Preparation Guide for Exam 70-220

Designing Security for a Microsoft Windows 2000 Network

Updated: May 13, 2008

On This Page
Exam newsExam news
Audience profileAudience profile
Credit toward certificationCredit toward certification
Preparation tools and resourcesPreparation tools and resources
Skills measuredSkills measured

Exam news

Exam 70-220 became available on July 20, 2000.


Top of pageTop of page

Audience profile

Candidates for this exam operate in medium-sized to very large computing environments that use the Windows 2000 network operating system. They have a minimum of one year of experience implementing and administering network operating systems in environments that have the following characteristics:

Supported users range from 200 to more than 26,000.

Physical locations range from 5 to more than 150.

Typical network services and applications include file and print, database, messaging, proxy server or firewall, dial-in server, desktop management, and Web hosting.

Connectivity needs include connecting individual offices and users at remote locations to the corporate network and connecting corporate networks to the Internet.

Top of pageTop of page

Credit toward certification

When you pass the Designing Security for a Microsoft Windows 2000 Network exam, you achieve Microsoft Certified Professional status. You also earn credit toward the following certifications:

Core or elective credit toward Microsoft Certified Systems Engineer on Windows 2000 certification

Top of pageTop of page

Preparation tools and resources

In addition to your hands-on experience working with the product, we recommend that you use the following tools and training to help you prepare for this exam.

Classroom training for this exam

Course 2150: Designing a Security-Enhanced Microsoft Windows 2000 Network

Course 2153B: Implementing a Microsoft Windows 2000 Network Infrastructure

Course 2830: Designing Security for Microsoft Networks

Microsoft Press self-paced training products

MCSE Training Kit (Exam 70-220): Designing Microsoft Windows 2000 Network Security

Microsoft certified practice tests

MeasureUp: Visit the MeasureUp Web site to take a practice test.

Self Test Software: Visit the Self Test Software Web site to take a practice test.

Microsoft online resources

TechNet: Designed for IT professionals, this site includes how-to instructions, best practices, downloads, technical chats, and much more.

MSDN: The Microsoft Developer Network (MSDN) is a reference for developers. It features code samples, technical articles, newsgroups, chats, and more.

Training and certification newsgroups: There is a newsgroup for every Microsoft certification. By participating in the ongoing dialogue, you take advantage of a unique opportunity to exchange ideas with and ask questions of others, including more than 750 Microsoft Most Valuable Professionals (MVPs) worldwide.

Top of pageTop of page

Skills measured

This exam measures your ability to analyze the business requirements for security and design a security solution that meets business requirements. Security includes:

Controlling access to resources

Auditing access to resources

Authentication

Encryption

Before taking the exam, you should be proficient in the job skills listed in the following matrix. The matrix shows which Official Microsoft Learning Products may help you reach competency in the skills being tested in the exam.

KEY:The course provides a general introductory overview of this task. You will need to supplement the course with additional work. = The course provides a general introductory overview of this task. You will need to supplement the course with additional work.     The course includes some material to prepare you for this task. You will need to supplement the course with additional work. = The course includes some material to prepare you for this task. You will need to supplement the course with additional work.     The course includes material to prepare you for this task. = The course includes material to prepare you for this task.
Skills measured by Exam 70-220Course 2150Course 2153BCourse 2830
Analyzing Business Requirements    

Analyze the existing and planned business models.

Analyze the company model and the geographical scope. Models include regional, national, international, subsidiary, and branch offices.

Analyze company processes. Processes include information flow, communication flow, service and product life cycles, and decision-making.

 The course includes some material to prepare you for this task. You will need to supplement the course with additional work.


 The course includes material to prepare you for this task.

Analyze the existing and planned organizational structures. Considerations include management model; company organization; vendor, partner, and customer relationships; and acquisition plans.

The course provides a general introductory overview of this task. You will need to supplement the course with additional work.


 The course includes some material to prepare you for this task. You will need to supplement the course with additional work.

Analyze factors that influence company strategies.

Identify company priorities.

Identify the projected growth and growth strategy.

Identify relevant laws and regulations.

Identify the company's tolerance for risk.

Identify the total cost of operations.

The course provides a general introductory overview of this task. You will need to supplement the course with additional work.


 The course includes some material to prepare you for this task. You will need to supplement the course with additional work.

Analyze business and security requirements for the end user.

 The course includes material to prepare you for this task.

The course provides a general introductory overview of this task. You will need to supplement the course with additional work.

 The course includes material to prepare you for this task.

Analyze the structure of IT management. Considerations include type of administration, such as centralized or decentralized; funding model; outsourcing; decision-making process; and change-management process.

 The course includes some material to prepare you for this task. You will need to supplement the course with additional work.


 The course includes material to prepare you for this task.

Analyze the current physical model and information security model.

Analyze internal and external security risks.

 The course includes material to prepare you for this task.

 The course includes some material to prepare you for this task. You will need to supplement the course with additional work.

 The course includes material to prepare you for this task.

