โ† All MCSE Flashcard Decks

MSCE Security Protocols & Compliance Standards Flashcards

7 cards from real MCSE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 MSCE Security Protocols & Compliance Standards flashcards as text
  1. An organization must ensure data transmitted between branch offices is encrypted and authenticated. Which protocol provides both confidentiality and data integrity for site-to-site VPN tunnels?

    Answer: IPsec with ESP in tunnel mode

    IPsec with ESP (Encapsulating Security Payload) in tunnel mode encrypts and authenticates the entire IP packet, making it ideal for site-to-site VPNs.

  2. A company's compliance team requires audit logs to be tamper-evident and retained for seven years. Which Windows Server feature best satisfies this requirement?

    Answer: Azure Monitor with Log Analytics workspace retention policy

    Azure Monitor with Log Analytics supports configurable retention up to seven years and provides immutable log storage that satisfies tamper-evident requirements.

  3. Which EAP method uses certificates on both the server and client, providing mutual authentication without needing a password?

    Answer: EAP-TLS

    EAP-TLS requires X.509 certificates on both the authenticating server and the client, achieving strong mutual authentication without passwords.

  4. Under PCI DSS, which control requires that cardholder data environments use multi-factor authentication for all non-console administrative access?

    Answer: Requirement 8

    PCI DSS Requirement 8 governs identification and authentication of access to system components, including the mandate for MFA for non-console admin access.

  5. A security architect needs to prevent internal hosts from initiating connections to known malicious IP addresses. Which Windows Server feature applies this control at the network layer without a third-party firewall?

    Answer: Windows Defender Firewall outbound rules

    Windows Defender Firewall outbound rules can block traffic to specific IP ranges, preventing hosts from reaching known malicious destinations.

  6. Which FIPS 140-2 validation level requires that cryptographic modules show evidence of tamper by using tamper-evident coatings or seals on physical hardware?

    Answer: Level 2

    FIPS 140-2 Level 2 adds requirements for tamper-evident physical security mechanisms such as coatings or seals on the cryptographic module.

  7. An administrator configures a Group Policy to enforce TLS 1.2 as the minimum protocol version on all Windows servers. Which registry path controls the Schannel TLS protocol settings?

    Answer: HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols

    The Schannel provider's protocol enable/disable settings are stored under HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols.