HOTSPOT
Your network contains an Active Directory forest named northwindtraders.com.
The client computers in the finance department run either Windows 8.1, Windows 8, or
Windows 7. All of the client computers in the marketing department run Windows 8.1.
You need to design a Network Access Protection (NAP) solution for northwindtraders.com
that meets the following requirements:
The client computers in the finance department that run Windows 7 must have a firewall
enabled and the antivirus software must be up-to-date.
The finance computers that run Windows 8.1 or Windows 8 must have automatic updating
enabled and the antivirus software must be up-to-date.
The client computers in the marketing department must have automatic updating enabled
and the antivirus software must be up-to-date.
If a computer fails to meet its requirements, the computers must be provided access to a
limited set of resources on the network.
If a computer meets its requirements, the computer must have full access to the network.
What is the minimum number of objects that you should create to meet the requirements?
To answer, select the appropriate number for each object type in the answer area.
Explanation:
Health Policies: 4
Network Policies: 4
System Health Validator Settings: 2
Tested in my lab.
SHV
1) firewall + Antivirus up to date
2) Windows automatic updates + Antivirus up to date
health policy
1) meet shv 1
2) meet shv 2
3) doesn’t meet shv 1
4) doesn’t meet shv 2
network policy
1) If OS = Win7 and health policy 1 -> grant access
2) If OS = Win 7 and health policy 3 -> deny access
3) If OS > Win7 AND health policy 2 –> grant access
4) If OS > Win7 AND health policy 4 –> deny access
Sjoerd is right
It should be 4 (health), 6 (network), 2 (SHV)
Marketing and Finance (groups or OUs) should be added to network policies
Agree in Sjoerd Stefma desciption there is not department diference taken into consideration.
4 4 2 or 4 6 2?
I disagree. The question asks for the minimum number of objects;
SHV
1) Windows automatic updates + firewall + Antivirus up to date
health policy
1) meet shv 1
network policy
1) meet health policy 1 -> grant access
Whoever doesn’t meet the network policy, falls back on the default deny access rule, and the requirements are all fulfilled.
@ MAX is this confirmed
Not all requirements are met by the 1-1-1 response and the Deny All fallback. “If the computer fails to meet its requirements, the computers must be provided access to a limited set of resources on the network.”
@Sjoerd Stefma thanks a lot! you make me to be enlightened!