Overview

Introduction

Welcome to the Compliance Patching Practice Lab. In this module you will be provided with the instructions and devices needed to develop your hands-on skills.

Learning Outcomes

In this module, you will complete the following exercises:

  • Install and Configure WSUS
  • WSUS Server Certificates Security
  • Create Computer Groups for WSUS
  • Configure GPO Policy for WSUS

After completing this lab, you will be able to:

  • Configure Disk Storage for WSUS
  • Install and Configure WSUS
  • Enable SSL for WSUS Server
  • Exporting Self-Signed Certificates
  • Configuring Domain to Trust Self-Signed Certificates
  • Create Computer Groups
  • Approve Downloaded Updates
  • Create a GPO for Update Services Client
  • Troubleshoot Password and Verify WSUS Client Functionality

Exam Objectives

The following exam objectives are covered in this lab:

  • CAS-003 2.1 Analyze a scenario and integrate network and security components, concepts and architectures to meet security requirement.
  • CAS-003 2.2 Analyze a scenario to integrate security controls for host devices to meet security requirements.
  • CAS-003 2.4 Given software vulnerability scenarios, select appropriate security controls..

Lab Duration

It will take approximately 1 hour to complete this lab.

Exercise 1 - Install and Configure WSUS

Windows Server Update Services (WSUS) provides a cost-effective patch management solution to deploy updates to domain-joined Windows servers and workstation in a corporate network. WSUS is fully integrated in Windows Server 2012 and can be enabled on Windows clients by configuring settings in Group Policy Objects - GPO.

Learning Outcomes

After completing this exercise, you will be able to:

  • Configure Disk Storage for WSUS
  • Install and Configure WSUS

Exercise 2 - WSUS Server Certificates Security

Security for certificates is a critical component to making sure information is kept confidential. By doing this, we can understand who has delivered said information, thereby confirming the integrity of not only the data, but also the sender. By applying the secure sockets layer, we help to ensure that the server is using the required security channel to communicate on.

Learning Outcomes

After completing this exercise, you will be able to:

  • Enable SSL for WSUS Server
  • Exporting Self-Signed Certificates
  • Configuring Domain to Trust Self-Signed Certificates

Exercise 3 - Create Computer Groups for WSUS

Computer groups enable you to target updates to specific computers and can allow for specific updates to be applied to specific computers in a granular fashion. This significantly speeds up computer administration processes and improves security by allowing for mass deployment of security patches to all affected machines in one movement. In this exercise, you will go through the steps of creating and assigning these groups.

Learning Outcomes

After completing this exercise, you will be able to:

  • Create Computer Groups
  • Approve Downloaded Updates

Exercise 4 - Configure GPO Policy for WSUS

In the following exercise, you will implement the tasks to deploy WSUS updates via Group Policy. Using Group Policy, we can designate the services and permissions for an update to affect computer groups of specific departments for example. However, changing relationships in Group Policy can have significant effects, and so care must be taken when working with this method of configuring devices.

Learning Outcomes

After completing this exercise, you will be able to:

  • Create a GPO for Update Services Client
  • Troubleshoot Password and Verify WSUS Client Functionality

Comprehensive Learning

See the full benefits of our immersive learning experience with interactive courses and guided career paths.