did-you-know? rent-now

Amazon no longer offers textbook rentals. We do!

did-you-know? rent-now

Amazon no longer offers textbook rentals. We do!

We're the #1 textbook rental company. Let us show you why.

9780789731388

MCSA/MCSE 70-299 Exam Cram 2: Implementing and Administering Security in a Windows 2003 Network

by ; ;
  • ISBN13:

    9780789731388

  • ISBN10:

    078973138X

  • Edition: 1st
  • Format: Paperback w/CD
  • Copyright: 2004-01-01
  • Publisher: Que
  • Purchase Benefits
List Price: $34.99

Summary

The 70-299 exam measures your ability to implement, manage, maintain, and troubleshoot security in a Windows Server 2003 network infrastructure and also plan and configure a Windows Server 2003 PKI. TheMCSE 70-299 Exam Cram 2gives you the essential information you need to know to learn how to implement, manage, and troubleshoot security policies, patch management infrastructure, security for network communications, as well as how to plan, configure and troubleshoot authentication, authorization, and PKI. This book can be used as a sole study guide for those experienced with Windows 2003 security or it is the perfect supplement guide for more comprehensive training materials, instructor-led classes, and/or computer-based training.

Table of Contents

Introductionp. xix
Self-Assessmentp. xxv
Implementing and Managing Security Policiesp. 1
Managing Security Mechanisms in Windows Server 2003p. 2
Planning Security Group Scopep. 2
Planning Nested Group Structurep. 3
Configuring Windows Server 2003 Security Mechanismsp. 5
Planning and Deploying Security Templatesp. 14
Planning the Deployment of Security Templatesp. 15
Deploying Security Templates by Using Active Directory-Based GPOsp. 16
Deploying Security Templates Using Command-Line Tools and Scriptingp. 18
Configuring Extra Security Based on Server Rolesp. 20
SQL Server Computerp. 21
Exchange Server Computerp. 21
Domain Controllerp. 22
Internet Authentication Service (IAS) Serverp. 23
Internet Information Services (IIS) Serverp. 24
Planning Security for the DHCP and DNS Infrastructure Servicesp. 25
Configuring Extra Security Based on Client Rolesp. 26
Planning and Configuring Security Settingsp. 27
Planning Network Zones for Computer Rolesp. 28
Planning and Configuring Software Restriction Policiesp. 29
Planning and Configuring Auditing and Logging Computer Rolesp. 31
Windows Eventsp. 31
Internet Information Services (IIS)p. 31
Firewall Log Filesp. 32
Netlogonp. 32
Remote Access Service (RAS) Log Filesp. 33
Analyzing Security Configurationp. 33
Using Microsoft Baseline Security Analyzer (MBSA)p. 33
Using the MBSA Command-Line Toolp. 33
Using Security Configuration and Analysisp. 34
Exam Prep Questionsp. 36
Implementing, Managing, and Troubleshooting Patch Management Infrastructurep. 41
Planning, Evaluating, and Testing the Deployment of Service Packs and Hotfixesp. 42
Evaluating the Applicability of Service Packs and Hotfixesp. 43
Testing the Compatibility of Service Packs and Hotfixes for Existing Applicationsp. 45
Planning Patch Deployment Environments for Both the Pilot and Production Phasesp. 47
Planning the Batch Deployment of Multiple Hotfixesp. 49
Planning Rollback Strategyp. 50
Using MBSA to Assess the Current Status of Service Packs and Hotfixesp. 51
Deploying Service Packs and Hotfixesp. 58
Troubleshooting Patch Management Infrastructurep. 66
Exam Prep Questionsp. 69
Implementing and Managing Security for Network Communicationsp. 75
Planning an IPSec Deploymentp. 76
Deciding Which IPSec Mode to Usep. 76
Planning Authentication Methods for IPSecp. 78
Security Authentication with IPSecp. 80
Testing the Functionality of Existing Applications and Servicesp. 82
Configuring IPSec Policiesp. 83
Transport Modep. 84
Tunnel Modep. 85
IPSec Policy Rulesp. 87
Deploying and Managing IPSec Policiesp. 90
Deploying IPSec Using Local Policy Objectsp. 91
Deploying IPSec Using Group Policy Objectsp. 92
Deploying IPSec Using Commands and Scriptsp. 92
Deploying IPSec Certificatesp. 93
Exam Prep Questionsp. 95
Planning and Configuring Authentication and Authorization for Remote Access Usersp. 101
Deploying, Managing, and Configuring SSL Certificatesp. 102
Configuration of the Web Server for SSL Certificatesp. 103
Configuration of the Client for SSL Certificatesp. 105
Configuring Security and Authentication for Remote Access Usersp. 106
Password Authentication Protocol (PAP)p. 106
Challenge Handshake Authentication Protocol (CHAP)p. 107
Microsoft Challenge Handshake Authentication Protocol (MS-CHAP)p. 107
MS-CHAPv2p. 108
Extensible Authentication Protocol (EAP)p. 108
Multifactor Authenticationp. 109
Configuring and Troubleshooting Virtual Private Network (VPN) Protocolsp. 110
Internet Service Providers (ISPs)p. 111
Client Operating Systemsp. 111
Network Address Translation (NAT) Devicesp. 112
Routing and Remote Access Serversp. 113
Firewalls (Servers or Devices)p. 113
Managing Client Configuration for Remote Access Securityp. 114
Remote Access Policyp. 114
Connection Manager Administration Kit (CMAK)p. 117
Exam Prep Questionsp. 118
Planning, Configuring, and Troubleshooting PKIp. 123
Public Key Infrastructure (PKI) and Certification Authority (CA) Hierarchiesp. 124
Certification Authority Hierarchies and Rolesp. 125
Installing and Configuring Root, Intermediate, and Issuing CAsp. 126
Managing CAsp. 130
Configuring Certificate Templatesp. 130
Configuring, Managing, and Troubleshooting CRLsp. 134
Configuring Archival and Recovery of Keysp. 136
Deploying and Revoking Certificates to Users, Computers, and CAsp. 138
Backing Up and Restoring the CAp. 142
Backing up and Restoring Certificate Storagep. 143
Troubleshooting Authentication, Authorization, and PKIp. 145
Exam Prep Questionsp. 147
Troubleshooting Security Policies and IPSecp. 153
Troubleshooting Security Policiesp. 154
Troubleshooting Security Policy Inheritancep. 154
Troubleshooting Security Template Problemsp. 159
Troubleshooting Security Templates in a Mixed Operating System Environmentp. 161
Troubleshooting IPSecp. 164
Monitoring IPSec Policies by Using IP Security Monitorp. 164
Configuring IPSec Loggingp. 167
Troubleshooting IPSec Across Networksp. 169
Troubleshooting IPSec Certificatesp. 173
Exam Prep Questionsp. 175
Planning and Implementing Security for Wireless Networksp. 181
Planning the Authentication Methods for a Wireless Networkp. 183
Planning the Encryption Methods for a Wireless Networkp. 185
Wired Equivalent Privacy (WEP)p. 185
802.1xp. 185
Use of IPSec with Wireless Networksp. 186
Planning and Configuring Wireless Access Policiesp. 186
Creating a Wireless Access Policy in Group Policyp. 187
Using IAS Server to Control Wireless Accessp. 189
Configuring SSL Certificates for Wireless Networksp. 191
Certificates and Certificate Templatesp. 191
Configuring the IAS Server for Certificatesp. 194
Configuring Wireless Encryptionp. 195
WEPp. 195
802.1xp. 196
Installing and Configuring Wireless Support for Client Computersp. 198
Windows XP and Windows Server 2003p. 198
Windows 2000 and Windows CEp. 200
Exam Prep Questionsp. 202
Practice Exam #1p. 209
Answer Key to Practice Exam #1p. 237
Practice Exam #2p. 255
Answer Key to Practice Exam #2p. 281
Table of Contents provided by Rittenhouse. All Rights Reserved.

