Microsoft 2 Testbank 15

25 July 2022
4.7 (114 reviews)
28 test answers

Unlock all answers in this set

Unlock answers (24)
question
A. NTLM is alles voor non domein
answer
Multiple Choice What is the default authentication protocol for non-domain computers? a. NTLM b. PAP c. CHAP d. Kerberos
question
C. NT Lan manager. NT LAN Manager (NTLM) is a suite of Microsoft security protocols that provides authentication, integrity, and confidentiality to users
answer
What does the acronym NTLM stand for? a. NT Link Messenger b. NT Link Manager c. NT LAN Manager d. NT LAN Messenger
question
c. sending a password to the server NTLM uses a challenge-response mechanism for authentication in which clients can prove their identities without sending a password to the server.
answer
NTLM uses a challenge-response mechanism for authentication without doing what? a. revealing the client's operating system to the server b. revealing the protocol to the server c. sending a password to the server d. sending an encrypt/decrypt message to the server
question
a. a secure network authentication protocol Kerberos is a computer network authentication protocol that allows hosts to prove their identity securely over a non-secure network
answer
What type of protocol is Kerberos? a. a secure network authentication protocol b. a simple Microsoft-only protocol c. a uni-directional authentication protocol d. a certificate-based authentication protocol
question
b. secret key With Kerberos, security and authentication are based on secret-key technology. Every host on the network has its own secret key
answer
Kerberos security and authentication are based on what type of technology? a. secure transmission b. secret key c. challenge-response d. legacy code
question
b. 5 minutes For all of this to work and to ensure security, the domain controllers and clients must have the same time. Windows operating systems include the Time Service tool (W32Time service). Kerberos authentication will work if the time interval between the relevant computers is within the maximum enabled time parameters. The default is five minutes
answer
. What is the default maximum allowable time lapse between domain controllers and client systems for Kerberos to work correctly? a. 1 minute b. 5 minutes c. 15 minutes d. 45 minutes
question
d. service class, host name, and port number The SPN consists of three components: the service class, such as HTTP (which includes both the HTTP and HTTPS protocols) or SQLService, the host name, and the port (if port 80 is not used).
answer
Which three components make up a service principal name (SPN)? a. service name, IP address, and port number b. service name, URL, and host name c. service name, host name, and IP address d. service class, host name, and port number
question
b. The client receives an access denied error. If a client submits a service ticket request for an SPN that does not exist in the identity store, no service ticket can be established and the client throws an access denied error.
answer
What happens if a client submits a service ticket request for an SPN that does not exist in the identity store? a. An event is written to the Kerberos server's event log. b. The client receives an access denied error. c. The Kerberos server receives an access denied error. d. The Kerberos ticket for that service is destroyed.
question
d. ADSI Edit
answer
Which tool can you use to add SPNs to an account? a. Notepad b. LDAP c. Microsoft Word d. ADSI Edit
question
a. Domain Administrator privileges d. the editor runs from the domain controller To configure an SPN for a service or application pool account, you must have domain administrative permissions or a delegation to modify the ServicePrincipalName property. You also must run ADSI Edit from a domain controller
answer
What are the two restrictions for adding SPNs to an account? a. Domain Administrator privileges b. full control permissions for the folder c. local administrator privileges d. the editor runs from the domain controller
question
c. setspn You can use setspn.exe to add SPNs to an account.
answer
Identify another utility that you can use to add SPNs to an account. a. dnscmd b. spnedit c. setspn d. netsh
question
c. service A service account is an account under which an operating system, process, or service runs.
answer
What type of account is an account under which an operating system, process, or service runs? a. user b. system c. service d. network
question
a. using strong passwords c. granting the least rights To reduce the risk of using service accounts, you should use a strong password for the service account and make sure that the password changes often. Also, give the account the least amount of access (user rights, NTFS permissions, and share permissions) that it needs to perform its necessary tasks.
answer
When creating accounts for operating systems, processes, and services, you should always configure them with what two things in mind? a. using strong passwords b. using cryptic user names c. granting the least rights possible d. using built-in accounts
question
b. automatic password management c. simplified SPN management To simplify administration, MSAs provide automatic password management and simplified SPN management.
answer
Name two benefits to using Managed Service Accounts (MSAs). a. Microsoft technology b. automatic password management c. simplified SPN management d. simplified account troubleshooting
question
