新题50 final.docx

上传人:b****7 文档编号:11104689 上传时间:2023-02-25 格式:DOCX 页数:24 大小:52.24KB
下载 相关 举报
新题50 final.docx_第1页
第1页 / 共24页
新题50 final.docx_第2页
第2页 / 共24页
新题50 final.docx_第3页
第3页 / 共24页
新题50 final.docx_第4页
第4页 / 共24页
新题50 final.docx_第5页
第5页 / 共24页
点击查看更多>>
下载资源
资源描述

新题50 final.docx

《新题50 final.docx》由会员分享,可在线阅读,更多相关《新题50 final.docx(24页珍藏版)》请在冰豆网上搜索。

新题50 final.docx

新题50final

1.YournetworkcontainsanActivedirectorydomainnamedcontainstwositesnamedSite1andsite2.Site1containsadomaincontrollernamedDC1.

InSite1,youinstallanewdomaincontrollernamedDC2.youshipDC2toSite2.

YoudiscoverthatcertainusersinSite2authenticatetoDC1.

YouneedtoensurethattheusersinSite2alwaysattempttoauthenticatetoDC2first.

Whatshouldyoudo?

A.FromActiveDirectorysitesandservices,movetheDC2serverobject.

B.FromActiveDirectorysitesandservices,modifytheLocationattributeforSite2.

C.FromActiveDirectoryusersandComputers,movetheDC2computerobject.

D.FromActiveDirectoryusersandComputers,modifytheLocationSettingsoftheDC2computerobject.

 

2.YournetworkcontainsanActiveDirectorydomain.ThedomaincontainsamemberservernamedServer1thatrunsWindowsserver2008R2.

Youneedtoconfiguresserver1asaglobalcatalogserver.

Whatshouldyoudo?

A.ModifytheActiveDirectoryschema.

B.FromNtdsutil,usetheRolesoption.

C.RuntheActiveDirectoryDomainServicesInstallationWizardonServer1.

D.MovetheServer1computerobjecttothedomainControllersorganizationalunit(OU).

 

3.YournetworkcontainsanActivedirectorydomain.Thedomaincontainsanorganizationunit(OU)namedOU1.OU1containsallmanagedserviceaccountsinthedomain.

Youneedtopreventthemanagedserviceaccountsfrombeingdeleteaccidentallyfromou1.

Whichcmdletshouldyouuse?

A.Set-ADObject

B.Set-ADOrganizationalUnit

C.Set-ADServiceAccount

D.Set-ADUser

 

4.YournetworkcontainsanActiveDirectorydomainnamed.

Youneedtoauditchangestoaserviceaccount.Thesolutionmustensuretheauditlogscontainthebeforeandaftervaluesofallthechanges.

Whichsecuritypolicysettingshouldyouconfigure?

A.AuditDirectoryServiceChanges

B.AuditOtherAccountManagementEvents

C.AuditSensitivePrivilegeUse

D.AuditUserAccountManagement

 

5.YournetworkcontainsanActiveDirectorydomainnamedcontainsamemberserverthatrunsWindowsserver2008Standard.

Youneedtoinstallanenterprisesubordinatecertificationauthority(CA)thatsupportsprivatekeyachieve.Youmustachievethisgoalbyusingtheminimumamountofadministrativeeffort.

Whatshouldyoudofirst?

A.InitializetheTrustedPlatformModule(TPM).

B.UpgradethememberservertoWindowsServer2008R2Standard.

C.InstallthecertificateEnrollmentPolicyWebServiceroleserviceonthememberserver.

D.RunthesecurityConfigurationWizard(SCW)andselecttheActiveDirectoryCertificateServices-CertificationAuthorityserverroletemplatecheckbox.

 

6.YournetworkcontainsanActiveDirectorydomain.

YourcreateandmountanActiveDirectorysnapshot.

Yourrundsamain.exeasshownintheexhibit.(ClicktheExhibitbutton.)

YouneedtoensurethatyoucanbrowsethecontentsoftheActiveDirectorysnapshot.

Whatshouldyou?

