Monday, 22 June 2015

Why are there still so many website vulnerabilities?

The cracks in the armor of most enterprise websites are many including recurring holes in OpenSSL, PHP, and WordPress and are largely due to a combination of extensive customizations paired with a shortage of testing and fixing of vulnerabilities when compared with that of long-standing commercial OS software.

CSO Magazine traverses the treacherous terrain of the massive security craters present in today’s websites. Find out what it takes to fix these holes from the start and throughout the development life cycle.
So many Website security punctures and protrusions

“The primary cause for constant and recurring website (and web application) vulnerabilities is the heavily-modified to fully custom-developed nature of these technologies,” says David J. Venable, CISSP, director, Masergy Communications & former intelligence collector, the NSA. The result is largely untested sites and applications that do not undergo the same rigorous and thorough testing that most commercial software packages such as operating systems and server packages do.
Lost in the clouds: Your private data has been indexed by Google

In fact, more vulnerabilities appear in websites and web applications than just about anywhere else in the enterprise. These security holes crop up in .PHP sites, third-party and homegrown software, and WordPress code and installations as well as in OpenSSL, Single Sign-On, and SQL and LDAP implementations and technologies.

PHP sites that use third-party software present inherent vulnerabilities due to the fact that third-party application development is out of the hands of the afflicted enterprise. “You can design your site so that all of your home-baked code is perfectly secure, but then if you rely on third-party software for anything, you inherit any vulnerability that might exist in it,” says Joe Sremack, director, Berkeley Research Group.
ADVERTISING

WordPress is a growing problem as sites that represent small to midsize enterprises increasingly incorporate it along with its countless plug-ins that require constant updating. “Companies want the WordPress functionality but unfortunately the risk also comes with it,” says Sremack.

OpenSSL is continuously running into trouble. As people innovate improvements to the technology, those innovations create new vulnerabilities that attackers discover and exploit. Attackers continue to exploit OpenSSL vulnerabilities new and old as part of large breaches a few times a year. Many seemingly new holes were actually old ones that had not yet been uncovered, says Sremack.
"Enterprises must adhere to security best practices such as those from the Open Web Application Security Project (OWASP) from the very start of the development process."

David J. Venable, CISSP, Director, Masergy Communications, & former intelligence collector, the NSA

Even when a coder produces an otherwise secure website, they are largely developing based on the vulnerabilities they are aware of, not the ones that no one has yet confirmed. There are always new vulnerabilities that appear for the first time in the wild.

Injection vulnerabilities are still common and attackers have adjusted how they approach these with the growing popularity of single sign-on. “Single sign-on is very popular at hotels where people check their accounts and the points they earn. New LDAP injection techniques attack vulnerabilities and pass parameters into the code to take over their web sessions,” explains Sremack.

Another website attack vector is the local and remote file inclusions. “A website’s code can call files either on a local server or on a remote public server. Using injection techniques, attackers can cause the site to display information from a password file or a list of usernames on the web server or to execute code that they want to run,” says Sremack. So the code calls that reach out from the website are also a way in for the attacker.
Fixing Website security holes

“Enterprises must adhere to security best practices such as those from the Open Web Application Security Project (OWASP) from the very start of the development process,” says Venable. All testing including web application assessments, pen tests, and static analysis should occur pre-production, after any code changes, and on at least an annual basis, according to Venable. Surround websites and web applications with WAFs and IDS and install a 24/7 monitoring team to identify and remediate attacks in real-time.

“During development, engage with the security team to perform regular tests of affected code and functionality,” says Sremack. If the enterprise is updating a current website, use the security team to test and ensure added capabilities have not added vulnerabilities. Teams inside development should also run scans and tests to isolate vulnerabilities and fix them.

“Rather than design around security, test using the same tools such as Grabber, W3AF, and Zed Attack Proxy that attackers use to break into your website,” says Sremack. Anyone, even with little knowledge of security or security tools can use these applications and gain insights into website vulnerabilities based on the outcomes of the tests, though the enterprise will need to dedicate a staff to this over time.

“Developers should specifically look at how they create and maintain web sessions, specifically checking any inputs that the sessions pass through the website, whether through URLs or input fields,” says Sremack, “then monitor any third-party code for vulnerabilities and watch for exploit announcements from the vendor.”
Final thoughts

The larger the site, the greater its functionality and visibility, and the more it uses third-party software, the more that the process of reducing inherent vulnerabilities in the site will be costly.

The enterprise must monitor and update the site several times a day to keep up with every new attack that cyber mercenaries will level against them using every new vulnerability they find, says Sremack. This process has to include change management, testing, and proper implementation as well as a new specialized security team and a designated testing site.

The more feature rich the site, the more it better be worth to the company in order to make it worth securing. “But there are a lot of open source freeware tools that any programmer can run that will help the developers to stay on top of new vulnerabilities and threats, even for homegrown code,” says Sremack. So all is not lost.

Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com

Thursday, 18 June 2015

How green is Amazon’s cloud?