c. group MSAs The Windows PowerShell cmdlets default to managing the group Managed Service Accounts rather than the original standalone MSAs.
answer
By default, which service accounts will the Windows PowerShell cmdlets manage? a. standalone MSAs b. standard local service accounts c. group MSAs d. domain user accounts designated as service accounts
question
c. NT Serviceservicename A virtual account is an account that emulates a Network Service account that has the name NT Serviceservicename. The virtual account has simplified service administration, including automatic password management, and simplified SPN management
answer
Which of the following is the format for a virtual account used with Windows Server 2008 R2, Windows Server 2012, and Windows Server 2012 R2? a. domainnameservicename b.computernameservicenme c. NT Serviceservicename d. NT Serviceservicename$
question
Complicated Although Kerberos is more secure than NTLM, it is also more complicated than NTLM, which requires additional configuration, such as requiring a service principal name (SPN) for the domain account.
answer
Kerberos is more secure than NTLM but it is also more __________________.
question
The Time Service. Systems need to be time synchronized within a certain amount of lapse. For all of this to work and to ensure security, the domain controllers and clients must have the same time. Windows operating systems include the Time Service tool (W32Time service). Kerberos authentication will work if the time interval between the relevant computers is within the maximum enabled time parameters.
answer
For Kerberos to work properly, which service needs to be accurate and generally synchronized between systems?
question
Current ticket, double hop authentication. When the client connects to a server or service, Kerberos uses the current client ticket proving that the client is authenticated. As a result, the service does not have to perform authentication to a domain controller. Kerberos also can perform a double-hop authentication. Both of these Kerberos benefits improve authentication performance.
answer
Name the two ways that Kerberos authentication improves overall authentication performance.
question
Kerberos forwards the authentication ticket from one service to another to prove
answer
What is meant by the term double-hop authentication?
question
To secure the double-hop authentication, you can configure Kerberos constrained delegation. Constrained delegation restricts which services are allowed to delegate user credentials by specifying—for each application pool or service—the services to which a Kerberos ticket can be forwarded.
answer
How do you make double-hop authentication more secure?
question
d. service principal name
answer
What is the name by which a client uniquely identifies an instance of a service? a. service instance name b. service account name c. service provider name d. service principal name
question
c. a key distribution services root key Before you can create an MSA object type, you need to create a key distribution services root key for the domain.
answer
Before you can create an MSA object type, you must create what? a. a key services MSA group b. a key services MSA distributed domain account c. a key distribution services root key d. a key distribution services Master MSA
question
b. log on as a service On the Log On tab, confirm that the name appears with a dollar sign ($). The account will be given the Log On As Service right
answer
What service right does an MSA account automatically receive upon creation? a. log on interactively b. log on as a service c. domain administrator d. domain power user
question
d. maximum tolerance for computer clock synchronization The setting for maximum tolerance for computer clock synchronization defines the maximum time skew that can be tolerated between a ticket's timestamp and the current time at the KDC. Kerberos uses a timestamp to protect against replay attacks. The default setting is 5 minutes.
answer
Which Kerberos setting defines the maximum time skew that can be tolerated between a ticket's timestamp and the current time at the KDC? a. maximum lifetime for service ticket b. maximum lifetime for user ticket c. maximum lifetime for user ticket renewal d. maximum tolerance for computer clock synchronization
question
b. maximum lifetime for user ticket The setting for maximum lifetime for user ticket defines the maximum lifetime ticket for a Kerberos TGT ticket (user ticket). The default lifetime is 10 hours.
answer
Which Kerberos setting defines the maximum lifetime ticket for a Kerberos TGT ticket? a. maximum lifetime for service ticket b. maximum lifetime for user ticket c. maximum lifetime for user ticket renewal d. maximum tolerance for computer clock synchronization
question
a. maximum lifetime for service ticket The setting for maximum lifetime for service ticket defines the maximum lifetime of a service ticket (Kerberos ticket). The default lifetime is 10 hours.
answer
Which Kerberos setting defines the maximum lifetime of a Kerberos ticket? a. maximum lifetime for service ticket b. maximum lifetime for user ticket c. maximum lifetime for user ticket renewal d. maximum tolerance for computer clock synchronization
question
c. maximum lifetime for user ticket renewal
answer
Which Kerberos setting defines how long a service or user ticket can be renewed? a. maximum lifetime for service ticket b. maximum lifetime for user ticket c. maximum lifetime for user ticket renewal d. maximum tolerance for computer clock synchronization