wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

MOC II 0 VII IV IV

Total questions: 91

Worksheet time: 51mins

Name
Class
Date
1.

What are the key target resources for attackers? Select 3 options from the following.

a)

Domain Controller

b)

Email servers

c)


Database servers

d)

DHCP servers

e)

DNS servers

2.

True / False. A server can have only one JEA endpoints

a)

True

b)

False

3.

One of the tools used to determine which applications are configured to start automatically when a computer boots up or user sign on. Select from the following.

a)

Accesschk

b)

Autorun

c)

Sysmon

d)

LogonSession

4.

Select 2 Attack against application from the following:

a)

SQL Injection

b)

Adware

c)

Distributed operating system

d)

Distributed denial of service

e)

Spyware

5.

PAM process is implemented through temporary group membership

a)

True

b)

False

6.

GMSA requires this following key

a)

Public key 

b)

Private Key

c)

KDS root key

7.

Select two statements for principles of least privilege from the knowledge you gain from this course. 

a)

Use a single over privileged account 

b)

Only use privileged accounts to perform administrative tasks 

c)

Use administrator account to perform administrative task 

d)

Avoid single over privileged account 

8.

Match the below with the correct response:

Research and Preparation

a)

Detecting breach evidence

b)

One of the 3 phase attack in Timeline

c)

A service that allows you to submit a file for a malware scan

d)

Malware type which encrypts important data

9.

Match the below with the correct response:

Intrusion Detection system 

a)

Detecting breach evidence

b)

One of the 3 phase attack in Timeline

c)

A service that allows you to submit a file for a malware scan

d)

Malware type which encrypts important data

10.

Match the below with the correct response:

Ransomware

a)

Detecting breach evidence

b)

One of the 3 phase attack in Timeline

c)

A service that allows you to submit a file for a malware scan

d)

Malware type which encrypts important data

11.

Match the below with the correct response:

Virus Total

a)

Detecting breach evidence

b)

One of the 3 phase attack in Timeline

c)

A service that allows you to submit a file for a malware scan

d)

Malware type which encrypts important data

12.

Which of the following protects the password of the domain by storing them in a virtual container instead of storing in RAM?

a)

Protected user group 

b)

Windows defender credential guard 

c)

Group managed service account 

d)

Microsoft managed service account 

13.

What are the two important files in Just Enough Administration?

a)

Role capability file

b)

Visible function file

c)

Session configuration file

d)

Visible cmdlet file

14.

Helps a computer resist attacks and infection from malware, only software or firmware signed with approved keys are allowed to execute.

a)

Dual boot 

b)

Secure Boot

c)

Antivirus

15.

What scanning options are available when you use Windows Defender? Select the best choice. 

a)

Full

b)

Quick

c)

Offline

d)

Custom

e)

All of the above

16.

Other than the host server operating system, which two Microsoft products do you need to deploy before you deploy MIM 2016? 

a)

MS Office 2016

b)

Sharepoint

c)

SQL Server

d)

Exchange Server 2016

17.

What is a shadow account?

a)

A copy of the account created in privileged domain, also exist in the production domain

b)

An existing user account from a privileged domain  

c)

A new account created without using the production source credentials 

18.

AppLocker uses _________________________service to verify a file attribute. App policies are not enforced if the service is not running.  

a)

Application Identity

b)

MIM

c)

Azure identity

19.

What is the default TTL for PAM?

a)

30 minutes

b)

1 hour

c)

24 hours

20.

What are the two extensions of JEA files?

a)

.psrc

b)

.pssc

c)

.psbc

d)

.pasc

21.

What are the three options available to control which application users can run in windows server 2016?

a)

Security Restriction Policy 

b)

Just enough administration 

c)

Applocker 

d)

Host Guardian Services 

e)

Windows Defender Device Guard 

22.

Select the common attack vectors from the following:

a)

Email attachment 

b)

Popup windows

c)

Deception

d)

All the above 

23.

Group managed service accounts passwords are managed by IT operation team 

a)

True

b)

False

24.

What is the expansion of ESAE forest deployed in Privileged Access Management?

a)

Enhanced Security Admin Environment

b)

OTHER ONE

25.

EFS encryption does not require a Certificate

a)

True

b)

False

26.

Message analyser is used to ________________________________

a)

Send messages through email.

b)

Capture network traffic and analyse.

c)

Capture email messages and analyse

27.

