Your network consists of an Active Directory forest that contains one domain named contoso.com.
All domain controllers run Windows Server 2008 R2 and are configured as DNS servers. You have two Active Directory-integrated zones: contoso.com and nwtraders.com.
You need to ensure a user is able to modify records in the contoso.com zone. You must prevent the user from modifying the SOA record in the nwtraders.com zone.
What should you do()
A.From the DNS Manager console, modify the permissions of the contoso.com zone.
B.From the DNS Manager console, modify the permissions of the nwtraders.com zone.
C.From the Active Directory Users and Computers console, run the Delegation of Control Wizard.
D.From the Active Directory Users and Computers console, modify the permissions of the Domain Controllers organiz
您可能感兴趣的试卷
你可能感兴趣的试题
Your network contains an Active Directory forest. All domain controllers run Windows Server 2008 R2 and are configured as DNS servers. You have an Active Directory-integrated zone for contoso.com.
You have a UNIX-based DNS server.
You need to configure your Windows Server 2008 R2 environment to allow zone transfers of the contoso.com zone to the UNIX-based DNS server.
What should you do in the DNS Manager console()
A.Disable recursion.
B.Create a stub zone.
C.Create a secondary zone.
D.Enable BIND secondaries.
Your network consists of an Active Directory forest named contoso.com. All servers run Windows Server 2008 R2. All domain controllers are configured as DNS servers. The contoso.com DNS zone is stored in the ForestDnsZones Active Directory application partition.
You have a member server that contains a standard primary DNS zone for dev.contoso.com.
You need to ensure that all domain controllers can resolve names for dev.contoso.com.
What should you do()
A.Create a NS record in the contoso.com zone.
B.Create a delegation in the contoso.com zone.
C.Create a standard secondary zone on a Global Catalog server.
D.Modify the properties of the SOA record in the contoso.com zone.
You have a domain controller that runs Windows Server 2008 R2 and is configured as a DNS server.
You need to record all inbound DNS queries to the server.
What should you configure in the DNS Manager console()
A.Enable debug logging.
B.Enable automatic testing for simple queries.
C.Enable automatic testing for recursive queries.
D.Configure event logging to log errors and warnings.
Your network consists of an Active Directory forest that contains two domains. All servers run Windows Server 2008 R2. All domain controllers are configured as DNS servers.
You have a standard primary zone for dev.contoso.com that is stored on a member server.
You need to ensure that all domain controllers can resolve names from the dev.contoso.com zone.
What should you do()
A.On the member server, create a stub zone.
B.On the member server, create a NS record for each domain controller.
C.On one domain controller, create a conditional forwarder. Configure the conditional forwarder to replicate to all DNS
D.On one domain controller, create conditionals forwarder. Configure the conditional forwarder to replicate to all DNS
Your company has an Active Directory domain named contoso.com. FS1 is a member server in contoso.com.
You add a second network interface card, NIC2, to FS1 and connect NIC2 to a subnet that contains computers in a DNS domain named fabrikam.com. Fabrikam.com has a DHCP server and a DNS server.
Users in fabrikam.com are unable to resolve FS1 by using DNS. You need to ensure that FS1 has an A record in the fabrikam.com DNS zone.
What are two possible ways to achieve this goal()
A.Configure the DHCP server in fabrikam.com with the scope option 044 WINS/NBNS Servers.
B.Configure the DHCP server in fabrikam.com by setting the scope option 015 DNS Domain Name to the domain nam
C.Configure NIC2 by configuring the Append these DNS suffixes (in order): option.
D.Configure NIC2 by configuring the Use this connection’s DNS suffix in DNS registration option.
E.Configure the DHCP server in contoso.com by setting the scope option 015 DNS Domain Name to the domain nam
Your company has an Active Directory domain named contoso.com. The company network has two DNS servers named DNS1 and DNS2.
The DNS servers are configured as shown in the following table: DNS1 DNS2
_msdcs.contoso.com contoso.com .(root)
_msdcs.contoso.com contoso.com
Domain users, who are configured to use DNS2 as the preferred DNS server, are unable to connect to Internet Web sites.
You need to enable Internet name resolution for all client computers.
What should you do()
A.Create a copy of the .(root) zone on DNS1.
B.Update the list of root hints servers on DNS2.
C.Update the Cache.dns file on DNS2. Configure conditional forwarding on DNS1.
D.Delete the .(root) zone from DNS2. Configure conditional forwarding on DNS2.
Your company has a main office and five branch offices that are connected by WAN links. The company has an Active Directory domain named contoso.com. Each branch office has a member server configured as a DNS server. All branch office DNS servers host a secondary zone for contoso.com.
You need to configure the contoso.com zone to resolve client queries for at least four days in the event that a WAN link fails.
What should you do()
A.Configure the Expires after option for the contoso.com zone to 4 days.
B.Configure the Retry interval option for the contoso.com zone to 4 days.
