term1 Definition1term2 Definition2term3 Definition3
Please sign in to your Google account to access your documents:
To define a domain-wide account policy you do the following:1 - Nav to ______(a)______ management console, click Forest -> ______(b)______ -> __(b)__name, then click Group Policy Objects2. Right-click default domain policy -> Edit. This opens a GP mgmt editor for this policy.3. Expand computer config -> p____(a)____ node -> w___(b)____ settings folder -> security settings node -> a___(c)____ policies -> password policy.
1. a. GPMC or group policy management consoleb. Domain3. a. policiesb. windowsc. account
Local policies are local to a computer. When they are part of a GPO in AD, they affect the ________ security settings of computer accounts to which the GPO is applied.Pg 162
local
To track what a user does on his computer you would define __________ policies in a GPO applied to that PC.
localPg 162
In auditing, tracking successful events allows you to find out how often resources are ____a_____. Tracking failed events can help determine when security breaches should be resolved. Auditing is turned ___b___ by default, so you must decide what will get audited. If an event is an AD event such as a user logon, it gets written to ____c____. On the other hand, local computer events such as accessing files gets written to the local computer's logs.Pg 164
Auditing best practices include:1. Only audit what is ____a_____ and no more. Auditing consumes system resources and too much can bog it down.2. Be specific in what you audit. If you need to monitor only writes to a folder, do not select __b__ Control.3. A__(c)___ security logs. They provide a history of security breaches and, if the intruder has administrative access, s/he can delete the logs.4. Plan carefully what size you will allocate for your log files based on the ____d____ of events that you anticipate logging.Pg 164
R____(a)____ Groups can be used to set exactly who is a member of security-sensitive groups, such as the administrators group. Once this is set, if administrators are added to the group outside this setting (e.g., in AD Users & Computers), they will be removed during the next cycle and replaced with only those specified in the r___(a)___ group.You can also use r___(a)___ groups to inject domain users into local group membership lists. Pg 168
a - Restricted
T_____(a)____ing refers to an administrative template setting that continues to apply until it is reversed using a policy that overwrites the setting. Put another way, it is a group policy setting that is not removed when it reverts to "Not Configured"
a - Tatooing, pg 173
Need help typing ? See our FAQ (opens in new window)
Please sign in to create this set. We'll bring you back here when you are done.
Discard Changes Sign in
Please sign in to add to folders.
Sign in
Don't have an account? Sign Up »
You have created 2 folders. Please upgrade to Cram Premium to create hundreds of folders!