Active directory Flashcards

1
Q

Two-way _______ _________ are automatically established upon the creation of a subdomain or with the addition of a domain tree into an AD DS forest

A

transitive trusts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

_________ trusts are those that are set up manually

A

Explicit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

__________ ___________ allow authentication verifications to be processed faster, as opposed to having to move up and down a domain tree.

A

Shortcut trusts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

__________ ____________allow different forests to share information without actually merging schema information or global catalogs

A

external trusts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are organizational units?

A

organizational units (OUs) are containers that logically store directory information and provide a method of addressing AD DS through LDAP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the primary method for organizing user, computer, and other object information into a more easily understandable layout?

A

organizational units

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the two different group types and their function?

A

A security group can be used to apply permissions to objects for the members of the group.
A distribution group, used to send mail to members of the group

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the components of Group scope in AD DS?

A

Machine local groups
Domain local groups
Global groups
universal groups

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the function of a Machine local groups?

A

Users and groups in the local domain, and other trusted domains and forests
local groups allow resources to be accessed only on the machine where they are located

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are Domain local groups?

A

Used to administer resources located only on their own domain.
They can contain users and groups from any other trusted domain. Most typically, these types of groups are used to grant access to resources for groups in different domains

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are Global groups?

A

contain users only in the domain in which they exist but are used to grant access to resources in other trusted domains.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are universal groups?

A

universal groups grant access to any resource in the forest

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the difference between an OU and a group?

A

groups can be used when applying security to objects, whereas OUs exist when certain administrative functionality needs to be delegated.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are active directory objects?

A

Containers

Leafs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are container objects in AD?

A

Domains, Organizational Units (OU), Sites

Create collections for organizational purpose

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are leaf objects in active directory?

A

Users, Computers, Security and Distribution Groups

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

How is a NetBIOS naming -legacy formatted?

A

domain\object name

e.g. dickson\jdickson

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

How is Universal Principal name (UPS) formatted?

A

object name@ domain

e.g. jdickson@dickson.local

19
Q

What is CN?

A

common name is an object name

20
Q

What is OU?

A

Organizational unit

Can have many OUs based on hierary

21
Q

___________ ________ represents the entire naming path that the object occupies
CN=Joel Oleson,OU=SLC,DC=Companyabc,DC=com

A

Distinguished name

22
Q

What do DC components define ?

A

The domain controllers define the DNS name of the Active Directory domain.

23
Q

AD DS uses ___________ ____________ to authenticate users

A

Domain Controllers(DC’s)

24
Q

The __________ _________, enables an administrator to view, delete, and modify schema attributes.

A

ADSIEdit utility

25
Q

What allows queries and updates to take place in AD DS?

A

LDAP

Lightweight Directory Access Protocol

26
Q

What is the Schema master?

A
  • has one writable master copy in a forests

- this limits access thus reducing potential replication conflicts

27
Q

What are AD DS DCs that contain a copy of the global catalog?

A

Global catalog servers (GCs)

28
Q

The global catalog is an index of the AD DS database that contains a _______ ______ of its contents

A

Partial Copy

29
Q

A common attribute extension occurs with the installation of _________________, which extends the schema

A

Microsoft Exchange Server

30
Q

Schema determines the way that all user, computer, and other object data are ________ in AD DS and ________ to be standard across the entire AD DS structure.

A

Stored, configured

31
Q

What is an AD DS schema?

A

A set of definitions for all object types and their related attributes in the directory

32
Q

Users and computers are all stored and managed from within the boundaries of the _________

A

Domain

33
Q

Domains in AD DS serve as administrative _________ __________ for objects and contain their own
________ ____________

A

security boundaries, security policies

34
Q

Each domain in an AD DS tree shares a common ________ and global catalog

A

Schema

35
Q

What is transitive trust?

A

The trusts flow through the domain structure.

36
Q

Forests are a group of ________________ __________ trees

A

Interconnected Domain Trees

They are a grouping of organization domains

37
Q

________ _________ connect the roots of each tree together into a common forest.

A

Implicit Trusts

38
Q

What authentication method does not send password information over the network and is the method used in AD?

A

Kerbos

39
Q

What are the 5 operations master (OM) roles?

A
Schema master 
Domain naming master 
PDC emulator
RID master
Infrastructure master
40
Q

What is the Domain naming master?

A
  • adds domains into the AD DS forest
  • must have a record of all domains and objects to perform its function
  • can only be one in a forest
41
Q

What is the PDC emulator?

A

the primary time sync server for the domain

42
Q

what is a RID master?

A

role owner is the single DC responsible for processing RID pool requests from all DCs within a given domain. It is also responsible for moving an object from one domain to another during an interdomain object move

43
Q

What is the Infrastructure Master

A

Manages references to domain objects not within its own domain

44
Q

What are the DC responsibilities?

A

Houses AD database
Provides Kerberos based authentication
Provides Kerberos based ticketing service (authorization)