TAILIEUCHUNG - mcse exam 70-293 planning and maintaining a windows server 2003 network infrastructure phần 10

Mẫu bảo mật được sử dụng để cấu hình các chính sách bảo đảm theo định nghĩa cài đặt sẵn và có thể được nhập khẩu vào Group Policy. Các thiết lập bảo mật mở rộng của Group Policy được sử dụng để cấu hình bảo mật trên một OU, một trang web, hoặc tên miền. | Self Test Questions Answers and Explanations Appendix A 963 0 C. The problem your boss is describing is cache pollution. Although you can enable protection against cache pollution to mitigate this risk you should try to stop the potential risk at the firewall if possible. By configuring the firewall to not allow any inbound traffic that uses the DNS ports from reaching DNS-B you are preventing any potentially malicious traffic in the form of bogus DNS queries from reaching DNS-B in the first place. You can t use the same restriction for DNS-A because it provides name resolution for Internet hosts that wish to connect to your Web and mail servers. However if recursion is disabled on DNS-A it will still answer queries for zones that it is authoritative for but it will send a negative response to recursive queries. Disabling recursion also has the added benefit of providing a degree of protection against DoS attacks. H A B A is workable and provides additional security. However the boss wants the highest level of protection against multiple common attacks on DNS servers so this choice is not as good as Answer C. Answers B and D are wrong because they compromise the ability of DNS-A to resolve the names of your Web and mail servers. 3. You are the administrator of a Windows network that consists of a mixture of Windows NT 4 Windows 2000 and Windows Server 2003 servers providing a mix of file print messaging and other services critical to your are currently running WINS DNS and DHCP services on your have already enabled dynamic DNS on your forward and reverse lookup zones but you want to ensure that all of your client computers can find the name-to-address mapping of all your servers using want to minimize the administrative effort for this action should you take Select the best answer. A. Place the DHCP servers in the DnsUpdateProxy group. B. Enable DHCP to update forward and reverse lookup zones on behalf of all .

Đã phát hiện trình chặn quảng cáo AdBlock
Trang web này phụ thuộc vào doanh thu từ số lần hiển thị quảng cáo để tồn tại. Vui lòng tắt trình chặn quảng cáo của bạn hoặc tạm dừng tính năng chặn quảng cáo cho trang web này.