-
Active Directory database information that is stored on each domain controller has what file name?
-
What is the max level of OU (Organizational Unit) depth recommended by Microsoft for Active Directory?
-
What is the name of the master database that contains definitions of all objects in Active Directory?
-
What is another name for Domain Partition which contains all of the objects within the local domain?
- Directory Partition
- (p.10)
-
What are the 4 partitions for Active Directory?
- Schema Partition
- Configuration Partition
- Domain Partition (Directory Partition)
- Application Partition
- (p.9-10)
-
What is not considered a formal partition, but must be replicated to each domain?
-
What is defined as one or more IP subnets that are connected by fast links?
-
What is the authentication protocol used by Windows Server 2003?
-
What is the default Functional Level for Windows Server 2003?
-
What can be used to clean up DNS database when records are no longer required?
- Aging and Scavenging
- (p.41)
-
What is the purpose of domain DNS zones?
-
What is a shortcut trust?
- Transitive (A trusts C)
- (p.49)
-
What is the purpose of transitive Trust?
- shorten number of hops
- (p.49)
-
What are the requirements to install Active Directory?
- Edition - Standard, Enterprise. Datacenter
- Administrator Account (local machine)
- NTFS-200MB free space (database)
- 50MB free space (transaction log)
- TCP/IP
- DNS
- (p.28)
-
What Windows Server 2003 Edition cannot install Active Directory?
-
How much free hard drive space is needed for Active Directory transaction log files?
-
What do you run to install Active Directory?
- dcpromo
- Manage Your Server Web page
- (p.30)
-
What folder contains the Active Directory domain's public files?
-
Where does Active Directory store its database file?
-
What are the 4 parts of DNS that are installed during the Active Directory install process?
- Application Directory Partition
- Aging and Scavenging
- Forward Lookup Zones and SRV records
- Reverse Lookup Zones
- (p.36)
-
What is stored in the Global Catalog to make them available Forest wide?
- UPN (User Principal Names)
- (p.54)
-
What is required to raise the Functional Level of a Forest?
- Member of Enterprise Admins group
- (p.40)
-
Will dcpromo allow you to remove Active Directory?
-
True/False – Domain Functional Levels can be raised independently?
-
What are the two application Directory Partitions?
- domaindnszones
- forestdnszones
- (p.40)
-
What is required in DNS to allow clients to login?
-
What Forest Functional Level must you be in to create cross-forest trust?
2003
-
What trust would you use to create non-Microsoft system trust?
-
How do you set the fastest site link?
-
What is the value range of cost?
-
What is the Intersite default frequency of replication during the schedule?
-
-
What must a multi-master domain controller have to do replication?
- Active Directory-Integrated Zone
- (p.??)
-
What is defined by IP subnets that are well connected?
-
When complete propagation of a partition's objects and attributes has taken place on all domain controllers within a site it is called?
-
How often does KCC check for changes?
-
What is the max amount of hops that KCC allows?
-
What is the best protocol for replication?
-
What is the range of time Frequency can be set (minutes)?
- 15 minutes - 1 week (10,080 minutes)
- (p.??)
-
What are the 5 FSMO Roles?
- D - Domain Naming Master
- R - Relative Identifier (RID) Master
- I - Infrastructure Master
- P - Primary Domain Controller (PDC) Emulator
- S - Schema Master
- (p.90/93)
-
Which FSMO are Forest-Wide?
- Domain Naming Master
- Schema Master
- (p.93)
-
Which are Domain wide FSMO Roles?
- R - Relative Identifier (RID) Master
- I - Infrastructure Master
- P - Primary Domain Controller (PDC) Emulator
- (p.90)
-
What 3 things does the Domain Naming Master do?
- Makes sure Domain names are unique
- New Domain Names
- Removes Domain Names
- (p.94)
-
What does RID Master do?
