Podcast
Questions and Answers
Which cloud delivery model provides the most management control to the user?
Which cloud delivery model provides the most management control to the user?
- SaaS
- IaaS (correct)
- XaaS
- PaaS
Which storage type is most suitable for storing unstructured data like images and videos in a cloud environment?
Which storage type is most suitable for storing unstructured data like images and videos in a cloud environment?
- Block Storage
- SAN Storage
- Object Storage (correct)
- DAS Storage
What is the primary purpose of an Application Pool in IIS?
What is the primary purpose of an Application Pool in IIS?
- To install server features
- To isolate web applications for improved reliability and security (correct)
- To configure website bindings
- To manage virtual directories
Which component is essential for running containers on Windows Server 2019?
Which component is essential for running containers on Windows Server 2019?
What is the function of LinuxKit in the context of Windows Server 2019?
What is the function of LinuxKit in the context of Windows Server 2019?
Which type of GPO configuration applies during computer startup?
Which type of GPO configuration applies during computer startup?
In PKI, what is the role of a Root CA?
In PKI, what is the role of a Root CA?
What protocol does 802.1X use to authenticate clients before granting network access?
What protocol does 802.1X use to authenticate clients before granting network access?
Which Microsoft Defender feature helps prevent ransomware attacks?
Which Microsoft Defender feature helps prevent ransomware attacks?
Why are hashes and checksums used in server administration?
Why are hashes and checksums used in server administration?
Which cloud delivery model allows developers to focus solely on application development without managing servers or infrastructure?
Which cloud delivery model allows developers to focus solely on application development without managing servers or infrastructure?
What is the purpose of Continuous Deployment (CD) in DevOps workflows?
What is the purpose of Continuous Deployment (CD) in DevOps workflows?
Which IIS component acts as an alias mapped to a physical directory on the server?
Which IIS component acts as an alias mapped to a physical directory on the server?
What is the significance of WebDAV in the context of IIS?
What is the significance of WebDAV in the context of IIS?
What is the purpose of a Container Image in Docker?
What is the purpose of a Container Image in Docker?
What type of container is required for Nano Server images in Windows Server 2019?
What type of container is required for Nano Server images in Windows Server 2019?
What is the primary function of Windows Subsystem for Linux (WSL)?
What is the primary function of Windows Subsystem for Linux (WSL)?
How do Group Policy Preferences differ from Group Policy Policies?
How do Group Policy Preferences differ from Group Policy Policies?
What is the purpose of a Public Key Certificate in PKI?
What is the purpose of a Public Key Certificate in PKI?
What is the function of a CRL (Certificate Revocation List) in PKI?
What is the function of a CRL (Certificate Revocation List) in PKI?
Which authentication protocol provides an encrypted tunnel for secure authentication in 802.1X?
Which authentication protocol provides an encrypted tunnel for secure authentication in 802.1X?
What is the primary function of WSUS (Windows Server Update Services)?
What is the primary function of WSUS (Windows Server Update Services)?
Which component of Microsoft Defender combines antivirus, firewall, and IPSec functionalities?
Which component of Microsoft Defender combines antivirus, firewall, and IPSec functionalities?
How can Windows Defender Firewall be configured?
How can Windows Defender Firewall be configured?
What is the purpose of WMI filters in Group Policy?
What is the purpose of WMI filters in Group Policy?
Which of the following is an example of a SaaS (Software as a Service) offering?
Which of the following is an example of a SaaS (Software as a Service) offering?
What is the main advantage of using Block Storage over Object Storage for databases?
What is the main advantage of using Block Storage over Object Storage for databases?
Which of the following is a key requirement for implementing Continuous Deployment?
Which of the following is a key requirement for implementing Continuous Deployment?
What is the function of the IIS Manager?
What is the function of the IIS Manager?
Which protocol is primarily used for real-time communication in web applications?
Which protocol is primarily used for real-time communication in web applications?
Nano Server images require Hyper-V isolation primarily for what reason?
Nano Server images require Hyper-V isolation primarily for what reason?
What is a 'distribution' (or 'distro') in the context of Linux containers?
What is a 'distribution' (or 'distro') in the context of Linux containers?
What is the purpose of the 'docker' command?
What is the purpose of the 'docker' command?
Which of the following best describes the term 'XaaS'?
Which of the following best describes the term 'XaaS'?
What role does the Docker Hub play in containerization?
What role does the Docker Hub play in containerization?
When would you typically use a subordinate CA in a PKI hierarchy?
When would you typically use a subordinate CA in a PKI hierarchy?
What is the purpose of auto-enrollment in the context of certificates?
What is the purpose of auto-enrollment in the context of certificates?
Which of the following is a function of the tool known as the 'Certificate Templates Console'?
