05.03.2013 Views

MCSA/MCSE Self-Paced Training Kit (Exam 70-270): Installing ...

MCSA/MCSE Self-Paced Training Kit (Exam 70-270): Installing ...

MCSA/MCSE Self-Paced Training Kit (Exam 70-270): Installing ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Lesson 4 Increasing Security by Using EFS<br />

10-53<br />

Security Alert The recovery agent can bring his or her private key to the owner’s computer,<br />

but it is never a good security practice to copy a private key onto another computer.<br />

It is a good security practice to rotate recovery agents. However, if the agent designation<br />

changes, access to the file is denied. For this reason, you should keep recovery<br />

certificates and private keys until all files that are encrypted with them have been<br />

updated.<br />

The person designated as the recovery agent has a special certificate and associated<br />

private key that allow data recovery. To recover an encrypted file, the recovery agent<br />

does the following:<br />

■ Uses Backup or another backup tool to restore a user’s backup version of the<br />

encrypted file or folder to the computer where his or her file recovery certificate<br />

is located.<br />

■ In Windows Explorer, opens the Properties dialog box for the file or folder, and in<br />

the General tab, clicks Advanced.<br />

■ Clears the Encrypt Contents To Secure Data check box.<br />

■ Makes a backup version of the decrypted file or folder and returns the backup version<br />

to the user.<br />

Practice: Increasing Security by Using EFS<br />

In this practice, you log on as an administrator and encrypt a folder and its files. You<br />

then log on using a different user account, and attempt to open an encrypted file and<br />

disable encryption on the encrypted file.<br />

1. In Windows Explorer, create a folder named Secret on the C drive.<br />

2. In the Secret folder, create a text file named SecretFile.txt.<br />

3. Right-click the Secret folder, and then click Properties.<br />

Windows XP Professional displays the Secret Properties dialog box with the General<br />

tab active.<br />

4. Click Advanced.<br />

The Advanced Attributes dialog box appears.<br />

5. Select the Encrypt Contents To Secure Data check box, and then click OK.<br />

6. Click OK to close the Secret Properties dialog box.<br />

The Confirm Attribute Change dialog box informs you that you are about to<br />

encrypt a folder. You have two choices: You can encrypt only this folder, or you<br />

can encrypt the folder and all subfolders and files in the folder.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!