Your company has a server that runs an instance of Active Directory Lightweight Directory Services
(AD LDS).
You need to create new organizational units in the AD LDS application directory partition. What should you do()
A.Use the Active Directory Users and Computers snap-in to create the organizational units on the AD LDS application directory partition.
B.Use the ADSI Edit snap-in to create the organizational units on the AD LDS application directory partition.
C.Use the dsadd OU
D.Use the dsmod OU
您可能感兴趣的试卷
你可能感兴趣的试题
You are decommissioning domain controllers that hold all forest-wide operations master roles. You need to transfer all forest-wide operations master roles to another domain controller. Which two roles should you transfer()
A.RID master
B.PDC emulator
C.Schema master
D.Infrastructure master
E.Domain naming master
Your company has an Active Directory domain. The company has two domain controllers named DC1
and DC2. DC1 holds the schema master role.
DC1 fails. You log on to Active Directory by using the administrator account. You are not able to transfer the schema master role.
You need to ensure that DC2 holds the schema master role. What should you do()
A.Register the Schmmgmt.dll. Start the Active Directory Schema snap-in.
B.Configure DC2 as a bridgehead server.
C.On DC2, seize the schema master role.
D.Log off and log on again to Active Directory by using an account that is a member of the Schema Admins group. Start the Active Directory Schema snap-in.
You are decommissioning one of the domain controllers in a child domain.
You need to transfer all domain operations master roles within the child domain to a newly installed domain controller in the same child domain.
Which three domain operations master roles should you transfer()
A.RID master
B.PDC emulator
C.Schema master
D.Infrastructure master
E.Domain naming master
Your company has an Active Directory domain.
You log on to the domain controller. The Active Directory Schema snap-in is not available in the Microsoft Management Console (MMC).
You need to access the Active Directory Schema snap-in.
What should you do()
A.Register Schmmgmt.dll.
B.Log off and log on again by using an account that is a member of the Schema Admins group.
C.Use the Ntdsutil.exe command to connect to the schema master operations master and open the schema for writing.
D.Add the Active Directory Lightweight Directory Services (AD?LDS) role to the domain controller by using Server Manager.
Your company has an Active Directory forest. Not all domain controllers in the forest are configured as Global Catalog Servers. Your domain structure contains one root domain and one child domain. You modify the folder permissions on a file server that is in the child domain.
You discover that some Access Control entries start with S-1-5-21 - and that no account name s listed.
You need to list the account names.
What should you do()
A.Move the RID master role in the child domain to a domain controller that holds the Global Catalog.
B.Modify the schema to enable replication of the friendlynames attribute to the Global Catalog.
C.Move the RID master role in the child domain to a domain controller that does not hold the Global Catalog.
D.Move the infrastructure master role in the child domain to a domain controller that does not hold the Global Catalog.
Your company has a main office and 10 branch offices. Each branch office has an Active Directory site that contains one domain controller. Only domain controllers in the main office are configured as Global Catalog servers.
You need to deactivate the Universal Group Membership Caching option on the domain controllers in the branch offices.
At which level should you deactivate the Universal Group Membership Caching option()
A.Site
B.Server
C.Domain
D.Connection object
Your company has a main office and 10 branch offices. Each branch office has an Active Directory site that contains one domain controller. Only domain controllers in the main office are configured as Global Catalog servers.
You need to deactivate the Universal Group Membership Caching option on the domain controllers in the branch offices.
At which level should you deactivate the Universal Group Membership Caching option()
A.Site
B.Server
C.Domain
D.Connection object
Your company has a branch office that is configured as a separate Active Directory site and has an Active Directory domain controller.
The Active Directory site requires a local Global Catalog server to support a new application. You need to configure the domain controller as a Global Catalog server. Which tool should you use()
A.The Dcpromo.exe utility
B.The Server Manager console
C.The Computer Management console
D.The Active Directory Sites and Services console
E.The Active Directory Domains and Trusts console
Your network consists of a single Active Directory domain. All domain controllers run Windows Server 2003.