Report gives Amazon a ‘D’ for energy efficiency; Google gets a ‘B’

Amazon Web Services has been under fire in recent weeks from a group of activist customers who are calling for the company to be more transparent in its usage of renewable energy.

In response, rather than divulge additional details about the source of power for its massive cloud infrastructure, the company has argued that using the cloud is much more energy efficient than customers powering their own data center operations.

But the whole discussion has raised the question: How green is the cloud?
In early June a pact of 19 AWS customers – including Hootsuite, Change.org and Tumblr - wrote Amazon Senior Vice President Andy Jassy requesting increased transparency in the company’s efforts to use clean energy.

The letter was in response to a report from environmental activist group Greenpeace, which singled out Amazon Web Services, saying “no company could do more” to help tech companies be more energy friendly than AWS. The company’s cloud platform hosts so many popular websites that any steps it takes to increase efficiency would benefit many other companies.

“Amazon Web Services is holding many of our favorite sites hostage to dirty energy,” the report notes. Specifically, it says AWS’s US East region, located in Virginia, houses 60% of the company’s servers and uses a mix of about one-third coal, one-third nuclear, one-fifth gas and only 2% renewable energy.

In response, the next week AWS announced plans to build an 80 megawatt solar farm in Virginia. Company officials are on the defensive again this week, releasing figures saying that overall, its cloud platform runs on 25% renewable energy, with a goal of using 40% renewable energy by 2016, and eventually 100% green power.

Greenpeace says that’s not enough. “It remains impossible for its customers or the public to benchmark any progress toward that goal, since the company refuses to disclose any of its energy data,” the report states.
amazon aws going green renewable

AWS officials argue that the simple fact that so many customers use the company’s cloud is saving energy. AWS is more efficient at running data centers compared to its customers, even if it uses fossil fuels to power those data centers, AWS Distinguished Engineer James Hamilton contends in a blog post.

AWS says customers use 77% fewer servers and 84% less power by running their workloads in its cloud compared to their own data centers. That creates an 88% reduction in carbon emissions for customers who use Amazon’s cloud, AWS Evangelist Jeff Barr’s blog post says.

Furthermore, the company’s US-West location in Oregon, its EU region in Frankfurt and its GovCloud region in the U.S. are what the company calls “carbon-neutral” – which refers to the practice of offsetting the amount of carbon the site is responsible for with the purchase of a corresponding number of carbon credits that fund green projects. And AWS is building a 150 megawatt wind farm in Indiana.

AWS isn’t alone in having work to do to become more environmentally-friendly. Competitor Google received higher grades from Greenpeace – the report gives Google a grade of B, while AWS got a D. Google has also committed to using 100% renewable energy too, although with no specific timeline. Google says about 35% of its operations are currently powered from green sources.

Microsoft, meanwhile stands somewhere in the middle between AWS and Google, receiving a C grade from Greenpeace. The company has committed to being 100% carbon-neutral.

“We know that 100% renewable energy is an ambitious goal that won’t be possible overnight,” the group of Amazon customers wrote. “While you pursue this journey, we would suggest some steps that will give us full confidence in AWS’ commitment to renewable energy.” Now there is more pressure than ever for the cloud to be green.

Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com

Monday, 8 June 2015

Exam 70-490 Recertification for MCSD: Windows Store Apps using HTML5

Exam 70-490 Recertification for MCSD: Windows Store Apps using HTML5

Published: 01 August 2014
Languages: English
Audiences: Developers
Technology: ASP.NET MVC
Credit towards certification: MCP, MCSD

Skills measured
This exam measures your ability to accomplish the technical tasks listed below.

Please note that the questions may test on, but will not be limited to, the topics described in the bulleted text.

Design Windows Store apps

Design the UI layout and structure
Evaluate the conceptual design; decide how the UI will be composed; design for the inheritance and re-use of visual elements (e.g. styles, resources); design for accessibility; decide when custom controls are needed; use the Hub App template

Develop Windows Store apps

Implement search

Provide search suggestions using the SearchPane and SearchBox control class; search and launch other apps; provide and constrain search within an app, including inside and outside of search charm; provide search result previews; implement activation from within search; configure search contracts

Implement Share in an app
Use the DataTransferManager class to share data with other apps; accept sharing requests by implementing activation from within Share; limit the scope of sharing using the DataPackage object; implement in-app Share outside of Share charm; use web links and application links

Integrate media features
Support DDS images; implement video playback; implement XVP and DXVA; implement TTS; implement audio and video playback using HTML5 DRM

Create the user interface
Implement WinJS controls

Flipview; flyout; grid layout; list layout; menu object; WebView; item container; repeater

Implement HTML layout controls
Implement layout controls to structure your layout; implement templates and bindings; support scrolling and zooming with CSS3; manage text flow and presentation, including overflow

Create layout-aware apps to handle windowing modes

Use CSS3 media queries to adapt to different devices; respond to changes in orientation; adapt to new windowing modes by using the ViewManagement namespace; manage setting for an apps view

Program user interaction

Notify users by using toast
Enable an app for toast notifications; populate toast notifications with images and text by using the ToastUpdateManager; play sounds with toast notifications; respond to toast events; control toast duration; configure and use Azure Mobile Services for push notifications

