nerdexam
Microsoft

70-243 · Question #93

You install System Center 2012 Configuration Manager in your Active Directory environment. You configure a single Configuration Manager site. You need to enable Network Access Protection in your…

The correct answer is A. Enable the Network Access Protection client agent. C. Configure the Configuration Manager site to publish settings to Active Directory. F. Configure a server with the system health validator point and the Network Policy Server role. Enabling NAP in SCCM 2012 requires activating the NAP client agent, configuring the site to publish to Active Directory, and deploying the system health validator point with the Network Policy Server role to enforce health policies.

Implementing Compliance Settings and Endpoint Protection

Question

You install System Center 2012 Configuration Manager in your Active Directory environment. You configure a single Configuration Manager site. You need to enable Network Access Protection in your environment. You extend the Active Directory schema. You create the System Management container in Active Directory. You set permissions on the System Management container for the site server. Which three actions should you perform next?(Each correct answer presents part of the solution. Choose three.)

Options

  • AEnable the Network Access Protection client agent.
  • BEnable the Software Updates client agent.
  • CConfigure the Configuration Manager site to publish settings to Active Directory.
  • DConfigure the Configuration Manager site for native mode.
  • EEnable the Desired Configuration Management client agent.
  • FConfigure a server with the system health validator point and the Network Policy Server role.

How the community answered

(48 responses)
  • A
    65% (31)
  • B
    19% (9)
  • D
    4% (2)
  • E
    13% (6)

Why each option

Enabling NAP in SCCM 2012 requires activating the NAP client agent, configuring the site to publish to Active Directory, and deploying the system health validator point with the Network Policy Server role to enforce health policies.

AEnable the Network Access Protection client agent.Correct

The Network Access Protection client agent must be enabled in SCCM site settings so that managed clients participate in NAP health evaluation and reporting.

BEnable the Software Updates client agent.

The Software Updates client agent is used for patch management and is not a prerequisite for enabling Network Access Protection.

CConfigure the Configuration Manager site to publish settings to Active Directory.Correct

After extending the schema and creating the System Management container, the site must be configured to publish its settings to Active Directory so clients can locate site information and policy.

DConfigure the Configuration Manager site for native mode.

Native mode (PKI certificate-based communication) is a site communication security configuration unrelated to the NAP feature setup steps.

EEnable the Desired Configuration Management client agent.

The Desired Configuration Management client agent is used for compliance settings baselines and is not required as part of the NAP enablement process.

FConfigure a server with the system health validator point and the Network Policy Server role.Correct

The system health validator (SHV) point integrates with the Network Policy Server (NPS) role on Windows Server to evaluate client health statements and enforce NAP policies - without this infrastructure, health validation cannot occur.

Concept tested: Enabling Network Access Protection in SCCM 2012

Source: https://learn.microsoft.com/en-us/previous-versions/system-center/system-center-2012-R2/hh508762(v=technet.10)

Topics

#Network Access Protection#NAP client agent#health validator point#NPS role

Community Discussion

No community discussion yet for this question.

Full 70-243 Practice