A.Changethevalueofthedbpathparameter,andthererundsamain.exe.

B.Changethevalueoftheldapportparameter,andthenrerundsamain.exe.

C.StopActiveDirectoryDomainServer(ADDS),andthererundsamain.exe

D.RestarttheVolumeShadowCopyService(VSS),andthenrerundsamain.exe

 

7.YournetworkcontainsanActiveDirectoryforest.Allclientcomputerrunwindows7.

Thenetworkcontainsahigh-volumeenterprisecertificationauthority(CA).

Youneedtominimizetheamountofnetworkbandwidthrequiredtovalidateacertificate.

Whatshouldyoudo?

A.Modifythesettingsofthedeltacertificaterevocationlist(CRL).

B.ConfigureanOnlineCertificationStatusProtocol(OCSP)responder.

C.ConfigureanLDAPpublishingpointforthecertificaterevocationlist(CRL).

D.Replicatethecertificaterevocationlist(CRL)byusingDistributedFilesystem(DFS).

 

8.YournetworkcontainsanActiveDirectorydomainnamed,CcontainstwodomaincontrollersnamedDC1andDC2,DC1andDC2areconfiguredasDNSserversandhosttheActiveDirectory-integratedzonefor.

YoudiscoverstaleDNSrecordsinthezone.

YouneedtoensurethatthestaleDNSrecordsaredeletedfrom.

Whatshouldyoudo?

A.FromDNSManager,reloadthezone.

B.FromDNSManager,modifythepropertiesofDC1.

C.Rundnscmd.exeandspecifytheageallrecordsparameter.

D.Rundnscmd.exeandspecifythestartscavengingparameter.

 

9.YournetworkcontainsanActiveDirectorydomainnamed.CcontainsawritabledomaincontrollernamedDC1andaread-onlydomaincontroller(RODC)namedDC2.AlldomaincontrollersrunWindowsServer2008R2.

YouneedtoinstallanewwritabledomaincontrollernamedDC3inaremotesite.ThesolutionmustminimizetheamountofreplicationtrafficthatoccursduringtheinstallationofActiveDirectoryDomainServices(ADDS)onDC3.

A.Runntdsutil.exeonDC1.

B.Runntdsutil.exeonDC2.

C.Rundcpromo.exe/advonDC3.

D.Rundcpromo.exe/createdcaccountonDC3.

 

10.YournetworkcontainsaservernamedServer1.Server1runsWindowsServer2008R2andhastheActiveDirectoryLightweightDirectoryServices(ADLDS)roleinstalled.Server1hoststwoADLDSinstancesnamedInstance1andInstance2.

YouneedtoremoveonlyInstance2fromServer1.

Whatshouldyouuse?

A.Dism

B.Dsdbutil

C.ProgramsandFeatures

D.ServerManager

 

11.YournetworkcontainsanActiveDirectorydomain.Thedomaincontains10domaincontrollersthatrunWindowsServer2008R2.

Youneedtomonitorthefollowinginformationonthedomaincontrollersduringthenextfivedays:

Memoryusage

Processorusage

ThenumberofLDAPqueries

Whatshouldyoudo?

A.UsetheSystemPerformanceDataCollectorSet(DCS).

B.UsetheActiveDirectoryDiagnosticsDataCollectorSet(DCS).

C.CreateaUserDefinedDataCollectorSet(DCS)theusestheSystemPerformancetemplate.

D.CreateaUserDefinedDataCollectorSet(DCS)thatusestheActiveDirectoryDiagnosticstemplate.

 

12.YournetworkcontainsanActiveDirectorydomain.ThedomaincontainsagroupnamedGroup1.

Theminimumpasswordlengthforthedomainissettosixcharacters.

YouneedtoensurethatthepasswordsforallusersinGroup1areatleast10characterslong.Allotherusersmustbeabletousepasswordsthataresixcharacterslong.

Whatshouldyoudofirst?

A.RuntheNew-ADFineGrainedPasswordPolicycmdlet.

B.RuntheAdd-ADFineGrainedPasswordPolicySubjectcmdlet.

C.FormtheDefaultDomainPolicy,modifythepasswordpolicy.

