742 Lesson 3 Q and A
Which command-line utility allows administrators to modify groups' type and scope as well as add or remove members? modify group type modify group scope add or remove members
Dsmod.exe
Even when OUs have been nested to many levels, they still will not adversely affect the response time to resource requests or complicate the application of Group Policy settings.
False
Which of the following is a container object within Active Directory?
OU organizational unit
When attempting to delete a global security group in the Active Directory Users and Computers console, the console does not allow the task to complete. Which of the following could possibly be causes for the failure?
One of the group's members has the group set as its primary group The user does not have the proper permissions for the container in which the group is located
What are the CORRECT reasons for creating an OU?
To duplicate the divisions in the organization, To delegate administration tasks To assign different Group Policy settings to a specific group of users or computers.
In a domain running at the Windows Server 2016 domain functional level, which of the following security principals/groups can be members of a global group?
Users Computers Global groups NOT universal groups
In windows server 2016, after a user logs on to Active Directory, a(an)________ is created that identifies the user and all the user's group memberships.
access token
If the user named Amy is located in the sales OU of the central.cohowinery.com domain, which of the following is the correct syntax for referencing the user in a command line utility?
cn=amy,ou=sales,dc=central,dc=cohowinery,dc=com
Members of a universal group can come ____.
from trusted forests
Of the key reasons for creating organizational units, which of the following is NOT one of them?
Assigning permissions to network resources
What ARE key reasons for creating organizational units?
Delegating administration, assigning Group Policy settings, and Duplicating organizational divisions.
As an administrator for Contoso Corporation, you are planning an Active Directory implementation. Contoso currently has sales, accounting and marketing departments. All department heads want to manage their own users and resources in Active Directory. Which of the following features will permit you to set up Active Directory to allow each manager to manage his or her own container but not any other containers?
Delegation of Control Wizard
What feature will permit you to setup Active Directory to allow each manager to manage his or her own container but not any other containers?
Delegation of control (wizard)
Which of the following is not an example of a special identity?
Dialup Service NOT DIALUP CUS DIALUP IS
Which of the following is the complete path through the hierarchical tree structure to a specific object in Active Directory?
Distinguished names
Which of these groups is not related to security and cannot have permissions assigned to it?
Distribution groups
Which of the following is the only OU created by default after installing Active Directory?
Domain Controllers OU
What command-line utility allows administrators to modify a group's type and scope as well as add or remove members? CMD commandline utility to modify group's type, modify group's scope, add members, and remove members.
Dsmod.exe
Which of the following default groups is a universal group?
Enterprise Admins
What is the group scope for Domain Admins, Domain Controllers, and Domain Users default groups?
Global
Some of the following groups might grant or deny permissions to any resource located in any domain in the forest. Of them, which one's membership is replicated only in the domain controllers of the same domain?
Global groups
What is the primary difference between universal groups and global groups in Windows Server?
Global groups use less data in the global catalog. So, in considering replication traffic, universal groups should be within a site.
Which of the following is the primary difference between universal groups and global groups in Windows Server 2016?
Global groups use less data in the global catalog. So, in considering replication traffic, universal groups should be within a site.
Which of the following group scope modifications are NOT permitted?
Global to domain local
How do groups differ from OUs?
Groups are security principals, meaning you assign access permissions to a resource based on membership in a group. OUs are for organization and for assigning Group Policy settings.
Generally, how do groups differ from OUs?
Groups are security principals, meaning you assign access permissions to a resource based on membership to a group. OUs are for organization and for assigning Group Policy settings.
What is a key difference between a domain tree hierarchy and the organizational unit (OU) hierarchy within a domain?
Inheritance
Of the default groups created when Active Directory is installed, what are the types of those groups?
Security groups
Which of the following is not a group scope?
Security groups
Within a domain, the primary hierarchical building block is which of the following?
The organizational Unit
Which of the following are the different kinds of groups?
There are two types: security and distribution, and three group scopes: domain local, global, and universal. There are two types: security groups and distribution groups, and three group scopes: domain local groups, global groups, and universal groups.
Which of the following is NOT a correct reason for creating an OU?
To create a permanent container that cannot be moved or renamed
Which of these groups' membership is stored in the global catalog?
Universal groups
Which of the following is the minimum domain functional level to use group membership expiration?
Windows Server 2016
You are attempting to delete a global security group in the Active Directory Users and Computers console, and the console will not let you complete the task. Which of the following could possibly be causes for the failure? Choose all that are correct
You do no have the proper permissions for the container in which the group is located. One of the group's members has the group set as its primary group.
Which of the following group scope modifications are PERMITTED?
global to universal universal to global domain local to universal
The Delegation of Control Wizard is capable of ________ permissions.
granting
The Delegation of Control Wizard is capable of which of the following permissions?
granting
Which of the following groups should be used to consolidate groups and accounts that either span multiple domains or the entire forest?
universal (groups)
What are examples of special identity?
Anonymous Logon, Authenticated Users, Batch, Creator Group, Creator Owner, Dialup, Digest Authentication, Enterprise Domain Controllers, Everyone, Interactive, Network, Remote Desktop Users, Remote Interactive Logon, Self, and Service.
An administrator needs to grant an e-mail distribution group of 100 members access to a database, how would the administrator proceed? The e-mail group is obsolete and can be dissolved/needs to be deleted.
Convert the distribution group to a security group and then assign the group access permissions. distribution group convert to security and assign database access permissions
Which of these groups would an administrator use to assign permissions to resources in the same domain?
Domain local groups
Specify the correct order of steps necessary to create an OU with Active Directory Administrative Center. create OU with ADAC
Step 1: In Server Manger, click Tools > Active Directory Administrative Center. Step 2: In the left pane, right click the object beneath which you want to create the new OU and choose New > Organizational Unit. Step 3: In the Name field, type a name for the OU and add any optional information you want. Step 4: Click OK. The organizational unit object appears in the container.
You can use a security group to grant permissions to resources and to enable email access. A distribution group, however, can only be used for email purposes; it cannot bu used to secure resources on your network.
True
Which of the following are the best reasons for using organizational units (OUs)? a. Organizing by geography, assigning Group Policy settings, and applying security boundaries b. Applying security boundaries based on rights and permissions c. Duplicating organizational divisions, assigning Group Policy settings, and delegating administration d. Assigning Group Policy settings, administering delegation, and delegating administration.
c. Duplicating organizational divisions, assigning Group Policy settings, and delegating administration