网友您好, 请在下方输入框内输入要搜索的题目:

题目内容 (请给出正确答案)

Your network contains an Active Directory forest. The forest contains two domains.  You have a standalone root certification authority (CA).   On a server in the child domain, you run the Add Roles Wizard and discover that the option to select an  enterprise CA is disabled.   You need to install an enterprise subordinate CA on the server.   What should you use to log on to the new server()

  • A、an account that is a member of the Certificate Publishers group in the child domain
  • B、an account that is a member of the Certificate Publishers group in the forest root domain
  • C、an account that is a member of the Schema Admins group in the forest root domain
  • D、an account that is a member of the Enterprise Admins group in the forest root domain

参考答案

更多 “ Your network contains an Active Directory forest. The forest contains two domains.  You have a standalone root certification authority (CA).   On a server in the child domain, you run the Add Roles Wizard and discover that the option to select an  enterprise CA is disabled.   You need to install an enterprise subordinate CA on the server.   What should you use to log on to the new server()A、an account that is a member of the Certificate Publishers group in the child domainB、an account that is a member of the Certificate Publishers group in the forest root domainC、an account that is a member of the Schema Admins group in the forest root domainD、an account that is a member of the Enterprise Admins group in the forest root domain” 相关考题
考题 Your network contains an Active Directory forest. The functional level of the forest is Windows Server 2008 R2.You plan to deploy DirectAccess.You need to configure the DNS servers on your network to support DirectAccess.What should you do?()A. Modify the GlobalQueryBlockList registry key and restart the DNS Server service.B. Modify the EnableGlobalNamesSupport registry key and restart the DNS Server service.C. Create a trust anchor that uses a certificate issued by an internal certification authority (CA).D. Create a trust anchor that uses a certificate issued by a publicly trusted certification authority (CA).

考题 You are the network administrator for Contoso Pharmaceuticals. The network consists of a single Active Directory forest. The forest contains Windows Server 2003 servers and Windows XP Professional computers.   The forest consists of a forest root domain named contoso.com and two child domains named child1.contoso.com and child2.contoso.com. The child1.contoso.com domain contains a member server named Server1. You configure Server1 to be an enterprise certification authority (CA), and you configure a user certificate template. You enable the Publish certificate in Active Directory setting in the certificate template. You instruct users in both the child1.contoso.com and the child2.contoso.com domains to enroll for user certificates.   You discover that the certificates for user accounts in the child1.contoso.com domain are being published to Active Directory, but the certificates for user accounts in the child2.contoso.com domain are not.   You want certificates issued by Server1 to child2.contoso.com domain user accounts to be published in Active Directory.   What should you do? ()A、 Configure user certificate autoenrollment for all domain user accounts in the contoso.com domain.B、 Configure user certificate autoenrollment for all domain user accounts in the child2.contoso.com domain.C、 Add Server1 to the Cert Publishers group in the contoso.com domain.D、 Add Server1 to the Cert Publishers group in the child2.contoso.com domain.

考题 Your network contains an Active Directory domain named contoso.com. Contoso.com contains a  member server that runs Windows Serever 2008 Standart.   You need to install an enterprise subordinate certification authority (CA) that support private key  archival. You must achieve this goal by using the minimum amount of administrative effort. What do you do first()A、Initialize the Trusted Platform Module (TPM)B、Upgrade the menber server to Windows Server 2008 R2 Standard.C、Install the Certificate Enrollment Policy Web Service role service on the member server.D、Run the Security Configuration Wizard (SCW) and select the Active Directory Certificate Services - Certification

考题 Your company has an Active Directory forest. You plan to install an Enterprise certification authority (CA) on a dedicated stand-alone server. When you attempt to add the Active Directory Certificate Services (AD CS) role, you find that the Enterprise CA option is not available. You need to install the AD CS role as an Enterprise CA. What should you do first()A、Add the DNS Server role.B、Join the server to the domain.C、Add the Web server (IIS) role and the AD CS role.D、Add the Active Directory Lightweight Directory Service (AD LDS) role.

