MCSE Designing Security for a Windows Server 2003 Network Exam 70-298 Study Guide

The following Frequently Asked Questions, answered by the authors of this book, are designed to both measure your understanding of the Exam Objectives presented in this chapter, and to assist you with real-life implementation of these concepts. You will also gain access to thousands of other FAQs at ITFAQnet.com.
| 1. | What exactly is the difference between DACLs and SACLs? |
|
| 2. | What is the difference between an account group and a resource group? |
|
| 3. | What s the best way to determine an auditing policy? |
|
| 4. | What is the difference between using EFS and using a third-party encryption program? What are the pros and cons of each? |
|
| 5. | Our company doesn t use certificates; can we still use EFS? |
|
| 6. | Can I still back up EFS encrypted files or do I need a special tool for this? |
|
| 7. | We use RAID and mirrored sets, so we don t need additional backups, do we? |
|
| 8. | What is the difference between ASR, Emergency Management Console, and Recovery Console? |
|
Answers
| 1. | A discretionary access control list (ACL) defines which users can access an object and with what level of privileges and is often referred to simply as the ACL. The system access control list (SACL) is the part of the object s description that specifies which events are to be audited per user or group. Auditing examples include access, logon attempts, or system shutdowns. |
| 2. | An account group contains users or other groups that are granted permissions to objects via ACLs. A resource group is associated specifically... |