Active Directory 5 Flashcards
What setspn.exe command is used to create an SPN?
the setspn -s command
What would you run from the command line to register SPN http/srv55.nutex.com for a Windows Server 2012 R2 server named srv55?
setspn -S http/srv55.nutex.com srv55
Which Kerberos policy setting determines the maximum time difference that Kerberos V5 tolerates between the client clock and the clock on the domain controller that performs authentication?
Maximum tolerance for computer clock synchronization
What parameter of the Install-ADDSDomainController cmdlet is used to install and configure DNS on the domain controller?
the -InstallDns parameter
What commands must you run at the ntdsutil prompt to clean up server metadata?
metadata cleanup
remove selected server
When you use the Dsamain tool to offer LDAP services to a mounted ntds.dit file, which port number can you NOT use for the ldapport number?
389
How can you restore the values of an object’s attributes after they have been modified?
Mount an Active Directory snapshot, export the object, and import the object to the live Active Directory database.
What PowerShell cmdlet would allow you to view the settings of a Password Settings Object (PSO)?
the Get-ADFineGrainedPasswordPolicy cmdlet
Which cmdlet is used to restore deleted objects from the Active Directory Recycle Bin to their original location?
Restore-ADObject
What two conditions govern the presence or absence of the Delegation tab on the properties of a service?
an SPN must exist and the domain must be at the Windows Server 2003 level, or later
To what container should you set the Base DN to in the Search box of the ldp.exe tool when performing tombstone reanimation of a user account in nutex.com?
CN=Deleted Objects, DC=nutex, DC=com
To use Kerberos authentication with SQL Server, which two conditions are required?
The client and server computers must be part of the same Windows domain, or in trusted domains.
Service Principal Name (SPN) must be registered with Active Directory
If you have enabled the Active Directory Recycle Bin in the forest, what container in Active Directory will contain users, groups, and other objects after they have been deleted?
The Deleted Objects container