Explanation/Reference:
Explanation:
Open Group Policy Management and edit the applicable GPO in your Active Directory.
Disable autorun:
Computer Configuration \ Administrative Templates \ Windows Components \ AutoPlay Policies Turn off Autoplay: Enabled

Limit to approved devices:
Computer Configuration \ Administrative Templates \ System > Device Installation \ Device Installation Restrictions Allow installation of devices that match any of these device IDs: (add the corporate device) Prevent installation of devices not described by other policy settings: Enabled

Testlet 1
Scenario:
You are an enterprise desktop support technician for City Power & Light.
City Power & Light is a utility company. The company has a main office and a branch office. The main office is located in Toronto. The branch office is located in Boston. The main office has 1,000 employees.
The branch office has 10 employees.
Active Directory Configuration
The network contains a single Active Directory domain named cpandl.com. The functional level of the forest is Windows Server 2008 R2.
Server Configuration
All servers run Windows Server 2008 R2. The relevant servers in the main office are configured as shown in the following table.

All computers in the main office are configured to use DHCP. All computers in the branch office are configured to use static IP addresses.
User Information
All user accounts are standard user accounts.

All client computers run Windows 7 Enterprise.

Each portable computer has a PPT P-based VPN connection to the internal network.

Corporate Security Guidelines
All users must be granted the least privileges possible.

All locally stored documents must be encrypted by using Encrypting File System (EFS).

The hard disk drives on all port able computers must be encrypted by using Windows BitLocker Drive

Encryption (BitLocker).
All encryption certificates must be stored on smart cards.
