考题
You are the administrator of a network that consists of a single Windows NT 4.0 domain. The network contains five Windows NT Server domain controllers and 1,000 Windows NT Workstation client computers.You want to install Windows 2000 Server on a new computer. You want the new computer to act as domain controller in the existing domain.What should you do?A.On the new computer, install Windows NT Server 4.0 and designate the computer as a BDC in the existing domain. Promote the computer to the PDC of the domain. Upgrade the computer to Windows 2000 Server.B.On the new computer, install Windows NT Server 4.0 and designate the computer as a PDC in a new domain that has the same NetBIOS name as the existing Windows NT domain. Upgrade the computer to Windows 2000 Server. Use the Active Directory sites and services to force synchronization of the domain controllers.C.Shut down the PDC of the existing Windows NT domain from the network. On the new computer, install Windows 2000 Server, and then run the Active Directory installation wizard to install Active Directory, specifying the same NetBIOS name for the Windows 2000 domain as the existing Windows NT domain. Restart the Windows NT PDC on the network and demote it to a BDC.D.Shut down the PDC of the existing Windows NT domain from the network. On the new computer, install Windows 2000 Server, and then run the Active Directory installation wizard to install Active Directory as a replica in the existing Windows NT domain. Promote the new computer to the PDC of the domain. Restart Windows NT PDC on the network and demote it to a BDC.
考题
You are the domain administrator for TestKing‘s Active Directory domain. Allservers run Windows Server 2003. All client computers run Windows XPProfessional.A newly installed server was added to your domain. You need to administer thisserver remotely from your client computer.You need to configure the new server to ensure that it can be administeredremotely.What should you do?()A. Install Terminal Server Licensing. Restart the server.B. Modify the system properties for the server. Enable Remote Desktop for the server by selecting the Allow users to connect remotely to this system check box.C. Start the Remote Access Connection Manager service and then configure the service to start automatically.D. Modify your user account properties to enable you to connect to the terminal server
考题
You are the network administrator for The network consists of a single Active Directory domain named The domain contains 352,000 Windows 2000 Professional computers. You install and configure Software Update Services (SUS) on a server named TestKing3. You need to scan all computers in the domain to find out whether they have received all approved updates that are located on the SUS server. What should you do?()A、On a server, install and run the mbsacli.exe command with the appropriate configuration switches.B、On a server that runs IIS, install and configure urlscan.exe.C、Edit and configure the Default Domain Policy to enable the Configure Automatic Updates policy.D、From a command prompt on TestKing3, run the netsh.exe command to scan all computers in the domain.
考题
You work as the enterprise exchange administrator at TestKing.com. The TestKing.com network consistsof an Active Directory forest that contains a single domain named testking.com. TestKing.com has anExchange Server 2010 organization. For the future, you envisage to add a new domain to the forest as well as deploying the Exchange Server2010 servers in the domain. A TestKing.com employee named Andy Reid that is a member of an ActiveDirectory group. You have received instructions from the CIO to allow Andy Reid to install ExchangeServer 2010 servers in the new domain. You thus nedd to identify the appropriate group to which AndyReid should be assigned()A、You should add Andy Reid to the Server Operators group.B、You should add Andy Reid to the Domain Admins group.C、You should add Andy Reid to the Enterprise Admins group.D、You should add Andy Reid to the Exchange Install Domain Servers group.
考题
Your network contains a single Active Directory domain. All servers on the network are members of the domain. You have a server named Server1 that runs Windows Server 2003 Service Pack 2 (SP2). Server1 has two NTFS partitions. You create and share a folder named Data in the root of a partition on Server1. You log on to your computer by using the domain Administrator account and discover that you cannot modify files in the Data share. You need to ensure that the Administrator can modify files in the Data share. The solution must use the minimum amount of permissions. What should you do? ()A、Modify the NTFS permissions on the Data folder.B、Modify the share permissions on the Data share.C、Add the domain administrator to the local Administrator’s group on Server1.D、Move the Data folder to a new file allocation table (FAT) partition. Share the folder by using the default permissions.
