nerdexam
Microsoft

70-647 · Question #56

Your network consists of one Windows Server 2008 domain. The network contains portable computers. You configure a server that runs Windows Server 2008 as a Routing and Remote Access Service (RRAS)…

The correct answer is B. Implement Network Access Protection (NAP) on the perimeter network. To ensure that the computers that connect to the corporate network meet all the required conditions, you need to implement Network Access Protection (NAP) on the perimeter network. NAP uses System Health Agent (SHA) to check if the specified system health requirements are…

Planning and Implementing Security

Question

Your network consists of one Windows Server 2008 domain. The network contains portable computers. You configure a server that runs Windows Server 2008 as a Routing and Remote Access Service (RRAS) server. Users connect remotely to the network through a virtual private network (VPN) connection to the RRAS server from both company-issued portable computers and non- company-issued computers. The relevant portion of the network is shown in the following diagram. You need to prepare the environment to secure remote access to the network. The solution must meet the following requirements:

  • Only computers that have Windows Firewall enabled can connect

remotely.

  • Only computers that have the most up-to-date antivirus definitions

can connect remotely.

  • Only computers that run Windows Vista and have the most up-to-date

updates can connect remotely. What should you do?

Options

  • AImplement Authorization Manager.
  • BImplement Network Access Protection (NAP) on the perimeter network.
  • CInstall a Microsoft Internet Security and Acceleration Server (ISA) 2006 on the network.
  • DCreate a domain Group Policy object (GPO).

How the community answered

(51 responses)
  • A
    8% (4)
  • B
    76% (39)
  • C
    4% (2)
  • D
    12% (6)

Explanation

To ensure that the computers that connect to the corporate network meet all the required conditions, you need to implement Network Access Protection (NAP) on the perimeter network. NAP uses System Health Agent (SHA) to check if the specified system health requirements are fulfilled. The SHA can verify whether the Windows Firewall is on; antivirus and antispyware software are installed, enabled, and updated; Microsoft Update Services is enabled, and the most recent security updates are installed. If the system is not in the required state, the SHA can then start a process to remedy the situation. For example, it can enable Windows Firewall or contact a remediation server to update the antivirus signatures

Topics

#NAP#VPN#RRAS#network access control

Community Discussion

No community discussion yet for this question.

Full 70-647 Practice