Define why change control management is relevant to security operations in an organization
- Change control is an approach to managing changes that are made to a product or system with the purpose of ensuring that only necessary changes are made, changes are documented, that services are not unnecessarily disrupted, and that resources are used efficiently.
What type of access control system uses security labels?
- A (LBAC) Label-base access control system
Describe two options you would enable in a Windows Domain password policy.
- Password must meet complexity and Minimum password length
Where would patch management and software updates fall under in security operations and management?
- The System Administrator or other authorized personnel are responsible for informing local administrators about patches that correlate to the software that is used by the organization.
Is there a setting in your GPO to specify how many logon attempts will lock out an account? Name two parameters that you can set to enhance the access control to the system.
- Yes, The account lockout threshold policy can be modified to specify the number of attempts before a lockout. You can increase access control to the system by forcing users to change their password every 30 days and by ensuring that users do not have Administrator access to their local machines
What are some password policy parameter options you can define for GPOs that can enhance the CIA or system access?
- Setting the Maximum age of a password, complexity requirements and the minimum password length will enhance the CIA.
What sources could you use as a source to perform the MBSA security state?
- MBSA will run Windows Server 2008 R2, Windows 7, Server 2003
What does WSUS stand for, and what does it do?
- Windows Server Update Services is a service that provides updates for Microsoft programs