Use LEFT and RIGHT arrow keys to navigate between flashcards;
Use UP and DOWN arrow keys to flip the card;
H to show hint;
A reads text to speech;
60 Cards in this Set
- Front
- Back
Schema defines what of all objects in an Active Directory database?
|
class
attributes |
|
What partitions are used to separtate forest-wide DNS information from domain-wide DNS information to control the scope of replication of different types of DNS data?
|
Application partitions
|
|
What is the security boundary in an Active Directory environment?
|
Forest
|
|
What files stores the AD db info?
|
ntds.dit
|
|
If two SRV records have the same priority, the frequency by which they are used by clients will be determined by what?
|
Relative weights
|
|
What trust can be created between two Windows Domains in the same forest to shorten the "tree-walk" process for users who require frequent access to resources in another domain in the same forest?
|
Shortcut trust
|
|
What is the default authentication protocol used by AD of server 2008?
|
Kerberos
|
|
What policy is used to configure which user accounts will or will not have their password information replicated to an RODC?
|
Password Replication Policy
|
|
Although an RODC is no writable, what replication does it participate in?
|
Inbound
|
|
What is the function of the KCC?
|
Create replication topology between multiple domain controllers within a site.
|
|
What doeseach DC maintain that keeps track of changes that are made at each domain controller and thus keeps track of which updates should be replicated to other domain controllers?
|
Update Sequence Number
|
|
In a replication conflict, what is the first attribute that AD will use as a tie-breaker?
|
version ID
|
|
Default cost of new site link?
|
100
|
|
What FSMO role is responsible for managing time synchronization within a domain?
|
PDC emulator
|
|
What must be running and accessible to add or remove a domain or a sub domain from an AD forest?
|
Domain Naming Master
|
|
What are the FSMO roles?
|
Schema Master
Domain naming master Infrastructure Master Relative ID(RID) Master PDC Emulator |
|
What FSMO role should not be housed on a DC that has been configured as a global catalog except that every DC is a global catalog in the domain?
|
Infrastructure Master
|
|
What group membership is stored in the global catalog?
|
Universal Group Membership
|
|
Which DNS resource records allow clients to locate an AD DC or global catalog?
|
SRV records
|
|
What internal process is responsible for selecting a bridgehead server and mapping the topology for replication between sites?
|
Intersite Topology Generator
|
|
What is the maximum number of hops that the KCC will allow between two domain controllers?
|
3
|
|
What is the convergence time within one AD site on the same LAN?
|
~1minute
|
|
What is the best reason to create and manage AD sites in an AD forest?
|
Improve replication performance and facilitate service location
|
|
What type of partitions do ADs use?
|
Application directory partition
|
|
What is the minimum number of DCs that are needed to hold all of the FSMO masters in the forest root domain?
|
3
|
|
Will clients be able to log in when the Schema Master is offline?
|
yes
|
|
The RID FSMO Master distributes RIDs to DCs in an increment of what?
|
500
|
|
Where would a client workstation look to synchronize its clock with the domain?
|
the DC that authenticates the workstation
|
|
What is the Global Catalog?
|
AD component that contains a partial attribute set of all objects within an AD forest
|
|
Which FSMO role cannot be performed on multiple servers in an AD forest?
|
Infrastructure master
|
|
What is the function of a trust relationship in an AD environment?
|
To provide authentication and authorization capabilities between clients and servers in different domains.
|
|
What does FSMO stand for?
|
Flexible Single Master Operations
|
|
What are the 4 functions of the PDC Emulator master?
|
1. Password changes
2. Authentication failures 3. Account lockout 4. Backwards compatibility |
|
What is KCC and how often does it run?
|
Knowledge Consistency Checker, every 15 minutes
|
|
What are the tie-breakers of replication conflicts?
|
1. Version ID
2. Timestamp 3. GUID of the DC where change happens |
|
What is the first GPO that is applied during a normal GPO processing?
|
Local GPO
|
|
What folder structure is located in the shared SYSVOL folder on a domain controller?
|
Group Policy Templates
|
|
What command can be used to manually force a group policy refresh?
|
gpupdate
|
|
What is the speed of a slow link?
|
< 500 Kb/s
|
|
What log entries are triggered by events such as user rights assignment changes, establishment or removal of trust relationships, IPSec policy agent change, and grants or removals of system access privileges.
|
Policy Change Audit logs
|
|
What folder under the Computer Configuration node in the GPME contains security settings and scripts that apply to all users who log on to the AD from that specific computer
|
Windows Settings
|
|
What are all the supported packages for windows installer?
|
.msi, installation package
.mst, transform file, for modification or customize install .msp, patch file .zap, non-Windows |
|
What are the 4 command types of powershell?
|
1. cmdlets
2. functions 3. scripts 4. native commands |
|
what is the help command for powershell?
|
get-help <command>
|
|
What is Loopback processing? What are its modes?
|
Used to apply Group Policy Objects (GPOs) that depend only on which computer the user logs on to. Merge and Replace modes
|
|
From which log can you view the Group Policy processing events in the Event Viewer Windows Logs?
|
System
|
|
What is the path to the default GPT structure for a domain?
|
systemroot\sysvol\sysvol\domain.com\Policies
|
|
What policy setting allows an admin to specify group membership lists?
|
Restricted Groups
|
|
What setting logs events related to successful user logons to a domain?
|
Account logon events?
|
|
What allows published software applications to be organized within specific groupings for easy navigation?
|
Software categories
|
|
When implementing multiple software restriction policy rules, which rule is always applied last?
|
Path rule
|
|
What software restriction policy properties allow admins to determine whether the policies apply to all files or whether library files are excluded?
|
Enforcement
|
|
What order are domain, OU, site, and local GPOs applied?
|
1. local
2. site 3. domain 4. OU |
|
AD is a database based on what format?
|
Extensible Storage Engine
|
|
What runs automatically on a DC every 12 hours by default during the garbage collection process?
|
Online defragmentation
|
|
What is the default Transaction log file?
|
edb.log
|
|
In Win2008, what type of backup media is not supported by the Server Backup?
|
Magnetic types
|
|
What service must be installed to deploy software?
|
Windows Installer
|
|
What default security level in software restriction policies will disallow any executable that requires administrative rights to run?
|
Basic
|
|
What software restriction policy rule types apply only to windows installer packages?
|
Internet zone rules
|