Manage security and data

Choose a data access strategy
Choose the appropriate data access strategy (file based; web service; remote storage, including Microsoft Azure storage and Azure Mobile Services) based on requirements

Retrieve data remotely
Use XHR or HttpClient to retrieve web services; set appropriate HTTP verb for REST; handle progress of data requests; consume SOAP/WCF services; use WebSockets for bidirectional communication

Manage Windows Authentication and Authorisation
Retrieve a user’s roles or claims; store and retrieve credentials by using the PasswordVault class; implement the CredentialPicker class; verify credential existence by using credential locker; store account credentials in app settings

Manage Web Authentication
Use the Windows.Security.Authentication.Web namespace; set up OAuth2 for authentication; CredentialPicker; set up single sign-on (SSO); implement credential roaming; implement the WebAuthenticationBroker class; support proxy authentication for enterprises

Develop Windows Store apps

Create background tasks
Implement the Windows.applicationmodel.background classes; implement WebUIBackgroundTaskInstance; create a background task to manage and preserve resources; create a background task to get notifications for an app; register the background task by using the BackgroundTaskBuilder class; prioritise tasks by using the Scheduler namespace

Discover and interact with devices

Capture media with the camera and microphone
Use CameraCaptureUI to take pictures or video, and configure camera settings; use MediaCapture to capture pictures, video and audio; configure camera settings; set media formats; handle media capture events; implement advanced photo capabilities, such as sequence mode, thumbnails and focus mode

Get data from sensors
Determine the availability of a sensor (Windows.devices.sensors); add sensor requests to the app manifest; handle sensor events; get sensor properties; determine location via GPS; enable geofencing

Implement device access
USB; Bluetooth; Human Interface Device (HID); 3D printer support; Point of Service (PoS) devices

Program user interaction
Implement Play To by using contracts and charms

Register an app for Play To; use PlayToManager stream media assets; register an app as a PlayToReceiver; programmatically implement PlayTo functionality

Notify users by using Windows Push Notification Service (WNS)

Authenticate with WNS; request, create and save a notification channel; call and poll the WNS; configure and implement push notifications by using Azure Mobile Services

Enhance the user interface

Design for and implement UI responsiveness
Choose an asynchronous strategy between web workers and promises; implement web workers; nest and chain promises; make custom functions promise-aware; improve interface performance by using the Scheduler namespace

Implement animations and transitions
Apply animations from the animation library (WinJS.UI.animation); create and customise animations and transitions by using CSS; apply transformations; create animations by using keypoints; apply timing functions; animate with the HTML5 < canvas > element

Manage data and security

Design and implement data caching

Choose which types of items (user data, settings, application data) in your app should be persisted to the cache based on requirements; choose when items are cached; choose where items are cached (Microsoft Azure, Azure Mobile Services, remote storage); select a caching mechanism; store data by using indexDB, LocalStorage, and SessionStorage

Save and retrieve files
Handle file streams; save and retrieve files by using the StorageFile and StorageFolder classes; set file extensions and associations; save and retrieve files by using file pickers and the folder picker; compress files to save space; access libraries and KnownFolders, for example, pictures, documents and videos; manage appearance of the file picker; improve searchability by using Windows Index; integrate OneDrive with apps; compare files; manage libraries

Secure application data
Encrypt data by using the Windows.Security.Cryptography namespace; enrol and request certificates; encrypt data by using certificates; revoke file permissions

Prepare for a solution deployment

Design and implement a test strategy
Design a functional test plan; implement a coded UI test; design a reliability test plan, including performance testing, stress testing, scalability testing and duration testing; simulate in-app purchases

Evaluate and configure for Windows Store deployment
Configure app options to submit to the Windows Store, such as age restrictions, privacy statement, permissions, images and contact information; create application files, resource files and application bundles; verify application readiness by using the Windows Application Certification Kit (WACK)


Wednesday, 27 May 2015

Windows 10: Which classic Microsoft default apps should be killed?

Windows 10: Which classic Microsoft default apps should be killed?
Based on what we’ve seen in Microsoft’s Windows 10 preview editions, here’s our take on which classic apps should be kept and which should be killed when the final version of Windows 10 ships.

Windows 10
One of the most important features in Windows 10 will be the ability to run Windows Store apps in resizable windows on the desktop environment. This will also cause redundancy with many of the classic default apps that have come preinstalled on previous versions of Windows. Based on what we’ve seen in Microsoft’s Windows 10 preview editions, here’s our take on which classic apps should be kept and which should be killed when the final version of Windows 10 ships.

Classic Calculator: KEEP
Windows 10 will have a new Calculator app with a revamped GUI to accommodate for resizing it in the desktop environment. It will have the same functions as the one that comes with Windows 8/8.1 (standard and scientific calculating, a unit converter), and add a mode for programmer calculations. Yet it still won’t be as full-featured as the old desktop Calculator application, which additionally has a statistics mode, and some extra tools, like for date and mortgage calculation. This trusty desktop Calculator is in Windows 8/8.1, but hasn’t shown up in the latest Windows 10 Insider Preview.