Supplemental Materials

What is included with this book?

The New copy of this book will include any supplemental materials advertised. Please check the title of the book to determine if it should include any access cards, study guides, lab manuals, CDs, etc.

The Used, Rental and eBook copies of this book are not guaranteed to include any supplemental materials. Typically, only the book itself is included. This is true even if the title states it includes any access cards, study guides, lab manuals, CDs, etc.

Excerpts

= 0) {slash = '\\';} else {slash = '/';}openLoc = figLoc.substring(0, figLoc.lastIndexOf(slash) + 1);while (pPage.substring(0,3) == '../') {openLoc = openLoc.substring(0, openLoc.lastIndexOf(slash, openLoc.length - 2)+ 1);pPage = pPage.substring(3, pPage.length + 1);}popUpWin =window.open('','popWin','resizable=1,scrollbars=1,location=0,toolbar=0,width=525,height=394');figDoc = popUpWin.document;zhtm= ' ' + pPage + ' ';zhtm += ' ';zhtm += ' ';zhtm += ' ';zhtm += '' + pPage.substring(pPage.lastIndexOf('/') + 1, pPage.length) + '';zhtm += ' ';figDoc.write(zhtm);figDoc.close();}// modified 3.1.99 RWE v4.1 --> Introduction IntroductionWelcome to theExam Cram 2series. The purpose of this book is to prepare you to take Microsoft certification exam 70-299 "Implementing and Administering Security in a Microsoft Windows Server 2003 Network."Books in theExam Cram 2series are designed to help you understand the material you will encounter on the exams. The purpose of the series is to cover the topics you are likely to encounter on the exams, but the books do not teach you everything you need to know about a topic. This book contains as much information as possible about the 70-299 exam.This book begins by providing useful information about how to prepare for the exam and what to expect on your exam day. To begin, we recommend that you take the self-assessment included in the book. This will help you to evaluate your current knowledge base against what is required for a Microsoft Certified Systems Engineer (MCSE) candidate. Then you can you determine where your training should begin, which may include some classroom training or reading one of the several study guides available.We also strongly recommended that you gain some hands-on experience with the technologies being covered on the exam. Again, this may be through classroom training or by installing and configuring the software on a home system. In any case, nothing beats hands-on experience when it comes to learning essential exam topics.Passing this exam can earn you credit toward the following certifications:Microsoft Certified Systems Administrator (MCSA) on Microsoft Windows Server 2003--This exam can be used as one of the electives required to achieve MCSA on Windows Server 2003 status.MCSA: Security on Microsoft Windows Server 2003--This is one of the core exams required to achieve MCSA: Security on Windows Server 2003 status.MCSE on Microsoft Windows Server 2003--This is one of the elective exams required to obtain MCSE on Windows Server 2003 status.MCSE: Security on Microsoft Windows Server 2003--This is one of the core exams required to obtain MCSE: Se

Rewards Program