考题 Your network contains an Active Directory forest. The forest contains two domains. You have a  standalone root certification authority (CA).     On a server in the child domain, you run the Add Roles Wizard and discover that the option to  select an enterprise CA is disabled.     You need to install an enterprise subordinate CA on the server.     What should you use to log on to the new server()A、an account that is a member of the Certificate Publishers group in the child domainB、an account that is a member of the Certificate Publishers group in the forest root domainC、an account that is a member of the Schema Admins group in the forest root domainD、an account that is a member of the Enterprise Admins group in the forest root domain

考题 Your network contains an Active Directory forest. The forest contains a single domain. You want  to access resources in a domain that is located in another forest.     You need to configure a trust between the domain in your forest and the domain in the other  forest.     What should you create()A、an incoming external trustB、an incoming realm trustC、an outgoing external trustD、an outgoing realm trust

考题 Your company has an Active Directory forest. You plan to install an Enterprise certification  authority (CA) on a dedicated stand-alone server. When you attempt to add the Active Directory Certificate Services (AD CS) server role, you find  that the Enterprise CA option is not available. You need to install the AD CS server role as an Enterprise CA.     What should you do first()A、Add the DNS Server server role.B、Join the server to the domain.C、Add the Web Server (IIS) server role and the AD CS server role.D、Add the Active Directory Lightweight Directory Services (AD LDS) server role.

考题 Your company has a single Active Directory directory service forest with multiple domains. The Schema FSMO role is held by one of the domain controllers in the forest root domain. The DomainThe safer , easier way to help you pass any IT exams. Naming Master FSMO role is held by one of the domain controllers in a child domain. All domain controllers have Windows Server 2003 installed.  You need to upgrade all domain controllers to Windows Server 2003 R2.  Which two actions should you perform?()A、 Run the adprep /forestprep command in the forest root domain.B、 Run the adprep /forestprep command in all the child domains.C、 Run the adprep /domainprep command in all the child domains only.D、 Run the adprep /domainprep command in all domains.

考题 Your network contains two Active Directory forests named contoso.com and adatum.com. The  functional level of both forests is Windows Server 2008 R2. Each forest contains one domain.  Active Directory Certificate Services (AD CS) is configured in the contoso.com forest to allow  users from both forests to automatically enroll user certificates.   You need to ensure that all users in the adatum.com forest have a user certificate from the  contoso.com certification authority (CA).   What should you configure in the adatum.com domain()A、From the Default Domain Controllers Policy, modify the Enterprise Trust settings.B、From the Default Domain Controllers Policy, modify the Trusted Publishers settings.C、From the Default Domain Policy, modify the Certificate Enrollment policy.D、From the Default Domain Policy, modify the Trusted Root Certification Authority settings.

考题 Your company has an Active Directory forest. You plan to install an Enterprise certification authority  (CA) on a dedicated stand-alone server.    When you attempt to add the Active Directory Certificate Services (AD CS) server role, you find that the  Enterprise CA option is not available.    You need to install the AD CS server role as an Enterprise CA.    What should you do first()A、Add the DNS Server server role.B、Join the server to the domain.C、Add the Web Server (IIS) server role and the AD CS server roleD、Add the Active Directory Lightweight Directory Services (AD LDS) server role. .

考题 Your network consists of an Active Directory forest that contains one domain. AlI domain controllers run Windows Server 2008 and are configured as DNS servers. You have an Actrve Directory-integrated zone. You have two Actrve Directory sites. Each site contains five domain controllers. You add a new NS record to the zone. You need to ensure that all domain controllers immediately receive the new NS record. What should you do()A、From the DNS Manager console, reload the zone.B、From the Services snap-in, restart the DNS Server service.C、From the command prompt, run repadmin /syncall.D、From the DNS Manager console, increase the version number of the SOA record.

考题 You are a security administrator for your company. The network consists of three Active Directory domains. All Active Directory domains are running at a Windows Server 2003 mode functionality level.    Employees in the editorial department of your company need access to resources on file servers that are in each of the Active Directory domains. Each Active Directory domain in the company contains at least one editorial department employee user account.    You need to create a single group named Company Editors that contains all editorial department employee user accounts and that has access to the resources on file server computers.  What should you do?()A、 Create a global distribution group in the forest root domain and name it Company Editors.B、 Create a global security group in the forest root domain and name it Company Editors.C、 Create a universal distribution group in the forest root domain and name it Company Editors. D、 Create a universal security group in the forest root domain and name it Company Editors.

考题 Your network consists of a single Active Directory forest that contains a root domain and two child domains. All servers run Windows Server 2008 R2.  A corporate policy has the following requirements:   èAll local guest accounts must be renamed and disabled. èAll local administrator accounts must be renamed.   You need to recommend a solution that meets the requirements of the corporate policy. What should you recommend?()A、Implement a Group Policy object(GPO) for each domain.B、Implement a Group Policy object(GPO) for the root domain.C、Deploy Network Policy and Access Services(NPAS)on all domain controllers in each domain. D、Deploy Active Directory Rights Management Services(AD RMS)on the root domain controllers.