Notepad: KEEP
Most users who compose lines for the Windows command prompt appreciate the bare-bones and fast-running nature of this application. Sure, there are lots of third-party clones of Notepad that have more features, but if you really need such a thing, then you should be using a simple word processor anyway. Notepad has appeared in the Windows 10 Insider Preview, and it’ll probably be in the final release of the OS, which we think it should, as a callback to the history of Windows.

Paint: KEEP
Along with Notepad, this is the second classic Windows desktop application that we think should appear for the sake of tradition in the next Windows and versions beyond into infinity. (Microsoft added Fresh Paint to Windows 8/8.1, and it will probably return in Windows 10, but this painting app is really for touchscreens.) And, odd as this may sound, we hope Microsoft doesn’t change a thing at all about Paint: Its charm is its consistent lack of sophisticated features and simplicity throughout the years. Even though its tools are limited, the pixel art that talented people have managed to make with them have a retro appeal and cult following nowadays.

Silverlight: KILL
Microsoft’s streaming video technology never matched use numbers in the marketplace against Adobe’s Flash, but it was at one point the required plug-in for watching content protected by DRM on major sites, like Amazon and Netflix. Despite this, Microsoft no longer develops it and will cease support for it. Silverlight wasn’t pre-installed on Windows 8/8.1. What happened?

Over the last few years, there’s been a move away from relying on the closed, proprietary Flash and Silverlight, and, instead, using open formats to stream video. This includes an open standard for streaming DRM-locked video, which is supported by Chrome, Firefox, Safari, and even Internet Explorer.

Sound Recorder: KILL
This dead-simple desktop application has just one button to press to start and stop recording audio from your device’s mic. The app version of Sound Recorder works about as simply, and also includes a basic tool to edit your audio clips. Both versions of Sound Recorder come with Windows 8/8.1, and were also together in the early builds of Windows 10 Insider Preview, but the latest Insider Preview no longer has this old desktop application version.

Windows Fax and Scan: KILL

There’s an app named Scan in Windows 8/8.1 and the Windows 10 Insider Preview, it doesn’t do the same thing as this desktop app. Scan is for scanning in images from a scanner. Windows Fax and Scan is for sending and receiving faxes, and scanning in documents with your scanner to send out as faxes. It’s so old school that it requires your computer be plugged into a telephone line. Yes, that’s right: Your computer needs to have a dial-up modem. (To be fair, alternately, you can connect your computer to a fax server.) So, surely, Windows Fax and Scan will not return for Windows 10? We wouldn’t count against it. This application has shown up in the Windows 10 Insider Preview.

Windows Journal: KILL
Here’s a good example of a classic Windows desktop application that should be retired to let its better Windows Store app successor fully take over. The OneNote app effectively does the same things as Windows Journal, and more. OneNote has been preinstalled in the Windows 10 Insider Preview -- but so has Windows Journal. Windows Journal’s name perhaps failed to convey accurately what it was designed for: jotting down handwritten notes, and sketching doodles, with a digital pen. Although typed text can be entered onto a note, you do so by first adding a graphical element (a text box) and then typing. This application’s GUI also muddled perceptions of how you’re supposed to use it since it looks like one for a text editor.

Windows Media Player: KILL
At one time, Microsoft angled for this media player to be the main application in their grand vision of a Windows home media center. Now, it’s pretty much hidden under the Windows Accessories folder/group of Windows 8/8.1, which also comes with two apps for playing media. The simply named Music and Video also let users buy music, movies and TV shows as downloads or streams. The current Windows 10 Insider Preview includes new versions of these apps, called Music Preview and Video Preview. Since both apps will run under Windows 10 in resizable windows in the desktop environment, Microsoft should probably not include Windows Media Player in the final Windows 10 release.

WordPad: KEEP
Along with Notepad, WordPad is the other text editor that has been in recent versions of Windows including the Windows 10 Insider Preview. It’s a surprisingly capable, basic word processor. It has a decent font selection; line, paragraph and spacing adjustment; plus the ability to insert images into your document; and to save documents in RTF or Microsoft Office DOCX formats. It’s probably safe to assume that WordPad will be in Windows 10.

XPS Viewer: KILL
Like Silverlight, XPS was devised by Microsoft to compete against another Adobe format (this one being PDF), and, obviously, never achieved widespread adoption. Unlike Silverlight, Microsoft hasn’t officially stopped developing XPS, though they haven’t talked it in over six years. Both an application for viewing XPS documents (XPS Viewer) and a driver to print documents into the format (XPS Document Writer) come with Windows 8/8.1 and appear in the Windows 10 Insider Preview. We think it’s time that Microsoft quietly admit defeat and get rid of both things. When’s the last time, if ever, you’ve looked at an XPS document… or even knew what XPS was before reading this?


Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com

Friday, 22 May 2015

Exam 74-338 Lync 2013 Depth Support Engineer

Exam 74-338 Lync 2013 Depth Support Engineer

Published: 29 April 2013
Languages: English, Chinese (Simplified), French, German, Japanese, Portuguese (Brazil)
Audiences: IT professionals
Technology: Microsoft Lync Server 2013
Credit towards certification: MCP, Microsoft Specialist

Skills measured
This exam measures your ability to accomplish the technical tasks listed below. The percentages indicate the relative weight of each major topic area in the exam. The higher the percentage, the more questions you are likely to see on that content area in the exam.

Please note that the questions may test on, but will not be limited to, the topics described in the bulleted text.

Analyse and troubleshoot Enterprise Voice (25-30%)
Troubleshoot call setup and tear down

Troubleshoot internal phone calls (PC to PC), external phone calls (PC to Public Switched Telephone Network [PSTN]), inbound and outbound routing, network configuration and internal and external clients

Troubleshoot Voice quality issues

Analyse Call Detail Recording/Quality of Experience (CDR/QOE) logs, analyse call flow by using Snooper and troubleshoot third-party devices, QOS and network bandwidth

Troubleshoot Voice configuration

Analyse dial plans (normalisation, translation), analyse session management (trunk routing); analyse policies, routes and usages; and troubleshoot external connectivity (gateways, SBA, PBX, SBC, PSTN) and media bypass

Analyse Voice applications

Troubleshoot call park, response groups, unassigned numbers, Exchange voicemail, third-party applications, and LIS and E911 implementation

Troubleshoot unified communications (UC) devices and peripherals

Troubleshoot device update issues, device connectivity issues (LPE + non-LPE), PIN authentication issues, peripherals and VDI plug-in device pairing

Troubleshoot mobile devices

Troubleshoot mobile auto-discover issues, mobile device usage issues, mobile callback feature, push notification, call establishment and mobile conference data

Troubleshoot conferencing and application sharing (20-25%)

Troubleshoot AV

Troubleshoot multi-party video, conference network bandwidth, server resources, media relay and third-party interop

Troubleshoot dial-in conferencing

Troubleshoot Conferencing Auto Application (CAA), Client Access Server (CAS), contact objects and conference directories

Troubleshoot the conference life cycle

Troubleshoot web scheduler, multipoint control unit (MCU) health, simple URLs (join launcher), UC add-in for Microsoft Outlook, Lync Web Access (LWA) and content expiry

Troubleshoot data

Troubleshoot Microsoft PowerPoint presentation connections, WAC server configurations, dataproxy and WAC topology

Analyse and troubleshoot application sharing

Troubleshoot network issues, latency, external access, connectivity and configuration

Troubleshoot IM and Presence (20-25%)

Troubleshoot sign-in issues

Troubleshoot DNS, certificates, registration, network connectivity, authentication and auto-discover

Troubleshoot Presence

Troubleshoot aggregation (OOF, calendar, machine, user), enhanced privacy, subscriptions, contact list and privacy relationship

Troubleshoot federation

Troubleshoot XMPP, connectivity, Public IM connectivity (PIC), federation types (open, direct, enhanced), federation policy and legacy interop

Troubleshoot client configuration

Troubleshoot file transfer, policy assignment, URL filtering, client version filtering, GPO assignment and user photo

Troubleshoot Address Book

Troubleshoot normalisation, local versus web lookup, internal file download, external file download, Address Book generation and contact merge

Troubleshoot Persistent Chat

Troubleshoot policies and settings, connectivity, Persistent Chat compliance role, migration issues with earlier group chat and Persistent Chat performance

Troubleshoot infrastructure and tools (20-25%)

Troubleshoot high availability and resiliency
Perform a cut-over from one Lync pool to another and troubleshoot server storage replication; file-share replication by using DFS; single-server failure (Lync, SQL); data centre failure, including CMS; and branch survivability

Identify issues by using troubleshooting tools
Identify issues using CLSlogging Scenarios, demonstrate use of Snooper for database analysis, and identify issues using NetMonitor, OCS Logger, Event Viewer and Performance Monitor

Troubleshoot topology and dependent infrastructure
Troubleshoot database synchronisation issues, including SQL mirroring and LYSS replication, topology replication, IIS, user placement and role-based access control (RBAC) rights assignment

Who should take this exam?

Candidates for this exam are IT consultants or telecommunications professionals who provide product support services for unified communications solutions. Candidates should be able to translate a support call, resolve the issue and produce a knowledge-base article for future support references.

Candidates should have a minimum of two years of experience with Microsoft Lync technologies and be familiar with various deployments and configurations. Candidates should be proficient in Lync Server 2013 solutions for end users, endpoint devices, telephony, audio/video and web conferences, security and high availability. Candidates should also know how to monitor and troubleshoot Lync Server 2013 using Microsoft tools and third-party vendor tools.

In addition, candidates should be proficient with Active Directory Domain Services, data networks, and telecommunications standards and components that support the configuration of Lync Server 2013. Candidates should be familiar with the requirements for integrating Lync Server 2013 with Microsoft Exchange Server and Office 365.




