单项选择题Your company has an Active Directory forest. Not all domain controllers in the forest are configured as Global Catalog Servers. Your domain structure contains one root domain and one child domain. You modify the folder permissions on a file server taht is in th child domain. You discover that some Access Control entries start with S-1-5-21 and that no account name is listed. You need to list the account names. What should you do()

A.Move the RID master role in the child domain to a domain controller that holds the Global Catalog.
B.Modify the schema to enable replication of the friendlynames attribute to the Global Catalog.
C.Move the RID master role in the child domain to a domain controller that does not hold the Global Catalog.
D.Move the infrastructure master role in the child domain to a domain controller that does not hold the Global Catalog.


您可能感兴趣的试卷

你可能感兴趣的试题

1.单项选择题You have an existing Active Directory site named Site1. You create a new Actrve Directory site and name it Site2.You need to configure Active Directory replication between Site1 and Site2. You install a new domain controller. You create the site link between Site1 and Site2. What should you do next()

A.Use the Active Directory Sites and Services console to configure a new site link bridge object.
B.Use the Active Directory Sites and Services console to decrease the site link cost between Site1 and Site2.
C.Use the Active Directory Sites and Services console to assign a new IP subnet to Site2. Move the new domain controller object to Site2.
D.Use the Active Directory Sites and Services console to configure the new domain controller as a preferred bridgehead server for Site1.

2.单项选择题Your company has an Active Directory domain. The company has two domain controllers named DC1 and DC2. DC1 holds the Schema Master role DC1 fails You log on to Actrve Directory by using the administrator account. You are not able to transfer the Schema Master operations role. You need to ensure that DC2 holds the Schema Master role. What should you do()

A.Register the Schmmgmt.dll. Start the Active Directory Schema snap-in.
B.Configure DC2 as a bridgehead server
C.On DC2, seize the Schema Master role
D.Log off and log on again to Active Directory by using an account that is a member of the Schema Administrators group. Start the Actrve Directory Schema snap-in.

3.多项选择题Your company has a main office and three branch offices. Each office is configured as a separate Active Directory site that has its own domain controller. You disable an account that has administratrve rights. You need to immediately replicate the disabled account information to all sites. What are two possible ways to achieve this goal()

A.Use Dsmod.exe to configure all domain controllers as global catalog servers.
B.Use Repadmin.exe to force replication between the site connection objects
C.From the Active Directory Sites and Services console, select the existing connection objects and force replication.
D.From the Actrve Directory Sites and Services console, configure all domain controllers as global catalog servers.

4.单项选择题The Certkiller has a Windows 2008 domain controller server. This server is routinely backed up over the network from a dedicated backup server that is running Windows 2003 OS. You need to prepare the domain controller for disaster recovery apart from the routine backup procedures. You are unable to launch the backup utility while attempting to back up the system state data for the data controller. You need to backup system state data from the Windows Server 2008 domain controller server. What should you do()

A.Add your user account to the local Backup Operators group
B.Install the Windows Server backup feature using the Server Manager feature.
C.Install the Removable Storage Manager feature using the Server Manager feature
D.Deactivating the backup job that is configured to backup Windows 2008 server domain controller on the Windows 2003 server.
E.None of the above

5.单项选择题

ertkiller .com has purchased laptop computers that will be used to connect to a wireless network. You create a laptop organizational unit and create a Group Policy Object (GPO) and configure user profiles by utilizing the names of approved wireless networks. You link the GPO to the laptop organizational unit. The new laptop users complain to you that they cannot connect to a wireless network. 
What should you do to enforce the group policy wireless settings to the laptop computers()

A.Execute gpupdate/target:computer command at the command prompt on laptop computers
B.Execute Add a network command and leave the SSID (service set identifier) blank
C.Execute gpupdate/boot command at the command prompt on laptops computers
D.Connect each laptop computer to a wired network and log off the laptop computer and then login again.
E.None of the above

6.多项选择题You had installed an Active Directory Federation Services (AD FS) role on a Windows server 2008 in your organization. Now you need to test the connectivity of clients in the network to ensure that they can successfully reach the new Federation server and Federation server is operational. What should you do()

