考题
Your network contains an Active Directory domain. The domain contains several domain controllers. All domain controllers run Windows Server 2008 R2. You need to restore the Default Domain Controllers Policy Group Policy object (GPO) to the Windows Server 2008 R2 default settings. What should you do()A、Run dcgpofix.exe /target:dc.B、Run dcgpofix.exe /target:domain.C、Delete the link for the Default Domain Controllers Policy, and then run gpupdate.exe /sync. D、Delete the link for the Default Domain Controllers Policy, and then run gpupdate.exe /force.
考题
You network consists of a single Active Directory domain. All domain controllers run Windows Server 2008 R2. You need to reset the Directory Services Restore Mode (DSRM) password on a domain controller. What tool should you use()A、dsmodB、ntdsutilC、Local Users and Groups snap-inD、Active Directory Users and Computers snap-in
考题
Your network consists of a single Active Directory domain. All domain controllers run Windows Server 2008 R2. You need to capture all replication errors from all domain controllers to a central location. What should you do()A、Configure event log subscriptions.B、Start the System Performance data collector set.C、Start the Active Directory Diagnostics data collector set.D、Install Network Monitor and create a new capture.
考题
Your network consists of a single Active Directory domain. The domain controllers run Windows Server 2008 R2. Your companyˉs enterprisesecurity policy states that the domain controllers cannot contain optical drives. ou need to recommend a backup and recovery plan that restores the domain controllers in the event of a catastrophic server failure. What should you recommend?()A、Use Windows Server Backup to back up each domain controller to a local disk. Create a Windows recovery Environment (Windows RE) partition on each domain controller.B、Use Windows Server Backup to back up each domain controller to a local disk. Use Windows deployment Services (WDS) to deploy the Windows Recovery Environment (Windows RE).C、Use Windows Server Backup to back up each domain controller to a remote network share. Create a windows Recovery Environment (Windows RE) partition on each domain controller.D、Use Windows Server Backup to back up each domain controller to a remote network share. Use windows Deployment Services(WDS)to deploy the Windows Recovery Environment (Windows RE).
考题
Your network contains a single Active Directory domain. The functional level of the forest is Windows Server 2008. The functional level of the domain is Windows Server 2008 R2. All DNS servers run Windows Server 2008. All domain controllers run Windows Server 2008 R2. You need to ensure that you can enable the Active Directory Recycle Bin. What should you do()A、Change the functional level of the forest.B、Change the functional level of the domain.C、Modify the Active Directory schema.D、Modify the Universal Group Membership Caching settings.
考题
Your network consists of a single Active Directory domain. All domain controllers run Windows Server 2008 R2. The Audit account management policy setting and Audit directory services access setting are enabled for the entire domain. You need to ensure that changes made to Active Directory objects can be logged. The logged changes must include the old and new values of any attributes. What should you do()A、Enable the Audit account management policy in the Default Domain Controller Policy.B、Run auditpol.exe and then configure the Security settings of the Domain Controllers OU.C、Run auditpol.exe and then enable the Audit directory service access setting in the Default Domain policy.D、From the Default Domain Controllers policy, enable the Audit directory service access setting and enable directory
考题
Your company has several branch offices. Your network consists of a single Active Directory domain. Each branch office contains domain controllers and member servers. The domain controllers run Windows Server 2003 SP2. The member servers run Windows Server 2008 R2. Physical security of the servers at the branch offices is a concern. You plan to implement Windows BitLocker Drive Encryption (BitLocker) on the member servers. You need to ensure that you can access the BitLocker volume if the BitLocker keys are corruptedon the member servers. The recovery information must be stored in a central location. What should you do?()A、Upgrade all domain controllers to Windows Server 2008 R2.Use Group Policy to configure Public Key policies.B、Upgrade all domain controllers to Windows Server 2008 R2. Use Group Policy to enable Trusted platform Module(TPM) backups to Active Directory.C、Upgrade the domain controller that has the schema master role to Windows Server 2008 R2. Use group Policy to enable a Data Recovery Agent (DRA).D、Upgrade the domain controller that has the primary domain controller (PDC) emulator role to windows Server 2008 R2. Use Group Policy to enable a Data Recovery Agent (DRA).
