Active Directory Rights Management Services (AD RMS) is deployed on your network.
You need to configure AD RMS to use Kerberos authentication.
Which two actions should you perform()
A.Register a service principal name (SPN) for AD RMS.
B.Register a service connection point (SCP) for AD RMS.
C.Configure the identity setting of the _DRMSAppPool1 application pool.
D.Configure the useAppPoolCredentials attribute in the Internet Information Services (IIS) metabase.
您可能感兴趣的试卷
你可能感兴趣的试题
Your network contains a single Active Directory domain named contoso.com.
An administrator accidentally deletes the _msdsc.contoso.com zone.
You recreate the _msdsc.contoso.com zone.
You need to ensure that the _msdsc.contoso.com zone contains all of the required DNS records.
What should you do on each domain controller()
A.Restart the Netlogon service.
B.Restart the DNS Server service.
C.Run dcdiag.exe /fix.
D.Run ipconfig.exe /registerdns.
Your network contains an Active Directory forest. The forest contains two domain controllers. The domain controllers are configured as shown in the following table.
All client computers run Windows 7.
You need to ensure that all client computers in the domain keep the same time as an external time server.
What should you do()
A.From DC1, run the time command.
B.From DC2, run the time command.
C.From DC1, run the w32tm.exe command.
D.From DC2, run the w32tm.exe command.
Your network contains three Active Directory forest named Forest1, Forest2, and Forest3. Each forest contains three domains.
A two-way forest trust exists between Forest1 and Forest2. A two-way forest trust exists between Forest2 and Forest3.
You need to configure the forest to meet the following requirements
Users in Forest3 must be able to access resources in Forest1.
Users in Forest1 must be able to access resources in Forest3. The number of trusts must be minimized.
What should you do()
A.In Forest2, modify the name suffix routing settings.
B.In Forest1 and Forest3, configure selective authentication.
C.In Forest1 and Forest3, modify the name suffix routing settings.
D.Create a two-way forest trust between Forest1 and Forest3.
E.Create a shortcut trust in Forest1 and a shortcut trust in Forest3.
What should you do()
A.Create a new site named Site1. Create a new subnet object that has the 10.1.1.0/24 prefix and assing the subnet to
B.Create a new site named Site1. Create a new subnet object that has the 10.1.1.1/32 prefix and assing the subnet to
C.Create a new site named Site1. Create a new subnet object that has the 10.1.1.2/32 prefix and assing the subnet to
D.Create a new site named Site1. Create a new subnet object that has the 10.1.2.0/24 prefix and assing the subnet to
You need to compact an Active Directory database on a domain controller that runs windows Server 2008 R2.
What should you do()
A.Run defrag.exe /a /c.
B.Run defrag.exe /c /u.
C.Form Ntdsutil, use the Files option.
D.From Ntdsutil, use the Metadata cleanup option.
Your company has four offices.
The network contains a single Active Directory domain.
Each office has domain controller. Each office has an organitational unit (OU) that contains the user accounts for the users in that office.
In each office, support technicians perform basic troubleshooting for the users in their respective office.
You need to ensure that the support technicians can reset the password for the user accounts in their respective office only. The solution must prevent the thechnicians from creating user accounts.
What shoul you do()
A.Four each OU, run the Delegation of Control Wizard.
B.For the domain, run the Delegation of Control Wizard.
C.For each office, create an Active Directory group, and then modify the security setting for each group.
D.For each office, create an Active Directory group, and then modify the contorlAccessRights attirbute for each group
Your network contains an Active Directory domain named contoso.com. Contoso.com contains a member server that runs Windows Serever 2008 Standart.
You need to install an enterprise subordinate certification authority (CA) that support private key archival. You must achieve this goal by using the minimum amount of administrative effort.
What do you do first()
A.Initialize the Trusted Platform Module (TPM)
B.Upgrade the menber server to Windows Server 2008 R2 Standard.
C.Install the Certificate Enrollment Policy Web Service role service on the member server.
D.Run the Security Configuration Wizard (SCW) and select the Active Directory Certificate Services - Certification
Your network contains an Active Directory domain named contoso.com. Contoso.com contains three servers.The servers are configure as shown in the following table.
Server name Server roel Service
Server1 Certification authority (CA)
Server2 Certificate Enrollment Web Service Server3 Certificate Enrollment Policy Web Service
You need to ensure that users can manually enroll and renew their certificates by using the Certificate Enrollment Web Service.
