Configure Active Directory and Implement Departmental and User Access Controls
In this lab, you configured Windows Active Directory to create Department and User accounts, and set unique read/write folder and fi le access privileges. You used the Windows Configuration Applet and Group Policy Management console to create and test configurations and read/write of several fi les with specific access controls. You also used group policy objects to restrict access to certain users and groups at the directory, folder, and fi le level.
Lab Assessment Questions & Answers
1. Relate how Windows Server 2008 R2 Active Directory and the configuration of access controls achieve
CIA for departmental LANs, departmental folders, and data.
2. Is it a good practice to include the account or user name in the password? Why or why not?
3. To enhance the strength of user passwords, what are some of the best practices to implement for user password definitions to maximize confidentiality?
4. Can a user defined in Active Directory access a shared drive if that user is not part of the domain?
5. Does Windows Server 2008 R2 require a user’s logon/password credentials prior to accessing shared drives?
6. When looking at the Active Directory structure for Users and Computers, which group has the least amount of implied privileges?
7. When granting access to LAN systems for guests (i.e., auditors, consultants, third-party individuals, etc.), what security controls do you recommend implementing to maximize CIA of production systems and data?
8. When granting access for the ShopFloor group to the SFfi les within the SFfi les folder, what must be configured within Active Directory?
9. When granting access for the HumanResources group to access the HRfi les within the HRfi les…...

