Study Guide 70-744

Info from the https://www.microsoft.com/en-us/learning/exam-70-744.aspx

Configure disk and file encryption
Determine hardware and firmware requirements for secure boot and encryption key functionality; deploy BitLocker encryption; deploy BitLocker without a Trusted Platform Module (TPM); deploy BitLocker with a TPM only; configure the Network Unlock feature; configure BitLocker Group Policy settings; enable Bitlocker to use secure boot for platform and BCD integrity validation; configure BitLocker on Clustered Shared Volumes (CSVs) and Storage Area Networks (SANs); implement BitLocker Recovery Process using self-recovery and recovery password retrieval solutions; configure BitLocker for virtual machines (VMs) in Hyper-V; determine usage scenarios for Encrypting File System (EFS); configure the EFS recovery agent; manage EFS and BitLocker certificates, including backup and restore
Secure boot on virtual machines: https://blogs.technet.microsoft.com/dubaisec/2016/03/29/secure-boot-on-virtual-machines/
Secure boot overview: https://technet.microsoft.com/en-us/library/hh824987.aspx
Bitlocker Encrypted CSV: https://technet.microsoft.com/en-us/library/dn383585(v=ws.11).aspx
Bitlocker FAQ: https://technet.microsoft.com/en-us/library/hh831507(v=ws.11).aspx
Bitlocker Self-Service: https://technet.microsoft.com/en-us/itpro/mdop/mbam-v2/how-to-use-the-self-service-portal-to-regain-access-to-a-computer

Install and configure Windows Server Update Services (WSUS), manage updates using WSUS, create computer groups, configure update approvals and deployments, configure automatic updates, configure WSUS reporting, troubleshoot WSUS configuration and deployments
Install and Configure WSUS 2016: https://technet.microsoft.com/en-us/windows-server-docs/management/windows-server-update-services/deploy/deploy-windows-server-update-services
WSUS Configuration guide: https://technet.microsoft.com/en-us/windows-server-docs/management/windows-server-update-services/manage/update-management-with-windows-server-update-services

Implement malware protection
Implement antimalware solution with Windows Defender, integrate Windows Defender with WSUS and Windows Update, configure Windows Defender using Group Policy, configure Windows Defender scans using Windows PowerShell, implement AppLocker rules, implement AppLocker rules using Windows PowerShell, implement Control Flow Guard, implement Code Integrity (Device Guard) Policies, create Code Integrity policy rules, create Code Integrity file rules
Windows Defender setup: https://technet.microsoft.com/en-us/windows-server-docs/security/windows-defender/windows-defender-overview-windows-server

Protect credentials
Determine requirements for implementing Credential Guard; configure Credential Guard using Group Policy, WMI, command prompt, and Windows PowerShell; implement NTLM blocking
Credential Guard: https://technet.microsoft.com/en-us/itpro/windows/keep-secure/credential-guard

Create security baselines
Install and configure Security Compliance Manager (SCM); create, view, and import security baselines; deploy configurations to domain and non-domain joined servers

 

Implement a Guarded Fabric solution
Install and configure the Host Guardian Service (HGS), configure Admin-trusted attestation, configure TPM-trusted attestation, configure the Key Protection Service using HGS, migrate Shielded VMs to other guarded hosts, configure Nano Server as TPM attested guarded host, troubleshoot guarded hosts
Implement Host Guardain Service: https://blogs.technet.microsoft.com/datacentersecurity/2016/03/16/windows-server-2016-and-host-guardian-service-for-shielded-vms/
Host guardian blog: https://blogs.technet.microsoft.com/datacentersecurity/category/host-guardian-service/
Configure Hyper-V for host guardian: https://technet.microsoft.com/en-us/windows-server-docs/security/guarded-fabric-shielded-vm/guarded-fabric-configure-hgs-with-authorized-hyper-v-hosts

Implement Shielded and encryption-supported VMs
Determine requirements and scenarios for implementing Shielded VMs, create a Shielded VM using only a Hyper-V environment, enable and configure vTPM to allow an operating system and data disk encryption within a VM, determine requirements and scenarios for implementing encryption-supported VMs, troubleshoot Shielded and encryption-supported VMs
Implement Shielded-VMs: https://technet.microsoft.com/en-us/windows-server-docs/security/guarded-fabric-shielded-vm/guarded-fabric-configuration-scenarios-for-shielded-vms-overview

 

Configure Windows Firewall
Configure Windows Firewall with Advanced Security; configure network location profiles; configure and deploy profile rules; configure firewall rules for multiple profiles using Group Policy; configure connection security rules using Group Policy, the GUI management console, or Windows PowerShell; configure Windows Firewall to allow or deny applications, scopes, ports, and users using Group Policy, the GUI management console, or Windows PowerShell; configure authenticated firewall exceptions; import and export settings
Windows Firewall configuration using Powershell: http://windowsitpro.com/windows-server-2012/controlling-windows-firewall-powershell

Implement a software-defined Distributed Firewall
Determine requirements and scenarios for Distributed Firewall implementation with software-defined networking, determine usage scenarios for Distributed Firewall policies and network security groups
Distributed Firewall Overview: https://technet.microsoft.com/en-us/windows-server-docs/networking/sdn/technologies/network-function-virtualization/datacenter-firewall-overview

Secure network traffic
Configure IPsec transport and tunnel modes, configure IPsec authentication options, configure connection security rules, implement isolation zones, implement domain isolation, implement server isolation zones, determine SMB 3.1.1 protocol security scenarios and implementations, enable SMB encryption on SMB Shares, configure SMB signing via Group Policy, disable SMB 1.0, secure DNS traffic using DNSSEC and DNS policies, install and configure Microsoft Message Analyzer (MMA) to analyze network traffic
SMB 3.1.1 encryption: https://blogs.msdn.microsoft.com/openspecification/2015/09/09/smb-3-1-1-encryption-in-windows-10/
Disable SMB 1 https://blogs.technet.microsoft.com/filecab/2016/09/16/stop-using-smb1/
DNSSEC: https://technet.microsoft.com/en-us/library/dn593684(v=ws.11).aspx
DNS Policies: https://technet.microsoft.com/en-us/windows-server-docs/networking/dns/deploy/dns-policies-overview
Microsoft Message Analyzer Download: https://www.microsoft.com/en-us/download/details.aspx?id=44226
SMB Signing http://www.windowsecurity.com/articles-tutorials/misc_network_security/Secure-SMB-Connections.html

 

Implement an Enhanced Security Administrative Environment (ESAE) administrative forest design approach
Determine usage scenarios and requirements for implementing ESAE forest design architecture to create a dedicated administrative forest, determine usage scenarios and requirements for implementing clean source principals in an Active Directory architecture
Enhanced Security Administrative Enviroment: http://download.microsoft.com/download/A/C/5/AC5D21A6-E04B-4DC4-B1F2-AE060319A4D7/Premier_Support_for_Security/Popis/Enhanced-Security-Admin-Environment-Solution-Datasheet-[EN].pdf
ESAE design principle: https://technet.microsoft.com/en-us/windows-server-docs/security/securing-privileged-access/securing-privileged-access-reference-material#a-nameesaebmaesae-administrative-forest-design-approach

Implement Just-in-Time (JIT) Administration
Create a new administrative (bastion) forest in an existing Active Directory environment using Microsoft Identity Manager (MIM), configure trusts between production and bastion forests, create shadow principals in bastion forest, configure the MIM web portal, request privileged access using the MIM web portal, determine requirements and usage scenarios for Privileged Access Management (PAM) solutions, create and implement MIM policies, implement Just-in-Time administration principals using time-based policies, request privileged access using Windows PowerShell
JIT and PAM: https://docs.microsoft.com/en-us/microsoft-identity-manager/pam/privileged-identity-management-for-active-directory-domain-services

Implement Just-Enough-Administration (JEA)
Enable a JEA solution on Windows Server 2016; create and configure session configuration files, create and configure role capability files, create a JEA endpoint, connect to a JEA endpoint on a server for administration, view logs, download WMF 5.1 to a Windows Server 2008 R2, configure a JEA endpoint on a server using Desired State Configuration (DSC)
Just-Enough-Administration samples and resources: https://github.com/PowerShell/JEA