Analyzing Technical Requirements   

Evaluate the company's existing and planned technical environment.

Analyze company size and user and resource distribution.

Assess the available connectivity between the geographic location of work sites and remote sites.

Assess the net available bandwidth.

Analyze performance requirements.

Analyze the method of accessing data and systems.

Analyze network roles and responsibilities. Roles include administrative, user, service, resource ownership, and application.

 The course includes some material to prepare you for this task. You will need to supplement the course with additional work.


 The course includes material to prepare you for this task.

Analyze the impact of the security design on the existing and planned technical environment.

Assess existing systems and applications.

Identify existing and planned upgrades and rollouts.

Analyze technical support structure.

Analyze existing and planned network and systems management.

 The course includes some material to prepare you for this task. You will need to supplement the course with additional work.


 The course includes material to prepare you for this task.

Analyzing Security Requirements    

Design a security baseline for a Windows 2000 network that includes domain controllers, operations masters, application servers, file and print servers, RAS servers, desktop computers, portable computers, and kiosks.

 The course includes material to prepare you for this task.

 The course includes some material to prepare you for this task. You will need to supplement the course with additional work.

 The course includes some material to prepare you for this task. You will need to supplement the course with additional work.

Identify the required level of security for each resource. Resources include printers, files, shares, Internet access, and dial-in access.

 The course includes material to prepare you for this task.

 The course includes some material to prepare you for this task. You will need to supplement the course with additional work.

 The course includes material to prepare you for this task.

Designing a Windows 2000 Security Solution    

Design an audit policy.

 The course includes some material to prepare you for this task. You will need to supplement the course with additional work.


 The course includes material to prepare you for this task.

Design a delegation of authority strategy.

The course provides a general introductory overview of this task. You will need to supplement the course with additional work.


 The course includes material to prepare you for this task.

Design the placement and inheritance of security policies for sites, domains, and organizational units.

 The course includes material to prepare you for this task.


 The course includes material to prepare you for this task.

Design an Encrypting File System strategy.

 The course includes material to prepare you for this task.


 The course includes material to prepare you for this task.

Design an authentication strategy.

Select authentication methods. Methods include certificate-based authentication, Kerberos authentication, clear-text passwords, digest authentication, smart cards, NTLM, RADIUS, and SSL.

Design an authentication strategy for integration with other systems.

The course provides a general introductory overview of this task. You will need to supplement the course with additional work.


 The course includes material to prepare you for this task.

Design a security group strategy.

 The course includes material to prepare you for this task.


 The course includes material to prepare you for this task.

Design a Public Key Infrastructure.

Design Certificate Authority (CA) hierarchies.

Identify certificate server roles.

Manage certificates.

Integrate with third-party CAs.

Map certificates.

 The course includes some material to prepare you for this task. You will need to supplement the course with additional work.

 The course includes material to prepare you for this task.


Design Windows 2000 network services security.

Design Windows 2000 DNS security.

Design Windows 2000 Remote Installation Services (RIS) security.

Design Windows 2000 SNMP security.

Design Windows 2000 Terminal Services security.

 The course includes material to prepare you for this task.

 The course includes material to prepare you for this task.

The course provides a general introductory overview of this task. You will need to supplement the course with additional work.

Designing a Security Solution for Access Between Networks   

Provide security-enhanced access to public networks from a private network.

 The course includes material to prepare you for this task.

 The course includes some material to prepare you for this task. You will need to supplement the course with additional work.

 The course includes material to prepare you for this task.

Provide external users with security-enhanced access to private network resources.

 The course includes material to prepare you for this task.

 The course includes some material to prepare you for this task. You will need to supplement the course with additional work.

 The course includes material to prepare you for this task.

Provide security-enhanced access between private networks.

Provide security-enhanced access within a LAN.

Provide security-enhanced access within a WAN.

Provide security-enhanced access across a public network.

 The course includes material to prepare you for this task.

 The course includes some material to prepare you for this task. You will need to supplement the course with additional work.

 The course includes material to prepare you for this task.

Design Windows 2000 security for remote-access users.

 The course includes material to prepare you for this task.

 The course includes some material to prepare you for this task. You will need to supplement the course with additional work.

 The course includes some material to prepare you for this task. You will need to supplement the course with additional work.

Designing Security for Communication Channels    

Design an SMB-signing solution.

The course provides a general introductory overview of this task. You will need to supplement the course with additional work.


 The course includes material to prepare you for this task.

Design an IPSec solution.

Design an IPSec encryption scheme.

Design an IPSec management strategy.

Design negotiation policies.

Design security policies.

Design IP filters.

Define security levels.

 The course includes material to prepare you for this task.

 The course includes material to prepare you for this task.

 The course includes material to prepare you for this task.

Note This preparation guide is subject to change at any time without prior notice and at the sole discretion of Microsoft. Microsoft exams might include adaptive testing technology and simulation items. Microsoft does not identify the format in which exams are presented. Please use this preparation guide to prepare for the exam, regardless of its format.


Top of pageTop of page