CHAPTER 4 – ACCOUNT-BASED SECURITY
TRUE/FALSE
1. A formal account policy may include decisions about the format of usernames and restrictions on how
passwords are constructed.
2. The advantage of having accounts based on the position or function is that, for the sake of security, it
is easier to know who is logged on to a server.
3. Red Hat Linux is capable of monitoring unsuccessful logon attempts, in case an attacker attempts to
break into an account by trying various password combinations or employing a brute force attack.
4. Windows 2000/XP Professional is designed to effectively support up to 25 simultaneous users over a
LAN.
5. If Active Directory is installed and you are working on a DC, Windows 2000 Server and Windows
Server 2003 will not allow you to use the Local Users and Groups tool.
6. Under most circumstances, it is best for the network administrator to create and control all user
passwords.
7. In many UNIX systems, including Red Hat Linux, any account that has a UID of 1 automatically has
access to anything in the system.
8. In Red Hat Linux, user accounts and groups can be created by editing the password, shadow, and
group files.
9. Accounts in NetWare 6.x can be created using the ConsoleOne tool.
10. The Mac OS X Server Admin tool allows you to create and manage accounts and groups.
MODIFIED TRUE/FALSE
1. Information about groups is stored in the /etc/shadow file, which typically contains an entry for each
group, consisting of the name of the group, an encrypted group password, the GID, and a list of group
members. _________________________
2. The useradd -m command enables you to create a new user and establishes the home directory, if it has
not previously been set up. _________________________
3. An effective defense against attackers is the use of long passwords. _________________________
4. To configure the security settings for an account, open the Red Hat Security Manager and select the
account you want to configure. _________________________
5. A Netware 6.x user template, is an object stored in NDS that contains properties associated with
designated accounts. _________________________
6. Windows 2003 access rights give the server administrator important security controls over who can
access server and Active Directory resources. _________________________
7. The Windows 2003 Common.adm administrative template is the default for managing Windows 2000
Professional and Windows XP Professional clients. _________________________
8. The first step in developing an account policy in a company is usually to establish conventions for
account names. _________________________
9. A password expiration period requires users to change passwords at regular intervals.
_________________________
10. Windows 2000 Professional is typically installed with an Administrator account and a Guest account.
_________________________
1. _____ is a set of basic user account and computer parameters that can be configured using Poledit.exe.
a.
User policy
c.
Account policy
b.
System policy
d.
Group policy
2. On which of the following can you set a group policy?
a.
Site
d.
Both a and b
b.
Domain
e.
a, b, and c
c.
User
3. Where are group policy settings stored?
a.
In the registry
c.
In a group policy object
b.
In a secure ini file
d.
In a system policy object
4. Nonlocal GPOs apply to which of the following?
a.
Sites
c.
OUs
b.
Domains
d.
All of the above
5. Administrative templates are preconfigured group policies for which of the following?
a.
Client connectivity
d.
Both a and b
b.
Using Software
e.
Both b and c
c.
Managing Accounts
6. Which User Configuration component controls access to Logon/Logoff capabilities, scripts, and Task
Manager functions?
a.
Desktop
c.
System
b.
Network
d.
Control Panel
7. Which preconfigured Windows Server 2003 administrative template is used for managing desktop
settings that are common to all of Windows 95, 98, and NT?
a.
Common.adm
c.
Inetcorp.adm
b.
Inetres.adm
d.
System.adm
8. Which preconfigured Windows Server 2003 administrative template is used for managing Windows
95 and 98 clients?
a.
Conf.adm
c.
Winnt.adm
b.
System.adm
d.
Windows.adm
9. Which preconfigured Windows Server 2003 administrative template is used for managing Internet
Explorer in Windows 2000 Professional clients?
a.
Inetcorp.adm
c.
Inetset.adm
b.
Inetres.adm
d.
System.adm
10. Which preconfigured Windows Server 2003 administrative template is used for dial-up, language, and
temporary Internet files settings in Internet Explorer?
a.
