单项选择题Your company, Contoso, Ltd , has offices in North America and Europe. Contoso has an Active Directory forest that has three domains. You need to reduce the time required to authenticate users from the labs.eu. contoso.com domain when they access resources in the eng.na.contoso.com domain. What should you do()

A.Decrease the replication interval for all Connection objects.
B.Decrease the replication interval for the DEFAULTIPSITELINK site link.
C.Set up a one-way shortcut trust from eng.na.contoso.com to labs.eu.contoso.com.
D.Set up a one-way shortcut trust from labs.eu.contoso.com to eng.na.contoso.com.


您可能感兴趣的试卷

你可能感兴趣的试题

1.单项选择题

Certkiller.com runs Window Server 2008 on all of its servers. It has a single Active Directory domain and it uses Enterprise Certificate Authority. The security policy at Certkiller .com makes it necessary to examine revoked certificate information. 
You need to make sure that the revoked certificate information is available at all times. What should you do to achieve that()

A.Add and configure a new GPO (Group Policy Object) that enables users to accept peer certificates and link the GPO to the domain.
B.Configure and use a GPO to publish a list of trusted certificate authorities to the domain
C.Configure and publish an OCSP (Online certificate status protocol) responder through ISAS (Internet Security and Acceleration Server) array.
D.Use network load balancing and publish an OCSP responder.
E.None of the above

2.单项选择题

As an administrator at Certkiller.com, you have installed an Active Directory forest that has a single domain. You have installed an Active Directory Federation services (AD FS) on the domain member server. 
What should you do to configure AD FS to make sure that AD FS token contains information from the active directory domain()

A.Add a new account store and configure it.
B.Add a new resource partner and configure it
C.Add a new resource store and configure it
D.Add a new administrator account on AD FS and configure it
E.None of the above

5.单项选择题Certkiller.com has a server with Active Directory Rights Management Services (AD RMS) server installed. Users have computers with Windows Vista installed on them with an Active Directory domain installed at Windows Server 2003 functional level. As an administrator at Certkiller.com, you discover that the users are unable to benefit from AD RMS to protect their documents. You need to configure AD RMS to enable users to use it and protect their documents. What should you do to achieve this functionality()

A.Configure an email account in Active Directory Domain Services (AD DS) for each user.
B.Add and configure ADRMSADMIN account in local administrators group on the user computers
C.Add and configure the ADRMSSRVC account in AD RMS server’s local administrator group
D.Reinstall the Active Directory domain on user computers
E.All of the above

6.多项选择题One of the remote branch offices of Certkiller branch is running a Windows Server 2008 having ready only domain controller (RODC) installed.For security reasons you don’t want some critical credentials like (passwords, encryption keys) to be stored on RODC. What should you do so that these credentials are not replicated to any RODC’s in the forest()

A.Configure RODC filtered attribute set on the server
B.Configure RODC filtered set on the server that holds Schema Operations Master role.
C.Delegate local administrative permissions for an RODC to any domain user without granting that user any user rights for the domain
D.Configure forest functional level server for Windows server 2008 to configure filteredattribute set.
E.None of the above

7.单项选择题Certkiller.com has servers on the main network that run Windows Server 2008. It also has two domain controllers. Active Directory services are running on a domain controller named CKDC1. You have to perform critical updates of Windows Server 2008 on CKDC1 without rebooting the server. What should you do to perform offline critical updates on CKDC1 without rebooting the server()

A.Start the Active Directory Domain Services on CKDC1
B.Disconnect from the network and start the Windows update feature
C.Stop the Active Directory domain services and install the updates. Start the Active Directorydomain services after installing the updates.
D.Stop Active Directory domain services and install updates. Disconnect from the network and then connect again
E.None of the above

9.单项选择题

Certkiller.com has installed a server. You are assigned to install and run an instance of Active Directory Lightweight Directory Service (AD LDS). After doing necessary configurations, you start an instance of AD LDS successfully. 
Now you need to create new Organizational Units in the AD LDS application directory partition. What should you do to create new OUs in the AD LDS application directory partition()

A.To create the OUs, use the dsmod OU  command
B.Employ ADSI Edit Snap-in to create the OUs on the AD LDS application directory partition.
C.Create OUs by executing dsadd OU  command
D.Create OUs on the AD LDS application directory partition by using Active Directory Users and computers snap-in.

10.单项选择题Your company has an Active Directory domain. All servers run Windows Server 2008. You deploy a Certification Authority (CA) server. You create a new global security group named CertIssuers. You need to ensure that members of the CertIssuers group can issue, approve, and revoke certificates. What should you do()

A.Assign the Certificate Manager role to the CertIssuers group.
B.Place CertIssuers group in the Certificate Publisher group
C.Run the certsrv -add CertIssuers command promt of the certificate server
D.Run the add -member-membertype memberset CertIssuers command by using Microsoft WindowsPowershell

最新试题

Your network contains an Active Directory domain. The domain contains a group named Group1.  The minimum password lenght for the domain is set to six characters.  you need to ensure that the passwords for all users in Group1 are at least 10 characters long. All  other users must be able to use passwords that are six characters long.    What should you do first()

题型:单项选择题

You create a new Active Directory domain. The functional level of the domain is Windows Server  2003.    The domain contains five domain controllers that run Windows Server 2008 R2.    You need to monitor the replication of the group policy template files.    Which tool should you use()

题型:单项选择题

You have Active Directory Certificate Services (AD CS) deployed. You create a custom certificate  template.  You need to ensure that all of the users in the domain automatically enroll for a certificate based  on the custom certificate template.    Which two actions should you perform()

题型:多项选择题

Your network contains an Active Directory domain named contoso.com. You have a management  computer named Computer1 that runs Windows 7.    You need to forward the logon events of all the domain controllers in contoso.com to Computer1.    All new domain controllers must be dynamically added to the subscription.  What should you do()

题型:单项选择题

You need to compact an Active Directory database on a domain controller that runs windows  Server 2008 R2.  What should you do()

题型:单项选择题

You need to receive an e-mail message whenever a domain user account is locked out.    Which tool should you use()

题型:单项选择题

Your network contains an Active Directory forest. The forest contains an Acitve Directory site for a  remote office. The remote site contains a read-only domain controller (RODC).    You need to configure the RODC to store only the password of users in the remote site.    What should you do()

题型:单项选择题

Your network contains an Active Directory domain. The domain contains 1000 user accounts.  You have a list that contains the mobile phone number of each user  You need to add the mobile number of each user to Active Directory.    What should you do()

题型:单项选择题

You have an enterprise subordinate certification authority (CA). The CA is configured to use a  hardware security module.  You need to back up Active Directory Certificate Services on the CA.    Which command should you run()

题型:单项选择题

Active Directory Rights Management Services (AD RMS) is deployed on your network.    You need to configure AD RMS to use Kerberos authentication.  Which two actions should you perform()

题型:多项选择题