1、2.your company,contoso,Ltd,has offices in Noth America and Europe. Contoso has an Active Directory forest that has three domains. You need to reduce the time required to authenticate users from the domain when they access resources in the domain. what should you do?a decrease the replication interva
2、l for all connection objects.b decrease the replication interval for the DEFAULTIPSITELINK site link.c set up a one-way shortcut trust from to d set up a one-way shortcut trust from to . C3.your company has an organizational unit named production. The production organizational unit has a child organ
3、izational unit named R&D . you create a GPO named software deployment and link it to the production organizational unit. You create a shadow group for the R&D organizational unit. You need to deploy an application to users in the production organizational unit. You also need to ensure that the appli
4、cation is not deployed to users in the R&D organizational unit. What are two possible ways to achieve this goal?(each correct answer presents a complete colution choose two.)A configure the enforce setting on the software deployment GPOB configure the block inheritance setting on the R&D organizatio
5、nal unit.C configure the block inheritance setting on the production organizational unit.D configure security filtering on the software deployment GPO to deny apply group policy for the R&D security group.Answer: BD4 your company has a main office and 10 branch offices. Each branch office has an act
6、ive directory site that contains one domain controller. Only domain controllers in the main office are configured as global catalog servers. You need to deactivate the universal group membership caching (ugmc) option on the domain controllers in the branch offices. At which level should you deactiva
7、te UGMC?A site.B serverC domainD connection object5 your company has an active directory domain. A user attempts to log on to the domain from a client computer and receives the following message. ”this user account has expired ask your administrator to reactivate the account” you need to ensure that
8、 the user is able to log on to the domain. What should you do?A modify the properties of the user account to set the account to never expire.B modify the properties of the user account to extend the logon hours setting.C modify the properties of the user account to set the password to never expire.D
9、 modify the default domain policy to decrease the account lockout duration. A6 your company has an active directory domain. You log on to the domain controller. The active directory schema snap-in is not available in the Microsoft management console (MMC). You need to access the avtrce directory sch
10、ema snap-in. what should you do?A register schmmgml.dllB log off and log on again by using an account that is a member of the schema administrators group.C use the ntdsutil.exe command to connect to the schema master operations master and open the schema for writing.D add the active directory lightw
11、eight directory services (AD LDS) role to the domain controller by using server manager.7 Your network consists of single active directory domain. All domain controllers run windows server 2008 the audit account management policy setting and audit directory services access setting are enabled for th
12、e entire domain. You need to ensure that changes made to active directory objects can be logged. The logged changes must include the old and new valued of any attributes what should you do?A enable the audit account management policy in the default domain controller policy.B run auditpol.exe and the
13、n configure security settings of the domain controllers OU.C run auditpol.exe and then enable the audit directory service access setting in the default domain policyD from the default domain controllers policy. Enable the audit directory service access setting and enable directory service changes. B
14、8 Your company has an active directory domain. You log on to the domain controller. The active directory schema snap-in is not available in the Microsoft management console (MMC). You need to access the active directory schema snap-in. what should you do?A register schmmgmt.dllB log off and log on a
15、gain by using an account that is a member of the schema administrators group9 your company has an active directory domain that runs windows 2008 the sales OU contains an OU for computers, an OU for groups, and an OU for users you perform nightly backups. An administrator deletes the groups ou you ne
16、ed to restore the groups OU without affecting users and computers in the sales OU what should you do?A perform an authoritative restore of the sales OU.B perform an authoritative restore of groups OU.C perform a non-authoritative restore of the groups OU.D perform a non-authoritative restore of the
17、sales OU.You have a windows server 2008 enterprise root certification authority (CA) you need to grant members of the account operators group the ability to only manage basic EFS certificates. You grant the account operators group the lssue and manage certificates permission on the CA. which three t
18、asks should you perform next? (each correct answer presents part of the solution. Choose three)A enable the restrict enrollment agents options on the caB enable the restrict certificate managers option on the caC add the basic efs certificate template for the account operators groupD grant the accou
19、nt operators group the manage ca permission on the caE remove all unnecessary certificate templates that are assigned to the account operators group. BCE11. all consultants belong to a global group named tempworkers. You place three file servers in a new organizational unit named secureservers. The
20、three file servers contain confidential data located in shared folders. You need to record any failed attempts made by the consultants to access the confidential data. Which two actions should you perform? (each correct answer presents part of the solution choose two.)A create and link a new gpo to
21、the SecureServers organizational unit configure the audit privilege use failure audit policy setting B create and link a new gpo to the secureservers organizational unit configure the audit object access failure audit policy settingC create and link a new gpo to the secureservers organizational unit
22、 configure the deny access to this computer from the network user rights setting for the tempworkers global group.D on each shared folder on the three file servers, add the three servers to the auditing tab configure the failed full control setting in the auditing entry dialog.E on each shared folde
23、r on the three file servers, add the tempworkers global group to the auditing tab configure the failed full control setting in the auditing entry dialog box BE12 your company has an active directory forest. The company has branch offices in three locations. Each location has an organizational unit.
24、You need to ensure that the branch office administrators are able to create and apply gpos only to their respective organizational units. Which two actions should you perform? (each correct answer presents part of the solution. Choose two)A add the user accounts of the branch office administrators t
25、o the group policy creator owners groupB modify the managed by tab in each organizational unit to add the branch office administrators to their respective organizational units.C run the delegation of control wizard and delegate the right to link gpos for the domain to the branch office administrator
26、sD run the delegation of control wizard an delegate the right to link gpos for their branch organizational units to the branch office administrators. AD13 your company has an active directory forest. Each branch office has an organizational unit and a child organizational unit named sales. The sales
27、 organizational unit contains all users and computers of the sales department. You need to install an office 2007 application only on the computers in the sales organizational unit. You create a gpo named salesapp gpo. What should you do next?A configure the gpo to assign the application to the comp
28、uter account. Link the salesapp gpo to the domain.B configure the gpo to assign the application to the user account. Link the salesapp gpo to the sales organizational unit in each locaton.C configure the gpo to publish the application to the user account. Link the salesapp gpo to the sales organizat
29、ional unit in each locaton.D configure the gpo to assign the application to the computer account. Link the salesapp gpo to the sales organizational unit in each locaton. D 14 your network consists of a single active directory domain. The domain contains 10 domain controllers. The domain controllers run windows server 2008 and are configured as dns servers. You plan to create a new active directory-intergrated zone. You need to ensure that the new zone is only replicated to four of your domain controllers. What should you do fir
copyright@ 2008-2022 冰豆网网站版权所有
经营许可证编号:鄂ICP备2022015515号-1