You upgrade all domain controllers to Windows Server 2008 R2.
You need to ensure that the Sysvol share replicates by using DFS Replication (DFS-R). What should you do()
A.From the command prompt, run netdom /reset.
B.From the command prompt, run dfsutil /addroot:sysvol.
C.Raise the functional level of the domain to Windows Server 2008 R2.
D.From the command prompt, run dcpromo /unattend:unattendfile.xml.
You have an existing Active Directory site named Site1. You create a new Active Directory site and name it Site2.
You need to configure Active Directory replication between Site1 and Site2. You install a new domain controller. You create the site link between Site1 and Site2. What should you do next()
A.Use the Active Directory Sites and Services console to configure a new site link bridge object.
B.Use the Active Directory Sites and Services console to decrease the site link cost between Site1 and Site2.
C.Use the Active Directory Sites and Services console to assign a new IP subnet to Site2. Move the new domain controller object to Site2.
D.Use the Active Directory Sites and Services console to configure the new domain controller as a preferred bridgehead server for Site1.
最新试题
Your network contains an Active Directory forest. The forest contains two domains. You have a standalone root certification authority (CA). On a server in the child domain, you run the Add Roles Wizard and discover that the option to select an enterprise CA is disabled. You need to install an enterprise subordinate CA on the server. What should you use to log on to the new server()
Your company has four offices. The network contains a single Active Directory domain. Each office has domain controller. Each office has an organitational unit (OU) that contains the user accounts for the users in that office. In each office, support technicians perform basic troubleshooting for the users in their respective office. You need to ensure that the support technicians can reset the password for the user accounts in their respective office only. The solution must prevent the thechnicians from creating user accounts. What shoul you do()
Your network contains an Active Directory domain. All domain controller run Windows Server 2003. You replace all domain controllers with domain controllers that run Windows Server 2008 R2. You raise the functional level of the domain to Windows Server 2008 R2. You need to minimize the amount of SYSVOL replication traffic on the network. What should you do()
You need to receive an e-mail message whenever a domain user account is locked out. Which tool should you use()
Your network contains two Active Directory forests named contoso.com and nwtraders.com. A two-way forest trust exists between contoso.com and nwtraders.com. The forest trust is configured to use selective authentication. Contoso.com contains a server named Server1. Server1 contains a shared folder named Marketing. Nwtraders.com contains a global group named G_Marketing. The Change share permission and the Modify NTFS permissions for the Marketing folder are assignes to the G_Marketing group. Members of G_Marketing report that they cannot accesss the Marketing folder. You need to ensure that the G_Marketing members can accesss the folder from the network. What should you do()
Your network contains an Active Directory domain named contoso.com. All domain controllers and member servers run Windows Server 2008. All client computer run Windows 7. From a client computer, you create an audit policy by using the Advanced Audit Policy Configuration settings in the Default Domain Policy Group Policy object (GPO). You discover that the audit policy is not applied to the member servers. The audit policy is applied to the client computers. You need to ensure that the audit policy is applied to all member servers and all client computers. What should you do()
You create a new Active Directory domain. The functional level of the domain is Windows Server 2008 R2. The domain contains five domain controllers. You need to monitor the replication of the group policy template files. Which tool should you use()
You have an enterprise subordinate certification authority (CA). You have a custom Version 3 certificate template. Users can enroll for certificates based on the custom certificate template by using the Certificates console. The certificate template is unavailable for Web enrollment. You need to ensure that the certificate template is available on the Web enrollment pages. What should you do()
Your network contains a single Active Directory domain named contoso.com. An administrator accidentally deletes the _msdsc.contoso.com zone. You recreate the _msdsc.contoso.com zone. You need to ensure that the _msdsc.contoso.com zone contains all of the required DNS records. What should you do on each domain controller()
Your network contains an Active Directory forest. The forest contains two domain controllers. The domain controllers are configured as shown in the following table. All client computers run Windows 7. You need to ensure that all client computers in the domain keep the same time as an external time server. What should you do()