考题
Your network consists of a single Active Directory domain. All domain controllers run Windows Server 2008 R2. You need to plan an auditing strategy that meets the following requirements: èAudits all changes to Active Directory Domain Services (AD?DS) èStores all auditing data in a central location. What should you include in your plan?()A、Configure an audit policy for the domain. Configure Event Forwarding.B、Configure an audit policy for the domain controllers. Configure Data Collector Sets.C、Implement Windows Server Resource Manager (WSRM) in managing mode.D、Implement Windows Server Resource Manager (WSRM) in accounting mode.
考题
Your network consists of a single Active Directory forest. The forest contains one Active Directory domain. The domain contains eight domain controllers. The domain controllers run Windows Server 2003 Service Pack 2. You upgrade one of the domain controllers to Windows Server 2008 R2. You need to recommend an Active Directory recovery strategy that supports the recovery of deletedobjects. The solution must allow deleted objects to be recovered for up to one year after the date of deletion. What should you recommend?()A、Increase the tombstone lifetime for the forest.B、Increase the interval of the garbage collection process for the forest.C、Configure daily backups of the Windows Server 2008 R2 domain controller.D、Enable shadow copies of the drive that contains the Ntds.dit file on the Windows Server 2008 R2 domain controller.
考题
Your network consists of a single Active Directory forest that contains a root domain and two child domains. All servers run Windows Server 2008 R2. A corporate policy has the following requirements: èAll local guest accounts must be renamed and disabled. èAll local administrator accounts must be renamed. You need to recommend a solution that meets the requirements of the corporate policy. What should you recommend?()A、Implement a Group Policy object(GPO) for each domain.B、Implement a Group Policy object(GPO) for the root domain.C、Deploy Network Policy and Access Services(NPAS)on all domain controllers in each domain. D、Deploy Active Directory Rights Management Services(AD RMS)on the root domain controllers.
考题
Your network consists of a single Active Directory domain. The functional level of the domain is Windows Server 2008 R2. All domain controllers run Windows Server 2008 R2. A corporate policy requires that the users from the research department have higher levels of account and password security than other users in the domain. You need to recommend a solution that meets the requirements of the corporate policy. Your solution must minimize hardware and software costs. What should you recommend?()A、Create a new Active Directory site. Deploy a Group Policy object (GPO) to the site.B、Create a new Password Settings Object (PSO) for the research department’s usersC、Create a new organizational unit (OU) named Research in the existing domain. Deploy a Group Policy object (GPO) to the Research OU.D、Create a new domain in the forest.Add the research department’s user accounts to the new domain.Configure a new security policy in the new domain.
考题
Your network consists of a single Active Directory domain. All domain controllers run Windows Server 2003. You upgrade all domain controllers to Windows Server 2008 R2. You need to ensure that the Sysvol share replicates by using DFS Replication (DFS-R). What should you do()A、From the command prompt, run netdom /reset.B、From the command prompt, run dfsutil /addroot:sysvol.C、Raise the functional level of the domain to Windows Server 2008 R2.D、From the command prompt, run dcpromo /unattend:unattendfile.xml.
考题
Your network consists of a single Active Directory domain. All domain controllers run Windows Server 2003 You upgrade all domain controllers to Windows Server 2008 You need to configure the Active Directory environment to support the application of multiple password policies What should you do()A、Create multiple Active Directory sites.B、On all domain controllers, run dcpromo /adv.C、On one domain controller, run dcpromo /adv.D、Raise the functional level of the domain to Windows Server 2008.
考题
Your company has a single Active Directory domain. AlI domain controllers run Windows Server 2003 You install Windows Server 2008 on a server. You need to add the new server as a domaincontroller in your domain.What should you do first()A、On the new server, run dcpromo /adv.B、On the new server, run dcpromo /createdcaccount.C、On a domain controller run adprep /rodcprep.D、On a domain controller, run adprep /forestprep.
