Question 1
What static IPv4 address and subnet were assigned to the DMZ interface?
Correct Answer:
172.16.1.1/16
Explanation:
Isolating the DMZ relies on placing its devices on a dedicated private subnet and giving the interface a static address within that subnet. In this setup, the DMZ uses the 172.16.0.0/16 private range, so the DMZ interface should have an address that falls inside 172.16.0.0 to 172.16.255.255 with a 255.255.0.0 mask. The address 172.16.1.1 with a /16 (255.255.0.0) mask fits exactly into that DMZ subnet, making it a proper static address for the DMZ interface. The other options place the interface on different private subnets (for example, 192.168.0.0/24, 10.0.0.0/8, or 172.30.0.0/16), which do not correspond to the designated DMZ network in this configuration.
Question 2
Which BIOS action must be performed to enable BitLocker on the OS drive in this lab?
Correct Answer:
Turn on and activate TPM Security
Explanation:
BitLocker on the OS drive uses the TPM to securely store the encryption keys and to verify boot integrity. The TPM provides hardware-backed protection so the encryption key remains with the hardware, making it much harder for an attacker to access the data if the drive is moved to another system or tampered with during boot. Because of this, the BIOS/UEFI must have the TPM enabled and activated (and initialized) so Windows can take ownership of the TPM and use it to protect the BitLocker key. That’s why turning on and activating TPM security is the required step. Enabling Secure Boot helps with boot integrity and overall security, but BitLocker can work without it, so it’s not strictly required to enable BitLocker. Disabling the TPM would prevent TPM-backed protection, potentially forcing BitLocker into a less secure software-only mode. Setting the BIOS to Legacy Boot bypasses UEFI features that BitLocker often relies on, and is not necessary for enabling BitLocker on the OS drive.
Question 3
Explain the NTFS permissions model and the difference between DACL and SACL.
Correct Answer:
DACL controls access to files/folders; SACL controls auditing
Explanation:
NTFS permissions revolve around two control lists attached to every file or folder. The DACL, or Discretionary Access Control List, defines who is allowed or denied access and what they can do with the object. Each entry specifies a user or group and the rights granted or denied (such as read, write, modify, or full control). The system evaluates a user’s identity and group memberships against this list, applying deny entries first and then allow entries, with the owner or an administrator able to modify the DACL at will. That flexibility is why it’s called discretionary. The SACL, or System Access Control List, handles auditing. It lists which access attempts should be recorded in the security audit log and whether successes, failures, or both should be logged. Importantly, the SACL does not change whether access is granted or denied; it only determines what events are remembered for monitoring and forensic purposes. So the key difference is that the DACL controls access decisions—who can do what with the object—while the SACL controls auditing of those access attempts. The other statements mix up these roles or introduce unrelated concepts like encryption or static behavior, which do not describe what DACLs or SACLs do.
Question 4
Which path allows restricting a user's logon to specific computers?
Correct Answer:
Account tab → Logon Hours
Explanation:
Restricting where a user can log on is controlled by a per-user setting that specifies which machines they may log on from. This is configured on the Account tab of the user’s properties, using the Log On To option to list the computers the user is allowed to log on to. This directly enforces login restrictions to designated devices. By comparison, Logon Hours controls when logon is allowed, not where; the Security tab focuses on permissions and access rights, not the computers a user can log on from; and a separate Login Restrictions path on the User tab isn’t the mechanism used here. So to limit a user’s logon to specific computers, use the Log On To setting on the Account tab.
Question 5
In the email filtering lab, which setting ensures only emails from the safe senders list are allowed?
Correct Answer:
Exclusive
Explanation:
This tests how strict the allowlist (safe senders list) policy is in email filtering. The safe senders list is an allowlist of trusted addresses. The Exclusive setting enforces a deny-all-else approach, meaning only emails from addresses on that safe senders list are allowed and anything not on the list is blocked. The other levels are less strict, letting non-listed senders through under some conditions, so they don’t guarantee that only safe-sender messages pass. So the setting that achieves an only-allowlisted pass is Exclusive.
Question 1
Exam overview

About this Exam

Prepare with the TestOut Labs Practice Test practice quiz. This question bank includes 10 questions covering configured, network, static, testout, and labs. Use it to review important concepts, identify knowledge gaps, and build confidence for the related exam, course, or assessment.

More details

Additional Information

TestOut Labs Practice Test

This practice set contains 10 questions from the matching question bank and focuses on configured, network, static, testout, and labs. Work through each question carefully, review the provided solutions, and revisit topics that need more study before your next attempt.

This is an independent study resource intended for practice and review; it is not an official examination or an endorsement by any organization named in the title.

Quiz information

Frequently Asked Questions

The complete question count is available after full access is unlocked.
No fixed duration is currently configured for this quiz.
Question explanations are included where they are available in the quiz content, helping you review the reasoning after answering.
Yes. You can retake the practice test again as you continue studying during your available access period.
After your access is confirmed, you can continue into the complete practice exam from this quiz flow.
Unless explicitly stated otherwise, this page provides independent practice material for study and exam preparation and is not the official examination itself.
Keep studying

Related Questions