考题
You are the network administrator for Testking.com. The network consists of a single Active Directory forest that contains three domains. The functional level of the forest is Windows Server 2003. The domain names are testking.com, europe.testking.com, and asia.testking.com. Each domain contains 500 user accounts. TestKing.com is in the process of acquiring several other companies whose networks will be add to the testking.com Windows Server 2003 domain. These acquisitions will entail the addition of several new offices, which will be connected to TestKing's network by means of dedicated 56-Kbps WAN connections. You create a new shared folder named NewProjects on a file server in testking.com. Several users in each existing domain need access to the NewProjects folder. These users are not in the same group in any domain. All users who need access to the NewProjects folder must be able to add, delete, and modify files and folders in the NewProjects folder. Users in the acquired companies also will require access to this folder. You need to create the required Active Directory groups and configure the required permissions for the NewProjects folder. Your solution must minimize ongoing administrative effort as you add new companies to the network. You must also minimize unnecessary traffic across the WAN connections. What should you do?()A、Create a single universal security group. Add all users that require access to the folder to the group. Create a domain local group in the testking.com domain. Add the universal group to the domain local group. Assign permissions to the shared folder by using the domain local group.B、Create a global security group in each domain. Add all users that require access to the folder to the global group in their domain. Create a domain local group in testking.com domain. Add the global groups to the domain local group. Assign permissions to the shared folder by using the domain local group.C、Create a universal security group in each domain. Add all users that require access to the folder to the group in their domain. Assign permissions to the shared folder by using the universal groups.D、Create a global security group in each domain. Add all users that require access to the folder to the group in their domain. Assign permissions to the shared folder by using the global groups.
考题
You are the administrator of an Active Directory domain named A user reports that he forgot his password and cannot log on to the domain. You discover that yesterday morning the user reset his password and successfully logged on to the domain. You need to enable the user to log on to the domain. What should you do? ()(Choose two)A、Use Active Directory Users and Computers to move the account to the default organizational unit (OU) named Users. Instruct the user to restart his computer.B、Use Active Directory Users and Computers to open the account properties for the user's user account. Clear the Account is locked out check box, and select the User must change password at next logon check box.C、Use Active Directory Users and Computers to reset the user's password. Give the user the new password.D、Use Computer Management to reset the password for the local Administrator account.
考题
You are the network administrator for TestKing.com. The network consists of a single Active Directory domain named testking.com. All network servers run Windows Server 2003. You place computer accounts for servers in OUs that are organized by server roles. You apply GPOs to these servers at the OU level. You need to add a new server to the domain. You need to ensure that the appropriate GPOs are applied to this server. What should you do?()A、Prestage a domain computer account for the new server in the appropriate OU. Join the server to the domain by using the prestaged computer account.B、On the server, add the domain name for the Active Directory domain to the DNS suffix setting. Join the server to the domain.C、Assign a user account the Allow - Create permission for the appropriate OU. Join the new server to the domain by using the user account.D、Join the new server to the Active Directory domain. On the new server, run the gpupdate /force command.
考题
You network consists of a single Active Directory domain. All domain controllers run Windows Server 2008 R2. You need to reset the Directory Services Restore Mode (DSRM) password on a domain controller. What tool should you use()A、dsmodB、ntdsutilC、Local Users and Groups snap-inD、Active Directory Users and Computers snap-in
考题
You are designing a plan to migrate an existing application to Windows Azure. The application must use the existing Active Directory Domain Services (AD DS) domain. You need to recommend an approach for joining Windows Azure virtual machines to the domain. What should you recommend?()A、 Install the Active Directory Certificate Services (AD CS) root certificate into the Enterprise Trust certificate store on each virtual machine.B、 Configure Windows Azure Connect.C、 Configure Windows Azure AppFabric Access Control.D、 Install Active Directory Federation Services (AD FS) in the existing domain.