C.Configure the Refresh interval option for the contoso.com zone to 4 days.
D.Configure the Minimum (default) TTL option for the contoso.com zone to 4 days.
Your company has a main office and a branch office. The company has a single-domain Active Directory forest.
The main office has two domain controllers named DC1 and DC2 that run Windows Server 2008 R2. The branch office has a Windows Server 2008 R2 read-only domain controller (RODC)named DC3. All domain controllers hold the DNS Server server role and are configured as Active Directory- integrated zones. The DNS zones only allow secure updates.
You need to enable dynamic DNS updates on DC3.
What should you do()
A.Run the Ntdsutil.exe DS Behavior commands on DC3.
B.Run the Dnscmd.exe /ZoneResetType command on DC3.
C.Reinstall Active Directory Domain Services on DC3 as a writable domain controller.
D.Create a custom application directory partition on DC1. Configure the partition to store Active Directory-integrated z
Your company has two domain controllers that are configured as internal DNS servers. All zones on the DNS servers are Active Directory-integrated zones. The zones allow all dynamic updates. You discover that the contoso.com zone has multiple entries for the host names of computers that do not exist.
You need to configure the contoso.com zone to automatically remove expired records.
What should you do()
A.Enable only secure updates on the contoso.com zone.
B.Enable scavenging and configure the refresh interval on the contoso.com zone.
C.From the Start of Authority tab, decrease the default refresh interval on the contoso.com zone.
D.From the Start of Authority tab, increase the default expiration interval on the contoso.com zone.
Your company, Contoso, Ltd., has a main office and a branch office. The offices are connected by a WAN link. Contoso has an Active Directory forest that contains a single domain named ad.contoso.com.
The ad.contoso.com domain contains one domain controller named DC1 that is located in the main office. DC1 is configured as a DNS server for the ad.contoso.com DNS zone. This zone is configured as a standard primary zone.
You install a new domain controller named DC2 in the branch office. You install DNS on DC2. You need to ensure that the DNS service can update records and resolve DNS queries in the event that a WAN link fails.
What should you do()
A.Create a new stub zone named ad.contoso.com on DC2.
B.Configure the DNS server on DC2 to forward requests to DC1.
C.Create a new secondary zone named ad.contoso.com on DC2.
D.Convert the ad.contoso.com zone on DC1 to an Active Directory-integrated zone.
最新试题
Your network contains an Active Directory domain. All domain controller run Windows Server 2003. You replace all domain controllers with domain controllers that run Windows Server 2008 R2. You raise the functional level of the domain to Windows Server 2008 R2. You need to minimize the amount of SYSVOL replication traffic on the network. What should you do()
Your network contains an Active Directory forest. All domain controllers run Windows Server 2008 Standard. The functional level of the domain is Windows Server 2003. You have a certification authority (CA). The relevant servers in the domain are configured as shown in the following table: Server name Operating system Server role Server1 Windows Server 2003 Enterprise root CA Server2 Windows Server 2008 Enterprise subordinate CA Server3 Windows Server 2008 R2 Web Server You need to ensure that you can install the Active Directory Certificate Services (AD CS) Certificate Enrollment Web Service on the network. What should you do()
You have a domain controller named Server1 that runs Windows Server 2008 R2. You need to determine the size of the Active Directory database on Server1. What should you do()
Your network contains an Active Directory domain. The domain contains a group named Group1. The minimum password lenght for the domain is set to six characters. you need to ensure that the passwords for all users in Group1 are at least 10 characters long. All other users must be able to use passwords that are six characters long. What should you do first()
Active Directory Rights Management Services (AD RMS) is deployed on your network. You need to configure AD RMS to use Kerberos authentication. Which two actions should you perform()
You need to compact an Active Directory database on a domain controller that runs windows Server 2008 R2. What should you do()
Your network contains an Active Directory domain named contoso.com. You have a management computer named Computer1 that runs Windows 7. You need to forward the logon events of all the domain controllers in contoso.com to Computer1. All new domain controllers must be dynamically added to the subscription. What should you do()
Your company has four offices. The network contains a single Active Directory domain. Each office has domain controller. Each office has an organitational unit (OU) that contains the user accounts for the users in that office. In each office, support technicians perform basic troubleshooting for the users in their respective office. You need to ensure that the support technicians can reset the password for the user accounts in their respective office only. The solution must prevent the thechnicians from creating user accounts. What shoul you do()
You have an enterprise subordinate certification authority (CA). You have a custom certificate template that has a key length of 1,024 bits. The template is enabled for autoenrollment. You increase the template key length to 2,048 bits. You need to ensure that all current certificate holders automatically enroll for a certificate that uses the new template. Which console should you use()
You create a new Active Directory domain. The functional level of the domain is Windows Server 2008 R2. The domain contains five domain controllers. You need to monitor the replication of the group policy template files. Which tool should you use()