QuestionQ14

Secure Windows Server on-premises and hybrid infrastructures

HOTSPOT

Your network has an on-premises Active Directory Domain Services (AD DS) domain. The domain includes the servers listed in the following table.

Question Image

For each server, Windows Defender Firewall is set to allow communication only between servers on the same segment.

Server1 has this connection security rule:

  • Name: Rule1
  • Rule type: isolation
  • Requirement: Require authentication for inbound connections and request authentication for outbound connections
  • Authentication method: Computer (Kerberos V5)
  • Profile: Domain, Private, Public

Server2 has no connection security rules.

Server3 has this connection security rule:

  • Name: Rule3
  • Rule type: Server-to-server
  • Endpoints
    • Computers in Endpoint 1: 192.168:5.0/24
    • Computers in Endpoint 2: 192.168.1.0/24
  • Requirement: Request authentication for inbound and outbound connections
  • Authentication method: Computer (Kerberos V5)
  • Profile: Domain, Private, Public

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

Yes or No
StatementsYesNo
Server1 can initiate communication with Server2 successfully.
Server2 can initiate communication with Server3 successfully.
Server3 can initiate communication with Server1 successfully.
Explanation

Server1 and Server2 are on the same 192.168.1.0/24 segment, so their firewall policy permits communication. Server1 requests, rather than requires, outbound authentication, so Server2's lack of a connection security rule does not prevent Server1 from initiating communication. Server2-to-Server3 and Server3-to-Server1 traffic crosses segments, which the firewall policy blocks.

Community Discussion

No comments yet. Be the first to start the discussion!