Font size
WorksheetsNetworks
Total questions: 166
Worksheet time: 1hrs 27mins
The computers that provide the NAP platform for contact and confirmation of a system's health before enabling network access. These computers called:
o Remediation Servers
o NAP clients
o DHCP Server
o VPN Server
Which one of the these tools we don't use to configure the NPS role ?
o Network Policy Server MMC snap-in
o Remote desktop
o Windows PowerShell
o Netsh commands
In order to enable security center on NAP capable clients, you can use -
o NAP client configuration console
o Remote access enforcement client.
o Network Access Protection Client service
o Group Policy
There are computers or network-access devices that use NAP or that you can use with NAP to enable a health assessment of a NAP client before granting restricted network access or contact.
o Remediation Servers
o Health requirement servers
o NAP clients
o NAP enforcement points
These are computers that run Windows Server 2012 and the NPS service, and that store health-requirement policies and provide health-state validation for NAP.
Health requirement servers
o NAP enforcement points
o NAP health policy servers
o Remediation Servers
Which server routes the RADIUS messages between RADIUS clients and RADIUS server?
o RADIUS router
o RADIUS proxy
o RADIUS tunnel
o RADIUS gate
which function that can check network-access authentication credentials and has access to user-account information?
o RADIUS Server
o RADIUS Proxy
o NAP Policy Server
o Active directory Domain Server
performs centralized connection authentication and accounting for Access-Points and switches connections
RADIUS Server
o RADIUS Client
o RADIUS Proxy
o NAP Policy Server
in Windows Deployment Services you can install the__by itself to allow a computer to send data by using multicast packets.
o Scheduled-Cast
o Deployment Server
o Autocast
o transport server
The image that contains only the operating system and drivers is known as
o Hybrid image
o Flat image
o Thin image
o Thick image
A domain administator has setup a Network Access Protection in corperation's network, he checked the event logs of the server and found the an event with ID 6273. What this even is mean?
o Successful authentication has occurred
o NAP client quarantined
o Successful authentication has not occurred
To provide authorization and authentication for member has a two-way trust with the NPS server’s member domain
o NAP Policy Server
o RADIUS Proxy
o LDAP Authentication Server
o RADIUS Server
Scheduled-Cast can be configured in two ways.______is one of them.
o Autocast
o Client time
o client count
o Client point
One of the functions that the deployment server provided is
ImageX
o Windows SIM
o Scheduled-Cast
o (PXE) Server
You may specify which RADIUS servers to use for RADIUS accounting by setting up
o Connection request policies
o Health Policies
o Conditions and Constraints
o Network policies
means that Network Policy Server rejected the call for a user
Event ID 6278
Event ID 6274
Event ID 6276
Event ID 6273
You can create and manage unattended installation answer files and distribution shares by using
Windows PE
DISM
USMT
Windows SIM
allows client computers to receive an IP address from multiple logical subnets even when the clients are located in the same physical subnet.
A superscope
Multicast Scopes
DHCP Name Protection
DHCP Failover
The image that contains some of the applications required by most users is knownas
Flat image
Thick image
Thin image
Hybrid image
DHCP manages the distribution of IP addresses in TCP/IP networks of all sizes. When this service fails, clients lose connectivity to the network and all of its resources. A new feature in Windows Server 2012_______addresses this issue.
DHCP scope
DHCP console
DHCP superscope
DHCP failover
You must specify the_______of a replication group when configuring it.
Bandwidth throttling
Properties
Topology
Features
File Management Tasks can:
1. Which reports to generate 2.Which parameters to use 1.Move files to other locations 2. Archive expired files
1.Log an event in Event Viewer
2. Run a command or script
1.Move files to other locations 2. Archive expired files
Using a variety of properties,_____helps you to define, categorize, and manage data.
File Screening
File Server Resource Manager (FSRM)
File Management
Classification
In windows Server 2012 a feature that optimizes volume storage by redirecting redenundant data to a single storage point, it is called
Database
Data Deduplication
Data Storage
Data Redentant
Methods for optimizing a namespace include:
Renaming or moving a folder
Specifying referral cache duration
Restrict network access for computers that are running Windows versions older than Windows XP SP2,when exception rules are configured for those computers
Prevent authorized users with compliant computers from performing malicious
To configure DHCP failover, you must establish a failover relationship between the services of the two DHCP servers. This relationship must also be given a
uniqe name
Duplicate name
bublic name
bublic name
During dynamic IP address allocation, the DHCP server creates____automatically for DHCP clients in the DNS database
NetBIOS
DHCP resource records
New ip address
DNS resource records
You want to control the types of files that can be saved on file servers. Which tool you should use?