Which of the following is a function of the tool known as the 'Certificate Templates Console'?
What information can be used to target GPOs when applying WMI filters?
What information can be used to target GPOs when applying WMI filters?
Which technology is used by WSUS for its internal database?
Which technology is used by WSUS for its internal database?
Flashcards
Cloud
Cloud
A global collection of internet-accessible servers, used for hosting Web apps and services, accessed via Web servers.
Cloud Providers
Cloud Providers
Examples include AWS, Azure, and Google Cloud, that host apps/services.
IaaS (Infrastructure as a Service)
IaaS (Infrastructure as a Service)
You rent virtualized computing resources (VMs, storage, networks). You manage OS, middleware, runtime, apps, and data.
PaaS (Platform as a Service)
PaaS (Platform as a Service)
Signup and view all the flashcards
SaaS (Software as a Service)
SaaS (Software as a Service)
Signup and view all the flashcards
XaaS
XaaS
Signup and view all the flashcards
Cloud Providers
Cloud Providers
Signup and view all the flashcards
Block Storage
Block Storage
Signup and view all the flashcards
Object Storage (BLOB)
Object Storage (BLOB)
Signup and view all the flashcards
Continuous Deployment (CD)
Continuous Deployment (CD)
Signup and view all the flashcards
IIS (Internet Information Services)
IIS (Internet Information Services)
Signup and view all the flashcards
Virtual Directory
Virtual Directory
Signup and view all the flashcards
Application Pools
Application Pools
Signup and view all the flashcards
CGI, ISAPI, ODBC
CGI, ISAPI, ODBC
Signup and view all the flashcards
SSI
SSI
Signup and view all the flashcards
WebSocket
WebSocket
Signup and view all the flashcards
WebDAV
WebDAV
Signup and view all the flashcards
Docker EE (Enterprise Edition)
Docker EE (Enterprise Edition)
Signup and view all the flashcards
Docker client
Docker client
Signup and view all the flashcards
Docker daemon
Docker daemon
Signup and view all the flashcards
Docker Hub
Docker Hub
Signup and view all the flashcards
Container Images
Container Images
Signup and view all the flashcards
LCOW (Linux Containers on Windows)
LCOW (Linux Containers on Windows)
Signup and view all the flashcards
LinuxKit
LinuxKit
Signup and view all the flashcards
WSL (Windows Subsystem for Linux)
WSL (Windows Subsystem for Linux)
Signup and view all the flashcards
GPOs (Group Policy Objects)
GPOs (Group Policy Objects)
Signup and view all the flashcards
Computer Configuration
Computer Configuration
Signup and view all the flashcards
User Configuration
User Configuration
Signup and view all the flashcards
Software Settings
Software Settings
Signup and view all the flashcards
Windows Settings
Windows Settings
Signup and view all the flashcards
Administrative Templates
Administrative Templates
Signup and view all the flashcards
Preferences
Preferences
Signup and view all the flashcards
Policies
Policies
Signup and view all the flashcards
Public Key Infrastructure (PKI)
Public Key Infrastructure (PKI)
Signup and view all the flashcards
CA (Certificate Authority)
CA (Certificate Authority)
Signup and view all the flashcards
Root CA
Root CA
Signup and view all the flashcards
Subordinate CA
Subordinate CA
Signup and view all the flashcards
Public Key Certificate
Public Key Certificate
Signup and view all the flashcards
Digital Signature
Digital Signature
Signup and view all the flashcards
Study Notes
Cloud Basics
- Cloud refers to a global network of internet accessible servers
- These servers are used for hosting web apps and services
- Access is facilitated through web servers, such as IIS, operating on cloud virtual machines (VMs)
Cloud Providers
- Examples of cloud providers: AWS, Azure, and Google Cloud
- Cloud providers host applications and services through IaaS, PaaS, and SaaS
- They can host services publicly or privately
- Hybrid cloud environments, combining on-premises infrastructure with public cloud, are also an option
Cloud Delivery Models
- IaaS (Infrastructure as a Service): Requires renting virtualized computing resources like VMs, storage, and networks, while managing the OS, middleware, runtime, apps, and data (e.g., Azure VM)
- PaaS (Platform as a Service): Focuses on application development, with the provider managing everything else like Azure App Services and Google App Engine
- SaaS (Software as a Service): Provides fully managed software accessed via the web, exemplified by Google Workspace and Microsoft 365
- XaaS: Is a general term for "Anything as a Service"
Cloud Storage Types
- Block Storage: Structured like a virtual hard drive, faster performance making it ideal for databases and virtual machines
- Object Storage (BLOB): Stores files as objects with metadata and is suitable for unstructured data like images and videos
- Binary Large Object (BLOB): File types stored in object storage, such as audio and images
Continuous Deployment (CD)
- Automated to build, test, and deploy code
- Requires code repositories (e.g., GitHub), build automation tools (e.g., Jenkins, GitLab CI), and orchestration tools
- CD is a key part of DevOps workflows
Internet Information Services (IIS)
- Web server software to host websites and apps on Windows Server
- Installed via Server Manager or PowerShell
- IIS Manager provides a GUI for configuration
- Supports protocols like HTTP/S, FTP, WebDAV and WebSocket
- An open-source alternative to IIS is Apache Web Server
IIS components
- Virtual Directory: Logical pointer to a physical folder on disk, allowing web apps to be accessed via structured URLs.
