Deck 1: Designing Active Directory Domain Services
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Match between columns
Unlock Deck
Sign up to unlock the cards in this deck!
Unlock Deck
Unlock Deck
1/42
Play
Full screen (f)
Deck 1: Designing Active Directory Domain Services
1
Fine-grained password policies can be implemented if the domain functional level is set to at least ____.
A) Windows NT
B) Windows Server 2000 Native
C) Windows Server 2003
D) Windows Server 2008
A) Windows NT
B) Windows Server 2000 Native
C) Windows Server 2003
D) Windows Server 2008
D
2
SID filtering should be disabled by an automated process.
False
3
The ____ for Active Directory defines the objects that can be created in Active Directory.
A) schema
B) directory
C) database
D) template
A) schema
B) directory
C) database
D) template
A
4
A ____ is a group of well-connected computers or well-connected subnets.
A) domain
B) site
C) forest
D) trust
A) domain
B) site
C) forest
D) trust
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
5
For most applications, a single-domain, single-forest design will work.
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
6
A ____ trust is granted between several domains without creating explicit trust relationships between the different domains.
A) non-transitive
C) transitive
B) one-way
D) foreign
A) non-transitive
C) transitive
B) one-way
D) foreign
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
7
____ is an Active Directory preparation tool that can modify the schema by adding objects and properties needed to support Windows Server 2008 domain controllers.
A) ADSIEdit
B) ADPrep
C) DCPromo
D) GPUpdate
A) ADSIEdit
B) ADPrep
C) DCPromo
D) GPUpdate
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
8
If you want users or groups to be able to access a resource using SID history, you must enable SID filtering.
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
9
A domain functional level or forest functional level can be raised and then undone (or lowered) as necessary.
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
10
Forest trusts are possible once the forest functional level has been raised to ____.
A) Windows NT
B) Windows Server 2000 Native
C) Windows Server 2003
D) Windows Server 2008
A) Windows NT
B) Windows Server 2000 Native
C) Windows Server 2003
D) Windows Server 2008
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
11
The ____ authentication option allows Windows to automatically authenticate any users in another forest to access resources in the local forest.
A) domain-wide
C) schema-wide
B) tree-wide
D) forest-wide
A) domain-wide
C) schema-wide
B) tree-wide
D) forest-wide
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
12
Fine-grained password and account ____ policies are a significant addition to Windows Server 2008.
A) lockout
B) length
C) timeout
D) login
A) lockout
B) length
C) timeout
D) login
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
13
When selective authentication is implemented on a forest trust, you need to grant the ____ permission on each server or computer where access is granted.
A) Allowed to Authenticate
C) Run as Service
B) Replace Token
D) Act as Part of the Operating System
A) Allowed to Authenticate
C) Run as Service
B) Replace Token
D) Act as Part of the Operating System
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
14
An Active Directory domain is hosted on a server called a ____.
A) member server
B) domain master
C) domain controller
D) role master
A) member server
B) domain master
C) domain controller
D) role master
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
15
A ____ trust creates an explicit trust relationship between two domains and is not transferred to any other domains.
A) non-transitive
B) transitive
C) one-way
D) foreign
A) non-transitive
B) transitive
C) one-way
D) foreign
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
16
The ____ authentication option can be used to prevent users in another forest from automatically being authenticated.
A) restricted
C) filtered
B) selective
D) one-way
A) restricted
C) filtered
B) selective
D) one-way
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
17
Trusts within a forest are ____ trusts.
A) one-way
B) foreign
C) non-transitive
D) transitive
A) one-way
B) foreign
C) non-transitive
D) transitive
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
18
When you see the forest functional level is Windows Server 2008, you also know that every domain and domain controller in the forest must be running at least ____.
A) Windows NT
B) Windows Server 2000 Native
C) Windows Server 2003
D) Windows Server 2008
A) Windows NT
B) Windows Server 2000 Native
C) Windows Server 2003
D) Windows Server 2008
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
19
In a ____, users in each domain can be granted access to resources in both domains.
A) one-way trust
B) two-way trust
C) foreign trust
D) restricted trust
A) one-way trust
B) two-way trust
C) foreign trust
D) restricted trust
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
20
It's possible to create alternative UPN suffixes and assign these to users in the domain.
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
21
List the domain functional levels that a target domain can be operating in when using ADMT v3.1.
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
22
A(n) _________________________ is used within a domain to organize objects.
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
23
____ is used when objects are migrated between domains in separate forests.
A) Interforest migration
C) Interdomain migration
B) Intraforest migration
D) Intradomain migration
A) Interforest migration
C) Interdomain migration
B) Intraforest migration
D) Intradomain migration
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
24
ADMT v3.1 should be installed and run on a Windows Server 2008 domain controller in the ____________________ domain.
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
25
Explain the difference between autonomy and isolation.
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
26
Access to any resource within the domain is controlled by a(n) ____.
A) Access Control Entity
C) Discretionary Access Control List
B) Discretionary Access Control Object
D) Access Control List
A) Access Control Entity
C) Discretionary Access Control List
B) Discretionary Access Control Object
D) Access Control List
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
27
Discuss the security risk of SID history if you are migrating accounts between forests that aren't completely trusted.
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
28
You can easily determine what servers hold all the roles by opening a command prompt and entering the following command: ____
A) netdom query trust
C) netdom query pdc
B) netdom query fsmo
D) netdom query dc
A) netdom query trust
C) netdom query pdc
B) netdom query fsmo
D) netdom query dc
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
29
How is the migration of objects handled between domains?
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
30
Discuss what happens when SID filtering is disabled.
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
31
Discuss the difference between domain controllers and servers when raising the level to Windows Server 2008.
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
32
Beyond autonomy, what are two other reasons to create separate domains?
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
33
You are designing a plan that will merge two companies and you need to create a forest trust relationship between two forests.What are some considerations you should keep in mind?
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
34
____ prevents the risk of an attacker obtaining SID history data by blocking the use of any SIDs that did not originate in the same domain.
A) SID blocking
C) SID masking
B) SID selecting
D) SID filtering
A) SID blocking
C) SID masking
B) SID selecting
D) SID filtering
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
35
The ADPrep switch ____ is used to prepare the forest for Windows Server 2008 or Windows Server 2008 R2 domain controllers.
A) /ForestBuild
C) /ForestPrep
B) /ForestNew
D) /ForestSelect
A) /ForestBuild
C) /ForestPrep
B) /ForestNew
D) /ForestSelect
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
36
An Active Directory ____________________ includes one or more trees comprised of one or more domains.
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
37
____________________ is achieved when an organization can independently manage their data.
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
38
_________________________ is used when objects are migrated between domains in the same forest.
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
39
You can disable SID filtering using the ____ command on the trusting domain.
A) Netdom
C) Wscript
B) Netf
D) Netsh
A) Netdom
C) Wscript
B) Netf
D) Netsh
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
40
List the extra steps that must be taken to allow SID history to work between different forests.
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
41
List the trusts that can be used to create a trust relationship in order to run ADMT.
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
42
Match between columns
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck