DCM

Device Management and Configuration

Domain 1: Windows Installation & Configuration

·         A computer cannot function without an operating system. It allows the user to communicate with the device and responsible for storing files running software and connecting to the internet.

·         Automatically, computers are loaded with one or a product key. A product key is a code which is used to activate the operating system and verifies it hasn’t been reused.

Types of Installations

1.     Upgrade: overwrites the operating system with a newer version

2.     Custom: allows users to install packages they might need

 

·         Users can sign in to Windows using a Microsoft or local account.

o   Local accounts use a password & username.

o   Microsoft accounts use an email address & password and allows the users to use two-step verification when signing in. It provides another layer of security and protection to your account.

·         PIN’s make signing in easier & keeps your computer more secure.

·         Cortana is Microsoft’s personal productivity assistant.

Manage Accessibility Settings

·         Settings -> Ease of Access

1.     Display: you can make text bigger, everything bigger, change brightness

2.     Mouse Pointer: change the size & color of your mouse. Also, can choose visual feedback.

Interaction

3.     Keyboard: use an On-Screen keyboard or turn on sticky keys. Sticky Keys keeps modifier keys (Shift & Alt) active until another key is pressed. It helps decrease the risk of repetitive strain injuries.

Vision

4.     Color filters: used to help see elements on the screen better. It can help people who is colorblind use a filter to increase colors to make them more distinct.

5.     High contrast: helps people with vision impairments help them see better.

6.     Narrator: reads text on the screen and notifications out loud.

Hearing

1.     Audio: increase or decrease device volume, turn on/off mono audio (combines left & right audio into one channel, or set audio visual alerts.

a.      Flash the title bar of the active window.

b.      Flash the active window.

c.      Flash the entire screen.

2.     Closed captions: determine the caption color, transparency, style, size, effects, and dim window content.

3.     Speech recognition: converts spoken words into text.

Account Types

·         Settings à Accounts

·         The first account created is automatically created is the administrator, you can have multiple.

1.     Standard User: allows users to access most features of the computer, they can’t make system-wide changes & needs an administrator permission before installing anything.

2.     Guest: usage is temporary, they can’t many any changes to the computer settings

3.     Child: built-in parental controls & can’t be used to monitor their children’s activity and protect them from content that is inappropriate

4.     Local: only exist on a single computer, does not require internet and have limited access to the account

Configure Desktop Settings

1.     Display settings

§  Night Light: reduces blue light & emits warmer colors.

§  Scaling: changes the size of items on the screen

§  Display resolution: changes how much pixels are displayed horizontally and vertically.

§  Duplicate the display shows the same display on 2 or more monitors.

§  Extend the display creates a panoramic display.

2.     Start Menu/Power settings:

§  Restarting is used to fix an application error or clear the RAM cache.

3.     Taskbar Setting

§  You can customize your desktop by pinning apps to your taskbar, it can be hidden or always visible and the location of your taskbar can be changed.

§  Application windows can be minimized, maximized, or closed.

Manage Updates

·         Windows Updates often fix newly discovered flaws in the operating system or application. Updates can be paused for 35 days.

1.     Patches: update that improves security & performance within a program or product

2.     General: includes many different features

3.     Optional: bug fixes or patches that do not need to be updated right away, does not include security fixes. They provide new or improved software to make it more user-friendly.

4.     Driver: helps devices communicates more efficiently. They should be automatically updated.

Domain 2: Application & Periphereal Management

·         Administrative users have permissions to uninstall/install all applications. Some applications are automatically installed on the computer, if you uninstall them, it could cause your computer to slow down and become vulnerable.

·         Microsoft Store allows users to install applications and make other purchases. Drive C; is where windows are stored on the computer.

·         64-bit apps: C:/Program Files | 32-bit: C:/Program Files (x86)

·         Peripherals are hardware input or output devices that can be attached to computers (ex, keyboard, mouse, camera, microphone, printer)

Common Connection Types

1.     HDMI (high-definition multimedia interface): transmits both digital video & audio to a computer from another source (ex; tv or laptop)

2.     Mini-HDMI’s transmits digital video & audio from smaller devices to a computer (ex, camera & tablets)

3.     DisplayPort: transmits high-definition video & audio. They are most found on PC than TV.

4.     VGA (Video Graphics Array): links computer & laptops to additional monitors. It is an analog video connector.

5.     USB (universal serial bus): connects to a wide range of peripherals & other devices.

Domain 3: Data Access & management

·         Cloud services allow uses to store data and programs on remote servers rather than a computer hard drive that are accessed through the internet or computing software.

o   SharePoint: a Microsoft cloud storage location used for document storage.

o   Cloud Storage allows users to share file, file-sharing allows individuals to use & work within the same file.