QUESTION 1
You work for a company named ABC.com. Your role of Lync Administrator includes the
management of the Microsoft Lync Server 2013 infrastructure.
Two Windows Server 2012 servers named ABC-DB01 and ABC-DB02 run SQL Server 2012.
ABC-DB01 and ABC-DB02 host a mirrored database for the Lync Server Central Management
Store (CMS). ABC-DB01 currently has the principle database and ABC-DB02 currently has the
mirror database. The mirrored database does not use a witness instance.
You need to manually failover the mirrored database to enable you to perform maintenance on
ABC-DB01.
Which of the following Windows PowerShell cmdlets should you run?

A. Invoke-CsPooIFailover
B. Invoke-CsManagementStoreReplication
C. Invoke-CsBackupServiceSync
D. Invoke-CSManagementServerFailover

Answer: D

Explanation:


QUESTION 2
You work for a company named ABC.com. The company has a Microsoft Lync Server 2013
infrastructure that includes two Lync Server pools. Your role of Lync Administrator includes the
management of the Microsoft Lync Server 2013 infrastructure.
An Edge server named ABC-Edge1 is configured to use a pool named ABC-LyncPool1.ABC.com
as its next hop. You plan to failover to a second pool named ABC-LyncPool2.ABC.com. Before
failing over the pool, you need to reconfigure the next hop for ABC-Edge1 to be ABCLyncPool2.
ABC.com.
Which of the following Windows PowerShell cmdlets should you run?

A. Set-CsEdgeServer
B. Set- CsAVEdgeConfiguration
C. New-CsEdgeAllowList
D. Set-CsAccessEdgeConfiguration
E. Move-CsApplicationEndpoint

Answer: A

Explanation:


QUESTION 3
You work for a company named ABC.com. The company has two Active Directory sites in a
single Active Directory Domain Services domain named ABC.com. Your role of Lync
Administrator includes the management of the Microsoft Lync Server 2013 infrastructure.
The Lync infrastructure consists of a single pool named ABC-LyncPool1.ABC.com.
You have been asked to design a disaster recovery (DR) plan in the event of a failure of ABCLyncPool1.
ABC.com. Part of the DR plan would be to configure a backup pool.
Which three of the following Windows PowerShell cmdlets would you need to run to recover the
CMS (Central Management Store) and the Lync user accounts? (Choose three)

A. Set-CsManagementServer
B. Install-CsDatabase
C. Set-CsLocationPolicy
D. Move-CsManagementServer
E. Invoke-CSManagementServerFailover
F. Invoke-CsPoolFailover

Answer: B,D,F

Explanation:


QUESTION 4
You work for a company named ABC.com. The company has a single Active Directory Domain
Services domain named ABC.com. The company has a datacenter located in New York.
The New York datacenter hosts two Microsoft Lync Server 2013 pools named ABCLyncPool1.
ABC.com and ABC-LyncPool2.ABC.com. ABC-LyncPool1.ABC.com hosts the CMS
(Central Management Store). All of the company’s 70,000 users are enabled for Lync. Your role
of Lync Administrator includes the management of the Microsoft Lync Server 2013 infrastructure.
The servers in ABC-LyncPool1.ABC.com suffer irreparable hardware failure. You need to recover
the Lync environment by failing over ABC-LyncPool1.ABC.com. All users will be hosted
permanently on ABC-LyncPool2.ABC.com.
Which of the following Windows PowerShell cmdlets should you run? (Choose all that apply)

A. Invoke-CSManagementServerFailover
B. Invoke-CsPoolFailover
C. Invoke-CsManagementStoreReplication
D. Invoke-CsPoolFailover
E. Move-CsManagementServer
F. Install-CsDatabase

Answer: D,E,F

Explanation:


QUESTION 5
You work for a company named ABC.com. Your role of Lync Administrator includes the
management of the Microsoft Lync Server 2013 infrastructure.
You receive reports from users that they are sometimes unable to make outbound calls. You
discover that the failures are caused by there being no available trunks.
To help troubleshoot the issue, you plan to run performance monitor counters to monitor the total
number of calls and the total number of inbound calls to determine trunk usage.
Against which server should you run the performance monitor counters?

A. Edge Server
B. Front End Server
C. Database Server
D. Mediation Server

Answer: D

Explanation:

Saturday, 16 May 2015

70-341: Core Solutions of Microsoft Exchange Server 2013

70-341: Core Solutions of Microsoft Exchange Server 2013
Published: 15 January 2013
Languages: English, Chinese (Simplified), French, German, Japanese, Portuguese (Brazil)
Audiences: IT professionals
Technology: Microsoft Exchange Server 2013
Credit towards certification: MCP, MCSE

Skills measured
This exam measures your ability to accomplish the technical tasks listed below. The percentages indicate the relative weight of each major topic area in the exam. The higher the percentage, the more questions you are likely to see on that content area in the exam.

From July 2014, the questions on this exam include content covering Microsoft Exchange Server 2013 Service Pack 1.

Please note that the questions may test on, but will not be limited to, the topics described in the bulleted text.