考题
Your network consists of a single Active Directory domain. All domain controllers run Windows Server 2008 The Audit account management policy setting and Audit directory services access setting are enabled for the entire domain. You need to ensure that changes made to Active Directory objects can be logged. The logged changes must include the old and new values of any attributes What should you do()A、Enable the Audit account management policy in the Default Domain Controller Policy.B、Run auditpol.exe and then configure the Security settings of the Domain Controllers OU.C、Run auditpol.exe and then enable the Audit directory service access setting in the Default Domain policy.D、From the Default Domain Controllers policy, enable the Audit directory service access setting andE、nable directory service changes.
考题
单选题Your network consists of a single Active Directory domain. The functional level of the domain is Windows Server 2008 R2. All domain controllers run Windows Server 2008 R2. A corporate policy requires that the users from the research department have higher levels of account and password security than other users in the domain. You need to recommend a solution that meets the requirements of the corporate policy. Your solution must minimize hardware and software costs. What should you recommend?()A
Create a new Active Directory site. Deploy a Group Policy object (GPO) to the site.B
Create a new Password Settings Object (PSO) for the research department’s usersC
Create a new organizational unit (OU) named Research in the existing domain. Deploy a Group Policy object (GPO) to the Research OU.D
Create a new domain in the forest.Add the research department’s user accounts to the new domain.Configure a new security policy in the new domain.
考题
单选题Your network contains a single Active Directory domain. The functional level of the forest is Windows Server 2008. The functional level of the domain is Windows Server 2008 R2. All DNS servers run Windows Server 2008. All domain controllers run Windows Server 2008 R2. You need to ensure that you can enable the Active Directory Recycle Bin. What should you do()A
Change the functional level of the forest.B
Change the functional level of the domain.C
Modify the Active Directory schema.D
Modify the Universal Group Membership Caching settings.
考题
单选题Your network contains an Active Directory domain. The domain contains several domain controllers. All domain controllers run Windows Server 2008 R2. You need to restore the Default Domain Controllers Policy Group Policy object (GPO) to the Windows Server 2008 R2 default settings. What should you do()A
Run dcgpofix.exe /target:dc.B
Run dcgpofix.exe /target:domain.C
Delete the link for the Default Domain Controllers Policy, and then run gpupdate.exe /sync. D
Delete the link for the Default Domain Controllers Policy, and then run gpupdate.exe /force.
考题
单选题Your network consists of a single Active Directory forest that contains a root domain and two child domains. All servers run Windows Server 2008 R2. A corporate policy has the following requirements: èAll local guest accounts must be renamed and disabled. èAll local administrator accounts must be renamed. You need to recommend a solution that meets the requirements of the corporate policy. What should you recommend?()A
Implement a Group Policy object(GPO) for each domain.B
Implement a Group Policy object(GPO) for the root domain.C
Deploy Network Policy and Access Services(NPAS)on all domain controllers in each domain. D
Deploy Active Directory Rights Management Services(AD RMS)on the root domain controllers.
考题
单选题Your network consists of a single Active Directory domain. All domain controllers run Windows Server 2008 R2. The Audit account management policy setting and Audit directory services access setting are enabled for the entire domain. You need to ensure that changes made to Active Directory objects can be logged. The logged changes must include the old and new values of any attributes. What should you do()A
Enable the Audit account management policy in the Default Domain Controller Policy.B
Run auditpol.exe and then configure the Security settings of the Domain Controllers OU.C
Run auditpol.exe and then enable the Audit directory service access setting in the Default Domain policy.D
From the Default Domain Controllers policy, enable the Audit directory service access setting and enable directory service changes.
