70-649 · Question #110
Your network contains a server named Server1 that runs Windows Server 2008 R2. You have a user named User1. You need to ensure that User1 can view the events in the Security event log. The solution…
The correct answer is D. In the Registry Editor, add a Security Descriptor Definition Language (SDDL) value. Microsoft Windows uses SDDL to develop and administer object security. SDDL defines security descriptors,which are text strings or binary data structures containing security information for one or more objects, e.g., file,folder, service or unnamed process. Security descriptors…
Question
Your network contains a server named Server1 that runs Windows Server 2008 R2. You have a user named User1. You need to ensure that User1 can view the events in the Security event log. The solution must minimize the number of rights assigned to User1. What should you do?
Options
- AIn the Local Security Policy console, modify the Security Options.
- BIn Event viewer, configure the properties of the Security log.
- CIn Event viewer, filter the Security log.
- DIn the Registry Editor, add a Security Descriptor Definition Language (SDDL) value.
How the community answered
(53 responses)- A6% (3)
- B11% (6)
- C4% (2)
- D79% (42)
Explanation
Microsoft Windows uses SDDL to develop and administer object security. SDDL defines security descriptors,which are text strings or binary data structures containing security information for one or more objects, e.g., file,folder, service or unnamed process. Security descriptors use access control lists (ACLs) to manage access and control entries and audits. Eachsecurity descriptor contains a discretionary access control list (DACL) and system access control list (SACL). The DACL controls access to an object, and the SACL controls logging of access attempts. In addition to the object owner name, most SDDL security descriptor strings are comprised of five parts. These include DACL, SACL, group and header, which specifies inheritance level and
Topics
Community Discussion
No community discussion yet for this question.