Form-based logins should NOT be used with HTTPS.
When using Basic Authentication the target server is NOT authenticated.
J2EE compliant web containers are NOT required to support the HTTPS protocol.
Web containers are required to support unauthenticated access to unprotected web resources.
第1题:
Which two statements about using the CHAP authentication mechanism in a PPP link are true?()
第2题:
Which activity supports the data integrity requirements of an application?()
第3题:
Which two statements regarding external authentication servers for firewall userauthentication are true?()
第4题:
Your company has a server that runs Windows Server 2008. The server has the Web Server (IIS) role installed. You need to activate SSL for the default Web site. Which two actions should you perform?()
第5题:
You need to ensure that the company’s standard password policy is enforced for all logins that areused to access SQL Server 2005.Which two actions should you perform?()
第6题:
Form-based logins should NOT be used with HTTPS.
When using Basic Authentication the target server is NOT authenticated.
J2EE compliant web containers are NOT required to support the HTTPS protocol.
Web containers are required to support unauthenticated access to unprotected web resources.
第7题:
Configure the Web site to the Require SSL setting.
Configure the /orders/ virtual directory to the Require SSL setting.
Configure the Digest Authentication setting to Enabled for the /orders/ virtual directory.
Configure the Basic Authentication setting to Enabled and the Anonymous Authentication setting to Disabled for the Web site.
Configure the Basic Authentication setting to Enabled and the Anonymous Authentication setting to Disabled for the /orders/ virtual directory.
第8题:
Up to three external authentication server types can be used simultaneously.
Only one external authentication server type can be used simultaneously.
If the local password database is not configured in the authentication order, and the configured authentication server is unreachable, authentication is not performed.
If the local password database is not configured in the authentication order, and the configured authentication server rejects the authentication request, authentication is not performed
第9题:
Enable SSL on the external Web site by using a Microsoft cryptographic service provider (CSP)
Enable Microsoft .NET Passport authentication on the external Web site. Use Passport Level 0 with SSL on the external Web site
Enable SSL on the external Web site by using a commercial digital certificate
Enable SSL on the intranet Web site by using an internal server certificate
Enable SSL on the external Web site by using an internal server certificate
第10题:
Shared key authentication is considered more secure than open authentication.
Shared key authentication is considered less secure than open authentication.
If the WEP keys do not match using the open authentication method, the client will not authenticate, associate, and transfer data.
If the WEP keys do not match using the open authentication method, the client will still be able to authenticate and associate, but will not transfer data.
If the WEP keys do not match using the open authentication method, the client will still be able to authenticate, associate, and transfer data.
第11题:
CHAP uses a two-way handshake
CHAP authentication periodically occurs after link establishment
CHAP has no protection from playback attacks
CHAP authentication is performed only upon link establishment
CHAP uses a three-way handshake
CHAP authentication passwords are sent in plaintext
第12题:
HTTP Basic Authentication
Form Based Authentication
HTTP Digest Authentication
HTTPS Client Authentication
第13题:
Which two authentication mechanisms provide weaker protection than other mechanisms?()
第14题:
Which basic authentication type is optional for a J2EE 1.4 compliant web container?()
第15题:
Which two statements regarding external authentication servers for firewall user authentication are true?() (Choose two.)
第16题:
You are an IIS Web server administrator implementing authentication settings for a new Web site.According to the requirements for the Human Resources Web site, users should be prompted forauthentication information when they attempt to access the site. The site will be accessed only by userswho have accounts in your organization’s Active Directory domain. You have already configured the filesystem permissions for the content based on the appropriate settings. You also want to maximize securityof the site. Which two actions should you take to meet these requirements?()
第17题:
You manage a server that runs Windows Server 2008. The server has the Web Server (IIS) role installed. The server hosts an Internet-accessible Web site that has a virtual directory named /orders/. A Web server certificate is installed and an SSL listener has been configured for the Web site. The /orders/ virtual directory must meet the following company policy requirements: Be accessible to authenticated users only. Allow authentication types to support all browsers. Encrypt all authentication traffic by using HTTPS. All other directories of the Web site must be accessible to anonymous users and be available withoutSSL. You need to configure the /orders/ virtual directory to meet the company policy requirements. Which two actions should you perform?()
第18题:
Obtain and import a server certificate by using the IIS Manager console.
Select the Generate Key option in the Machine Key dialog box for the default Web site.
Add bindings for the HTTPS protocol to the default Web site by using the IIS Manager console.
Install the Digest Authentication component for the Web server role by using the Server Manager console.
第19题:
If none of the authentication servers that are configured for the current authentication mode responds to an authentication request, the DCNM-LAN server falls back to localauthentication.
DCNM-LAN only supports TACACS+.
Each DCNM-LAN server will have the same device credentials.
Administering DCNM-LAN authentication settings requires an authentication license.
DCNM-LAN server users are local to the DCNM-LAN server.
第20题:
shared key authentication is considered more secure than open authentication
shared key authentication is considered less secure than open authentication
if the WEP keys do not match using the open authentication method, the client will not authenticate, associate, and transfer data
if the WEP keys do not match using the open authentication method, the client will still be able to authenticate and associate, but will not transfer data
if the WEP keys do not match using the open authentication method, the client will still be able to authenticate, associate, and transfer data
第21题:
Up to three external authentication server types can be used simultaneously.
Only one external authentication server type can be used simultaneously.
If the local password database is not configured in the authentication order, and the configured authentication server bypassed.
If the local password database is not configured in the authentication order, and the configured authentication server authentication is rejected.
第22题:
Set the appropriate local password policies for all computers on which SQL Server is installed.
Set the server authentication mode of all SQL Server instances to Windows Authentication mode.
Install all instances of SQL Server 2005 on computers that run Windows Server 2003 or later.
Create SQL Server logins that have CHECK_POLICY enabled.
第23题:
HTTP Basic Authentication
Form Based Authentication
HTTP Digest Authentication
HTTPS Client Authentication
第24题:
Enable Windows authentication.
Enable basic authentication.
Disable anonymous authentication.
Enable anonymous authentication.