web flashcards
DirectAccess was introduced with which workstation/server pair?
Windows 7/Windows Server 2008 R2
What kind of connectivity does DirectAccess establish between workstation and server?
bi-directional
What type of server is the network location server (NLS)?
web
What does the acronym ISATAP stand for?
Intra-Site Automatic Tunnel Addressing Protocol
What utility do you use to configure DirectAccess?
Remote Access Management Console
Windows Server 2012 varies from the Windows Server 2008 R2 implementation in that it does not require which one of the following?
two consecutive public IP addresses
What is the most basic requirement for a DirectAccess implementation?
The DirectAccess server must be part of an Active Directory domain.
If the client cannot reach the DirectAccess server using 6to4 or Teredo tunneling, the client tries to connect using what protocol?
IP-HTTPS
What does the netsh namespace show policy command do?
determines the results of network location detection and the IPv6 addresses of the intranet DNS servers
What kind of connectivity does DirectAccess provide between client computers and network resources?
seamless and always on
DirectAccess is for clients connected to which network?
Internet
How do the DirectAccess server and DirectAccess client authenticate each other?
computer and user credentials
Which one of the following operating systems may not act as a DirectAccess client?
Windows Server 2008
What kind of RADIUS server is placed between the RADIUS server and RADIUS clients?
a RADIUS proxy server
What process determines what a user is permitted to do on a computer or on a network?
authorization
What is a RADIUS server known as in Microsoft parlance?
Network Policy Server
Which ports do Microsoft RADIUS servers use officially?
1812 and 1813
When an access client contacts a VPN server or wireless access point, a connection request is sent to what system?
the NPS server
Which system, in a RADIUS infrastructure, handles the switchboard duties of relaying requests to the RADIUS server and back to the client?
the access server
What is the final step in the authentication, authorization, and accounting scenario between an access client and the RADIUS server?
an Accounting-Response to the access server
To configure RADIUS service load balancing, you must have more than one kind of what system per remote RADIUS server group?
RADIUS server
Which parameter specifies the order of importance of the RADIUS server to the NPS proxy server?
priority
Using what feature can streamline the creation and setup of RADIUS servers?
templates
What information does the Accounting-Start message contain?
the type of service and the user it’s delivered to
Which system is the destination for Accounting-Start messages?
the RADIUS accounting server
What type of NPS authentication is recommended over password authentication?
certificate
Why is password-based authentication not recommended?
Usernames and passwords are sent in plain text.
Where do you get certificates for authentication purposes?
a certificate authority
An NPS policy is a set of permissions or restrictions that determine what three aspects of network connectivity?
who, when, and how
Which variable can be set to authorize or deny a remote connection?
group membership
The default connection request policy uses NPS as what kind of server?
RADIUS
Where is the default connection policy set to process all authentication requests?
locally
What is the last setting in the Routing and Remote Access IP settings?
how IP addresses are assigned
What command-line utility is used to import and export NPS templates?
netsh
To which type of file do you export an NPS configuration?
XML
When should you not use the command-line method of exporting and importing the NPS configuration?
when the source NPS database has a higher version number than the version number of the destination NPS database
Network policies determine what two important connectivity constraints?
who is authorized to connect AND the connection circumstances for connectivity
When the Remote Access server finds an NPS network policy with conditions that match the incoming connection attempt, the server checks any _______________ that have been configured for the policy.
constraints
If a remote connection attempt does not match any configured constraints, what does the Remote Access server do to the connection?
denies
Identify the correct NPS templates. Select all that apply.
Shared Secrets
Health Policies
RADIUS Clients
Which two of the following are Routing and Remote Access IP settings?
Client May Request an IP Address
Server Must Supply an IP Address
Which Routing and Remote Access IP setting is the default setting?
Server Settings Determine IP Address Assignment
Network Access Protection (NAP) is Microsoft’s software for controlling network access of computers based on what?
a computer’s overall health
Because NAP is provided by _________, you need to install _________ to install NAP.
NPS
NPS
DHCP enforcement is not available for what kind of clients?
IPv6
Identify two remediation server types.
Anti-virus/anti-malware servers
Software update servers
What type of Active Directory domain controller is recommended to minimize security risks for remediation servers?
read-only
When you fully engage NAP for remediation enforcement, what mode do you place the policy in?
isolation
To verify a NAP client’s configuration, which command would you run?
> netsh nap client show state
Which two components must a NAP client have enabled in order to use NAP?
Security Center
NAP Agent
Why do you need a web server as part of your NAP remediation infrastructure?
to provide user information in case of a compliance failure
Where do you look to find out which computers are blocked and which are granted access via NAP?
the NAP Server Event Viewer
Health policies are in pairs. What are the members of the pair? Select two.
NAP-compliant
NAP-noncompliant
You should restrict access only for clients that don’t have all available security updates installed if what situation exists?
the computers are running Windows Update
What happens to a computer that isn’t running Windows Firewall?
The computer is isolated.