- Application Pools: Isolate apps for reliability and security where each pool has its own worker process (w3wp.exe).
Supported Interfaces & Extensions
- CGI, ISAPI, ODBC provide support for dymanic content
- SSI includes extrenal content in pages
- WebSocket allows for persistent two way communication
- WebDAV enables web based file management
Web App Technologies
- Web App Frameworks include: Django, Node.js and ASP.NET
- Web app files include: HTML, CGI and ISAPI
Containers on Windows Server 2019
- Docker EE (Enterprise Edition) is required to run containers
- The docker command in the CLI pulls images, runs containers, and manages apps
- Types of containers are Windows Containers, Hyper-V Containers and Linux Containers on Windows (LCOW)
- Nano Server requires Hyper-V isolation
Docker EE Components
- Docker client is a CLI tool to interact with Docker
- Docker daemon manages containers/images
- Docker Hub is a public registry for images
Container Images
- Container images are immutable and executable
- Container Image is a read only snapshot used to create a container
Linux Containers on Windows (LCOW) & LinuxKit
- LCOW is for running Linux containers on Windows
- LinuxKit is a toolkit to build minimal Linux OS for containers
Windows Subsystem for Linux (WSL)
- Runs Linux distros directly on Windows
- Allows to run Linux native web apps
- Choose a distro (like Ubuntu) via Microsoft Store
Group Policy
- GPOs (Group Policy Objects): Control configuration of users and computers
- Edit using Group Policy Management Editor
- Linked to Sites, Domains, or OUs
Configuration Types
- Computer Configuration: Applies during boot and affects system-level settings
- User Configuration: Applies at logon and affects user profiles
GPO Categories
- Software Settings: Install/manage applications
- Windows Settings: Scripts, security settings, folder redirection
- Administrative Templates: Registry-based policies
Preferences vs Policies
- Preferences: User can override, more flexible
- Policies: Enforced and user cannot override
Certificates and PKI
- PKI (Public Key Infrastructure) establishes trust using certificates
PKI Components
- CA (Certificate Authority): Issues and verifies certs
- Root CA: Top-level, must be trusted
- Subordinate CA: Issues certs on behalf of root
Certificate Concepts
- Public Key Certificate: Binds a public key to an identity
- Digital Signature: Verifies authenticity/integrity
- Auto-Enrollment: Users/computers get certs automatically via GPO
Tools & Concepts
- Certificate Templates Console
- CA Hierarchy: Trust chain structure
- CRL / OCSP: Used to check revocation status
Network Security & Updates
- 802.1X
- Wired & Wireless security protocol
- Works with RADIUS to authenticate clients before granting access
- PEAP is an encrypted authentication tunnel
- WSUS (Windows Server Update Services)
- Local management of Windows updates
- GPOs configure when/how clients check WSUS
- Microsoft Defender
- Antivirus, firewall, and IPSec in one
- Controlled Folder Access prevents ransomware
- Core Isolation / Memory Integrity protects from kernel-level threats
Other Important Concepts & Tools
- Windows Defender Firewall
- Controlled via Group Policy or Windows Defender Firewall with Advanced Security
- Configure firewall rules, connection security rules (IPSec)
- Windows Installer & Internal Database
- Used for deploying apps via GPO
- WID is used by WSUS
- Hashes & Checksums
- Used for verifying file integrity
- SHA/MD5 common in digital signatures
- WMI Filters
- Target GPOs based on system attributes (e.g., OS version)
Key Terms
- Docker EE: Enterprise container platform
- Container Image: Blueprint for creating containers
- Orchestration: Automates deployment/management of containers
- LCOW: Linux Containers on Windows
- WebDAV: Edit/manage files over HTTP
- ISAPI/CGI: Interfaces for server-side processing
- Virtual Directory: Alias to a physical folder in IIS
- Application Pool: Isolated environment for web apps
- BLOB Storage: Stores unstructured data (media, files)
- Distribution (Distro): A version of a Linux OS
- WSL: Run Linux on Windows natively
Studying That Suits You
Use AI to generate personalized quizzes and flashcards to suit your learning preferences.