MSCE Security Protocols & Compliance Standards Flashcards
7 cards from real MCSE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 MSCE Security Protocols & Compliance Standards flashcards as text
An organization must ensure data transmitted between branch offices is encrypted and authenticated. Which protocol provides both confidentiality and data integrity for site-to-site VPN tunnels?
Answer: IPsec with ESP in tunnel mode
IPsec with ESP (Encapsulating Security Payload) in tunnel mode encrypts and authenticates the entire IP packet, making it ideal for site-to-site VPNs.
A company's compliance team requires audit logs to be tamper-evident and retained for seven years. Which Windows Server feature best satisfies this requirement?
Answer: Azure Monitor with Log Analytics workspace retention policy
Azure Monitor with Log Analytics supports configurable retention up to seven years and provides immutable log storage that satisfies tamper-evident requirements.
Which EAP method uses certificates on both the server and client, providing mutual authentication without needing a password?
Answer: EAP-TLS
EAP-TLS requires X.509 certificates on both the authenticating server and the client, achieving strong mutual authentication without passwords.
Under PCI DSS, which control requires that cardholder data environments use multi-factor authentication for all non-console administrative access?
Answer: Requirement 8
PCI DSS Requirement 8 governs identification and authentication of access to system components, including the mandate for MFA for non-console admin access.
A security architect needs to prevent internal hosts from initiating connections to known malicious IP addresses. Which Windows Server feature applies this control at the network layer without a third-party firewall?
Answer: Windows Defender Firewall outbound rules
Windows Defender Firewall outbound rules can block traffic to specific IP ranges, preventing hosts from reaching known malicious destinations.
Which FIPS 140-2 validation level requires that cryptographic modules show evidence of tamper by using tamper-evident coatings or seals on physical hardware?
Answer: Level 2
FIPS 140-2 Level 2 adds requirements for tamper-evident physical security mechanisms such as coatings or seals on the cryptographic module.
An administrator configures a Group Policy to enforce TLS 1.2 as the minimum protocol version on all Windows servers. Which registry path controls the Schannel TLS protocol settings?
Answer: HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols
The Schannel provider's protocol enable/disable settings are stored under HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols.