Chapter 4 Review Questions
19. To reset a password, you use the _____ tool.
Active Directory Users and Computers
6. Domains in a tree are in a _____ relationship.
Kerberos transitive trust relationship
12. Which of the following are actions performed by the global catalog? (Choose all that apply.) a. Provide lookup and access to all resources in all domains b. Caches IP addresses for all computers in a forest for faster sign-in c. Stores shared DFS folders and files for centralized shared file access d. Authenticates users when they sign in
a
2. Using the example in Question 1, what Active Directory capability can you use to establish different account lockout policies for each of the four departments? a. Fine-grained password policies b. Lightweight group policies c. Password distribution groups d. Shadow password files
a
4. You receive a message that Active Directory Domain Services has experienced an error and the Active Directory Domain Services service must be stopped and restarted. Which of the following tools can you use? (Choose all that apply.) a. Component Services b. Active Directory Domain Services Configuration Wizard c. Device Manager d. Active Directory Users and Computers
a
9. Your school has a parent object named straton.edu and the child object names stratonalum.org and studentarts.org. What kind of namespace is this? a. Disjointed b. Distributed c. Contiguous d. Coordinated
a
20. Which of the following are required attributes for a user account? (Choose all that apply.) a. Domain b. User's full name c. Password d. Logon name
a, b, c, d
15. Which of the following is true about all trees in a forest? (Choose all that apply.) a. They all use the same schema b. They all use the same OUs c. They all use the same global catalog d. They all use the same groups
a, c
16. The list of security descriptors associated with a user account in Active Directory is called a(n) _________.
access control list
14. You are creating a special user profile for all members of the inventory control unit in your business. After you create the profile, what tool can you use to copy it to all of the user accounts in the inventory control unit? a. Active Directory Users and Computers b. System applet in Control Panel c. Server Manager d. MMC Profiles snap-in
b
18. You manage the servers for your city government. You've installed a new Windows Server 2016 server and one of your first tasks is to configure user accounts for the police patrol division. All of the police officers will have the same security configuration on their user accounts. Which of the following is a good practice for managing the security on these user accounts? a. Create a separate forest to hold the accounts b. Create a global security group and make all of the user accounts members c. Establish a new domain to hold the accounts and provide extra security d. Ensure all of the properties associated with these accounts are identical
b
7. What tool can you use to manage fine-grained password policies? a. Active Directory Users and Computers b. Active Directory Administrative Center c. Password Administrator d. Security Configuration tool
b
1. Your company has four departments: Marketing and Sales, Manufacturing, Product Research, and Business. Which of the following Active Directory container design plans might you use to best manage the user accounts and network access needs of each department? a. Create four trees b. Create four parent domains in the one site c. Create four OUs in one domain d. Create four trees and map them to four domains
c
10. Your company's management has decided that the accounts in all OUs should be set up and managed by the Information Technology department's security specialist. As the AD DS administrator, how can you best give this capability to the security specialist? a. Give her Full Control rights to AD DS b. Make her user account a member of the AD DS Admins local security group c. Use the delegate control feature to give her control of all OUs that contain user accounts d. Give her Accounts Management permissions in AD DS
c
3. Your colleague has installed Active Directory Domain Services as a server role, but he has discovered that Active Directory cannot be used at this point. What next step must he take to get Active Directory ready for use? a. He must create a domain local group for Active Directory administrators b. He must create a universal distribution group and make Active Directory a member c. He must perform initial configuration to promote the server housing the Active Directory Domain Services role to a domain controller d. He must initialize the Active Directory Changes and Use log
c
5. Which of the following server operating systems can be used when the domains in Windows Server 2016 Active Directory are set at the Windows Server 2012 domain functional level? (Choose all that apply.) a. Windows Server 2003 with Server 2008 Domain Services installed b. Windows Server 2008 c. Windows Server 2012 R2 d. Windows Server 2016
c, d
13. You work for a bank that has five branch offices and one to two servers are located at each branch office. For best security, what kind of domain controller should be used at each branch office? a. An Active Directory Branch Controller b. A domain controller with Active Directory Federation Services installed as a role c. A Protected Security Domain Controller d. A Read-Only Domain Controller
d
8. A _____ is a unique number associated with each object in AD DS.
globally unique identifier (GUID)
11. A local security group is used on a ________ server.
stand alone
17. A site reflects interconnected _____ and is used for DC _____.
subnets, replication