·         File Permissions

o   Editing: those you have shared the file with can read, edit, forward the link, and assign permissions

o   Reviewing: allows others to add suggestions & comments to the document

o   Viewing: can only read the document and cannot make any changes

·         Sync Center allows users to create or open offline files & work within them.

·         Virtual machines allow users to run an operating system in an app window, they emulate a separate computer (Hyper-V, Microsoft Azure). The operating system running on your computer is called the “host” and the one you are running on a virtual machine is called “guest.”

·         NTFS (New Technology File System) is a process that operating system use to organize store and find files on the computer’s hard disk.

·         File Sharing allows multiple users to use and work within the same file using the internet or network.

o   Full Control: highest, read, edit, and take ownership of the file. It grants the user the ability to decide who can access the file.

o   Change: read, execute, write, delete folders, and file share

o   Read: view and read files but can’t change anything

·         Effective Permissions: resultant permissions a user has for an object. Thy are made up of Explicit permissions (default ones) and inherited permissions that are given to the file due to it being a child or parent object.

Share Types

·         Public Folders: used to share files with other using your shared network or share files with others using your PC. It helps organizing and sharing info within a workplace.

·         Mapped drive: provides a shortcut with others in your network to a physical location in a different computer. They are a perfect way to allow others to access files without storing the large files on their hard drive, multiple ppl can share access to the same file.

·         When both NTFS and share, permissions are assigned to a resource, the most restrictive permissions are used. For example, if a folder share contains read/write permissions, but a review group had read permissions to the folder, the review group will only have read permissions.

·         When copying files from a source to a destination, the permissions on the copied files are inherited from their parent folders.

·         You can protect your files by backing them up. Backing up your files creates a copy of your important files if your PC breaks or files get lost.

·         Network is a local hard drive that is a shared data storage location for your company or organization. It is accessed through an Ethernet cable or wirelessly.

Types of Backups

1.     Full Back up: one or more copies of selected data

2.     Mirror Backup: automatically creates copies of data as it Is changed.

3.     Differential: only backs up data that has change or been created since the last fall backup

4.     Incremental: only backs up data has been changed or been created since the last full backup

Data Access & Retention Policies

·         Data Retention Policy:

o   Determines what data should be stored be stored & what should be archived.

o   Where the data should be stored & how long

o   Clarifies what happens with data after the retention policy.

·         MOU (Memorandum of Understanding)

o   Document that describes a bilateral agreement between parties

o   Communicates the expectation that have been mutually accepted by all parties. IT IS NOT A LEGALLY BINDING CONTRACT

·         AUP (Acceptable use Policy):          

o   Document that states any stipulating constraints & practices that users must obey to get access to a corporate network or internet.

o   Includes specific rules & consequences when broken.

·         Remote Wipe:

o   Security feature for mobile devices that allows users to erase data.

o   Commonly used when a mobile device is stolen or lost.

·         Data Ownership:

o   The possession of and the responsibility for information

o   Determine others’ access privileges to their data & if they are allowed to create, modify, sell, or remove the date.

Domain 4: Device Security

·         A firewall is a security system that defends your network, it blocks and controls anu malicious attacks that is threatening your computer. It acts as a barrier between your trusted and untrusted network. In built-in fireworks lower the risk of email viruses and pop-up windows, & malware attacks.

Types of Networks

1.     Private: trusted networks w/ restricted access that allows the computer to be discoverable & use resources such as printers & shared files

2.     Public: tells the system that you do not trust the network & do not control the users connected. They set the computer to be undiscoverable & limits the access to the network resources.

3.     Guest: grants visitors access to wi-fi w/o giving access to shared resources

·         User authentication is the process the server uses to determine if you are what you say you are when your signing in. The most common form is username & passwords.

Types of Authentications

·         Factors include.

o   What you know (usernames & passwords)

o   What you have (smart cards & badges)

o   Who you are (biometrics)

§  Fingerprints

§  Retina Scans

§  Voice Reader

§  Facial Recognition

·         Multifactor authentication provides additional account security to an account by requiring two or more credentials when signing in. It consists of something you own & something you are.

·         BYOD devices (bring your own devices) are devices that you bring from home to use at work.

·         Corporate-managed devices are devices owned & managed by the corporation that are given to employees to use at work. Devices are easily lost or stolen & easily are accessed by others when taken out of the workplace, strong password policies should include passwords with:

o   8 characters

o   Uppercase and lowercase

o   Numbers

o   Symbols

Mitigating attacks

1.     Computer virus: copies itself to your device & other devices to interrupt, damage, or steal data. In order to spread it must be attached to a program

2.     Worm: spreads itself, needs no help to replicate

3.     Spyware: software that secretly tracks your computer & uses it to collect data about you & your activity online to send to a third-party w/o your knowledge

4.     Trojan Horse: similar to a virus that must be executed by the user, type of malware that looks legit.

5.     Keylogger: captures every keyboard keystroke, including the keystrokes used to sign in to personal accounts. It is a type of spyware.

