Name: 
 

Chapter 6 Study Guide, Advanced Windows - 2000-Pro, Richard Goldman



True/False
Indicate whether the sentence or statement is true or false.
 

1. 

A complex string of bits represents the access token, which is attached to every process that the user initializes until that user logs off.
 

2. 

Whenever an object is requested, the ACL and the access token are carefully compared, and a request for the object is granted only when a match is found.
 

3. 

Windows 2000 Professional, as a standalone desktop system, uses the Active Directory.
 

4. 

Windows 2000 Professional participates in the Active Directory when it is used as a client in a Windows 2000 domain network.
 

5. 

Both domain and local security use logon authentication, objects, and access control to gain access to Windows 2000 resources.
 

6. 

Access to the system is allowed only after the user receives the access token.
 

7. 

Every activity within the user mode and kernel mode is performed by a process.
 

8. 

Each object hosts its own access control list, which defines which users and groups have access permissions and exactly what type of access they are granted.
 

9. 

Access or permission to use an object is determined on the basis of the entire object and also for each of the services defined for that object.
 

10. 

Windows 2000 is able not only to control access at the object level, but also to control which services defined for the object's type a particular security token is allowed to perform or request.
 

11. 

An individual object is identified by its type, which defines its permitted range of contents and the kinds of operations that may be performed on it.
 

12. 

Everything within the Windows 2000 environment is an object.
 

13. 

By default, the logon window does not display the name of the last user to log on.
 

14. 

The default shell is Windows Explorer.
 

15. 

You can not change the shell to a custom or third-party application.
 

16. 

By default, the Windows 2000 Professional logon window includes an enabled Shutdown button.
 

17. 

Automated logon creates a situation in which the computer automatically makes itself available to users without requiring an account name or a password.
 

18. 

The Kerberos authentication system was designed to allow two parties to exchange private information across an open network.
 

19. 

The Kerberos process is completely invisible to the user.
 

20. 

The contents of the local computer policy are determined during installation and based on system configuration, existing devices, and selected options and components.
 

21. 

The effective local computer policy is the result of the combination of all group policies applicable to the system.
 

22. 

You can manage domain policies from a Windows 2000 Professional machine.
 

23. 

Software Settings is empty by default.
 

24. 

The Administrative Templates folder contains a multilevel collection of computer-related controls.
 

25. 

Every object in the Windows 2000 system has audit events related to it.
 

26. 

Auditing can provide valuable information about security breaches, resource activity, and user adeptness.
 

27. 

To view the items related to auditing, select the Access Log node.
 

28. 

Microsoft has extended the native NTFS file system to include encrypted storage.
 

29. 

When EFS is enabled on a file, folder, or drive, only the enabling user can gain access to the encrypted object.
 

Multiple Choice
Identify the letter of the choice that best completes the statement or answers the question.
 

30. 

An object's ____ are its named characteristics, such as "filename", read-only, hidden, file size, and date created for an object whose type is file.
a.
type
b.
services
c.
attributes
d.
class
 

31. 

An object's ____ may be file, directory, printer, or network share.
a.
type
b.
services
c.
attributes
d.
class
 

32. 

In Windows 2000, access to individual resources is controlled at the ____ level.
a.
object
b.
user
c.
system
d.
class
 

33. 

An object's ____ define how the object can be manipulated.
a.
type
b.
services
c.
attributes
d.
class
 

34. 

A(n) ____ is a collection of computers with centrally managed security and activities.
a.
arena
b.
group
c.
domain
d.
class
 

35. 

A(n) ____ offers increased security, centralized control, and broader access to resources than any other computer system configuration.
a.
arena
b.
group
c.
domain
d.
class
 

36. 

Security ____ are domain-wide controls that specify password requirements, account lockout settings, auditing, user rights, and security options.
a.
settings
b.
policies
c.
keys
d.
classes
 

37. 

Domain ____ is the control of user accounts, group memberships, and resource access for all members of a network instead of for only a single computer.
a.
settings
b.
policies
c.
keys
d.
security
 

38. 

All of the information about user accounts, group memberships, group policies, and access controls for resources is contained in the ____.
a.
Active Directory
b.
Domain Directory
c.
Active Domain
d.
Securities Database
 

39. 

____ occurs when you press the attention sequence, then enter your username and password.
a.
Interactive logon
b.
Active logon
c.
Network authentication
d.
Network login
 

40. 

A(n) ____ occurs when you attempt to connect to or access resources from some other member of the domain network.
a.
interactive logon
b.
active logon
c.
network authentication
d.
network login
 

41. 

Windows 2000 uses ____ as the primary protocol for authentication security.
a.
Secure Sockets Layer/Transport Layer Security
b.
Kerberos v5
c.
NTLM
d.
Kerberos v6
 

42. 

____ is an authentication scheme often used by web-based applications and supported in Windows 2000 via IIS.
a.
Secure Sockets Layer/Transport Layer Security
b.
Kerberos v5
c.
NTLM
d.
Kerberos v6
 

43. 

SSL functions by issuing an identity ____ to both the client and server.
a.
ticket
b.
token
c.
certificate
d.
key
 

44. 

The .adm files used by the Group Policy editor reside in the ____ subfolder of the main Windows 2000 directory.
a.
\Sub
b.
\Pol
c.
\Inf
d.
\Grp
 

45. 

____ is the authentication mechanism used by Windows NT 4.0.
a.
Secure Sockets Layer/Transport Layer Security
b.
Kerberos v5
c.
NTLM
d.
Kerberos v6
 

46. 

Custom policies can be created through the use of ____ files, such as those used by the Windows NT 4.0 System Policy Editor.
a.
.ini
b.
.adm
c.
.sys
d.
.com
 

47. 

The ____ IPSec policy is for systems that do not require secure communications at all times.
a.
workstation
b.
client
c.
primary
d.
server
 

48. 

The ____ IPSec policy is for systems that need to use secure communications most of the time.
a.
workstation
b.
client
c.
primary
d.
server
 

49. 

Once enabled, audited events are recorded in the ____ Log of the Event Viewer.
a.
Security
b.
Audit
c.
System
d.
Processes
 



 
Check Your Work     Reset Help