| Windows
Server 2003 Security MCSE 70-298: Designing
a Secure Network Framework |
- Analyzing existing security
- Policies and procedures
- Determining requirements for securing
data
- Analyzing current security practices
- Predicting network threats
- Recognizing external threats
|
- Implementing risk analysis
- Responding to security incidents
- Analyzing technical constraints
|
|
| Windows
Server 2003 Security MCSE 70-298: Defining
a Baseline Security Template |
- Administrative security tools
overview
- Working with predefined security
templates
- Adding security templates snap-ins
- Reapplying default security settings
- Configuring security templates
|
- Configuring security for down-level
clients
- Deploying security templates
- Reviewing the result of security
policy settings
- Using security configuration and
analysis to review security settings
- Using the secedit.exe command-line
tool
|
|
| Windows
Server 2003 Security MCSE 70-298: Designing
Role-Based Server Security |
- Common server roles
- Adding or changing server roles
- Configuring security for domain
controllers
- Securing the Internet Information
- Server (IIS)
- Configuring security for POP3
mail servers
|
- Securing network infrastructure
servers
- Securing remote access servers
- Securing file, print, terminal,
and streaming media servers
- Modifying baseline security templates
according to role
|
| Windows
Server 2003 Security MCSE 70-298: Securing
a Public Key Infrastructure and Network
Management Processes |
- PKI basics
- Designing a certification
authority implementation
- Designing a logical authentication
strategy
- Designing security for CA
servers
- Designing certificate distribution
- Requesting, approving, and
revoking certificates
- Renewing and auditing certificates
Managing the risks of network
administration |
- Securing MMC, Remote
- Assistance, and Telnet
- Securing Terminal Services
and
- Remote Desktop
- Designing security for EMS
- Designing a Security Update
infrastructure
- Trust relationship basics
- Designing forest and domain
trust models
- Designing security for interoperability
|
|
|
| Windows
Server 2003 Security MCSE 70-298: Designing
Network Infrastructure Security |
- Network infrastructure security
basics
- Assessing risk for network services
- IPSec overview
- Phase I security association
- Phase II security association
- IPSec policies overview
|
- IPSec rules
- How IPSec policy is applied
- IPSec driver modes and best practices
- Designing IPSec policies
- Designing IP filtering and configuring
a firewall
- Securing DNS
|
|
| Windows
Server 2003 Security MCSE 70-298: Securing
Data Transmissions and Wireless Networks |
- SSL/TLS,SMIME and SMB
- Configuring IIS to use SSL
- Securing switches and segments
- Wireless network types and threats
- Wireless history
- PKI and RADIUS/IAS overview
|
- WLAN network infrastructure
- Creating a wireless network policy
- Designing authentication for wireless
networks
- Designing and testing wireless
access infrastructure
|
|
| Windows
Server 2003 Security MCSE 70-298: Securing
Internet Information Services |
- Designing user authentication
for IIS
- Designing certificate authentication
- Configuring anonymous and basic
authentication
- Configuring digest and integrated
- Windows authentication
- Designing RADIUS authentication
- Securing IIS installations
|
- Hardening IIS
- New security features in IIS 6.0
- Designing a monitoring strategy
for IIS
- Configuring IIS logging and monitoring
Event Log activities
- Enabling security auditing and
health detection
|
|
| Windows
Server 2003 Security MCSE 70-298: Securing
VPNs, Extranets, and Network Clients |
- Using Windows Server 2003 as
a router
- Building routing tables
- Designing demand dial routing
between internal networks
- Designing VPN connectivity
- PPTP
- L2TP
Using remote access policies
- Designing an extranet infrastructure
- Hardening client operating systems
|
- Securing laptop computers
- Analyzing authentication requirements
- Choosing authentication protocols
- Choosing a remote access method
- Designing remote access policies
- Creating a remote access policy
- Using Internet Authentication
service
|
|
| Windows
Server 2003 Security MCSE 70-298: Securing
Active Directory |
- Designing an access control strategy
for directory services
- Analyzing risks to directory services
- Establishing account security
policies
- Using restricted groups
Creating a Kerberos policy
- Establishing password security
- Creating an account lockout policy
|
- Creating an auditing policy
- Auditing logon events and object
access
- Analyzing auditing data
- Creating a delegation strategy
- Designing the appropriate group
strategy for accessing resources
|
|
| Windows
Server 2003 Security MCSE 70-298:Designing
an Access Control Strategy for Files and Folders |
- Analyzing risks to data
- Reviewing access control and access
control lists
- Access to resources
Working with security groups
- Defining a security group retirement
policy
- Delegating security group maintenance
|
- Analyzing auditing requirements
- Designing an access control strategy
for the registry
- Setting registry access permissions
via group policy
- Designing a permission structure
for registry objects
|
|
| Windows
Server 2003 Security MCSE 70-298: Designing
an Encrypted File System and Securing Backup/Restore
Processes |
- Encrypted File System
- Encrypting files and folders
- Certificate storage, enrollment,
and renewal
- Creating a strategy for the encryption
and decryption of files and folders
- Configuring file recovery agents
- Backing up keys
- Disabling EFS
- Backup and restore process security
basics
|
- Designing a secure backup process
- Designing a secure recovery process
- Securing EMS
- Securing the Recovery Console
- Configuring startup and recovery
options
|
|
| Windows
Server 2003 Security MCSE 70-298: Practice
Exam |
- Practice Exam 1
- Practice Exam 2
- Practice Exam 3
|
- Practice Exam 4
- Practice Exam 5
|
|
|