考题
You network consists of a single Active Directory domain. All domain controllers run Windows Server 2008. You need to reset the Directory Services Recovery Mode (DSRM) password on a domain controller. What tool should you use()A、dsmodB、ntdsutilC、Local Users and Groups snap-inD、Active Directory Users and Computers snap-in
考题
You are the network administrator for TestKing.com Active Directory domain. The domain includes Windows Server 2003 domain controllers and Windows XP Professonal client computers. A new administrator named Sandra is hired to assist you in deploying Windows XP Professional to 100 new computers. Sandra installs the operating system on a new computer named TestKing11. However, when Sandra tries to log on to the domain from TestKing11, she is unsuccessful. The logon box does now allow her to view and select the domain name. You need to ensure that Sandra can log on to the domain from TestKing11. What should you do?()A、Enable the computer account for Testking11.B、Configure TestKing11 as a member of the domain.C、Add Sandra's user account to the Enterprise Admins group.D、Add Sandra's user account to the Server Operators group.
考题
You are the network administrator for. The network consists of a single Active Directory forest that contains two domains. You have not modified the default Active Directory site configurations. The functional level of both domains is Windows 2000 native. Servers run either Windows Server 2003 or Windows 2000 Server. TestKing's internal domain is named testking.local. Testking's external domain is named . The external domain is accessed only by TestKing's business partners. You install a Windows Server 2003 computer named Testking7 in the domain. You install and configure Terminal Services on Testking7. Testking7 is configured as a member server in the domain. You install a secure database application on Testking7 that will be accessed by TestKing's business partnersA few months later, users report that they can no longer establish Terminal Services session to Testking7. You verify that only the default ports for HTTP, HTTPS, and Terminal Services on your firewall are open to the Internet. You need to ensure that TestKing's business partners can establish Terminal Services sessions to Testking7. What are two possible ways to achieve this goal?() (Each correct answer presents a complete solution. Choose two)A、Install Terminal Services Licensing on a Windows 2000 Server computer in testking.local. Configure the computer as an Enterprise License Server.B、Install Terminal Services Licensing on a Windows 2000 Server computer in extranet.testking.com. Configure the computer as an Enterprise License ServerC、Install Terminal Services Licensing on a Windows Server 2003 computer in extranet.testking.com. Configure the computer as an Enterprise License Server.D、Install Terminal Services Licensing on a Windows Server 2003 computer in testking.local. Configure the computer as an Enterprise License Server.E、Instruct TestKing's business partners to connect by using the Terminal Services Advanced Client (TSAC) over HTTPS.
考题
As an administrator at Certkiller.com, you have installed an Active Directory forest that has a single domain. You have installed an Active Directory Federation services (AD FS) on the domain member server. What should you do to configure AD FS to make sure that AD FS token contains information from the active directory domain()A、Add a new account store and configure it.B、Add a new resource partner and configure itC、Add a new resource store and configure itD、Add a new administrator account on AD FS and configure itE、None of the above
考题
You are the network administrator for The network consists of a single Active Directory domain named All servers run Windows Server 2003, and all client computers run Windows XP Professional. A user named Lilli receives a new computer named Client223. She successfully logs on to the domain. The next day, she tries to log on again. The domain name appears in the domain dropdown list in the dialog box. However, Lilli cannot log on. You try to log on by using Client223, but you are also unsuccessful. Then you use a local Administrator account to log on. You read the following error message in the system event log. "NETLOGON Event ID 3210: Failed to authenticate with //Server5, a Windows NT domain controller for domain TestKing". You search the computer account for Client223 in Active Directory Users and Computers, but the account does not appear. You need to ensure that Lilli can log on to the domain successfully. What should you do?()A、Recreate the user account for Lilli and add her to all appropriate security groups.B、Run the netdom reset 'Client223' /domain:'testking' command and then restart Client223.C、Add Client223 to a workgroup. Then join Client223 to the domain.D、Reset the computer account for Server5 in Active Directory Users and Computers.
