ITN 266 chapter 4
For members of a protected users global group, how often must the Kerberos Ticket Granting Ticket be renewed?
4 hours
What statement regarding trust relationships between domains is accurate?
Due to the trust relationship between parent and child domains, any one domain can have access to the resources of all others.
What is the most typically used boundary for an Active Directory site?
A site boundary is typically defined by a network or subnet boundary.
What tab under a user's account properties allows you to define the hours at which the user is able to log on to the domain?
Account tab
What feature provided at the Windows Server 2012 domain functional level creates a secure channel or tunnel between a client seeking authentication for a computer service and the server providing secure access keys for secure communications?
Flexible Authentication Secure Tunneling (FAST)
Under what conditions can a global group be converted to a universal group?
It can be converted as long as it is not nested in another global group or in a universal group.
When should an organization consider using Microsoft Azure Active Directory?
It should be considered if the organization subscribes to Office 365 services, or other compatible web services.
How are changes made within Active Directory maintained on different domain controllers?
Multimaster replication is used to replicate changes to other DCs.
How do you make a user profile a mandatory profile, preventing all changes?
Rename the Ntuser.dat file to Ntuser.man in the user's profile directory.
After deleting an account, what happens to the associated GUID?
The GUID will be permanently deleted and never re-used.
What statement regarding functional domain functional levels is accurate?
The functional level at both the domain and forest level should be set to the lowest version of Windows Server used.
A Read-Only Domain Controller (RODC) cannot be used to update information in Active Directory, and it does not replicate to regular DCs.
True
A transitive trust means that if A and B have a trust and B and C have a trust, A and C automatically have a trust as well.
True
According to Microsoft, what is the minimum number of DCs that should be present in any organization using Active Directory?
Two
What statement regarding Active Directory objects that can be members of a domain local group is NOT accurate?
Universal groups in any domain in a tree or forest can be a member of the domain local group, without requiring a trust relationship.