本盘书是微软认证高级技术培训中心(CTEC)标准教材系列之一,课程号是2150A。本盘书详细讨论了Microsoft Windows 2000及其安全性设计的基本知识,并通过具体实验培养读者的动手能力。全书由15个单元和3个附录组成,分别为:评估安全性风险、介绍Windows 2000安全性、规划系统管理访问、规划用户帐号、基于Windows 2000的计算机安全性、文件和打印资源安全性、通信通道安全性、为非微软客户机提供安全访问、为远程用户提供安全访问、为远程办公提供安全访问、为Internet用户提供安全网络访问、为网络用户提供安全Internet访问、将网络延伸向伙伴组织、设计公共密钥的基础结构、开发安全规划等。在每个单元中,都给出了考察读者对本单元内容掌握情况的练习题,有助于读者自我评价课程掌握情况。本盘书内容新颖,全面涵盖了Microsoft Windows 2000安全设计的基础知识,是Microsoft Windows 2000认证考试的权威教材。它是参加微软认证考试的各类读者的必备读物,也是需要掌握Microsoft Windows 2000安全设计基础知识的从业人员的不可缺少的自学读物和社会相关领域培训班教材。本光盘内容包括:在课堂中使用的所有练习文件。\r\n
Contents\r\nlntrod uction\r\nInstructOr Notes \r\nIntroduction \r\nCourse Materials\r\nPrerequisites\r\nCourse Outline \r\nCourse Outline continued\r\nCourse Outline continued\r\nCourse Outline continued\r\nCourse Outline continued\r\nMicrosoft Official Curriculum\r\nMicrosoft Certified Professional Program \r\nFacilities \r\nModule 1: Assessing Security Risks \r\nInstructor Notes \r\nOverview \r\nIdentifying Risks to Data\r\nIdentifying Risks to Services \r\nIdentifying Potential Threats \r\nIntroducing Common Security Standards\r\nPlanning Network Security\r\nReview\r\nModuIe 2:lntroducing Windows 2000 Security\r\nInstructor Notes \r\nOverview \r\nIntroducing Security Features in Active Directory \r\nAuthenticating User Accounts \r\nSecuring Access to Resources\r\nIntroducing Encryption Technologies \r\nEncrypting Stored and Transndtted Data \r\nIntroducing Public Key Infrastructure Technology\r\nReview \r\nModuIe 3: Planning Administrative Access\r\nInstructor Notes \r\nOverview\r\nDetendning the Appropriate Adndnistrative Model\r\nDesigning Adndnistrative Group Strategies \r\nPlanning Local Adndnistrative Access\r\nPlanning Remote AdIninistrative Access\r\nLab A: Planning Secure Adndnistrative Access \r\nReview \r\nModule 4: Planning User Accounts \r\nInstructor Notes\r\nOverview \r\nDesigning Account Policies and Group Policy \r\nPlanning Account Creation and Location \r\nPlanning Delegation of Authority \r\nAuditing User Account Actions \r\nLab A Planning a Securitybased OU Structure \r\nReview \r\nModule 5: Secuing Windows 2000based Computers\r\nInstructor Notes \r\nOverview \r\nPlanning Physical Security fOr Windows 2000based Computers \r\nEvaluating Security Requirements \r\nDesigning Security Configuration Templates \r\nLab Af Analyzing a Security Template\r\nEvaluating Security Configuration\r\nDeploying Security Configuration Templates\r\nLab B: Designing Custondzed Security TemPlates \r\nReview \r\nModuIe 6:Securing FiIe and Print Resources \r\nInstructor Notes \r\nOverview\r\nExandning Windows 2000 File System Security \r\nProtecting Resources Using DACLs\r\nEncrypting Data Using EFS \r\nLab A:Managing EFS Recovery Keys\r\nAuditing Resource Access\r\nSecuring Backup and Restore Procedures \r\nProtecting Data frOm Viruses\r\nLab B Planning Data Security \r\nReview \r\nModuIe 7: Securing Cmmunication Channels \r\nInstructor Notes \r\nOverview \r\nAssessing Network Data Visibility Risks\r\nDesigning ApplicationLayer Security \r\nDesigning IPLayer Security \r\nDeploying Network Traffic Encryption\r\nLab A: Planning Transndssion Security \r\nReview \r\nModuIe 8:Providing Secure Access to NonMicrosoft CIier\r\nInstructor Notes \r\nOverview\r\nProviding Secure Network Access to UNIX Clients \r\nProviding Secure Network Access to NetWare Clients \r\nProviding Secure Access to Macintosh Clients \r\nSecuring Network Services in a Heterogeneous Network \r\nMonitoring for Security Breaches\r\nLab A: Securing Telnet Transndssions\r\nReview \r\nModuIe 9: Providing Secure Access to Remote Users \r\nInstructor Notes \r\nOverview \r\nIdentifying the Risks of Providing Remote Access \r\nDesigning Security fOr DialUp Connections \r\nDesigning Security for VPN Connections \r\nCentralizing Remote Access Security Settings\r\nLab A: Using RADIUS Authentication \r\nModuIe 10: Providing Secure Access to Remote Offices\r\nInstructor Notes \r\nOverview:\r\nDefining Private and Public Networks \r\nSecuring Connections Using Routers \r\nSecuring VPN Connections Between Remote Offices \r\nIdentifying Security Requirements \r\nLab A: Planning Secure Connections for Remote Offices \r\nReview \r\nModule 11:Providing Secure N6tWork Access to lnternot Users\r\nInstructOr NotCs t\r\nOverview t\r\nIdentifying POtential Risks from the Intemet \r\nUsing Firewalls to Protect Network Resources \r\nUsing Screened Subnets to Protect Network Resources\r\nSecuring PUblic Access tO a Screened Subnet\r\nLab A: Designing a Screened Subnet\r\nReview \r\nModuIe 12:Providing Secure lnt6rn6t Access to NatWork Users\r\nInstructor NotCs \r\nOverview*\r\nProtecting Internal Network Resources \r\nPlanning Intemet Usage Policies \r\nManaging lntemet Access Thrugh boxy Server Configuration\r\nManaging Intemet Access Thrugh Clientside Configuration \r\nLab Af Securing the Intemal Network When Accessing the Internet\r\nReview t\r\nMQdule 13: Extending the NetWork to Partner Organizations \r\nInstfuctor Notes \r\nOverview\r\nPrOviding Access to Partner Organizations \r\nSecuring Applications Used by Pedners\r\nSecuring Connections Used by Remote Partners\r\nSmicturing Active DirectOry to Manage Patner Accounts \r\nAuthenticating Pwtners from Trusted Domains \r\nLab A: Planning Partner Connectivity \r\nReview \r\nInstructor Notes \r\nOverview\r\nIntroducing a Public Key Infrastructure \r\nUsing Certificates \r\nExandning the Certificate Life Cycle \r\nChoosing a Certification Authority\r\nPlanning a Certification Authority Hierarchy\r\nMapping Certificates to User Accounts\r\nManaging CA Maintenance Strategies \r\nLab A: Using Certificatebased Authentication\r\nReview \r\nModule 15:DeveIoping a Security PIan \r\nInstructOr Notes\r\nOverview\r\nDesigning a Security Plan\r\nDefining Security Requirements\r\nMaintaining the Security Plan\r\nLab A: Developing a Security Plan \r\nReview \r\nAppendix A:SSL Port Assignments\r\nAppendix B:Acceptable lnternet Use Policy\r\nAppendix C:lnternet Explorer Security Settings