考题
单选题Your company has several branch offices. Your network consists of a single Active Directory domain. Each branch office contains domain controllers and member servers. The domain controllers run Windows Server 2003 SP2. The member servers run Windows Server 2008 R2. Physical security of the servers at the branch offices is a concern. You plan to implement Windows BitLocker Drive Encryption (BitLocker) on the member servers. You need to ensure that you can access the BitLocker volume if the BitLocker keys are corruptedon the member servers. The recovery information must be stored in a central location. What should you do?()A
Upgrade all domain controllers to Windows Server 2008 R2.Use Group Policy to configure Public Key policies.B
Upgrade all domain controllers to Windows Server 2008 R2. Use Group Policy to enable Trusted platform Module(TPM) backups to Active Directory.C
Upgrade the domain controller that has the schema master role to Windows Server 2008 R2. Use group Policy to enable a Data Recovery Agent (DRA).D
Upgrade the domain controller that has the primary domain controller (PDC) emulator role to windows Server 2008 R2. Use Group Policy to enable a Data Recovery Agent (DRA).
考题
单选题Your network consists of a single Active Directory forest. The forest contains one Active Directory domain. The domain contains eight domain controllers. The domain controllers run Windows Server 2003 Service Pack 2. You upgrade one of the domain controllers to Windows Server 2008 R2. You need to recommend an Active Directory recovery strategy that supports the recovery of deletedobjects. The solution must allow deleted objects to be recovered for up to one year after the date of deletion. What should you recommend?()A
Increase the tombstone lifetime for the forest.B
Increase the interval of the garbage collection process for the forest.C
Configure daily backups of the Windows Server 2008 R2 domain controller.D
Enable shadow copies of the drive that contains the Ntds.dit file on the Windows Server 2008 R2 domain controller.
考题
单选题Your network consists of a single Active Directory domain. All domain controllers run Windows Server 2008 R2. You need to plan an auditing strategy that meets the following requirements: èAudits all changes to Active Directory Domain Services (AD?DS) èStores all auditing data in a central location. What should you include in your plan?()A
Configure an audit policy for the domain. Configure Event Forwarding.B
Configure an audit policy for the domain controllers. Configure Data Collector Sets.C
Implement Windows Server Resource Manager (WSRM) in managing mode.D
Implement Windows Server Resource Manager (WSRM) in accounting mode.
考题
单选题Your network consists of a single Active Directory domain. All domain controllers run Windows Server 2008 The Audit account management policy setting and Audit directory services access setting are enabled for the entire domain. You need to ensure that changes made to Active Directory objects can be logged. The logged changes must include the old and new values of any attributes What should you do()A
Enable the Audit account management policy in the Default Domain Controller Policy.B
Run auditpol.exe and then configure the Security settings of the Domain Controllers OU.C
Run auditpol.exe and then enable the Audit directory service access setting in the Default Domain policy.D
From the Default Domain Controllers policy, enable the Audit directory service access setting andE
nable directory service changes.
考题
单选题Your network consists of a single Active Directory domain. All domain controllers run Windows Server 2003. You upgrade all domain controllers to Windows Server 2008 R2. You need to ensure that the Sysvol share replicates by using DFS Replication (DFS-R). What should you do()A
From the command prompt, run netdom /reset.B
From the command prompt, run dfsutil /addroot:sysvol.C
Raise the functional level of the domain to Windows Server 2008 R2.D
From the command prompt, run dcpromo /unattend:unattendfile.xml.
考题
单选题Your network consists of a single Active Directory domain. All domain controllers run Windows Server 2008 R2. You need to capture all replication errors from all domain controllers to a central location. What should you do()A
Configure event log subscriptions.B
Start the System Performance data collector set.C
Start the Active Directory Diagnostics data collector set.D
Install Network Monitor and create a new capture.
考题
单选题Your network consists of a single Active Directory domain. All domain controllers run Windows Server 2003 You upgrade all domain controllers to Windows Server 2008 You need to configure the Active Directory environment to support the application of multiple password policies What should you do()A
Create multiple Active Directory sites.B
On all domain controllers, run dcpromo /adv.C
On one domain controller, run dcpromo /adv.D
Raise the functional level of the domain to Windows Server 2008.