A.Go to Services tab, and check if Active Directory Federation Services is running
B.In the event viewer, Applications, Event ID column look for event ID 674.
C.Open a browser window, and then type the Federation Service URL for the new federation server. 
D.None of the above

9.单项选择题

As the Certkiller administrator you had installed a read-only domain controller (RODC) server at remote location. 
The remote location doesn’t provide enough physical security for the server. 
What should you do to allow administrative accounts to replicate authentication information to Read-Only Domain Controllers()

A.Remove any administrative accounts from RODC’s group
B.Add administrative accounts to the domain Allowed RODC Password Replication group
C.Set the Deny on Receive as permission for administrative accounts on the RODC computer account security tab for the Group Policy Object (GPO)
D.Configure a new Group Policy Object (GPO) with the Account Lockout settings enabled. Link the GPO to the remote location. Activate the Read Allow and the Apply group policy Allow permissions for the administrators on the Security tab for the GPO.
E.None of the above

10.单项选择题Your company has an Active Directory forest. Each branch office has an organizational unit and a child organizational unit named Sales. The Sales organizational unit contains all users and computers of the sales department. You need to install an Office 2007 application only on the computers in the Sales organizational unit. You create a GPO named SalesApp GPO. What should you do next()

A.Configure the GPO to assign the application to the computer account. Link the SalesAPP GPO to the domain.
B.Configure the GPO to assign the application to the user account. Link the SalesAPP GPO to the Sales organizational unit in each location.
C.Configure the GPO to publish the application to the user account. Link the SalesAPP GPO to the Sales organizational unit in each location.
D.Configure the GPO to assign the application to the computer account. Link the SalesAPP GPO to the Sales organizational unit in each location.

最新试题

Your network contains an Active Directory domain that has two sites.    You need to identify whether logon scripts are replicated to all domain controllers.    Which folder should you verify()

题型:单项选择题

You remotely monitor several domain controllers.  You run winrm.exe quickconfig on each domain controller. You need to create a WMI script query  to retrieve information from the bios of each domain controller.    Which format should you use to write the query()

题型:单项选择题

Active Directory Rights Management Services (AD RMS) is deployed on your network.    You need to configure AD RMS to use Kerberos authentication.  Which two actions should you perform()

题型:多项选择题

You have an enterprise subordinate certification authority (CA). The CA is configured to use a  hardware security module.  You need to back up Active Directory Certificate Services on the CA.    Which command should you run()

题型:单项选择题

You create a new Active Directory domain. The functional level of the domain is Windows Server  2003.    The domain contains five domain controllers that run Windows Server 2008 R2.    You need to monitor the replication of the group policy template files.    Which tool should you use()

题型:单项选择题

Your network contains an Active Directory domain named contoso.com. You have a management  computer named Computer1 that runs Windows 7.    You need to forward the logon events of all the domain controllers in contoso.com to Computer1.    All new domain controllers must be dynamically added to the subscription.  What should you do()

题型:单项选择题

You install a standalone root certification authority (CA) on a server named Server1.  You need to ensure that every computer in the forest has a copy of the root CA certificate  installed in the local computer’s Trusted Root Certification Authorities store.    Which command should you run on Server1()

题型:单项选择题

Your network contains an Active Directory domain. The domain contains 1000 user accounts.  You have a list that contains the mobile phone number of each user  You need to add the mobile number of each user to Active Directory.    What should you do()

题型:单项选择题

Your network contains an Active Directory domain. The domain contains a group named Group1.  The minimum password lenght for the domain is set to six characters.  you need to ensure that the passwords for all users in Group1 are at least 10 characters long. All  other users must be able to use passwords that are six characters long.    What should you do first()

题型:单项选择题

You have an enterprise subordinate certification authority (CA) configured for key archival. Three  key recovery agent certificates are issued.  The CA is configured to use two recovery agents.    You need to ensure that all of the recovery agent certificates can be used to recover all new  private keys.    What should you do()

题型:单项选择题