Information Technology Reference
In-Depth Information
Correct answer: A
2.
Correct . This is the least privilege that will allow the command to run.
A.
Incorrect . Domain Users isn't an option here; Furthermore, it would provide
substantially more privilege than local service if it were available.
B.
Incorrect . Local System is full access and control. Way more than you need to use
for this question.
C.
Incorrect . Protected Users is not an option and has no special limitations on
privilege that would help even if it were an option.
D.
Correct answer: B
3.
Incorrect. All Monitor templates are soft quotas and will warn but not actually
limit.
A.
Correct. This template has a hard limit of 200 MB, with warnings, but
automatically extends the limit to 250 MB.
B.
Incorrect. You can't create limits on shares; you can create limits only on file
system folders or disks. Also, Monitor templates are soft quotas and will warn but
not actually limit.
C.
I ncorrect. You can't create limits on shares; you can create limits only on file
system folders or disks.
D.
Objective 2.3: thought experiment
Wired network and a TPM. Further, the computers being unlocked must support DHCP
in UEFI.
1.
The WDS role must be enabled on the network on a Windows Server 2012 or Windows
Server 2012 R2 server (you don't need to set up full WDS deployment.) AD DS and a
working DHCP server must be present on the network (for Group Policy). Addition-
ally, only computers running Windows 8 or Windows 8.1, or servers running Windows
Server 2012 or Windows Server 2012 R2 can participate in Network Unlock, and the
private and public keys for Network Unlock must be deployed.
2.
To enable Network Unlock, use the Allow Network Unlock At Startup policy, and add
the public key certificate from the WDS server to the BitLocker Drive Encryption Net-
work Unlock Certificate folder. To require BitLocker encryption of data drives, use the
Deny Write Access To Fixed Drives Not Protected By BitLocker policy; and to require
BitLocker on the operating system drive, use the Require Additional Authentication
At Startup policy for operating system drives. Set it to Allow TPM and Allow BitLocker
Without A Compatible TPM.
3.
Search WWH ::




Custom Search