Patch Tuesday: Microsoft to release 6 patches, 1 critical

Patch Tuesday: Microsoft to release 6 patches, 1 critical
Microsoft, Patch Tuesday for March: A continued drop in critical security bulletins has the security community overlooking a rise in total patches issued this year.

Microsoft announced today that next week’s Patch Tuesday will be the lightest of 2012, with six security bulletins and just one rated critical.

More: Windows 8’s 8 top apps (so far)

RELATED: Microsoft patch blows ‘perfect game’ but sends important message

The critical patch will pertain to all Windows customers as it addresses a vulnerability that affects the entire family of the operating system, up to and including Windows 7.

Four of the patches address vulnerabilities in Windows, including the critical patch for a remote code execution vulnerability and the moderate patch for a denial-of-service exploit. The remaining two patches, both rated important, target an elevation of privilege vulnerability in Visual Studio and a remote code execution in Expression Design, respectively.

 

MCTS Training, MCITP Trainnig

Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com

With six patches this month, Microsoft’s total for the year will reach 22, up from the 17 bulletins issued through March of 2011. The total for the month also exceeded that of last year, when Microsoft issued just three bulletins.

The year-over-year increase comes just one month after Microsoft was able to reduce its total number of bulletins issued in February from 12 in 2011 to nine this year. And while the year is still young, Microsoft is in danger of surpassing the 100 bulletins issued in all of 2011.

However, Lumension security and forensic analyst Paul Henry says those numbers are a poor representation of Microsoft’s progress with security. Citing recent improvements, as well as the novelty that its Internet Explorer web browser went “at least somewhat spared” during the Pwn2Own conference at which Google Chrome took a beating, Henry says the main point to focus on is the decrease in severity of vulnerabilities.

“I think they’re doing a better job. They’ve got the processes in place to better manage their software development in line with security,” Henry says. “They really have put a great deal of effort into this, and if you look at the longer-term trend, I think they’re really starting to bear some fruit from it.”

Both the security community and IT support professionals will welcome an increase in total patches issued if it means the number of critical patches remains low, Henry says.

“Part of the reason for that is that Microsoft, having cleared a large number of critical issues, is now focusing a lot of its attention on moderate and important issues and is just trying to clean things up,” Henry says. “So the number of bulletins won’t actually go down, but the critical bulletins absolutely will.”

Just 32 of the 100 patches Microsoft issued throughout 2011 were deemed critical, the lowest rate since the Patch Tuesday routine launched in 2004. So far this year, Microsoft has issued six critical vulnerabilities, putting it on pace to reduce that rate by 25%.

Colin Neagle covers Microsoft security and network management for Network World. Keep up with his blog: Rated Critical, follow him on Twitter: @ntwrkwrldneagle. Colin’s email is cneagle@nww.com.

 

MCTS Training, MCITP Trainnig

Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com

 

7003-1 Q&A / Study Guide / Testing Engine

Cisco CCNA Training, Cisco CCNA Certification

Best Avaya Certification Training and Avaya Exams Training  and more Cisco exams log in to Certkingdom.com


QUESTION 1
A technician deployed a Communication Server 1000E with dual homing feature configured. Both
the T and 2T ports are connected on the media Gateway Controller (MGC) one connection is
active to avoid network loops.
Which two statements are true, if the connection to the active port on the MGC is host?
(Choose two)

A. The MGC will issue a link down error.
B. The MGC will switch to the active pert.
C. The MGC and CPPM will have no loss of service.
D. The MGC will switch to the active port after 12 seconds.

Answer: B,C

Explanation:


QUESTION 2
A customer has deployed a Communication Server 100 Rls. 7x system at their site. The technician
has been asked to add the Call pickup feature to the 100 IP telephone in the sales department.
The customer wants to be sure active calls not lost when the changes are made.
Which Phones Configuration feature can be enabled that will ensure changes to the telephone are
not transmitted to the call server until the telephone are busy?

A. Bulk change
B. Courtesy change
C. Group change
D. Template change

Answer: B

Explanation:


QUESTION 3
A customer wants to build a new Ip node on their Communication Server (CS) 1000E system with
three Signaling Servers. This node will support virtual trunks, IP media services, TPS and
personnel directories. A technician logs into Elements manager to complete the configuration,
after creating and saving the node configuration, the transfer now option chosen, then the servers
are selected, the start sync is selected followed by restart application.
What is expected outcome from the system?

A. The node file will be transferred from Signaling Servers to the call servers, and INI files will be
transferred from the call server to the selected servers.
B. The node file will be transferred from Call Servers to the Signaling servers, and the INI files will
be transferred from the Call Servers to the selected servers.
C. The node file will be transferred from Signaling Servers to the Call Server, and the INI files will
be transferred from Call Servers to the Signaling servers.
D. The node will be transferred from Element manager to the call server, and INI files will be
transferred from Element manager to CallServer.

Answer: B

Explanation:


QUESTION 4
A customer wants to deploy an Avaya Server (CS) 1000 Rls. 7x system in Avaya Aura solution.
They plan to have the system support 50,000 users.
Which system type will meet the customer’s needs?

A. CS 1000E Co-Resident Call Server and Signaling Server
B. CS 1000E Standard Availability (SA)
C. CS 1000E High Availability (HA)
D. CS 1000E High Scalability (HS)

Answer: D

Explanation:


QUESTION 5
You are installing a new Communication Server 1000E (CS 1000E) SA release 7x system for your
customer. They have asked you to implement the corporate Directory Feature during the
installation.

A. SFTP must be disabled in LD 117.
B. Valid telephony accounts must already exist in Subscriber Manager.
C. The CS 1000E Call Server must be joined to security domain.
D. Centralized authentication must be disabled.

Answer: C

Explanation:


Cisco CCNA Training, Cisco CCNA Certification

Best Avaya Certification Training and Avaya Exams Training  and more Cisco exams log in to Certkingdom.com