1. What are the three fundamental elements of an effective security program for information systems?
2. Of these three fundamental controls, which two are used by the Domain User Admin to create users and assign rights to resources?
3. If you can browse a file on a Windows network share, but are not able to copy it or modify it, what types of access controls and permissions are probably configured?
4. What is the mechanism on a Windows server that lets you administer granular policies and permissions on a Windows network using role based access?
5. What is two-factor authentication, and why is it an effective access control technique?
6. Relate how Windows Server 2012 Active Directory and the configuration of access controls achieve C-I-A for departmental LANs, departmental folders, and data.
7. Is it a good practice to include the account or username in the password? Why or why not?
8. Can a user who is defined in Active Directory access a shared drive on a computer if the server with the shared drive is not part of the domain?
9. When granting access to LAN systems for guests (i.e., auditors, consultants, third-party individuals, etc.), what security controls do you recommend be implemented to maximize confidentiality, integrity, and availability of production systems and data?