Inetcorp.adm
c.
Inetset.adm
b.
Inetres.adm
d.
Conf.adm
11. Which functional area in the Windows Server 2003 is used to manage who can perform specific tasks
on a server designated as a domain controller?
a.
Domain controller
c.
Microsoft network client
b.
Domain member
d.
Network security
12. Which functional area in the Windows Server 2003 is used to require digitally signed communications
with the server and to control what happens when a user’s session is idle or when the logon hours
expire?
a.
Microsoft network client
c.
Network access
b.
Microsoft network server
d.
Network security
13. Which functional area in the Windows Server 2003 is used to manage authentication options when
NTLM is used instead of Kerberos for older clients?
a.
Microsoft network server
c.
Network security
b.
Network access
d.
System cryptography
14. Which functional area in the Windows Server 2003 is used to control the use of keys and algorithms
for encryption?
a.
Network security
c.
System objects
b.
System cryptography
d.
System security
15. Which functional area in the Windows Server 2003 is used to govern the certificate rules that are used
on applications?
a.
Devices
c.
System cryptography
b.
Network security
d.
System settings
16. How many characters does Windows 2000 limit its user account names to?
a.
15
c.
128
b.
20
d.
256
17. Which of the following operating systems are capable of monitoring unsuccessful logon attempts?
a.
Windows Server 2003
d.
Both a and b
b.
NetWare 6.x
e.
Both a and c
c.
Mac OS X
18. Which operating system may come configured to automatically boot into an account without an
account or password screen enabled?
a.
Windows XP Professional
d.
Both a and b
b.
Red Hat Linux
e.
Both a and c
c.
Netware 6.x
19. What type of accounts are created when Active Directory is not installed on Windows Server 2003?
a.
Domain
c.
Enterprise
b.
Local
d.
OUs
20. How are new accounts set up for servers that do not use Active Directory?
a.
MMC Local Users and Groups Snap-in
b.
Computer Management tool
c.
MMC Active Directory Users and Computers Snap-in
d.
Both a and b
e.
Both b and c
21. How are new accounts set up for servers that use Active Directory?
a.
MMC Local Users and Groups Snap-in
b.
Computer Management tool
c.
MMC Active Directory Users and Computers
d.
Active Directory Users and Computers option on the Administrative Tools menu
e.
Both c and d
22. Which user account option should be used for a utility account needed to run a program process?
a.
Password never expires
c.
Account is disabled
b.
User cannot change password
d.
None of the above
23. Which account properties tab enables you to enter or modify personal information about the account
holder, including the first name and last name?
a.
Address
c.
Account
b.
General
d.
Profile
24. Which account properties tab provides information about the logon name, domain name, and account
options?
a.
General
c.
Address
b.
Account
d.
Environment
25. Which account properties tab is used to add the account to an existing group of users?
a.
Organization
c.
Member Of
b.
Profile
d.
Sessions
26. Which of the following tabs is available only in Windows Server 2003?
a.
Terminal Services Profile
c.
Environment
b.
Remote Control
d.
COM+
27. Which of the following options is available in the account properties Address tab?
a.
Street address
d.
Post Office Box
b.
Postal code
e.
All of the above
c.
State
28. Which account properties Dial-in tab option enables the server to verify that a call is from a known
location?
a.
Allow access
c.
Static routing
b.
Callback security
d.
None of the above
29. What is the largest number that a Linux UID can be?
a.
20,000
c.
60,000
b.
40,000
d.
100,000
30. Which useradd command parameter gives an account description?
a.
-c
c.
-e
b.
-d
d.
-f
31. Which useradd command parameter specifies an account expiration date?
a.
-p
c.
-M
b.
-G
d.
-e
32. Which useradd command parameter designates the default shell associated with the account?
a.
-q
c.
-s
b.
-R
d.
-f
33. Which operating system uses the dialog in the figure above to create accounts?
a.
Windows Server 2003
c.
