click below
click below
Normal Size Small Size show me how
70-299
Managing a Microsoft Windows Server 2003 environment, enhanced
| Question | Answer |
|---|---|
| At what level should password policies be implemented to be effective for domain accounts? | At the domain level, |
| If a new security template named pwsec.inf is configured with the appropriate password policy for domin accounts how should it be deployed? | Import the pwsec.inf security template into the Default Domain Group Policy object (GPO). d |
| What is the lockout threshold? | The number of invalid attempts allowed before an account is locked out. |
| What is the lockout duration? | The lenght of time an account is locked out after exceeding the account lockout threshold. |
| What is the reset account locout counter after? | The length of time before the count towards the account lockout threshold is reset to zero. |
| How should the account locout duration be configured to force administrator intervention when an account needs to be re-enabled? | Set the value to zero. |
| How should the account lockout thereshold be configured to minimize the number of calls to the helpdesk regarding locked accounts? | Increase the account lockout threshold to a value that will prevent brute force attacks but allow the user a reasonable number of logon attempts (i.e. 10). |
| In a multi-site enterprise environment user passwords that are reset by administrative staff should be done on a ____ ____ in the same site the user is working in. | domain controller. |
| When accounts are manually locked out by a member of administrative staff, the lockout should be done on a ____ ____ in the same site the user is working in. | domain controller. |
| When the administrator account is disabled through a GPO an administrative user can still logon to the systems through ___ ___ using the administrator account. | Safe Mode |