Plan, install, configure and manage transport (25%)

Plan a high availability solution for common scenarios

Set up redundancy for intra-site scenarios; plan for SafetyNet; plan for shadow redundancy; plan for redundant MX records

Design a transport solution

Design inter-site mail flow; design inter-org mail flow; plan for Domain Secure/TLS; design Edge transport; design message hygiene solutions; design shared namespace scenarios

Configure and manage transport

Configure Edge servers; configure Send/Receive connectors; configure transport rules; configure accepted domains; configure email policies; configure Address Rewriting

Troubleshoot and monitor transport

Interpret message tracking logs and protocol logs; troubleshoot a shared namespace environment; troubleshoot SMTP mail flow; given a failure scenario, predict mail flow and identify how to recover; troubleshoot Domain Secure/TLS; troubleshoot the new transport architecture

Configure and manage hygiene

Manage content filtering; manage recipient filtering; manage SenderID; manage connection filtering; manage Spam Confidence Level (SCL) thresholds; manage anti-malware

Preparation resources

Transport high availability
Use an Edge Transport Server in Exchange 2013
Hygiene management

Install, configure and manage the mailbox role (25%)

Plan the mailbox role

Plan for database size and storage performance requirements; plan for virtualisation requirements and scenarios; plan mailbox role capacity and placement; design public folder placement strategy; validate storage by running JetStress

Configure and manage the mailbox role

Create and configure Offline Address Book (OAB); create and configure public folders; deploy mailbox server roles; design and create hierarchical address lists

Deploy and manage high availability solutions for the mailbox role

Create and configure a Database Availability Group (DAG); identify failure domains; manage DAG networks; configure proper placement of a file share witness; manage mailbox database copies

Monitor and troubleshoot the mailbox role

Troubleshoot database replication and replay; troubleshoot database copy activation; troubleshoot mailbox role performance; troubleshoot database failures; monitor database replication and content indexing

Develop backup and recovery solutions for the mailbox role and public folders

Manage lagged copies; determine most appropriate backup solution/strategy; perform a dial tone restore; perform item-level recovery; recover the public folder hierarchy; recover a mailbox server role

Create and configure mail-enabled objects

Configure resource mailboxes and scheduling; configure team mailboxes; configure distribution lists; configure moderation; configure a linked mailbox

Manage mail-enabled object permissions

Configure mailbox folder permissions; configure mailbox permissions; set up room mailbox delegates; set up team mailbox membership; set up auto-mapping; determine when to use Send As and Send On Behalf permissions

Preparation resources

Mailbox server
Database availability groups
Perform a dial tone recovery

Plan, install, configure and manage client access (25%)

Plan, deploy and manage a Client Access Server (CAS)

Design to account for differences between legacy CAS and Exchange CAS/CAF; configure Office web application

Plan and configure namespaces and client services

Design namespaces for client connectivity; configure URLs; plan for certificates; configure authentication methods; implement auto-discover for a given namespace

Deploy and manage mobility solutions

Deploy OWA for Devices; configure OWA policies; configure mobile device mailbox policies; configure Allow Block Quarantine (ABQ); deploy and manage Office Apps

Implement load balancing

Configure namespace load balancing; configure Session Initiation Protocol (SIP) load balancing; plan for differences between layer seven and layer four load balancing methods; configure Windows Network Load Balancing (WNLB)

Troubleshoot client connectivity

Troubleshoot Outlook Anywhere connectivity; troubleshoot POP/IMAP; troubleshoot authentication; troubleshoot web services; troubleshoot AutoDiscover; troubleshoot mobile devices

Preparation resources

Client access server
Clients and mobile
Load balancing

Design and manage an Exchange infrastructure (25%)

Plan for impact of Exchange on Active Directory services

Plan the number of domain controllers; plan placement of Global Catalogue (GC); determine DNS changes required for Exchange; prepare domains for Exchange; evaluate impact of schema changes required for Exchange; plan around Active Directory site topology

Administer Exchange workload management

Configure user workload policies; configure system workload policies; monitor system workload events; monitor user workload events

Plan and manage Role Based Access Control (RBAC)

Determine appropriate RBAC roles and cmdlets; limit administration using existing role groups; evaluate differences between RBAC and Active Directory split permissions; configure a custom-scoped role group; configure delegated setup

Design an appropriate Exchange solution for a given SLA

Plan for updates; plan for change management; design a solution that meets SLA requirements around scheduled downtime; design a solution that meets SLA requirements around RPO/RTO; design a solution that meets SLA requirements around message delivery

Preparation resources

Prepare Active Directory and domains
Exchange workload management
Planning for role-based access control




QUESTION 1
You need to prepare the environment for the implementation of phase 1.
What changes must be made to the environment before you can install Exchange Server 2013?

A. The operating system or service pack level of TexDC1 needs to be upgraded.
B. The Windows 2008 R2 domain controllers in Washington and Boston need to be upgraded.
C. A server running Exchange Server 2007 or Exchange Server 2010 needs to be installed in
Texas.
D. The PDC emulator role needs to be transferred to a domain controller in Washington or Boston.