Mac OS X
b.
Red Hat Linux
d.
Netware 6.x
34. Which operating system uses the dialog in the figure above to create accounts?
a.
Windows Server 2003
c.
Mac OS X
b.
Red Hat Linx
d.
Netware 6.x
35. Which operating system uses the dialog in the figure above to configure password settings?
a.
Windows Server 2003
c.
Mac OS X
b.
Red Hat Linux
d.
Netware 6.x
YES/NO
1. Is the option “User must change password at next logon” necessary for accounts used by the server
administrator in WIndows 2003?
2. If the payroll supervisor of a company decides to leave the company, should the administrator disable
his or her account?
3. In Red Hat Linux, are the group names that a user belongs to included in the /etc/passwd file?
4. In Red Hat Linux, is every account a member of a least one group?
5. In Red Hat Linux, is an account enabled by default even if there is no password specified when the
account is created?
6. Can ConsoleOne be run from a workstation under the Remote Console NLM?
7. Is the Mac OS X Server Admin tool a tool for managing users, groups, and computers that access the
server?
8. Do common slang terms make strong passwords?
9. Does Windows 2000 Server allow the administrator to set the account lockout option, so that an
account is inaccessible for a specified time after a specified number of unsuccessful attempts to log
on?
10. Are security and other properties that are associated with specific accounts in NetWare configured
through user templates before accounts are created?
COMPLETION
1. In Windows Server 2003, ____________________ generally relate to managing server or Active
Directory functions.
2. The most efficient way to assign user rights is to assign them to ____________________ instead of to
individual user accounts.
3. Windows 2000 group policy has evolved from the Windows NT Server 4.0 concept of
____________________.
4. The ____________________ template is used to manage how Windows updates are performed
through the Internet.
5. The ____________________ functional area is used to manage security functions used by members of
a domain (e.g., using digital encryption options).
6. When you have a specialized security need, consider the ____________________ group policies as
one of the first places to look to fulfill that need.
7. ____________________ accounts not only provides orderly access to server and network resources, it
also enables server administrators to maintain security by monitoring which users are accessing the
server and what resources they are using.
8. Windows 2000/XP Professional is designed to support a maximum of 2 simultaneous
_________________________ users using a dial-up connection.
9. The Windows XP Professional ____________________ account is used for remote desktop help.
10. In UNIX/Linux, when two or more groups use the same ______________________________, there is
a serious security risk.
MATCHING
Match the following terms to the appropriate definition.
a.
COM
f.
Role-based security
b.
GID
g.
Site
c.
GPO
h.
System policy
d.
Inherited rights
i.
User rights
e.
Logon script
j.
User template
1. Enables some control of specific client configuration settings in Windows NT
2. Contains group policy settings for a site, domain, OU, or local computer
3. Used to enable efficient Active Directory operations on a network
4. Used to distinguish a group from all other groups on the same system
5. Global or over-riding rights to access a server in Windows 2000 Server
6. Netware 6.x global security access configured on the basis of function
7. Windows Server 2003 user rights that are assigned to a group and that automatically apply to all
members of that group
8. Account settings, such as password restrictions, that are associated with specific accounts in NetWare
6.x
9. A set of standards for building software from individual objects
10. Commands that automatically run each time the user logs on to the domain
SHORT ANSWER
1. List three conventions for account names based on the user’s actual name.
2. In UNIX/Linux systems, what seven pieces of information does the password file contain?
3. What password restriction information is contained in the shadow file?
4. What are the four ways the Mac OS X can be customized for different logon options?
5. What two important tools are included with Mac OS X Server that enable server management?
6. List seven of the strong password guidelines.
7. What are the six specific password security options that can be in Windows 2000 Server and Windows
Server 2003?
8. What three account lockout options are available in Windows 2000 Server and Windows Server 2003?
9. What three security properties can be configured in the Red Hat User Manager?
10. List and describe the five roles available in Netware 6.x that relate to managing network services.