WorksheetsA+ - 17A - Managing Security Settings
Total questions: 2
Worksheet time: 14mins
Password best practices are crucial for ensuring the security of workstations and networks. Effective user security relies on strong credential management, account policies, and user behavior. Password-based authentication systems face vulnerabilities, especially from weak passwords. To enhance security, users should follow certain password rules such as using sufficiently long passwords, avoiding personal information, and incorporating complexity requirements. Account management policies, including restricting user permissions and changing default administrator accounts and passwords, are essential for maintaining security. End-user best practices involve securing hardware, protecting personally identifiable information (PII), and adhering to account policies. Execution control, including trusted software sources and auto-run/auto-play settings, helps prevent malware execution. Antivirus software, such as Windows Defender Antivirus, plays a critical role in detecting and preventing malware. Windows Defender Firewall provides host-based firewall protection, and Encrypting File System (EFS) and BitLocker offer data encryption solutions to safeguard data-at-rest.
What are some key principles of good password practice?
Using short passwords with personal information
Using complex passwords with personal information
Choosing memorable phrases without personal information
Using significant dates and family names in passwords
Which vulnerability of knowledge factor authentication to cyberattacks is highlighted in the text?
Weak passwords
Expiration requirements
Unauthorized physical access
Account lockout policies
What is the primary purpose of a BIOS/UEFI password?
Protecting access to firmware system-setup program
Preventing unauthorized physical access to servers
Enhancing network security
Providing access to embedded systems
What should users do to secure laptops when in public?
Leave laptop cases unattended
Keep laptops out of sight
Lock laptops with cable locks
Share administrative passwords
Which feature is NOT included in Windows Defender Antivirus?
Real-time protection
File encryption
Malware detection
Automatic updates
What is the primary purpose of Windows Defender Firewall?
Filtering inbound and outbound network traffic
Encrypting data-at-rest
Preventing malware execution
Managing user permissions
Which tool is used to configure advanced filtering rules for Windows Defender Firewall?
Local Security Policy snap-in
Group Policy Editor snap-in
Windows Defender Firewall with Advanced Security console
TPM Management snap-in
What is the purpose of encryption in the Encrypting File System (EFS)?
Protecting data-in-use
Preventing malware execution
Securing data-at-rest
Filtering inbound and outbound network traffic
Which edition of Windows includes BitLocker disk encryption?
Windows Home
Windows Professional
Windows Enterprise
All editions except Windows Home
What does BitLocker use to store the encryption key?
TPM chip
USB stick
Removable smart card
All of the above
Which policy enforces a maximum number of incorrect sign-in attempts within a certain period?
Restrict login times
Failed attempts lockout
Concurrent logins
Use timeout/screen lock
What is the primary means of detection used by antivirus software?
Digital certificates
Encryption keys
Definitions or signatures
Execution control
What happens when a user account violates a security policy?
The account is locked against further use
The account is deleted permanently
The account is granted administrator privileges
The account is automatically logged out
What does Execution Control refer to?
Filtering inbound and outbound network traffic
Logical security technologies to prevent malware execution
Configuration of encryption keys
Managing user permissions
Which feature of Windows Defender Antivirus can be temporarily disabled?
Automatic updates
Real-time protection
Firewall settings
System scan
What is the purpose of auto-run/auto-play settings?
Filtering inbound and outbound network traffic
Encrypting data-at-rest
Preventing malware execution
Automatically running commands from inserted media
How can users configure Windows Defender Firewall on a standalone PC?
Via Group Policy Editor snap-in
Through TPM Management snap-in
Using the Local Security Policy snap-in
With the Windows Defender Firewall with Advanced Security console
Which edition of Windows does NOT include the Encrypting File System (EFS)?
Windows Professional
Windows Enterprise
Windows Home
All editions include EFS
What is the primary advantage of full disk encryption?
It does not depend on user behavior
It prevents malware execution
It filters inbound and outbound network traffic
It encrypts individual files and folders
Which tool is used to manage TPM settings in Windows?
TPM Management snap-in
Group Policy Editor snap-in
Local Security Policy snap-in
Windows Defender Firewall with Advanced Security console
What happens when a file is encrypted using EFS and accessed by another user?
The file cannot be opened
The file is automatically decrypted
The user is prompted for a password
The file permissions are overridden
How does Execution Control prevent malware from running on a host?
By encrypting data-at-rest
By filtering inbound and outbound network traffic
By enforcing digital certificates
By using logical security technologies
Have you submitted your standup form yet?
Click the link below
Not yet
I have now.