D.FromtheDefaultdomainControllerPolicy,modifythepasswordpolicy.

 

13.YournetworkcontainsanActiveDiretorydomaincontrollernamedDC1.DC1runswindowsServer2008R2.

YouneedtodefragmenttheActiveDirectorydatabaseonDC1.ThesolutionmustminimizedowntimeonDC1.

Whatshouldyoudofirst?

A.Atthecommandprompt,runnetstopntds.

B.Atthecommendprompt,runnetstopnetlogon.

C.RestartDC1inSafeMode.

D.RestartDC1inDirectoryServicesRestoreMode(DSRM).

14.yournetworkcontains10domaincontrollersthatrunwindowsserver2008R2.

Thenetworkcontainsamemberserverthatisconfiguredtocollectalloftheeventsthatoccuronthedomaincontrollers.

Youneedtoensurethatadministratorsarenotifiedwhenaspecificeventoccursonanyofthedomaincontrollers,youwanttoachievethisgoalbyusingtheminimumamountofadministrativeeffort.

Whatshouldyoudo?

A.Fromeventvieweronthememberserver,createasubscription.

B.Fromeventvieweroneachdomaincontroller,createasubscription.

C.Fromeventvieweronthememberserver,runthecreateBasicTaskWizard.

D.Fromeventvieweroneachdomaincontroller,runthecreateBasicTaskWizard.

Answer:

A

15.YournetworkcontainsaserverthathastheactivedirectoryLightWeightDirectoryServices(ADLDS)roleinstalled.

YouneedtoperformanautomatedinstallationofanADLDSinstance.

Whichtoolshouldyouuse?

A.Adaminstall.exe

B.Dism.exe

C.Ocsetup.exe

D.Servermanagercmd.exe

Answer:

A

 

16.YournetworkcontainanActiveDirectoryforest.Theforestcontainsonedomain.ThedomaincontainstwodomaincontrollersnamedDC1andDC2thatrunwindowsServer2008R2.DC1wasinstalledbeforeDC2.

DC1fails

Youneedtoensurethatyoucanadd1,000newuseraccountstothedomain.

Whatshouldyoudo?

A.SeizetheRIDmasterFSMOrole.

B.SeizetheschemamasterFSMOrole.

C.ConfigureDC2asaglobalcatalogserver.

D.ModifythepermissionsoftheDC2computeraccount.

Answer:

A

 

17.ActiveDirectoryRightsManagementServices(ADRMS)isdeployedonyournetwork.

YourneedtoconfigureADRMStouserKerberosauthentication.

Whichtwoactionsshouldyouperform?

(Eachcorrectanswerpresentspartofthesolution.Choosetwo)

A.Registeraservicesprincipalname(SPN)forADRMS.

B.Registeraservicesconnectionpoint(SCP)forADRMS

C.ConfiguretheidentitysettingoftheDRMSAppPool1applicationpool.

D.ConfiguretheuseAppPoolCredentialsattributeintheInternetInformationServices(IIS)metabase

Answer:

BD

 

18YournetworkcontainanActiveDirectoryforest.TheforestcontainsanActiveDirectorysiteforaremoteoffice.Theremotesitecontainsaread-onlydomaincontroller(RODC).

YouneedtoconfiguretheRODCtostoreonlythepasswordsofusersintheremotesite.

Whatshouldyoudo?

A.CreateapasswordSettingobject(PSO)

B.ModifythePartial-Attribute-Setattributeoftheforest.

C.AddtheuseraccountsoftheremotesiteuserstotheAllowedRODCPasswordReplicationGroup.

D.AddtheuseraccountsofuserswhoarenotintheremotesitetothedeniedRODCPasswordReplicationGroup.

Answer:

C

 

19.yournetworkcontainsanActiveDirectory-integratedDNSzonenamedcont

展开阅读全文
相关资源
猜你喜欢
相关搜索

当前位置:首页 > 工程科技 > 能源化工

copyright@ 2008-2022 冰豆网网站版权所有

经营许可证编号:鄂ICP备2022015515号-1