考题
单选题You work as the enterprise exchange administrator at TestKing.com. TestKing.com makes use of Microsoft Exchange Server messaging solution. The TestKing.com network consists of a single ActiveDirectory forest with one domain. The internal network of TestKing.com contains a perimeter network. You have received instructions fromthe CIO to install 15 Edge Transport servers on the perimeter network with the following criteria: * The Edge Transport servers should have a security policy, applied by the administrators. * The minimization of the administrative overhead towards the servers. * The minimization the attack surface of the perimeter network. What should you do?()A
The best option is to set up a new Active Directory domain in the internal forest and then join all EdgeTransport servers to the new domain.B
The best option is to make use of Active Directory Federation Services (AD FS).C
The best option is to make use of Network Policy and Access Services (NPAS).D
The best option is to set up a new Active Directory domain in the perimeter network and then join all Edge Transport Servers to the new domain.
考题
单选题You are the network administrator for TestKing. The network consists of a single Active Directory domain. All servers run Windows Server 2003. The domain contains two domain controllers named Testking1 and Testking2. You use a Windows XP Professional client computer named Client1. In Active Directory, the domain administrator creates two new user accounts named NetAdmin1 and AdminUser1. The NetAdmin1 account is a member of the Domain Admins global group. The AdminUser1 account is a member of only the Users local group. You assign the AdminUser1 logon account the Allow log on locally user right in the Default Domain Controller Group Policy object (GPO). A new written security policy states that user accounts that are member of the Domain Admins global group should not be used to log on to the console of a domain controller. It also states that administrative tasks should be performed by using the Secondary Logon service. You need to create a new computer account in Active Directory, and you must comply with the new company security policy. What should you do?()A
Log on to Testking1 by using the AdminUser1 user account. Run the dsa.msc command.B
Log on to Testking1 by using the NetAdmin1 user account. Run the dsa.msc command.C
Log on to Client1 by using the AdminUser1 user account. Run the runas /user:netadmin1 dsa.mscD
Log on to Client1 by using the NetAdmin1 user account. Run the runas /user:adminuser1 dsa.msc
考题
单选题You work as the enterprise exchange administrator at TestKing.com. The TestKing.com network consistsof an Active Directory forest that contains a single domain named testking.com. TestKing.com has anExchange Server 2010 organization. For the future, you envisage to add a new domain to the forest as well as deploying the Exchange Server2010 servers in the domain. A TestKing.com employee named Andy Reid that is a member of an ActiveDirectory group. You have received instructions from the CIO to allow Andy Reid to install ExchangeServer 2010 servers in the new domain. You thus nedd to identify the appropriate group to which AndyReid should be assigned()A
You should add Andy Reid to the Server Operators group.B
You should add Andy Reid to the Domain Admins group.C
You should add Andy Reid to the Enterprise Admins group.D
You should add Andy Reid to the Exchange Install Domain Servers group.
考题
单选题Your company has an Active Directory domain. A user attempts to log on to a computer that was turned off for twelve weeks. The administrator receives an error message that authentication has failed. You need to ensure that the user is able to log on to the computer. What should you do()A
Run the netdom TRUST /reset command.B
Run the netsh command with the set and machine options.C
Run the Active Directory Users and Computers console to disable, and then enable the computer account.D
Reset the computer account. Disjoin the computer from the domain, and then rejoin the computer to the domain.
考题
单选题You are the network administrator for TestKing.com. The network consists of a single Active Directory domain named testking.com. The domain contains Windows Server 2003 computers and Windows XP Professional computers. You use a non-administrative user account named Joseph to log on to a client computer. You need to change the password for a domain user account named Sophia. You open the Active Directory Users and Computers console. When you attempt to change Sophia's password, you receive the following error message: "Access is denied". You need to remain logged on to the client computer as Joseph, and you need to be able to change Sophia's password. What should you do?()A
Add the non-administrative domain user account to the local Administrators group.B
Use the runas command to run Active Directory Users and Computers with domain administrative credentials.C
From a command prompt, run the net user Sophia /add /passwordreq:yes command.D
From a command prompt, run the net accounts /uniquepw: /domain command.