Implement Privileged Access Workstations (PAWs) and User Rights Assignments
Implement a PAWS solution, configure User Rights Assignment group policies, configure security options settings in Group Policy, enable and configure Remote Credential Guard for remote desktop access
Privileged Access Workstation: https://technet.microsoft.com/en-us/windows-server-docs/security/securing-privileged-access/privileged-access-workstations
Credential Guard: https://technet.microsoft.com/en-us/itpro/windows/keep-secure/credential-guard

Implement Local Administrator Password Solution (LAPS)
Install and configure the LAPS tool, secure local administrator passwords using LAPS, manage password parameters and properties using LAPS
LAPS Download: https://www.microsoft.com/en-us/download/details.aspx?id=46899
Setup LAPS: https://4sysops.com/archives/set-up-clients-for-microsoft-laps-local-administrator-password-solution/

 

Configure advanced audit policies
Determine the differences and usage scenarios for using local audit policies and advanced auditing policies; implement auditing using Group Policy and AuditPol.exe; implement auditing using Windows PowerShell; create expression-based audit policies; configure the Audit PNP Activity policy; configure the Audit Group Membership policy; enable and configure Module, Script Block, and Transcription logging in Windows PowerShell
Audit policieS: https://technet.microsoft.com/en-us/windows-server-docs/identity/ad-ds/plan/security-best-practices/audit-policy-recommendations
Security Audit: https://technet.microsoft.com/en-us/windows-server-docs/security/access-control/security-auditing-overview

Install and configure Microsoft Advanced Threat Analytics (ATA)
Determine usage scenarios for ATA; determine deployment requirements for ATA, install and configure ATA Gateway on a dedicated server, install and configure ATA Lightweight Gateway directly on a domain controller, configure alerts in ATA Center when suspicious activity is detected, review and edit suspicious activities on the attack time line
Requirements and configuraiton of Microsoft ATA https://docs.microsoft.com/en-us/advanced-threat-analytics/

Determine threat detection solutions using Operations Management Suite (OMS)
Determine usage and deployment scenarios for OMS, determine security and auditing functions available for use; determine Log Analytics usage scenariosGet Started with threat detection and audit on Microsoft OMS: https://azure.microsoft.com/en-us/documentation/articles/oms-security-getting-started/
Threat detection in OMS: https://blogs.technet.microsoft.com/msoms/2016/08/03/operations-management-suite-oms-adds-security-analytics-to-power-threat-detection/

Secure application development and server workload infrastructure
Determine usage scenarios, supported server workloads, and requirements for Nano Server deployments; install and configure Nano Server; implement security policies on Nano Servers using Desired State Configuration (DSC); determine usage scenarios and requirements for Windows Server and Hyper-V containers; install and configure Hyper-V containers

Security CMDlets on Nano Server: https://blogs.msdn.microsoft.com/powershell/2016/05/09/new-security-cmdlets-in-nano-server/
Install Nano Server: https://technet.microsoft.com/en-us/windows-server-docs/get-started/getting-started-with-nano-server
DSC on Nano Server: https://msdn.microsoft.com/en-us/powershell/dsc/nanodsc

Implement a secure file services infrastructure and Dynamic Access Control (DAC)
Install the File Server Resource Manager (FSRM) role service, configure quotas, configure file screens, configure storage reports, configure file management tasks, configure File Classification Infrastructure (FCI) using FSRM, implement work folders, configure file access auditing, configure user and device claim types, implement policy changes and staging, perform access-denied remediation, create and configure Central Access rules and policies, create and configure resource properties and lists
Dynamic Access Control: Scenario Overview: https://technet.microsoft.com/en-us/windows-server-docs/identity/solution-guides/dynamic-access-control–scenario-overview
Access denied remediation: https://technet.microsoft.com/en-us/windows-server-docs/identity/solution-guides/scenario–access-denied-assistance