70-293 Planning and Maintaining a Microsoft Windows Server 2003 Network Infrastructure Practice Test


Microsoft ™

70-293 Planning and Maintaining a Microsoft Windows Server 2003 Network Infrastructure



Note 1: 70-293 Exhibit and all related diagrams are not shown in demo questions.
Note 2: 70-293 Answers are not shown in demo questions.
Exhibits and Answers are only provided in the Full Version.


Demo Question 3.


You work as the network security administrator at EliteCertify.com. The EliteCertify.com network consists of a single Active Directory domain named EliteCertify.com. All servers on the EliteCertify.com network run Windows Server 2003 and all client computers run Windows XP Professional. The perimeter network hosts an application server that is used by external users. One morning you examine the intrusion-detection system (IDS) on the router. You notice that an extensive number of TCP SYN packets are being transmitted to the application server on the perimeter network. You notice that the application server is responding to the SYN packets with SYN-ACK packets to a number of different IP addresses. No ACK responses are being received. You work out that all incoming SYN packets seem to be coming from IP addresses located within the subnet address range of the perimeter network. However, there are no computers on the perimeter network that have these specific IP addresses configured. You examine the router logs and determine that the SYN packets are coming from the Internet. You must implement a solution that will prevent the attack from reoccurring until such time that a patch is made available from the specific application vendor. Your solution should not affect acceptable traffic to the application server. You cannot add additional hardware or software when you implement your solution. How will you accomplish the task?

A. Move the application server on the perimeter network to the company intranet. Configure the firewall to allow inbound and outbound traffic on the specific ports and protocols utilized by the application.
B. Create network ingress filters on the router and configure it to drop packets that have local addresses but that appear to come from the public network.
C. Configure access control lists (ACLs) and packet filters on the router to allow perimeter network access to only authorized users and to drop other packets coming from the Internet.
D. Configure a response rule on the IDS to send a remote shutdown command to the application server when a denial-of-service attack occurs.


Display Answer


Purchase Full Version:


70-293 Printable PDF Prep Guide $49.95 BUY NOW!

70-293 Test Simulation Engine $69.95 BUY NOW!

70-293 PDF & Test Simulation Engine $99.95 BUY NOW!




Answer: B

Explanation: In an ideal world, each router would be configured with ingress filters that would drop packets arriving from "internal" networks whose source address was not a member of the set of network addresses that this router serves. The majority of routers could be so configured. These ingress filters should be required as part of a "good neighbor policy." Ingress filters would not totally eliminate denial of service attacks but could greatly reduce such attacks. An attacker could still spoof an address within a local subnet, but that would permit back-tracking the packets to the source subnet. Incorrect



  • Based on the latest 70-293 exam objectives!
  • Designed like actual 70-293 exam questions!
  • 100% Verified Realistic 70-293 Exam Questions and Answers!
  • Exhibits, Drag&Drop and Simulation 70-293 Questions Included!
  • Constantly Updated Guide to Reflect the Current 70-293 Exams!
  • Detailed Explanations for Most Guide Practice Exams!
 Sponsored Links
Japan Exam



MCSD .NET
70-229 70-300
70-306 70-310
70-315 70-316
70-320
$209 Get Detail

HTI+
HT0-101 HT0-102

$59 Get Detail

10g OCA
1Z0-311
$49.95 Get Detail

MCAD .NET
70-305 70-306
70-310 70-315
70-316 70-320

$179 Get Detail

CCNP
642-901 642-812
642-825 642-845

$119 Get Detail


Demark
Took my last CCNP test last Friday. EliteCertify tests really made the difference, I passed every one on the first ...


England
Many thanks to your complete solution in 3Com Test Simulation Engine, Study Guides and PDF practice exams which are very ...


NY, USA
I wanted to take a few minutes to thank EliteCertify for passing 3 exams towards my MCSE. ...





Keyword
This site is both PayPal and VeriSign Verified. 128-bit SSL Encryption!
More questions about Order Security?