考题
单选题You are the network administrator for . The network consists of a single Active Directory domain. All domain controllers run Windows Server 2003, and all client computers run Windows XP Professional. TestKing acquires a subsidiary. You receive a comma delimited file that contains the names of all user accounts at the subsidiary. You need to import these accounts into your domain. Which command should you use?()A
ldifdeB
csvdeC
ntdsutil with the authoritative restore optionD
dsadd user
考题
单选题You are the network administrator for TestKing. The network consists of a single Active Directory domain. All network servers run Windows Server 2003 and all client computers run Windows XP Professional. Terminal Services is installed on a member server named Testking1. Currently, 30 active terminal server sessions are connected to Testking1. An unforeseen hardware upgrade will require shutting down the server. You need to provide a two-minute warning about the shutdown to all active terminal sessions. First, you log on to Testking1 as an administrator. What should you do next?()A
From a command prompt, run the tsdisconn command.B
From a command prompt, run the net send /users command to send a warning message. After two minutes, manually shut down Testking1.C
From a command prompt, run the tsshutdn 120 /server:Testking1 command.D
Run Tsadmin.exe to disconnect all active sessions. After two minutes, manually shut down Testking1.
考题
单选题Certkiller .com has a network that is comprise of a single Active Directory Domain. As an administrator at Certkiller .com, you install Active Directory Lightweight Directory Services (AD LDS) on a server that runs Windows Server 2008. To enable Secure Sockets Layer (SSL) based connections to the AD LDS server, you install certificates from a trusted Certification Authority (CA) on the AD LDS server and client computers. Which tool should you use to test the certificate with AD LDS()A
Ldp.exeB
Active Directory Domain servicesC
ntdsutil.exeD
Lds.exeE
wsamain.exeF
None of the above
考题
单选题You are designing a plan to migrate an existing application to Windows Azure. The application must use the existing Active Directory Domain Services (AD DS) domain. You need to recommend an approach for joining Windows Azure virtual machines to the domain. What should you recommend?()A
Install the Active Directory Certificate Services (AD CS) root certificate into the Enterprise Trust certificate store on each virtual machine.B
Configure Windows Azure Connect.C
Configure Windows Azure AppFabric Access Control.D
Install Active Directory Federation Services (AD FS) in the existing domain.
考题
单选题You are the network administrator for your company. The network consists of a single Active Directory domain.All servers run Windows Server 2003.You place computer accounts for servers in organizational units (OUs) that are organized by server roles. You apply Group Policy objects (GPOs) to these servers at the OU level.You need to add a new server to the domain. You need to ensure that the appropriate GPOs are applied to this server.What should you do? ()A
Prestage a domain computer account for the new server in the appropriate OU. Join the server to the domain by using the prestaged computer account.B
On the new server, add the domain name for the Active Directory domain to the DNS suffix setting. Join the server to the domain.C
Assign a user account the Allow - Create permission for the appropriate OU. Join the new server to the domain by using the user account.D
Join the new server to the Active Directory domain. On the new server, run the gpupdate /force command.
考题
单选题You are the network administrator for Active Directory domain. The domain includes Windows Server 2003 domain controllers and Windows XP Professional client computers. A new administrator named Sandra is hired to assist you in deploying Windows XP Professional to 100 new computers. Sandra installs the operating system on a new computer named TestKing11. However, when Sandra tries to log on to the domain from TestKing11, she is unsuccessful. The logon dialog box does now allow her to view and select the domain name. You need to ensure that Sandra can log on to the domain from TestKing11. What should you do?()A
Enable the computer account for Testking11.B
Configure TestKing11 as a member of the domain.C
Add Sandra's user account to the Enterprise Admins group.D
Add Sandra's user account to the Server Operators group.