单项选择题

Your company has an Active Directory domain named contoso.com. The company network has two DNS servers named DNS1 and DNS2. 
The DNS servers are configured as shown in the following table.

Domain users, who are configured to use DNS2 as the preferred DNS server, are unable to connect to Internet Web sites. 
You need to enable Internet name resolution for all client computers. 
What should you do()

A.Create a copy of the .(root) zone on DNS1.
B.Update the list of root hints servers on DNS2.
C.Update the Cache.dns file on DNS2 Configure conditional forwarding on DNS1.
D.Delete the .(root) zone from DNS2. Configure conditional forwarding on DNS2.


您可能感兴趣的试卷

你可能感兴趣的试题

1.单项选择题Your company has an Active Directory domain. You log on to the domain controller. The Active Directory Schema snap-in is not available in the Microsoft Management Console (MMC). You need to access the Actrve Directory Schema snap-in. What should you do()

A.Register Schmmgml.dll.
B.Log off and log on again by using an account that is a member of the Schema Administrators group.
C.Use the Ntdsutil.exe command to connect to the Schema Master operations master and open the schema for writing.
D.Add the Active Directory Lightweight Directory Services (AD LDS) role to the domain controller by using Server Manager.

2.单项选择题Your company, Contoso, Ltd , has offices in North America and Europe. Contoso has an Active Directory forest that has three domains. You need to reduce the time required to authenticate users from the labs.eu. contoso.com domain when they access resources in the eng.na.contoso.com domain. What should you do()

A.Decrease the replication interval for all Connection objects.
B.Decrease the replication interval for the DEFAULTIPSITELINK site link.
C.Set up a one-way shortcut trust from eng.na.contoso.com to labs.eu.contoso.com.
D.Set up a one-way shortcut trust from labs.eu.contoso.com to eng.na.contoso.com.

3.单项选择题

Certkiller.com runs Window Server 2008 on all of its servers. It has a single Active Directory domain and it uses Enterprise Certificate Authority. The security policy at Certkiller .com makes it necessary to examine revoked certificate information. 
You need to make sure that the revoked certificate information is available at all times. What should you do to achieve that()

A.Add and configure a new GPO (Group Policy Object) that enables users to accept peer certificates and link the GPO to the domain.
B.Configure and use a GPO to publish a list of trusted certificate authorities to the domain
C.Configure and publish an OCSP (Online certificate status protocol) responder through ISAS (Internet Security and Acceleration Server) array.
D.Use network load balancing and publish an OCSP responder.
E.None of the above

4.单项选择题

As an administrator at Certkiller.com, you have installed an Active Directory forest that has a single domain. You have installed an Active Directory Federation services (AD FS) on the domain member server. 
What should you do to configure AD FS to make sure that AD FS token contains information from the active directory domain()

A.Add a new account store and configure it.
B.Add a new resource partner and configure it
C.Add a new resource store and configure it
D.Add a new administrator account on AD FS and configure it
E.None of the above

7.单项选择题Certkiller.com has a server with Active Directory Rights Management Services (AD RMS) server installed. Users have computers with Windows Vista installed on them with an Active Directory domain installed at Windows Server 2003 functional level. As an administrator at Certkiller.com, you discover that the users are unable to benefit from AD RMS to protect their documents. You need to configure AD RMS to enable users to use it and protect their documents. What should you do to achieve this functionality()

A.Configure an email account in Active Directory Domain Services (AD DS) for each user.
B.Add and configure ADRMSADMIN account in local administrators group on the user computers
C.Add and configure the ADRMSSRVC account in AD RMS server’s local administrator group
D.Reinstall the Active Directory domain on user computers
E.All of the above

8.多项选择题One of the remote branch offices of Certkiller branch is running a Windows Server 2008 having ready only domain controller (RODC) installed.For security reasons you don’t want some critical credentials like (passwords, encryption keys) to be stored on RODC. What should you do so that these credentials are not replicated to any RODC’s in the forest()

A.Configure RODC filtered attribute set on the server
B.Configure RODC filtered set on the server that holds Schema Operations Master role.
C.Delegate local administrative permissions for an RODC to any domain user without granting that user any user rights for the domain
D.Configure forest functional level server for Windows server 2008 to configure filteredattribute set.
E.None of the above

9.单项选择题Certkiller.com has servers on the main network that run Windows Server 2008. It also has two domain controllers. Active Directory services are running on a domain controller named CKDC1. You have to perform critical updates of Windows Server 2008 on CKDC1 without rebooting the server. What should you do to perform offline critical updates on CKDC1 without rebooting the server()

A.Start the Active Directory Domain Services on CKDC1
B.Disconnect from the network and start the Windows update feature
C.Stop the Active Directory domain services and install the updates. Start the Active Directorydomain services after installing the updates.
D.Stop Active Directory domain services and install updates. Disconnect from the network and then connect again
E.None of the above

最新试题

Your network contains an Active Directory domain. All domain controller run Windows Server  2003.    You replace all domain controllers with domain controllers that run Windows Server 2008 R2.    You raise the functional level of the domain to Windows Server 2008 R2.    You need to minimize the amount of SYSVOL replication traffic on the network.    What should you do()

题型:单项选择题

Your network contains an Active Directory domain named contoso.com. All domain controllers  and member servers run Windows Server 2008. All client computer run Windows 7.  From a client computer, you create an audit policy by using the Advanced Audit Policy  Configuration settings in the Default Domain Policy Group Policy object (GPO).  You discover that the audit policy is not applied to the member servers.    The audit policy is  applied to the client computers.  You need to ensure that the audit policy is applied to all member servers and all client computers.    What should you do()

题型:单项选择题

You have an enterprise subordinate certification authority (CA). You have a custom certificate  template that has a key length of 1,024 bits. The template is enabled for autoenrollment.    You increase the template key length to 2,048 bits.  You need to ensure that all current certificate holders automatically enroll for a certificate that  uses the new template.    Which console should you use()

题型:单项选择题

Your network contains an Active Directory forest. The forest contains two domains. You have a  standalone root certification authority (CA).    On a server in the child domain, you run the Add Roles Wizard and discover that the option to  select an enterprise CA is disabled.    You need to install an enterprise subordinate CA on the server.    What should you use to log on to the new server()

题型:单项选择题

Your network contains an Active Directory domain named contoso.com. The domain contains five  domain controllers.You add a logoff script to an existing Group Policy object (GPO). You need to verify that each  domain controller successfully replicates the updated group policy.    Which two objects should you verify on each domain controller()

题型:多项选择题

You have a domain controller named Server1 that runs Windows Server 2008 R2.    You need to determine the size of the Active Directory database on Server1.    What should you do()

题型:单项选择题

What should you do() 

题型:单项选择题

Your network contains three Active Directory forest named Forest1, Forest2, and Forest3. Each  forest contains three domains.  A two-way forest trust exists between Forest1 and Forest2. A two-way forest trust exists between  Forest2 and Forest3.     You need to configure the forest to meet the following requirements    Users in Forest3 must be able to access resources in Forest1.  Users in Forest1 must be able to access resources in Forest3.  The number of trusts must be minimized.    What should you do()

题型:单项选择题

You have an enterprise subordinate certification authority (CA). The CA is configured to use a  hardware security module.  You need to back up Active Directory Certificate Services on the CA.    Which command should you run()

题型:单项选择题

You remotely monitor several domain controllers.  You run winrm.exe quickconfig on each domain controller. You need to create a WMI script query  to retrieve information from the bios of each domain controller.    Which format should you use to write the query()

题型:单项选择题