考题 Your network contains an Active Directory forest. All domain controllers run Windows Server  2008 Standard. The functional level of the domain is Windows Server 2003. You have a  certification authority (CA).   The relevant servers in the domain are configured as shown in the following table:     Server name  Operating system  Server role   Server1  Windows Server 2003  Enterprise root CA  Server2  Windows Server 2008  Enterprise subordinate CA  Server3  Windows Server 2008 R2  Web Server   You need to ensure that you can install the Active Directory Certificate Services (AD CS)  Certificate Enrollment Web Service on the network.     What should you do()A、Upgrade Server1 to Windows Server 2008 R2.B、Upgrade Server2 to Windows Server 2008 R2.C、Raise the functional level of the domain to Windows Server 2008.D、Install the Windows Server 2008 R2 Active Directory Schema updates.

考题 Your network consists of an Active Directory forest that contains one domain. All domain controllers  run Windows  Server  2008  R2  and  are  configured  as  DNS  servers.  You  have  an  Active  Directory-integrated zone.   You have two Active Directory sites. Each site contains five domain controllers.   You add a new NS record to the zone.   You need to ensure that all domain controllers immediately receive the new NS record.   What should you do()A、From the DNS Manager console, reload the zone.B、From the Services snap-in, restart the DNS Server service.C、From the command prompt, run repadmin /syncall.D、From the DNS Manager console, increase the version number of the SOA record.

考题 You are the network administrator for Alpine Ski House. The network consists of a single Active Directory forest that contains five domains. The functional level of the forest is Windows 2000. You have not configured any universal groups in the forest. One domain is a child domain named child1.alpineskihouse.com  that contains two domain controllers and 50 client computers. The functional level of the domain is Windows Server 2003. The network includes an Active Directory site named Site1 that contains two domain controllers. Site1 represents a remote clinic, and the location changes every few months. All of the computers in child1.alpineskihouse.com are located in the remote clinic. The single WAN connection that connects the remote clinic to the main network is often saturated or unavailable. Site1 does not include any global catalog servers. You create several new user accounts on the domain controllers located in Site1. You need to ensure that users in the remote clinic can always quickly and successfully log on to the domain.  What should you do?()A、 Enable universal group membership caching in Site1.B、 Add the HKEY_LOCAL_MACHINE/System/CurrentControlSet/Control/Lsa/IgnoreGCFailures key to the registry on both domain controllers in Site1.C、 Add the HKEY_LOCAL_MACHINE/System/CurrentControlSet/Control/Lsa/IgnoreGCFailures key to the registry on all global catalog servers in the forest.D、 Raise the functional level of the forest to Windows Server 2003.

考题 Your network contains an Active Directory domain. The domain contains 1000 user accounts.  You have a list that contains the mobile phone number of each user  You need to add the mobile number of each user to Active Directory.     What should you do()A、Create a file that contains the mobile phone numbers, and then run ldifde.exeB、Create a fila that contains the mobile phone numbers, and then run csvde.exeC、From Adsiedit, select the CN=Users container, and then mofify the properties of the container.D、From Active Directory Users and Computers, select all of the users, and then modify the properties of the users.

考题 Your network contains an Active Directory forest. All domain controllers run Windows Server 2008   Standard. The functional level of the domain is Windows Server 2003.  You have a certification authority (CA).   The relevant servers in the domain are configured as shown in the following table.  Server name  Operating system  Server role   Server1  Windows Server 2003  Enterprise root CA  Server2  Windows Server 2008  Enterprise subordinate CA    Server3  Windows Server 2008 R2    Web Server   You need to ensure that you can install the Active Directory Certificate Services (AD CS) Certificate   Enrollment Web Service on the network.   What should you do()A、Upgrade Server1 to Windows Server 2008 R2.B、Upgrade Server2 to Windows Server 2008 R2.C、Raise the functional level of the domain to Windows Server 2008.D、Install the Windows Server 2008 R2 Active Directory Schema updates.

考题 You have an Active Directory domain that runs Windows Server 2008 R2. You need to implement  a certification authority (CA) server that meets the following requirements:     - Allows the certification authority to automatically issue certificates  - Integrates with Active Directory Domain Services     What should you do()A、Install and configure the Active Directory Certificate Services server role as a Standalone Root CA .B、Install and configure the Active Directory Certificate Services server role as an Enterprise Root CA .C、Purchase a certificate from a third-party certification authority. Install and configure the Active Directory Certificate SD、Purchase a certificate from a third-party certification authority. Import the certificate into the computer store of the sc

考题 Your network contains an Active Directory forest named contoso.com.   You plan to add a new domain named nwtraders.com to the forest.  All DNS servers are domain controllers.   You need to ensure that the computers in nwtraders.com can update their Host (A) records on any of the  DNS servers in the forest.   What should you do()A、Add the computer accounts of all the domain controllers to the DnsAdmins group.B、Add the computer accounts of all the domain controllers to the DnsUpdateProxy group.C、Create a standard primary zone on a domain controller in the forest root domain.D、Create an Active Directory-integrated zone on a domain controller in the forest root domain.

