Overview
Introduction
The Compliance Patching module provides you with the instructions and devices to develop your hands-on skills in the following topics:
- Install and Configure WSUS
- WSUS Server Certificates Security
- Create Computer Groups for WSUS
- Configure GPO Policy for WSUS
Lab time: It will take approximately 1 hour and 30 minutes to complete this lab.
Exam Objectives
The following exam objectives are covered in this lab:
- CS0-001 1.3: Given a network-based threat, implement or recommend the appropriate response and countermeasure
- CS0-001 2.1: Given a scenario, implement an information security vulnerability management process
- CS0-001 3.5: Summarize the incident recovery and post-incident response process
- CS0-001 4.1: Explain the relationship between frameworks, common policies, controls, and procedures
- CS0-001 4.2: Given a scenario, use data to recommend remediation of security issues related to identity and access management
Exercise 1 - Install and Configure WSUS
Windows Server Update Services (WSUS) provides a cost-effective patch management solution to deploy updates to domain-joined Windows servers and workstation in a corporate network. WSUS is fully integrated in Windows Server 2012 and can be enabled on Windows clients by configuring settings in Group Policy Objects - GPO.
In this exercise, you will learn the following:
- Configure Disk Storage for WSUS
- Install and Configure WSUS
Exercise 2 - WSUS Server Certificates Security
Security for certificates is a critical component to making sure information is kept confidential and that we understand who has delivered said information thereby confirming the integrity of not only the data but also the sender. By applying the secure sockets layer, we help to insure that the server is using the requires security channel to communicate on.
In this exercise, you will learn the following:
- Enable SSL for WSUS Server
- Exporting Self-Signed Certificates
- Configuring Domain to Trust Self-Signed Certificates
Exercise 3 - Create Computer Groups for WSUS
Computer groups enable you to target updates to specific computers and can allow for specific updates to be applied to specific computers in a granular fashion, this significantly speeds up computer administration processes and improves security by allowing for mass deployment of security patches to all affected machines in one movement. In this exercise, you will go through the steps of creating and assigning these groups.
In this exercise, you will learn the following:
- Create Computer Groups
- Approve Downloaded Updates
Exercise 4 - Configure GPO Policy for WSUS
In the following exercise, you will implement the tasks to deploy WSUS updates via group policy. Using a group policy, we can designate the services and permissions for an update to affect computer groups of specific departments for example. However changing relationships in Group Policy can have significant effects and so care must be taken when working with this method of configuring devices.
In this exercise, you will learn the following:
- Create a GPO for Update Services Client
- Troubleshoot Password and Verify WSUS Client Functionality
Comprehensive Learning
See the full benefits of our immersive learning experience with interactive courses and guided career paths.