt for consent from non-Windows binaries.
  2. User Account Control: Switch to secure desktop when prompting for elevation is : Disabled.
  3. Behavior of the elevation prompt for standard users is set to: Prompt for credentials.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Group Policy Equivalent for: Never Notify

A
  1. Behavior of the elevation prompt for administrators in Admin Approval Mode is set to: Elevate without prompting.
  2. User Account Control: Switch to secure desktop when prompting for elevation is : Disabled.
  3. User Account Control: Run all administrators in Admin Approval Mode is set to : Disabled.
17
Q

What must be done after turning off UAC via Group Policies?

A

The system must be rebooted.