6.     Adware: causes pop-up windows to appear w/ advertisements. Once loaded into the device, it starts copying personal info & transmits credit card information.

7.     Ransomware: malicious code that is installed & systematically encrypts the hard drive of the device & locks users out of their sensitive data. It Is delivered through phishing emails.

8.     Phishing attacks: socially engineered attacks where victims are tricked into revealing sensitive info or are provided with a malicious link.

Combatting attacks

·         Have a good antivirus & antimalware program

o   Antivirus best protect against viruses, worms, and trojan horses

o   Antimalware (windows Defender) protects best against malware

·         Use caution when surfing the internet

o   Ensure your websites are legit by visiting websites that use https.

o   Do not open emails from unknown senders

o   Avoid using links within emails, visit the website directly

·         Be aware of social engineering & physical attack

o   Social engineering attacks trick individuals into providing sensible info (example is vishing)

o   Physical attack: individual steals valuable equipment or data or harms the individual to mitigate them (a security system can help)

UAC Settings

·         User Account Control (UAC) is a security feature that protects your computer from potentially harmful changes being made to it by apps, users, and viruses

1.     Always Notify: users when apps are making changes or the individual makes changes

2.     Notify me only when apps are making changes to my computer (default setting for administrators)

3.     Notify me only when apps try to make changes to my computer is the same but your computer won’t dim & you can perform other talks

4.     Never notify me  is like turning of UAC, there are no restrictions and changes can be made freely

·         When deploying a policy to a domain computer, you will need to use the Group Policy management console

 

Manage Mobile Device Security

·         Mobile Device Management (MDM) uses an agent or an application to monitor the device

o   It allows companies to monitor user compliance with company policies

o   Remotely wipe or lock the device

o   Remain in full control over sensitive info on the operating system

·         They can be installed by downloading an application from Google Play Store, iTunes, or the MDM server (Microsoft Itune)

·         Users can increase mobile device security by implementing a lock screen. It prevents unauthorized users from accessing the device and its data

Types of Lock

1.     Pattern: a pattern is traced on a device to unlock it

2.     PIN: consists of a 4-digit code to increase security, avoid using consecutive digits

3.     Password: recommended to be strong, it only has to be 4 characters long but 8 is the recommended.

Domain 5: Troubleshooting

·         Troubleshooting is a way to determine what is causing the problem & how to fix it.

o   Local Polies: applies only to one computer

o   Group Policies: applies to multiple computers in a domain, make administrative tasks easier and faster to complete

o   Site Group Policies: allows administrators to control the environment of computer & user accounts

o   Domain Policy: grants security settings for users & computer

o   Organizational Unit (OU) allows admins to place different users, groups, and computers into subcategories.

·         How to apply group policy

1.     The machine’s local policy is evaluated

2.     Site policies

3.     Domain group policies

4.     The organizational unit policy

·         Windows has a schedule for updating policies automatically, if you want them to occur immediately then run the gpupdate command in the command prompt

·         A domain policy takes [precedence over any local policies bc it is processed after the local policy, if one of your policies are not function, running a gpresult can check

·         Resetting allows you to remove application that have been installed on the system & PC manufacturer

·         A rollback takes your computer system back to the previous version

Advanced Troubleshooting Settings

1.     Boot-logging: windows creates a log of drivers used in the startup process

2.     Safe-mode: starts the computer in basic mode w/ limited files and drivers

a.      Windows Safe Mode Command: boots in a stripped down session w/ a limited number of files & drivers w/ no network & no desktop

b.      Safe Mode: with loads of minimum number of drivers required to connect to other computers during start up

c.      Lost Known Good Config: used when having difficulty starting windows normally. It loads the last successful set of drivers & registry settings that were installed

·         Reinstalling an application is another trouble shooting option

Ways to Troubleshoot Devices

1.     Check the Connection

a.      Does the hardware have power?

b.      Is the cable connected to the port & power source?

·         Device Manager displays all the hardware that the computer has installed, it allows users to view & manage their devices

2.     Outdated Drivers

a.      After a software or operating system updates, drivers will need to as well

b.      The roll back driver option allows users to return to the previous version of your driver

3.     Uninstalling a device

a.      Connections are made wirelessly or through a physical wired connection

4.     A failed domain connection

a.      The pc may not be on the same network as the domain controller

·         169.254.x.x is APIPA (Automatic Private IP Addressing) that provides a PHCP fail-safe autoconfiguration dress that protects the computer from a system failure

·         Periphereal devices are auxiliary devices that connect to & work with your computer

·         To troubleshoot device connections:

o   Manually check the port connect (unplug & plug)

o   Check Device Manager (driver may need to be updated)

·         Order of Group Policy Application

o   L (Local)

o   S (Site)

o   D (Domain)

o   OU (Organizational Unit)