Your company has a main office and a branch office. The branch office contains a read-only domain controller named RODC1.
You need to ensure that a user named Admin1 can install updates on RODC1. The solution must prevent Admin1 from logging on to other domain controllers.
What should you do()
A.Run ntdsutil.exe and use the Roles option.
B.Run dsmgmt.exe and use the Local Roles option.
C.From Active Directory Sites and Services, modify the NTDS Site Settings.
D.From Active Directory Users and Computers, add the user to the Server Operators group.
您可能感兴趣的试卷
你可能感兴趣的试题
Your network contains an Active Directory Rights Management Services (AD RMS) cluster.
You have several custom policy templates. The custom policy templates are updated frequently.
Some users report that it takes as many as 30 days to receive the updated policy templates.
You need to ensure that users receive the updated custom policy templates within seven days.
What should you do()
A.Modify the registry on the AD RMS servers.
B.Modify the registry on the users computers.
C.Change the schedule of the AD RMS Rights Policy Template Management (Manual) scheduled task.
D.Change the schedule of the AD RMS Rights Policy Template Management (Automated) scheduled task.
Your network contains a server named Server1. The Active Directory Rights Management Services (AD RMS) server role is installed on Server1.
An administrator changes the password of the user account that is used by AD RMS. You need to update AD RMS to use the new password.
Which console should you use()
A.Active Directory Rights Management Services
B.Active Directory Users and Computers
C.Component Services
D.Services
Active Directory Rights Management Services (AD RMS) is deployed on your network. Users who have Windows Mobile 6 devices report that they cannot access documents that areprotected by AD RMS. You need to ensure that all users can access AD RMS protected content by using Windows Mobile 6 devices.
What should you do()
A.Modify the security of the ServerCertification.asmx file.
B.Modify the security of the MobileDeviceCertification.asmx file.
C.Enable anonymous authentication for the _wmcs virtual directory.
D.Enable anonymous authentication for the certification virtual directory.
Your network contains an Active Directory domain named contoso.com. The network contains client computers that run either Windows Vista or Windows 7.
Active Directory Rights Management Services (AD RMS) is deployed on the network.
You create a new AD RMS template that is distributed by using the AD RMS pipeline. The template is updated every month.
You need to ensure that all the computers can use the most up-to-date version of the AD RMS template.
You want to achieve this goal by using the minimum amount of administrative effort.
What should you do()
A.Upgrade all of the Windows Vista computers to Windows 7.
B.Upgrade all of the Windows Vista computers to Windows Vista Service Pack 2 (SP2).
C.Assign the Microsoft Windows Rights Management Services (RMS) Client Service Pack 2 (SP2) to all users by using a Software Installation extension of Group Policy.
D.Assign the Microsoft Windows Rights Management Services (RMS) Client Service Pack 2 (SP2) to all computers by using a Software Installation extension of Group Policy.
Your network contains two Active Directory forests named contoso.com and adatum.com. Active Directory Rights Management Services (AD RMS) is deployed in contoso.com.
An AD RMS trusted user domain (TUD) exists between contoso.com and adatum.com.
From the AD RMS logs, you discover that some clients that have IP addresses in the adatum.com forest are authenticating as users from contoso.com.
You need to prevent users from impersonating contoso.com users.
What should you do()
A.Configure trusted e-mail domains.
B.Enable lockbox exclusion in AD RMS.
C.Create a forest trust between adatum.com and contoso.com.
D.Add a certificate from a third-party trusted certification authority (CA).
Your network contains a single Active Directory domain.
Active Directory Rights Management Services (AD RMS) is deployed on the network.
A user named User1 is a member of only the AD RMS Enterprise Administrators group.
You need to ensure that User1 can change the service connection point (SCP) for the AD RMS installation. The solution must minimize the administrative rights of User1.
To which group should you add User1()
A.AD RMS Auditors
B.AD RMS Service Group
C.Domain Admins
D.Schema Admins
Your network contains an Active Directory domain. The domain contains a server named Server1.
