tailieunhanh - actualtests microsoft 070 290 exam managing and maintaining ms win 2003 phần 5

Bản cập nhật phải được sự chấp thuận trước khi nó có thể được cài đặt. Câu hỏi 14 Bạn là quản trị mạng cho . Mạng lưới bao gồm một miền Active Directory. Tất cả các máy chủ mạng chạy Windows Server 2003, và tất cả các máy tính khách hàng chạy Windows XP | 070-290 security states that all confidential data must be stored and transmitted in a secure manner. To comply with the security policy you enable Encrypting File System EFS on the confidential files. You also add EFS certificates to the data decryption field DDF of the confidential files for the users who need to access them. While performing network monitoring you notice that the confidential files that are stored on Certkiller1 are being transmitted over the network without encryption. You must ensure that encryption is always used when the confidential files on Certkiller1 are stored and transmitted over the network. What are two possible ways to accomplish this goal Each correct answer presents a complete solution. Choose two A. Enable offline files for the confidential files that are stored on Certkiller1 and select the Encrypt offline files to secure data check box on the client computers of the users who need to access the files. B. Use IPSec encryption between Certkiller1 and the client computers of the users who need to access the confidential files. C. Use Server Message Block SMB signing between Certkiller1 and the client computers of the users who need to access the confidential files. D. Disable all LM and NTLM authentication methods on Certkiller1. E. Use IIS to publish the confidential files. Enable SSL on the IIS server. Open the files as a Web folder. Answer B E Explanation We can use IPSEC to encrypt network traffic. We can use SMB to encrypt network traffic. We can use SSL to secure the files Thing about MS THUMB RULE less administrative effort. Thing about MS FAQS some question can have two valid answers. In this case C and E can both be valid answers. We need to think about whether SMB singing is a valid option or not because they do not tell us if they are forcing the set Secure channel in the clients or server Secure channel Digitally encrypt or sign secure channel data always Enabled SMB signing By default domain controllers running .

TỪ KHÓA LIÊN QUAN