Which two actions should you perform()
A.Configure the policy module setting.
B.Configure the issuance requeriments for the certificate templates.
C.Configure the Certificate Services Client - Certificate Enrollment Policy Group Policy setting.
D.Configure the delegation setting for the Certification Enrollment Web Service application pool account.
Your network contains two Active Directory forests named contoso.com and nwtraders.com. A two-way forest trust exists between contoso.com and nwtraders.com. The forest trust is configured to use selective authentication.
Contoso.com contains a server named Server1. Server1 contains a shared folder named Marketing. Nwtraders.com contains a global group named G_Marketing. The Change share permission and the Modify NTFS permissions for the Marketing folder are assignes to the G_Marketing group.
Members of G_Marketing report that they cannot accesss the Marketing folder.
You need to ensure that the G_Marketing members can accesss the folder from the network.
What should you do()
A.From Windows Explorer, modify the NTFS permissions of the folder
B.From Windows Explorer, modify the share permissions of the folder
C.From Active Directory Users and Computers, modify the computer object for Server1
D.From Active Directory Users and Computers, modify the group object for G_Marketing
Your network contains an Active Directory domain. The domain contains 1000 user accounts. You have a list that contains the mobile phone number of each user You need to add the mobile number of each user to Active Directory.
What should you do()
A.Create a file that contains the mobile phone numbers, and then run ldifde.exe
B.Create a fila that contains the mobile phone numbers, and then run csvde.exe
C.From Adsiedit, select the CN=Users container, and then mofify the properties of the container.
D.From Active Directory Users and Computers, select all of the users, and then modify the properties of the users.
最新试题
You install a standalone root certification authority (CA) on a server named Server1. You need to ensure that every computer in the forest has a copy of the root CA certificate installed in the local computer’s Trusted Root Certification Authorities store. Which command should you run on Server1()
You have an enterprise subordinate certification authority (CA). You have a custom certificate template that has a key length of 1,024 bits. The template is enabled for autoenrollment. You increase the template key length to 2,048 bits. You need to ensure that all current certificate holders automatically enroll for a certificate that uses the new template. Which console should you use()
You create a new Active Directory domain. The functional level of the domain is Windows Server 2008 R2. The domain contains five domain controllers. You need to monitor the replication of the group policy template files. Which tool should you use()
You remotely monitor several domain controllers. You run winrm.exe quickconfig on each domain controller. You need to create a WMI script query to retrieve information from the bios of each domain controller. Which format should you use to write the query()
You have an enterprise subordinate certification authority (CA) configured for key archival. Three key recovery agent certificates are issued. The CA is configured to use two recovery agents. You need to ensure that all of the recovery agent certificates can be used to recover all new private keys. What should you do()
You have a domain controller named Server1 that runs Windows Server 2008 R2. You need to determine the size of the Active Directory database on Server1. What should you do()
Your network contains an Active Directory domain named contoso.com. All domain controllers and member servers run Windows Server 2008. All client computer run Windows 7. From a client computer, you create an audit policy by using the Advanced Audit Policy Configuration settings in the Default Domain Policy Group Policy object (GPO). You discover that the audit policy is not applied to the member servers. The audit policy is applied to the client computers. You need to ensure that the audit policy is applied to all member servers and all client computers. What should you do()
Your network contains two Active Directory forests named contoso.com and nwtraders.com. A two-way forest trust exists between contoso.com and nwtraders.com. The forest trust is configured to use selective authentication. Contoso.com contains a server named Server1. Server1 contains a shared folder named Marketing. Nwtraders.com contains a global group named G_Marketing. The Change share permission and the Modify NTFS permissions for the Marketing folder are assignes to the G_Marketing group. Members of G_Marketing report that they cannot accesss the Marketing folder. You need to ensure that the G_Marketing members can accesss the folder from the network. What should you do()
You have Active Directory Certificate Services (AD CS) deployed. You create a custom certificate template. You need to ensure that all of the users in the domain automatically enroll for a certificate based on the custom certificate template. Which two actions should you perform()
Your network contains an Active Directory domain named contoso.com. You have a management computer named Computer1 that runs Windows 7. You need to forward the logon events of all the domain controllers in contoso.com to Computer1. All new domain controllers must be dynamically added to the subscription. What should you do()