- assigns RIDs
- first 500 RIDs
- request more 250 RIDs
- (p.91)
-
What is use to move an object to a different domain?
-
Can you create new users if your Domain Naming Master is down but you have 5 rids left?
-
The Infrastructure Role is like what other role?
-
What is the need for Universal Group Membership Caching?
- Process a logon without presence of Global Catalog Server
- (p.85)
-
What Functional level must you be in to do Universal Group Caching?
- Windows 2000 Native or higher
- (p.87)
-
How often does the Universal Cache get updated?
-
If you have a single DC what are its roles?
- Everything (DRIPS, Global Catalog)
- (p.90)
-
What role must you transfer if you are taking down a server?
- Infrastructure Master
- (p.??)
-
What server must you be on when using movetree.exe?
- RID Master (Source Domain)
- (p.91)
-
What can you use to add users to Active Directory users from the command-line with Excel (csv) document?
-
What would you use for a CSV file to add, delete or modify objects from the command-line?
-
What are the two situations you will have the Inf Master on the server with the Global Catalog?
- One Global Catalog
- All are Global Catalog
- (p.??)
-
What defines how users logon names should be created?
- Naming Standards Document
- (p.140)
-
What is the most important part of a secure network?
- Education of Users
- (p.140)
-
Where do you enable Smart Card login for user?
- Active Directory Users and Computers --> User Properties --> Account Tab --> Smart Card is Required
- (p.145)
-
What service must be running to use Run As?
- Secondary Logon Service
- (p.146)
-
What is a strong password (by the book)?
- 8 characters
- special, number
- one character off previous
- (p.142)
-
How can you elevate to another user account?
-
If you have set delegation what location will you remove delegation?
-
How do you move OUs around in Active Directory Users and Computers?
- Drag and Drop
- Move Option
- DSmove
- (p153-154)
-
What is the method of controlling settings across your network?
-
Nonlocal Group Policy Objects(GPO) can be can be linked to what 3 things?
- Sites
- Domains
- OUs
- (last is strongest)
- (p.162)
-
In what order are Group Policies processed?
- Local-Site-Domain-OU (LSDOU)
- (p.172)
-
How can you access Local Group Policies?
-
What are examples of group policy containers?
-
How many GPOs can they contain?
- as many as it can hold
- (p.??)
-
What is in a GPO folder?
- contain GPO settings in Sysvol folder
- (p.??)
-
If you create a GPO at the domain level what will it affect?
- everything in the domain
- (p.171)
-
What would you do if you wanted to prevent the GPO from affecting a particular OU?
- Block Policy Inheritance
- (p.175)
-
If you have a GPO and you want to set the strongest precedence over everything else what do you use?
-
What is the location of the key in the Group Policy editor for changing password settings?
- Computer Configuration --> Windows Settings --> Security Settings --> Account Policies --> Password Policies
- (p.186)
-
What is the default mechanism for authenticating domain users in Server 2003?
-
Logon Event Category and Account Logon Event Category are different in what way?
- Logon Event Category - logs local workstation
- Account Logon - logs for logon to domain controller
- (p.192)
-
What give the administrator the ability to redirect storing of files?
- Folder Redirection
- (p.205)
-
If you have shutdown on full security log what can be used as an attack on your system?
-
What are the reason(s) to set a service to Manual or Disable?
- Optimize (Security - not in the book)
- (p.197)
-
What are the diffence in Basic and Advanced Folder Redirection?
- Ability to specify location
- (p.206)
-
If you turn on auditing what two locations in the GPO must be set?
- Group Policy Object Editor (p.191)Active Directory Users and Computers --> Object --> Properties --> Security --> Advanced --> Auditing
- (p.193)
-
How do you force GPO update?
-
What are the four parts of the Software Life Cycle?
- P - Planning
- I - Implementation
- M - Maintenance
- R - Removal
- (p.222)
-
What are the 3 extension of Windows Installer packages and what do they do?
