exam questions

Exam MD-100 All Questions

View all questions & answers for the MD-100 exam

Exam MD-100 topic 3 question 88 discussion

Actual exam question from Microsoft's MD-100
Question #: 88
Topic #: 3
[All MD-100 Questions]

HOTSPOT -
Your network contains an Active Directory domain. The domain contains three computers named Computer1, Computer2, and Computer3 that run Windows 10.
The computers are on the same network and have network connectivity.
Windows Defender Firewall on Computer1 has the server-to-server connection security rule shown in the following table.

Windows Defender Firewall on Computer2 has the server-to-server connection security rule shown in the following table.

Windows Defender Firewall on Computer3 has the server-to-server connection security rule shown in the following table.

All the connection security rules are enabled and configured to use only the Computer (Kerberos V5) authentication method.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Reference:
https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-firewall/create-an-authentication-request-rule

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
mikl
Highly Voted 3 years, 7 months ago
I agree!
upvoted 6 times
...
DestinysPower
Most Recent 2 years, 4 months ago
no no yes is the correct answer If Computer1 initiates communication to Computer2, network traffic will NOT be encrypted because the connection security rule on Computer2 does not require authentication. Computer2 cannot establish communication to Computer3 because the connection security rule on Computer3 requires inbound authentication, which Computer2 does not provide. If Computer3 initiates communication to Computer1, network traffic will be encrypted because the connection security rule on Computer1 requires inbound authentication, which Computer3 provides.
upvoted 2 times
...
ccontec
2 years, 4 months ago
Answer is correct, NO NO YES. Keyword here is: "All the connection security rules are enabled and configured to use only the Computer (Kerberos V5) authentication method." And Kerberos has data encryption implied https://learn.microsoft.com/en-us/windows/security/threat-protection/security-policy-settings/network-security-configure-encryption-types-allowed-for-kerberos
upvoted 1 times
...
flabezerra
2 years, 8 months ago
Correct answers: NO NO NO Server-to-server - Authenticate connection between the specified computers. Do Not Authenticate - No connections will be authenticated. Inbound connections must be authenticated to be allowed. Outbound connections are authenticated whenever possible but authentication is not required.
upvoted 1 times
flabezerra
2 years, 8 months ago
First NO Traffic will not be encrypted by default. The question does not have this option configured by default. Encryption is optional, not default to authentications. Encryption needs to be enabled in the GPO. The default is data integrity which is not default to encrypt. Actually, if you encrypt you will use both integrity with encryption. Devices in the encryption zone require authentication to communicate with other devices.
upvoted 1 times
flabezerra
2 years, 8 months ago
Second NO As Computer3 has require inbound, and require inbound must be authenticated to be allowed, then there is no connection because Computer3 will not allow it.
upvoted 1 times
flabezerra
2 years, 8 months ago
Third NO No, it will not encrypt. Encryption is not enabled by default. Data integrity is default.
upvoted 1 times
...
...
...
...
AUP123
2 years, 9 months ago
Looks right.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...