Server1 runs Windows Server 2008 R2.
You need to mount an Active Directory Lightweight Directory Services (AD LDS) snapshot from Server1.
What should you do()
A.Run ldp.exe and use the Bind option.
B.Run diskpart.exe and use the Attach option.
C.Run dsdbutil.exe and use the snapshot option.
D.Run imagex.exe and specify the /mount parameter.
Your network contains a server named Server1 that runs Windows Server 2008 R2. On Server1, you create an Active Directory Lightweight Directory Services (AD LDS) instance named Instance1.
You connect to Instance1 by using ADSI Edit.
You run the Create Object wizard and you discover that there is no User object class.
You need to ensure that you can create user objects in Instance1.
What should you do()
A.Run the AD LDS Setup Wizard.
B.Modify the schema of Instance1.
C.Modify the properties of the Instance1 service.
D.Install the Remote Server Administration Tools (RSAT).
Your network contains a server named Server1 that runs Windows Server 2008 R2.
You create an Active Directory Lightweight Directory Services (AD LDS) instance on Server1.
You need to create an additional AD LDS application directory partition in the existing instance.
Which tool should you use()
A.Adaminstall
B.Dsadd
C.Dsmod
D.Ldp
Your network contains two standalone servers named Server1 and Server2 that have Active Directory Lightweight Directory Services (AD LDS) installed.Server1 has an AD LDS instance. You need to ensure that you can replicate the instance from Server1 to Server2.
What should you do on both servers()
A.Obtain a server certificate.
B.Import the MS-User.ldf file.
C.Create a service user account for AD LDS.
D.Register the service location (SRV) resource records.
最新试题
Your network contains three Active Directory forest named Forest1, Forest2, and Forest3. Each forest contains three domains. A two-way forest trust exists between Forest1 and Forest2. A two-way forest trust exists between Forest2 and Forest3. You need to configure the forest to meet the following requirements Users in Forest3 must be able to access resources in Forest1. Users in Forest1 must be able to access resources in Forest3. The number of trusts must be minimized. What should you do()
Your network contains an Active Directory forest. The forest contains two domain controllers. The domain controllers are configured as shown in the following table. All client computers run Windows 7. You need to ensure that all client computers in the domain keep the same time as an external time server. What should you do()
You need to compact an Active Directory database on a domain controller that runs windows Server 2008 R2. What should you do()
You remotely monitor several domain controllers. You run winrm.exe quickconfig on each domain controller. You need to create a WMI script query to retrieve information from the bios of each domain controller. Which format should you use to write the query()
Your network contain 10 domain controller that run Windows Server R2. The network contain a member server that is configured to collect all of events that occur on the domain controllers. Your need to ensure that administrators are notified when a specific event occurs on any of the domain controllers. You want to achive the goal by using the minimum amount effort. What should you do()
You have an enterprise subordinate certification authority (CA) configured for key archival. Three key recovery agent certificates are issued. The CA is configured to use two recovery agents. You need to ensure that all of the recovery agent certificates can be used to recover all new private keys. What should you do()
You create a new Active Directory domain. The functional level of the domain is Windows Server 2008 R2. The domain contains five domain controllers. You need to monitor the replication of the group policy template files. Which tool should you use()
You need to receive an e-mail message whenever a domain user account is locked out. Which tool should you use()
Your network contains a single Active Directory domain named contoso.com. An administrator accidentally deletes the _msdsc.contoso.com zone. You recreate the _msdsc.contoso.com zone. You need to ensure that the _msdsc.contoso.com zone contains all of the required DNS records. What should you do on each domain controller()
You have an enterprise subordinate certification authority (CA). You have a custom certificate template that has a key length of 1,024 bits. The template is enabled for autoenrollment. You increase the template key length to 2,048 bits. You need to ensure that all current certificate holders automatically enroll for a certificate that uses the new template. Which console should you use()