- Installer - .msi
- Transform - .mst
- Patches - .msp
- (p.223)
-
What are the two Nodes you can assign an application?
-
What Nodes can you publish an application?
-
What file extension is used for older software and can only be published?
-
What are the four levels of Software Restriction Rules?
- Hash
- Certificate
- Internet Zone
- Path
- (p.238-240)
-
What is the default security of software when installed?
-
What security applies only to msi files?
-
How do you deploy installation with GPOs?
-
What are the 3 ways to control Group Policy?
- Block Policy Inheritance
- Security Filtering (ACL)
- WMI Filters
- (p.252)
-
How many WMI filters can be created for a GPO?
-
What is used to Manage GPOs?
- GPMC - Group Policy Management Console
- (p.256)
-
What tool is used to test the affect of policies applied to users or computers after all filters, Security Group Permissions, Block Policy, Ect.?
- RSoP - Resultant Set of Policies
- (p.261)
-
96. What are the two RSoP modes?
- Planning Mode
- Logging Mode
- (p.262)
-
What is used in RSoP to obtain information from the client computer/users?
-
What is a command line tool that allows you to create and display n RSoP query from the command line?
-
How do you stop a GPO from a Group of People?
- Security Filtering (ACL/ACE)
- (p.252)
-
What OS must you have to use WMI filters?
- Windows Server 2003/Windows XP Pro SP1
- (p.??)
-
What is the database engine for Active Directory?
- Extensible Storage Engine (ESE)
- (p.282)
-
What is the default life of a "tombstone"?
-
What must be done to perform Manual Offline Defragmentation?
- F8 (Advanced Option Menu) --> Directory Services Restore Mode --> ntdsutil
- (p.283)
-
What tool would you use to backup System State?
-
What is the method to restore domain controller to a point in time it was considered good?
-
What tool must be used to do authoritative restore?
-
When a catastrophic event affecting all your domain controllers requires an entire domain to be restored you should preform?
-
What is the tool used to give you the state of your Domain Controller and help with troubleshooting?
-
What is the tool you use to compare directory information on more than one domain controller and detect differences?
-
What is the tool used to display replication and status?
-
What tool can check replication consistency and force replication events (KCC)?
-
What is the tool that can manage and verify trust, join computers to domains and verify replication ability?
-
What is the first thing you should check if you are having problems with your Active Directory?
- Event Viewer (Directory Service Logs)
- (p.297)
-
What must be on the root forest domain for you to raise the forest functional level?
-
What is the standard that defines the naming of all objects?
-
What is the location that all Active Directory information is stored that is replicated across the domain?
-
What is the purpose of Windows 2003 Interim Functional Level?
-
What was the naming service pre-Windows 2000?
-
What is the type of trust used to minimize hops?
-
What is the default cost of a site link?
-
What is the server that connects two sites/domains for replication?
-
What does Active Directory use to track changes along with timestamps?
-
What type of updates does Active Directory-Integrated Zones provide?
-
What is the role of the Global Catalog Server?
- Facilitation of searches for objects in the forest
- Resolution of UPNs
- Provision of universal group membership
- (p.84)
-
What is the term for putting a Group inside a Group?
-
What is the lowest role you can convert a Group?
- Windows Server 2000 Native
- (p.117)
-
What is the best way to hide objects in an OU?
- ACL --> List Content Permission
- (p.147-148)
-
Where do you edit the GPO for an OU?
- Active Directory Users and Computers --> Properties of OU --> Group Policies Tab --> Edit
- (p.??)
-
-
Where do you go to edit GPOs?
- Active Directory Users and Computers (you will end up in Group Policy Object Editor - MMC Snap-in)
- (p.166)
-
What order will GPOs be loaded and then processed?
- (load) LSDO (process) LSDO
- (p.171-172)
-
What are the 3 running levels of Services?
- Automatic
- Man
- Disable
- (p.??)
|
|