Implementing Access Controls with Windows Active Directory

  1. Relate how Windows Server 2012 Active Directory and the configuration of
    access controls achieve CIA for departmental LANs, departmental folders, and
    data.
     
  2. Is it a good practice to include the account or user name in the password? Why
    or why not?
     
  3. To enhance the strength of user passwords, what are some of the best
    practices to implement for user password definitions to maximize
    confidentiality?
     
  4. Can a user who is defined in Active Directory access a shared drive on a
    computer if the server with the shared drive is not part of the domain?
     
  5. When granting access to network systems for guests (i.e., auditors,
    consultants, third-party individuals, etc.), what security controls do you
    recommend implementing to maximize CIA of production systems and data?

Sample Solution