A.A
B.B
C.C
D.D
第1题:
A.A
B.B
C.C
D.D
第2题:
You are the administrator of 10 Windows XP Professional computers for your company. The computers are members of a Windows 2000 domain. Because the computers are used in a public area in the cafeteria, you audit all security events on the computers. A user named Marc reports that he was using one of the Windows XP Professional computers when the computer suddenly shut down with a STOP error. When the computer restarted, Marc attempted to log on by using the same user name and password that he used before. Marc received the following error message: "Your account is configured to prevent you from using this computer. Please try another computer." Marc states that he did not do anything to cause the STOP error to occur. You want to ensure that Marc can use this computer. What should you do?()
第3题:
You need to design an audit strategy for Southbridge Video. Your solution must meet business requirements.What should you do?()
第4题:
Your company has an Active Directory domain. A user attempts to log on to the domain from a client computer and receives the following message: "This user account has expired Ask your administrator to reactivate the account." You need to ensure that the user is able to log on to the domain. What should you do()
第5题:
You have a computer that runs Windows 7. Multiple users log on to your computer. You enable auditing ona folder stored on your computer. You need to ensure that each access to the folder is logged. What should you do?()
第6题:
You are the network administrator for your company. The network consists of a single Active Directory domain named . All domain controllers run Windows Server 2003, and all client computers run Windows XP Professional. All client computer accounts are stored in the Computer container. A user named Peter reports that he cannot log on to the domain from his computer. Peter receives the logon message shown in the exhibit. Exhibit: Logon Message Your account is configured to prevent you from using this computer. Please try another computer. You need to enable Peter to log on. What should you do?()
第7题:
You are the administrator of a SQL Server 2005 computer named SQL1. SQL1 is a member of a Microsoft Active Directory domain. You do not have any rights or privileges to perform domain administration. However, you have been granted membership in the local Administrators group on SQL1. You perform most of the management of SQL1 from your administrative workstation. However, for security reasons, you want to track all attempts for interactive logons and network connections to SQL1. What should you do?()
第8题:
Enable the Require domain controller to unlock policy.
Set the Number of previous logons to cache policy to 0.
Remove all user and group accounts from the Log on locally user right.
Remove all user and group accounts from the Access this computer from the network user right.
第9题:
In the Default Domain Controller Policy, enable success and failure for the Audit logon events policy setting.
In the Default Domain Controller Policy, enable success and failure for the Audit account logon events policy setting.
In the Local Security Policy on Server1, enable success and failure for the Audit logon events policy.
In the Local Security Policy on Server1, enable success and failure for the Audit account logon events policy setting.
第10题:
Examine the System Event Log on the user’s computer.
Examine the System Event Log on both domain controllers.
Examine the Security Event Log on both domain controllers.
Examine the Application Event Log on the user’s computer.
第11题:
From the Security Templates snap-in, open the hisecdc template. Modify the Retain System Log setting.
From the Security Templates snap-in, open the securedc template. Modify the Retain Security Log setting.
Open the Default Domain Policy. Modify the Retain System Log setting.
Open the Default Domain Controller Policy. Modify the Retain Security Log setting.
第12题:
Your company has an Active Directory directory service domain. All servers run Windows Server 2003. All domain controllers are configured to audit specific events. You are developing a security monitoring plan for the domain controllers. You must back up the following information. Local logon attemptsDomain logon attemptsSecurity update installation attempts You need to specify the appropriate log files to back up. Which files should you specify? ()
第13题:
You discover audit log entries that report attempts to log on to your computer. You need to be notified of all logon attempts that occur on your computer. What should you do?()
第14题:
You need to design a method to log changes that are made to servers and domain controllers. You also need to track when administrators modify local security account manager objects on servers. What should you do?()
第15题:
Your network consists of a single Active Directory domain that contains two domain controllers. Both domain controllers run Windows Server 2003 Service Pack 2 (SP2). Auditing of successful account logon events is enabled on all computers in the domain. You need to identify the last time a specific user logged on to the domain. What should you do? ()
第16题:
You need to identify all failed logon attempts on the domain controllers. What should you do()
第17题:
A Windows Communication Foundation (WCF) service is required to log all authorization attempts to the Windows Event Log. You need to configure a behavior and apply it to the service to support this requirement. Which behavior should you configure and apply?()
第18题:
Your network consists of a single Active Directory domain. You have a member server named Server1 that runs Windows Server 2003 Service Pack 2 (SP2).You need to record all attempts by domain users and local users to log on to Server1. What should you do?()
第19题:
Run the netdom TRUST /reset command.
Run the netsh command with the set and machine options.
Run the Active Directory Users and Computers console to disable, and then enable the computer account.
Reset the computer account. Disjoin the computer from the domain, and then rejoin the computer to the domain.
第20题:
AppEvent.Evt and NTDS.Evt
NTDS.Evt and SecEvent.Evt
SecEvent.Evt and SysEvent.Evt
AppEvent.Evt and SysEvent.Evt
第21题:
Configure a directory service access audit policy. Increase the maximum size of the security log.
Configure a directory service access audit policy. Set the system log to overwrite events older than 7 days.
Configure an object access audit policy for the directory. Increase the maximum size of the system log.
Configure an object access audit policy for the directory. Set the security log to overwrite events older than 7 days.
第22题:
Configure the system event log to Do not overwrite.
In IAS, in Remote Access Logging, enable the Authentication requests setting.
Configure the Remote Access server to Log all events.
Create a custom remote access policy and configure it for Authentication-Type.