考题 单选题Your company has an Active Directory forest. You plan to install an Enterprise certification  authority (CA) on a dedicated stand-alone server.   When you attempt to add the Active Directory Certificate Services (AD CS) server role, you find  that the Enterprise CA option is not available.   You need to install the AD CS server role as an Enterprise CA.     What should you do first()A Add the DNS Server server role.B Join the server to the domain.C Add the Web Server (IIS) server role and the AD CS server role.D Add the Active Directory Lightweight Directory Services (AD LDS) server role.

考题 单选题Your network contains an Active Directory domain named contoso.com. Contoso.com contains a  member server that runs Windows Serever 2008 Standart.   You need to install an enterprise subordinate certification authority (CA) that support private key  archival. You must achieve this goal by using the minimum amount of administrative effort. What do you do first()A Initialize the Trusted Platform Module (TPM)B Upgrade the menber server to Windows Server 2008 R2 Standard.C Install the Certificate Enrollment Policy Web Service role service on the member server.D Run the Security Configuration Wizard (SCW) and select the Active Directory Certificate Services - Certification

考题 单选题Your network contains an Active Directory forest. The forest contains two domains.  You have a standalone root certification authority (CA).   On a server in the child domain, you run the Add Roles Wizard and discover that the option to select an  enterprise CA is disabled.   You need to install an enterprise subordinate CA on the server.   What should you use to log on to the new server()A an account that is a member of the Certificate Publishers group in the child domainB an account that is a member of the Certificate Publishers group in the forest root domainC an account that is a member of the Schema Admins group in the forest root domainD an account that is a member of the Enterprise Admins group in the forest root domain

考题 单选题Your company has an Active Directory forest. You plan to install an Enterprise certification authority  (CA) on a dedicated stand-alone server.    When you attempt to add the Active Directory Certificate Services (AD CS) server role, you find that the  Enterprise CA option is not available.    You need to install the AD CS server role as an Enterprise CA.    What should you do first()A Add the DNS Server server role.B Join the server to the domain.C Add the Web Server (IIS) server role and the AD CS server roleD Add the Active Directory Lightweight Directory Services (AD LDS) server role. .

考题 单选题Your company has an Active Directory forest. You plan to install an Enterprise certification authority (CA) on a dedicated stand-alone server. When you attempt to add the Active Directory Certificate Services (AD CS) role, you find that the Enterprise CA option is not available. You need to install the AD CS role as an Enterprise CA. What should you do first()A Add the DNS Server role.B Join the server to the domain.C Add the Web server (IIS) role and the AD CS role.D Add the Active Directory Lightweight Directory Service (AD LDS) role.

考题 单选题Your network contains an Active Directory forest named contoso.com.   You plan to add a new domain named nwtraders.com to the forest.  All DNS servers are domain controllers.   You need to ensure that the computers in nwtraders.com can update their Host (A) records on any of the  DNS servers in the forest.   What should you do()A Add the computer accounts of all the domain controllers to the DnsAdmins group.B Add the computer accounts of all the domain controllers to the DnsUpdateProxy group.C Create a standard primary zone on a domain controller in the forest root domain.D Create an Active Directory-integrated zone on a domain controller in the forest root domain.

考题 单选题Your network contains an Active Directory forest. The forest contains a single domain. You want  to access resources in a domain that is located in another forest.     You need to configure a trust between the domain in your forest and the domain in the other  forest.     What should you create()A an incoming external trustB an incoming realm trustC an outgoing external trustD an outgoing realm trust

考题 单选题You are a security administrator for your company. The network consists of three Active Directory domains. All Active Directory domains are running at a Windows Server 2003 mode functionality level.    Employees in the editorial department of your company need access to resources on file servers that are in each of the Active Directory domains. Each Active Directory domain in the company contains at least one editorial department employee user account.    You need to create a single group named Company Editors that contains all editorial department employee user accounts and that has access to the resources on file server computers.  What should you do?()A  Create a global distribution group in the forest root domain and name it Company Editors.B  Create a global security group in the forest root domain and name it Company Editors.C  Create a universal distribution group in the forest root domain and name it Company Editors. D  Create a universal security group in the forest root domain and name it Company Editors.