Cisco CCIP 642-691 answer question

You are planning a security template for an Internet Authentication Service (IAS) server that is to be located on your company’s perimeter network (also known as DMZ, 642-481 demilitarized zone, and screened subnet) LAN. Users will authenticate against the server with their domain accounts. The internal firewall has been configured to allow necessary traffic between the IAS server and the organization’s domain controllers. At present, you are considering which services the template should start automatically. The template will be configured so that all services that are not critical to the function of the IAS server will be disabled. Which of the following services is critical for the function of an IAS server? 642-524 (Select all that apply.)

  1. Certificate Services

  2. Background Intelligent Transfer Service

  3. Distributed Link Tracking Server

  4. Netlogon 350-018

  5. IAS service

    Correct Answers: D and E

    1. Incorrect Certificate Services is critical for the function of a Certificate Server, but not for an IAS server. 70-630

    2. Incorrect The Background Intelligent Transfer Service is not used by an IAS server.

    3. Incorrect Distributed Link Tracking Server is used for tracking linked files across NTFS drives and has nothing to do with running an IAS server. n10-003

    4. Correct Netlogon maintains a secure channel between the IAS server and a domain controller so that authentication can occur against domain accounts.

    5. Correct The IAS Service forms the core of an IAS server’s functions, and hence is mandatory in any security template supporting the IAS server role. 642-691

Leave a Reply