Both ATA gateway and ATA light gateway can be installed on the Domain Controllers

a)

True

b)

False

28.

Select 2 incident strategies for security breach from the list.

a)

Disconnect from network

b)

Relocate the server to different location

c)

Law enforcement

d)

Forensic analysis

e)

Change the password of the administrator

29.

____________________used in windows 2016 to enable quotas

a)

Bitlocker encryption

b)

Encrypted File system

c)

File service resource manager

d)

File service replication manager

e)

Distributed file system replication

30.

What is the designated port no. for HTTPS

a)

8080

b)

80

c)

443

d)

4443

31.

A shielded VM is a generation 2 VM (supported on Windows Server 2012 and later)

a)

True

b)

False

32.

You can use BitLocker without TPM

a)

True

b)

False

33.

Select the settings to increase security for privileged accounts

a)

Logon hours

b)

Late hours

c)

Logon workstation

d)

Logoff hours

e)

Admin workstation

34.

What is the minimum number of forests required to deploy PAM?

a)

2

b)

3

c)

4

35.

What are the 3 network profiles available in firewall

a)

Domain networks

b)

Private networks

c)

Guest or public networks

36.

What are the 3 ways to deploy firewall rules?

a)

Manually

b)

Group Policy

c)

Export and import

37.

What are the 2 modes used in Hosted Guardian services? Select 2 answers

a)

TPM Trusted

b)

Forest Trusted

c)

Admin Trusted

d)

Domain Trusted

38.

What are the options available to encrypt Files in Windows server 2016?

a)

EFS

b)

DFS

c)

FRS

d)

BitLocker

39.

Helps a computer resist attacks and infection from malware, only software or firmware signed with approved keys are allowed to execute.

a)

Dual boot

b)

Antivirus

c)

Secure boot

40.

What is the tool available in SCT to view and compare your local policy and local registry

a)

Shielded VM

b)

Host guardian services

c)

Policy Analyzer

d)

GPO Editor

41.

What are the 2 types of containers supported in windows server Virtualisation Security? Select 2 answers.

a)

Organisational unit

b)

Container

c)

Hyper-V container

d)

Silos

e)

Windows server container

42.

Bitlocker provides a recovery mechanism with a _______digit recovery key

a)

57

b)

42

c)

48

d)

32

43.

What are the 2 modes in a container where the codes can run?

a)

User mode

b)

Kernel mode

c)

Computer mode

d)

Virtual mode

44.

IPsec is predominantly used in VPN’s

a)

True

b)

False

45.

Select one malware which is self-copying  and replicate itself, that infects computers

a)

Trojan

b)

Ransomware

c)

Viruses

d)

Worms

46.

You can configure user rights assignment in 2 ways

a)

Add a user to the remote desktop user group

b)

Group policy

c)

User policy

d)

Network policy

47.

Select the built-in service account types

a)

Local system

b)

Local service

c)

Remote service

d)

Database service

e)

Network service

48.

Organizations want to give IT Operations personnel the ability to perform administrative tasks such as resetting user passwords, without giving them the ability to perform other tasks, such as creating or deleting accounts. How do you do that

a)

Add the member of the IT operations personal to Administrator group

b)

Create a Group managed service account and link to the IP operations personnel

c)

Use delegation wizard to delegate the IT Operations personnel with specific task

49.

Select the ways to secure Domain controller, select 2

a)

Use the server core installation

b)

Install windows server 2016

c)

User RODC where security is not assured

d)

Disable wired and wireless network.

50.

LAPS is a password manager that uses active directory to manage and periodically change the passwords for local administrator accounts

a)

True

b)

False

51.

What is the powershell cmdlet used in LAPS to view the password

a)

GET-AdmPwdPassword

b)

GET-AdmPassword

c)

GET-AdmPwd

d)

GET-LAPSPassword

52.

You can search for problematic accounts, where no sign-in has occurred for more than 90 days using?

a)

Active directory users and computer

b)

Active directory Federation services

c)

Active directory Administrative center

d)

Active directory domain and trust

53.

Actions are performed by using a special machine local virtual account in Just enough administration

a)

True

b)

False

54.

The above 2 important files are automatically created in JEA.

a)

True

b)

False

55.

What are the limitation of JEA. Write one limitation.

a)

JEA only works with Windows PowerShell sessions, and does not work with management consoles or other remote administration GMSPAM

b)

OTHER ONE

56.