Answer: A

Explanation:


QUESTION 2
You are evaluating whether the proposed Exchange solution will meet the current and future
capacity requirements.
You want to gather statistics about the current Exchange environment.
Which of the following tools would you use to determine the number of emails sent to and received
by the current users?

A. Remote Server Administration Tools.
B. Microsoft Exchange Server Profile Analyzer.
C. Microsoft Exchange Server Deployment Assistant.
D. ESEUtil.exe.
E. Microsoft Exchange Server Jetstress.

Answer: B

Explanation:


QUESTION 3
You need to apply the required size restriction to the mailboxes in the new environment.
Which of the following commands should you run?

A. Get-MailboxDatabase | Set-MailboxDatabase –ProhibitSendReceiveQuota
B. Get-MailboxDatabase | Set-Mailbox –ProhibitSendReceiveQuota
C. Get-Mailbox | Set-Mailbox –ProhibitSendReceiveQuota
D. Get-MailboxDatabase | Get-Mailbox | Set-Mailbox –ProhibitSendReceiveQuota

Answer: A

Explanation:


QUESTION 4
You are evaluating whether the proposed Exchange solution will meet the current and future
capacity requirements.
You want to gather statistics about the current Exchange environment.
Which of the following tools would you use to determine the number of IOPS (Input/Output
Operations Per Second) required for the mailbox database storage?

A. ESEUtil.exe.
B. Microsoft Exchange Server Jetstress.
C. Microsoft Exchange Server Deployment Assistant.
D. Exchange Mailbox Server Role Requirements Calculator.
E. SQL Server Analysis Services.

Answer: D

Explanation:


QUESTION 5
You need to install and configure anti-spam and antimalware filtering.
Which servers should you install the anti-spam agents and enable the anti-spam and antimalware
filtering? (Choose two).

A. You should install the anti-spam agents on the Client Access Servers only.
B. You should install the anti-spam agents on the Mailbox serversonly.
C. You should install the anti-spam agents on the Client Access Servers and the Mailbox Servers.
D. You should enable antimalware filtering on the Client Access Serversonly.
E. You should enable antimalware filtering on the Mailbox serversonly.
F. You enable antimalware filtering on the Client Access Servers and the Mailbox Servers.

Answer: B,E

Explanation:

Tuesday, 5 May 2015

Microsoft Exam 70-668, PRO: Microsoft SharePoint 2010, Administrator - See more at:

Microsoft MCTS 70-668
PRO: Microsoft SharePoint 2010, Administrator

Examination Details:

This certificate examination is all about Administrating Microsoft SharePoint. This certification was originated on July 12, 2010 and designed in different languages such as English, Japanese, Portuguese, German and French. It’s developed mainly for IT professionals who want to develop their career.

Audience Profile
Candidates for this exam are required to design and deploy SharePoint Online and on-premise SharePoint. The candidates can be senior administrators who act as the technical hear over a group of administrators. Applicants with minimum of two of experience of deployment, managing, administering, upgrading, designing and migrating are ideal.

Candidates are mainly required to plan, design, and maintain:
Infrastructure capacity
Disaster recovery and availability
Physical topologies and services architecture
Migration, coexistence, and upgrade
Farm performance and availability
Information architecture
Security and compliance requirements
Information search strategy integration
Deployment of Client application services

Applicants should have a deep understanding of:
Windows Power-Shell scripting
Performance concepts and Server availability
Authentication methods and Security concepts
Windows Server 2008
Active Directory administration
Networking infrastructure services (DNS and IIS)

Skills to be measured:
The applicants will be tested on the following topics. However, this is not an exhaustive list of topics and they might change and questions other than these areas can also be asked to evaluate the candidate’s knowledge.

Designing SharePoint’s Farm Topology (27 percent)
Designing a physical architecture.
Designing SharePoint integration with network infrastructure.
Designing logical taxonomy.
Planning for sandbox solutions.
Planning for farm deployment.
Planning for availability.

Planning SharePoint’s Deployment (26 percent)
Planning service applications.
Planning a SharePoint component strategy.
Planning an upgrade strategy.
Designing a migration strategy.
Designing security architecture.
Planning and deploying authentication methods.

Defining SharePoint’s Business Continuity and Operations Strategy (25 percent)
Designing a maintenance strategy.
Recommending provisioning strategies.
Establishing enterprise monitoring plan.
Planning SharePoint backup and restore.

Planning for Business Solutions (22 percent)
Defining search requirements.
Planning search topology.
Planning an enterprise search strategy.
Planning enterprise content management.
Planning for social computing and collaboration.
Planning for a business intelligence strategy

Preparation:
Microsoft offers an array of training resources. From classroom training to online sessions, they have it all. You can join forums, newsgroups and chats to take peers advice and talk to certified Microsoft professionals if you have any doubts regarding the course. Take up practice test to analyze where you stand and determine your weak areas. Microsoft recommends that you purchase the study material for clearing the exam with a high score. You will not be disappointed after purchasing the material which comes with money back guarantee.




Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com