可学答题网 > 问答 > MCSE(70-291)题库
目录: 标题| 题干| 答案| 搜索| 相关
问题

You are the network&en


You are the network administrator for your company. The network consists of a single Active Directory domain. The functional level of the domain is Windows Server 2003. All client computers in the domain run Windows XP Professional. An application named Inventory.exe is installed on all computers in the domain to remotely gather software inventory information. The application runs as a service in the security context of the Local System. The startup type of the service is set to Automatic.In the Default Domain Policy Group Policy object (GPO), the security administrator has configured a software restriction policy that is applied to all computers in the domain. The policy contains a hash rule for the Inventory.exe application, and the hash rule is configured with a security level of Unrestricted. The client computers on the network are attacked by a worm that is distributed by e-mail messages received over the Internet. The worm detects the presence of Inventory.exe on a computer, then starts a new instance of the application in the security context of the logged-on user. The worm exploits a bug in the application to cause the computer to fail.You need to ensure that Inventory.exe cannot be started by the worm, while still allowing the application to run as a service.   What should you do?()

  • AIn the computer settings section of the Default Domain Policy GPO, configure a software restriction policy that contains a zone rule for the Internet zone. Configure the zone rule with a security level of Disallowed.
  • BIn the user settings section of the Default Domain Policy GPO, configure a software restriction policy that contains a zone rule for the Internet zone. Configure the zone rule with a security level of Disallowed.
  • CIn the user settings section of the Default Domain Policy GPO, configure a software restriction policy that contains a hash rule for the Inventory.exe application. Configure the hash rule with a security level of Disallowed.
  • DIn the computer settings section of the Default Domain Policy GPO, modify the existing software restriction policy hash rule for the Inventory.exe application so that the hash rule has a security level of Disallowed.
参考答案
参考解析:
分类:MCSE(70-291)题库
相关推荐

1、You are the network&en

You are the network administrator for Fabrikam, Inc. The network contains a DNS server named&e...

2、You are the network&en

You are the network administrator for Company.com. You have a print device attached to the&ensp...

3、You are the network&en

You are the network administrator for your company. The network consists of a single Active&ens...

4、You are the network&en

You are the network administrator for your company. The network contains 12 Windows Server 2003...

5、You are the network&en

You are the network administrator for ExamSheet. You install a 16-bit ISA sound card on yo...

6、You are the network&en

You are the network administrator for Company. Your network consists of one Windows NT Server&e...