← All MCSE Flashcard Decks

70-299: Implementing Network Security Flashcards

6 cards from real MCSE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 70-299: Implementing Network Security flashcards as text
  1. Which Windows Server 2003 service must be running for IPSec policy to be applied to network traffic?

    Answer: IPSec Policy Agent (IPSECPOL)

    The IPSec Policy Agent service (also called IPSECPOL or PolicyAgent) retrieves and enforces IPSec policies on the local computer.

  2. What is the difference between an IPSec transport mode and tunnel mode?

    Answer: Transport mode encrypts only the payload; tunnel mode encapsulates the entire IP packet

    IPSec transport mode encrypts and authenticates the payload only, while tunnel mode encapsulates the entire original IP packet inside a new IP header — used for VPNs.

  3. Which Group Policy setting prevents users from installing device drivers without administrator approval?

    Answer: Prevent installation of devices not described by other policy settings

    This policy blocks unapproved hardware installations, reducing the risk of malicious or unauthorized devices being added to corporate computers.

  4. What type of attack does account lockout policy specifically help mitigate?

    Answer: Brute-force password guessing

    Account lockout policy limits the number of failed logon attempts before locking the account, making automated brute-force password guessing attacks ineffective.

  5. Which Windows Server 2003 feature allows administrators to restrict which software can run on a computer?

    Answer: Software Restriction Policies

    Software Restriction Policies use rules based on certificate, hash, path, or zone to control which applications are allowed or denied from running.

  6. What is the recommended action when a certificate is compromised before its expiration date?

    Answer: Revoke the certificate and publish an updated CRL immediately

    Compromised certificates must be immediately revoked and a new CRL published so relying parties can check and reject the compromised certificate.