File Screening Management
Classification Management
Storage Reports Management
Quota Management
contains single-label names that are unique across an entire forest.
secondary zone
GlobalNames zone
Primary zone
stub zone
These functions take advantage of classification management's capabilities to let you remove old files or transfer them to a particular location depend on a file property like file name or file type
File Management Tasks
File Server Resource Manager (FSRM)
Classification Management
_______is a DNS server on your network that you set up to forward DNS queries for host names and it can't resolve to other DNS servers for resolution.
Netmask Ordering
Conditional Forwarding
Stub Zones
A forwarder
A single IPAM server can support many DHCP servers and DNS servers, What is the maximum number of DNS servers that IPAM can support?
500
600
550
50
By default the DHCP server dynamically updates both the client computer's host (A) and pointer (PTR) resource records. Moreover, there is a feature in Windows Server 2012 R2 which introduces the ability to disable only____
the PTR record registration
host (A) record registration
(NS) resource records
(SOA) resource record
Among each participant server, a___________is synchronizedAmong each participant server, a___________is synchronized
data Distribution
data collection
replicated folder
replication group
______can distribute IP addresses and other network configuration information to clients who request it.
DHCP database
DHCP Server service
DHCP options
DHCP scopes
How many years of forensic IP data will IPAM server store?
3 years
2 years
1 year
4 years
Which of the following is a distributed file system protocol ?
DFS
NES
SMB
NAS
________is a collection of servers that work together to replicate one or more folders.
Data deduplication
A replication group
Data Collection
A replicated folder
______is commonly known as a Multicast Address Dynamic Client Allocation Protocol (MADCAP) scope
A superscope
DHCP Name Protection
DHCP Failover
Multicast Scopes
You need to manage and monitor your server's storage capacity effectively, which role service you need to install?
NES
NAS
DFS
FSRM
This happend when a communication-interrupted state between the two DHCP servers that uses as failover server
MOLT
Auto State Switchover interval
Auto State Switchover interval
Firewall
The Domain Admin group can perform the following tasks in DFS administration
Manage a domain-based namespace
Add a namespace server to a domain-based namespace
Create a replication group
Create a stand-alone namespace
IPsec enforcement is the weakest form of limited network access or communication in NAP.
True
False
Deployment Server uses TFTP protocol because it is a faster transmission protocol
True
False
A radius client Provides authentication, authorization, and accounting (AAA) services
True
False
You can configure network access server (NAS) to act as a RADIUS server.
True
False
NPS is implemented as a server feature in Windows Server 2012 and newer versions
True
False
We can use .vhd files as install images in WDS.
True
False
You can define client health policies in NPS by adding one or more SHVs to the health policy
True
False
WSUS allows you to deploy to computers that don't have an operating system installed.
True
False
Direct Access enforcement is more complex to implement than other enforcement methods, because it requires an HRA and a CA
True
False
You can defend your network from hackers by implementing NAP.
True
False
A server with routing service can be RADIUS client.
True
False
DFS Replication isn't self-healing and can't automatically recover from failure.
True
False
One of the replication Topologies is Full mesh that Each member replicates to all others, as required if the member of group are 10 or more in the replication group.
True
False
Storage reports provides a method for controlling the types of files that can be saved on file servers
True
False
When the amount of data exceeds each configured threshold, a soft quota prohibits users from saving files after the space limit has been reached, and it produces notifications.
True
False
Health Report is one of the tools available for monitoring and troubleshooting DFS Replication. It creates a test file in a replicated folder to ensure that replication is working and to provide statistics for the propagation study.
True
False
A DFS namespace can be configured as Domain-based namespace only
T
F
The refresh interval is the period during which a record is not available for a refresh.
T
F
The DNS Admins group is a Domain Local security group, and by default has no members in it
T
F
File screen templates provide information about file usage on a file server
T
F
A multicast scope is a collection of multicast addresses from the class B IP address range of 224.0.0.0 to 239.255.255.255 (224.0.0.0/3).
T
F
Multicast scopes allow applications to reserve multicast IP address for data and content delivery.
T
F
As files are modified, DFS Replication uses RDC, which allows it to replicate only the changed file blocks.
T
F
Replication Group is a set of servers that participate in replicating one or more replicated folders
T
F
What are the two types of images that you can use in Windows Deployment Services?
Install image
Boot Image
What are the uses of NAP tracing?
records NAP events in a log file
troubleshooting and maintenance
evaluate network’s health and security
NPS can enforce health- requirement policies on client computers?
True
False
A remediation server group is list of servers on the restricted network that noncompliant NAP clients can access for software updates
TRUE
FALSE
A Soft quota prevents users from saving files after the space limit is reached, and it generates notifications when the volume of data reaches each configured threshold
TRUE
FALSE
The multicasting engine provides the main utility of the Transport Server component
TRUE
FALSE
FSRM is a role service under the File Services role in Windows Server 2012
TRUE
FALSE
For client computers to communicate with a WDS server without an operating system, the client computer must support perboot execution environment (PXE)
TRUE
FALSE
........... provides a method for controlling the types of files that can be saved on file servers
File screen management
Classification management
Quota management
Storage reports management
……………. the weakest form of NAP enforcement?
IPsec Enforcement
802.1X Enforcement
VPN Enforcement
DHCP Enforcement
Storage reports provide information about file usage on a file server by
DFS
FSRM
NPS
NAP
A server or device that forwards RADIUS requests to a RADIUS server.
NPS
NAP
RADIUS client
Access client
which of the following is NOT a type of NPS logging?
Logging user authentication and accounting requests to a local file
Event logging
gging user authentication and accounting requests a Microsoft SQL Server KMLcompliant database
Logging failure action
It is a software platform and technology that allows you to perform automated networkbased installations based on network-based boot and installation media?
FSRM
WDS
DFS
NPS
Which of these list is not requirements in WDS?
ADDC
DHCP
NPS
DNS
Shows a list of files that are the same size and have the same last modified data?
Files by File Group
File Screening Audit
Duplicate Files
A set of technologies that enable a Windows server to organize multiple distributed SMB file shares into a distributed file system.
NPS
DFS
FSRM
NAP
What is the default time a DFS client will hold a list of targets before it requests a new list?
300 seconds
60 seconds
3 minutes
3 seconds
It contains just the operating system and the necessary settings for a computer to be used in a network environment.
Thick Images
Hybrid Images
Thin Images
Which NAP enforcement client would be appropriate for enforcing health policies when a client computer is accessing your network through a 802.1x wireless connection?
IPsec
EAP
DHCP
Remote Access
Which of the following setting for NAP enforcement NOT an available option when setting up how want to enforce NAP?
Allow limited access
Allow full network access for limited time
Allow full access
Allow full access
Which of the following windows options will need your laptop users to use folder redirection?
Offline folders
Folder syncing
Monile folders
Mobile folders
It enables you to service and manage Windows images.
User State Migration Tool (USMT)
Pre-Boot Execution Environment (PXE) Server
DISM
Windows PE
………….. uses plaintext passwords and is the least secure authentication protocol in Authentication methods for NPS.
PAP
MS-CHAPv2
MS-CHAP
CHA
NAP can prevent authorized users with compliant computers from performing malicious activities on the network
TRUE
FALSE
The current system health state is provided by these computers to NAP health policy servers
Health requirement servers
.
Network policies are sets of conditions and settings that designate which RADIUS servers perform the authentication and authorization of connection requests that NPS receives from RADIUS clients
TRUE
FALSE
………is one of the strategies for enforcing the NAR When we apply this strategy on noncompliant devices, network access is limited using an IPv4 address setup. So, it allow only access to the restricted network
• DHCP enforcement
.
The service that enables you to perform network-based installations is :
(a)
The client computer sends………………. to the NPS when NAP-capable clients connect to the network.
(a)
You should not nable the Network Acces Protection Clent service when you deploy NAP to NAP capable client computers.
TRUE
FALSE
A RADIUS proxy is required for Providing authentication and authoritationfor user ccounts that are not Active Directory members
TRUE
FALSE
VPN enforcement is the strongest form of limited network access or communication in NAP.
TRUE
FALSE
When You generate cnnection request policy, the messages are forwarded from Radius client to RADIUS server where NPS functions as a
(a)
…………. evaluates statements of health sent by client computers which attempt to connect to the private network
NAP Policy Server
NPS
The transport server component provides two types of multicasting, what are they?
Scheduled-Cast
Autocast
Ater you instal NPS,a default connection request policy is ereated with the Authentication is configured.
TRUE
FALSE
The image that contains every application required by an end-user known as
Thick image
.
A domain administrator has setup a Network Access Protection in corperation's network, he checked the event logs of the server and found the an event with ID 6274. What this even is mean
A configuration problem exists
Successful authentication has not occurred
A domain administrator has setup a Network Access Protection in corperation's network, he checked the event logs of the server and found the an event with ID 6276. What this even is mean
NAP client quarantined
.
NPS can record events inte the system and serurity lags
TRUE
FALSE
Windows Deployment Services allows you to deploy only installation images for appreved operating systems and works with wim, whd., and.vhdx image files.
TRUE
FALSE
When you choose EAP as the authentication method the negotiation of the EAP type occurs between the access client and the NPS client.
TRUE
FALSE
What is the name of command set that is equivalent to all configuration NPS MMC snap-in settings?
The netsh commands
.
We can use vhd files as install images in WDS
True
False
You are a network administrator Example.com. You have a server named SVR1 that runs Windows Server 2012 R2. SVR1 has the DHCP Server server role and the Network Policy Server role service installed. You enable Network Access Protection (NAP) on all of the DHCP scopes on SVR1. You need to create a DHCP policy that will apply to all of the NÁP noncompliant DHCP clients. Which criteria should you specify when you create the DHCP policy?
The client identifier
The user class
The relay agent information
The vendor class
Your Network Policy Server (NPS) servers named Server1, Server2, Servers, and Server4. Server1 is configured as a RADIUS proxy that forwards connection requests to a remote RADIUS server group named Groupt1 You need to ensure that Server2 and Server3 receive connection requests. Server 4 must only receive connection requests if both Server2 and Server3 are unavailable. How should you configure Group1?
Change the Weight of Server4 to 10
Change the Weight of Server2 and Server3 to 10.
Change the Priority of Server2 and Server3 to 10.
Change the Priority of Server 4 to 10.
Your network contains an Active Directory domain named contoso.com. The domain contains a server named SRVI that runs Windows Server 2012 Ihas the following role services instaled • DirectAccess and VPN (RRASI • Network Policy Server Remote users have dient computers that run either Windows XP. Windows 7, or Windows 8. You need to ensure that only the client computers that run Windows 7 or Windows 8 can establish VPN connections to SRVI. What should you configure on SRV1?
A constraint of a Network Policy Server (NPS) network policy
A condition of a Network Policy Server (NPS) connection request policy
A condition of a Network Policy Server (NPS) network policy
A vendor-specific RADIUS atribute of a Network Policy Server (NPS) connection request policy
In Windows Deployment Service, you can perform network-base d installation without DHCP server in your network.
TRUE
FALSE
The network access server (NAS) can be set up to serve
Radius proxy
Client Access
RADIUS client
Radius server
Default ports for accounting requests that forwarded to a RADIUS server are (Choose two ansers)
18120
18130
1815
1811
By default, NPS sends and receives RADIUS traffic by using (TCP) ports 1812 (for authentication ) and 1813 (for accounting).
True
False
It's a separate logical or physical network made up of Remediation servers or NAP dients that have limited access.
802.1X devices
NAP clients
Restricted network
NAP enforcement points
Default ports for authentication requests that forwarded to a RADIUS server are (Choose two answers)
1644
1646
1645
1643
WIM imge type can only has one operating system's image
True
False
vhd files can store up to 4 gigabytes (GB) of data
True
False
System health agents are NAP infrastructure components that provide health state status and validation
TRUE
FALSE
System (SHAS) and SHVS are NAP infrastructure components that provide healthstate status and validation
TRUE
FALSE
The port 1645 is used by NPS to forward accounting requests
TRUE
FALSE
--means that the NPS granted access to a user
Event ID 6272
.
is used to perform authentication by using a database that is not a Windows account database or AD A
RADIUS proxy
.
The Deployment Server component of Windows Deployment Services doesn't require the installation of the Transport Serve.
TRUE
FALSE
You can use NPS as a RADIUS proxy when:
You want to perform authentication and authorization by using a database that is not a Windows account database.
.
has connection request policies that indicate which connection requests the NPS server will be forwarded to
RADIUS Proxy
.
Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2012 R2 and has the Network Policy Server role service installed. An administrator creates a RADIUS client template named Template1. You create a RADIUS client named Client1 by using Template 1. You need to modify the shared secret for Client 1. What should you do first?
Set the Shared secret setting of Template1 to Manual
Clear Select an existing template for Client1.
Clear Enable this RADIUS client for Client1
Configure the Advanced settings of Templatet.
What are the default ports that NPS listens to for RADIUS traffic?
port 1645 for authentication requests and port 1646 for accounting requests.
.
The least secure authentication methods for an NPS server is
PAP
.
What is the process's name of verifying that find out a user who try to connect to a network?
Authentication
.
The IPsec NAP enforcement is comprised of …….. and an IPsec NAP enforcement client.
HRA
.
The deployment server provides the following functionality: (choose two)
Pre-Boot EXecution Environment (PXE)
Server Image store
MS-CHAP v2 provides stronger security for network access connections than its predecessor, MS-CHAP
TRUE
FALSE
FSRM is a role service under the File Services role in Windows Server 2012.
TRUE
FALSE
When a Windows dient operating system is configured to use the DHCP service, the client can use …………in its subnet to request IP configuration from any DHCP server that receives the request.
an ARP unicast
an ARP multicast
an ARP broadcast
is a collection servers together replicate one or more folders
A replicated folder
Data Collection
A replication group
Data deduplication
Which storage feature in Windows server 2012 that provides bandwidth efficiency with scale and performance toolbar
Data Deduplication
.
………….... enable users to access business data securely at any location and on any device
Claim
Work Folders Access
Denied Assistance
You have a server named HQ1. You install the IP Address Management (IPAM) Server feature on HQ1. You need to provide a user named AHMED with the ability to set the access scope of all the DHCP servers that are managed by IPAM. The solution must use the principle of least privilege.Which user role should you assign to AHMED?
o IPAM DHCP Administrator Role
o IPAM Administrator Role
o IPAM DHCP Reservations Administrator Role.
o DNS Record Administrator Role
Joe will be performing a basic installation of Windows 8.1 on a clean hard disk. Where will he obtain the images for his istallation?
o Use the Windows Assessment and Deployment Kit.
o Use the DVD media.
o Use the install.wim image from the sources directory.
o Use the boot.wim and install.wim images fro the Windows 8.1 DVD
A............... is a collection of individual scopes that are grouped together for administrative purposes
o DHCP Fallover
o Name Protection DHCP
DNSSEC
o Superscope DHCP
Windows 8 or newer microsoft OS is not necessary if you want to use device claims in conditional expressions.
TRUE
FALSE
Prevents Windows operating systems from having their DNS name registrations overwritten by non-Windows operating systems that have the same name
o Superscope DHCPA
DNSSEC
DHCP Failover
o Name Protection DHCP
You can not deploy claims between trusted forests in Microsoft Dynamic Access Control
TRUE
FALSE
AD RMS provides greater protection for documents by controlling how applications use them, and also works with user or group SID
TRUW
FALSE
DHCP failover do not supports the hot standby mode and the load sharing mode
TRUE
FALSE
A software component or host adapter on the server that provides access to ISCSI Targets
o Storage Array
o iSCSI initiators
IQNCO
ISCSI Larges
Global Names zones provide single-label name resolution for large enterprise networks that donot deploy WINS and that have multiple DNS domain environments
True
False
DAC in Windows Server 2012 is a new access control mechanism for……………
Network
Storage
File system
The DHCP server are leased IP addresses to clients for a configurable period, and are regularly renewed
TRUE
FALSE
In IPAM server the minimum RAM Requirement is
3GB
4GB
2GB
1 GB
The IPAM server must be member in a domain, and can be a domain controller
TRUE
FALSE
In PAM server the minimum free disk space Requirement is
70 GB
80 GB
50 GB
60 GB
NTFS file system permissions and ACLS provide access control that is based on a user's SID
TRUE
FALSE
A............. is something that AD DS states about a specific object
Resource properties
Access Control Rules
Claim
Which of the updates settings would you want to use on your Windows Server?
o install updates automaticaaly
o Check for updates ut let me choose whether to download and install them
o Download updates but let me choose whether to install therm
o Never check for updates
You can use Miinath TO IMPLOY when you have more than one physical network connection between your iSCSI initiator and your ISCS targets
TRUE
FALSE
Enables two DHCP servers to provide IP addresses and optional configurations to the same subnets or scopes
Superscope DHCP
DNSSEC
DHCP Failover
Name ProtectionDHCPD
In DNS Security: Which technolgy make Randomizes the source port for issuing DNS queries
DNS cache locking
DNS socket pool
DNSSECCO
Run on the storage device and enable access to the disks
iSCSI targets
Storage Array
IONC
iSCSI initiators
In hosted cache mode in BranchCache, the content cache at the branch office is hosted on one or more server computers that are hosted cache servers
TRUE
FALSE
Forwards queries for specific DNS suffixes to specific DNS servers
Conditional forwarding
Netmask ordering
o Stub zones
Forwarding