What are the component of PAM?

a)

ESAE Forest

b)

Production Forest

c)

PAM Client

57.

What is the tool which does same as ADDS with better Graphical user interface

a)

Privileged access management

b)

Microsoft identity management

c)

Microsoft password manager

58.

Shadow accounts are created automatically by PAM

a)

True

b)

False

59.

What are the rule actions available in Applocker?

a)

Allow

b)

Deny

c)

Audit

d)

Enforce

60.

Which service provides the transport keys that are needed to unlock and run shielded VMs on affirmatively attested (or healthy) Hyper-V hosts?

a)

KPS

b)

Attestation services

61.

To install guarded fabric to your existing windows server 2012

a)

update hyper-v host windows server 2016 Datacenter edition

b)

update hyper-V host to windows server 2012 datacenter edition

c)

update hyper-v host windows server enterprise edition

62.

What is the Powershell command to verify the host guardian Hyper-V support feature is enabled

a)

Install -WindowsFeature –Name HostGuardianServiceRole

b)

Get-WindowsFeature HostGuardian

c)

Set-WindowsFeature HostGuardian

63.

What is abbreviation of SCT in windows server 2016

a)

Session control toolkit

b)

Self-certificate toolkit

c)

Security compliance tool kit

64.

Security baselines are used to do what?

a)
  1. Ensure that user and device configuration settings are compliant with the baseline.

b)
  1. Ensure that user configuration settings are complaint with the baseline.

c)
  1. Ensure that device configuration settings are compliant with the baseline.

65.

Containers share the kernel of the host Operating System

a)

True

b)

False

66.

What is HAL in Hyper-V Virtualisation

a)

Hardware abstraction layer

b)

OTHER ONE

67.

What are the 2 methods used in EFS encryption?

a)

Symmetric encryption to encrypt the file.

b)

Public encryption to protect the symmetric key.

68.

Hyper-V containers provide an extra isolation boundary where each container has its own copy of the operating-system binaries

a)

True

b)

False

69.

Match below items:

Container

a)

Runs a complete operating system including the kernel

b)

The container host doesn’t share its kernel with other hyper-v  containers

c)

Docker

d)

Runs on the same O/S as the host

70.

Match below items:

Virtual machine

a)

Runs a complete operating system including the kernel

b)

The container host doesn’t share its kernel with other hyper-v  containers

c)

Docker

d)

Runs on the same O/S as the host

71.

Match below items:

Hyper-V containers

a)

Runs a complete operating system including the kernel

b)

The container host doesn’t share its kernel with other hyper-v  containers

c)

Docker

d)

Runs on the same O/S as the host

72.

Match below items:

Enables you to separate your applications from your infrastructure

a)

Runs a complete operating system including the kernel

b)

The container host doesn’t share its kernel with other hyper-v  containers

c)

Docker

d)

Runs on the same O/S as the host

73.

Cipher.exe

a)

Is a PowerShell tool used to encrypt and decrypt the data

b)

Is a command line tool used to encrypt and decrypt the data?

c)

Is a Microsoft tool to decrypt the data

74.

What is the use of file screening template in FSRM?

a)

Used to block files in a file server.

b)

Used to allow files in a file server

c)

Used to allow / block files in a file server

75.

Select the data governance technology that works along with NTFS permission and shared folder permission to grant or block user based on their identity.

a)

Distributed File System

b)

Data Access Control

c)

Digital Access Control

76.

IP sec is a tunnelling protocol which provides security for IP traffic only.

a)

True

b)

False

77.

What is the risk associated with leaving SMB 1.x  enabled in your environment?

a)

If it is disabled in your environment, it could be vulnerable to attacks

b)

If it is enabled in your environment, it could be vulnerable to attacks

78.

Test -Nonconnection PowerShell cmdlet is equivalent to Ping command

a)

True

b)

False

79.

What is the latest version of SMB, which supports both Kerberos authentication and connection restore?

a)

SMB 1.0

b)

SMB 2.0

c)

SMB 3.1.1

80.

What is the protocol used in DNSSec

a)

SMB 3.0

b)

DANE

c)

DORA

81.

What do you mean by DNS socket pool, what is the use of it.

a)

Instead of using the predictable source port, it randomizes the port numbers

b)

Overwriting information in DNS cache

c)

Used to analyse the network traffic

82.

