MCTS 70-642 Network Access Protection (NAP) & Network Policy Server 1 — Questions and Answers
Question 1: What is the primary purpose of Network Access Protection (NAP) in Windows Server 2008?
- To encrypt all network traffic between clients and servers
- To enforce health policies and restrict network access for non-compliant computers (Correct answer)
- To provide firewall protection at the network perimeter
- To authenticate users before they can log on to the domain
Correct answer: To enforce health policies and restrict network access for non-compliant computers
NAP enforces health policies by checking client health state and restricting or granting network access based on compliance with those policies.
Question 2: Which Windows Server 2008 server role must be installed to act as a NAP policy server?
- Active Directory Domain Services
- Network Policy and Access Services (NPAS) (Correct answer)
- Windows Deployment Services
- Active Directory Certificate Services
Correct answer: Network Policy and Access Services (NPAS)
The Network Policy and Access Services (NPAS) role includes Network Policy Server (NPS), which serves as the NAP health policy server.
Question 3: Which NAP component on the client computer collects and reports the client's health status to the server?
- System Health Validator (SHV)
- NAP Agent (Correct answer)
- NAP Enforcement Client (EC)
- Health Registration Authority (HRA)
Correct answer: NAP Agent
The NAP Agent service runs on the client and aggregates health data from System Health Agents (SHAs) to report health status to the NAP infrastructure.
Question 4: What is a System Health Validator (SHV) in a NAP deployment?
- A client-side component that generates health certificates
- A server-side component that evaluates the health reports submitted by clients (Correct answer)
- A network switch that enforces 802.1X policies
- A Group Policy object that configures NAP settings on clients
Correct answer: A server-side component that evaluates the health reports submitted by clients
An SHV runs on the NPS server and verifies the health state reported by the corresponding System Health Agent (SHA) on the client.
Question 5: Which NAP enforcement method uses IEEE 802.1X to restrict network access for non-compliant clients?
- DHCP enforcement
- VPN enforcement
- 802.1X enforcement (Correct answer)
- IPsec enforcement
Correct answer: 802.1X enforcement
802.1X NAP enforcement uses 802.1X-capable switches or wireless access points to restrict non-compliant clients to a restricted VLAN until they meet health requirements.
Question 6: In a NAP deployment, what is the purpose of a Remediation Server?
- To issue health certificates to compliant clients
- To provide resources that help non-compliant clients become compliant (Correct answer)
- To log all NAP enforcement events to a central database
- To act as the RADIUS proxy for remote access requests
Correct answer: To provide resources that help non-compliant clients become compliant
Remediation servers host software updates, patches, and configuration tools that quarantined non-compliant clients can access to achieve compliance.
Question 7: Which NAP enforcement method provides the strongest isolation because it uses cryptographic health certificates?
- DHCP enforcement
- VPN enforcement
- 802.1X enforcement
- IPsec enforcement (Correct answer)
Correct answer: IPsec enforcement
IPsec NAP enforcement uses health certificates issued by a Health Registration Authority (HRA) to cryptographically enforce communication between only compliant computers.
What is the primary purpose of Network Access Protection (NAP) in Windows Server 2008?