You are the administrator of an Active Directory Domain Services (AD DS) domain. All server computers run Windows Server 2016. Some malicious software infects a specific network subnet. The malicious software performs DNS queries to the domain's DNS servers in an attempt to spread itself to other hosts.

You need to prevent the infected subnet from performing DNS queries to the domain's DNS servers. Your actions must not disrupt the DNS service in the rest of the subnets in the domain.

What technology should you configure?

a)

Domain Name System Security Extensions (DNSSEC) on the DNS servers

b)

DNS-based Authentication of Named Entities (DANE) on the DNS servers

c)

DNS policies on the DNS servers

d)

IP Address Management (IPAM) in the domain

83.

Your network contains an Active Directory domain named contoso.com. You create a Microsoft Operations Management Suite (OMS) workspace. You need to connect several computers directly to the workspace.

Which two pieces of information do you require?

a)

the ID of the workspace

b)

the name of the workspace

c)

the URL of the workspace

d)

the key of the workspace

84.

The New-CI Policy cmdlet creates a Code Integrity policy as an .xml file. If you do NOT supply either driver files or rules what will happen?

a)

The cmdlet performs a system scan

b)

An exception/warning is shown because either one is required

c)

Nothing

d)

The cmdlet searches the Code Integrity Audit log for drivers

85.

Windows PowerShell is a task-based command-line shell and scripting language designed especially for system administration. Windows Defender comes with a number of different Defender-specific cmdlets that you can run through PowerShell to automate common tasks.

Which Cmdlet would you run first if you wanted to perform an offline scan?

a)

Set-MpPreference -DisablePrivacyMode $true

b)

Set-MpPreference -DisableRestorePoint $true

c)

Start-MpScan

d)

Start-MpWDOScan

86.

A shielding data file (also called a provisioning data file or PDK file) is an encrypted file that a tenant or VM owner creates to protect important VM configuration information. A fabric administrator uses the shielding data file when creating a shielded VM, but is unable to view or use the information contained in the file.

Which information can be stored in the shielding data file?

a)

Administrator credentials

b)

All of these

c)

A Key Protector

d)

Unattend.xml

87.

You are the administrator for your company. Your company is planning to deploy shielded virtual machines (VMs) to an external cloud platform that uses a guarded fabric with Trusted Platform Module (TPM)-attestation.

You are implementing an on-premises guarded host on a server that will run Windows Server 2016. You are evaluating the following two installation options for the guarded host server:

- Nano Server

- Desktop Experience

 

You need to identify any requirements that can only be met by using the Desktop Experience installation option for the on-premises guarded host.

Which capability can only be met by the Desktop Experience installation option?

a)

Create new shielded VMs on premises and move the VMs to a guarded fabric.

b)

Manage the server remotely by using PowerShell.

c)

Implement measured boot sequence and code integrity policies.

d)

Manage guarded hosts by using System Center Virtual Machine Manager (SCVMM) 2016.

88.

____________ enables easier management for BitLocker enabled desktops and servers in a domain environment by providing automatic unlock of operating system volumes at system reboot when connected to a wired corporate network.

This feature requires the client hardware to have a DHCP driver implemented in its UEFI firmware.

a)

Credential Guard

b)

JEA

c)

EFS recovery agent

d)

Network Unlock

89.

Your network contains an Active Directory domain. Microsoft Advanced Threat Analytics (ATA) is deployed to the domain. A database administrator named DBA1 suspects that her user account was compromised.

a)

Spam messages received by DBA1.

b)

Phishing attempts that targeted DBA1

c)

The last time DBA1 experienced a failed logon attempt

d)

Domain computers into which DBA1 recently signed.

e)

Servers that DBA1 recently accessed.

90.

This question relates to Windows Firewall and related technologies. These rules use IPsec to secure traffic while it crosses the network. You use these rules to specify that connections between two computers must be authenticated or encrypted.

What is the name for these rules?

a)

Firewall Rules

b)

Connection Security Rules

c)

TCP Rules

d)

DHP Rules

91.

You are building a guarded fabric.You need to configure Admin-trusted attestation. Which cmdlet should you use?

a)

Add-HgsAttestationHostGroup

b)

Add-HgsAttestationTpmHost

c)

Add-HgsAttestationCIPolicy

d)

Add-HgsAttestationTpmPolicy