AD 70-640 Flashcards

1
Q

What is Schema?

A

Defines all attributes for all objects in AD

Is what gives the ability to create object:
Examples: tables, the fields in each table, and the relationships between fields and tables.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What file is the core of Active Directory?

A

NTDS.DIT

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the Advantages of Active Directory?

A

Centralized - makes all activities under one authority

Scale-able - allows you to make a lot of objects

Extensible - allows you to add fields to the schema
Examples:pictures, Social #, ETC

Manageable

Secure- Cuborose Tickets traffic is automatically encrypted

DNS Intergration -

Replication- Create users accounts can get replicated to another server convergence

GPO- items it can use to control every aspect what each user can see and do.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is Convergence?

A

convergence is when active directory agrees with itself in all of its different locations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is a Domain?

A

A group of computers and devices on a network

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is a Forest?

A

A collection of one or more AD domains that share a common logical structure, directory schema, directory configuration, and Global catalog

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How do you open the Initial Configuration Task after you check do not show?

A

OOBE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is DCPROMO?

A

starts the AD DS install wizard

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is dynamically assigned IP address?

A

It automatically assigns an IP address that changes on its own.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is a static IP address?

A

Manually assigned IP address that will only changes when manually changed by a admin.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How do you change your IP address from Dynamic to Static?

A

Network and sharing - Manage network connections - Local area connection - Properties

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is a subnet mask?

A

it determines if the information is on your network or on another. If the information is located on another network the request will be forwarded to the Default gateway.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is a common preferred DNS server address?

A

127.0.0.1 because it is a loop back address.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

How do you preform an unattended installation?

A

dcpromo /unattend:location\myanswerfile.txt

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

How to tell the version of windows you are on?

A

WinVer in the command prompt

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

How to determine the version of the schema?

A

regedit- hkeylocal system- currentcontrolset- services - NTDS - Prameters

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

How to add a Child Domain?

A

Run DCPromo and create new domain in existing forest

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

How to update the schema?

A

put dvd in drive
run cmd
adprep /forest prep
once complete run adprep /domain prep /gpprep

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

How are RODC updated?

A

Updates are replicated to the RODC from a Read Write Domain Controller

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

How does Credential Caching work?

A

RODC verifies credentials instead of forwarding the request.

Admins are denied Caching credentials by default

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What can a admin on a RODC do?

A

Install updates and drivers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

How many RODC and be on one domain?

A

One RODC per domain per site

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What happens if you want a RODC in a site that contains outlook users?

A

You will have to make the RODC a GC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

How do you install a RODC?

A

DCPROMO w/Advance (Full)

For Server Core you have to have a answer file

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

What are the 5 operations maters roles?

A
Forest Operations: 
the schema master
domain naming master
Domain:  
Infrastructure - 
relative identifier (RID) master,
primary domain controller (PDC) emulator
infrastructure master.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

How to access the schema?

A
  1. You have to register the schema, regsvr32 schmmgmt.dll
  2. run mmc console
  3. add/remove snap in
  4. add the schema
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

What is the primary domain controller (PDC) emulator?

A

The final Authority for password changes, responsible for master time source, domain master browser,

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

What is the Domain Naming Master?

A

checks to make sure that the name space is not in use.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

What is Domain Master Browser?

A

find

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

What is the Master Time Source?

A

find

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

What is the Schema Master role?

A

Is what gives the options for active directory. Provided the field (Text Box )

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

What does command dcdiag?

A

tells you about the domain and what roles it haves. Can be used to diagnosed issues.

33
Q

What does command dcdiag /test:ridmanager /v do?

A

it provided information about the RID

34
Q

What is a stand by master?

A

Stand by master is used when a server goes down. you can transfer the servers roles to the stand by master
( A back up server )

35
Q

Why should the Domain Naming Master Role and Global Catalog be installed on the same server?

A

The domain naming master role refers to the GC to see if the name space already exist.

36
Q

What does the Infrastructure Master Role do?

A

Check the cross domain references to verify their group membership . Refers to the GC for verification.

37
Q

Where are the Domain Operation Roles?

A

Server manager - active directory user and computers - right click on domain - operations masters

38
Q

Where do you find the Forrest Operations Roles?

A

Domain Naming Master Role can be found in Open Active Directory Domains and Trust - right click on Directory Domains and Trust - Operations masters roles

Schema master role can be found in console - right click on active directory schema - operations master role

39
Q

How to transfer the Schema Master Role?

A

have to be a schema admin - console - right click on change active directory domain controller - select the new server. - once connected you right click on right click on active directory schema - operations master role - then select the word change

40
Q

How do you see what Domains are running what Operation master roles?

A

in cmd run netdom query fsmo

41
Q

How to rename a domain controller?

A

start - right click on computer - properties - change settings - select the change button

42
Q

How to raise the domain functional level.

A

rick click on the domain inside of server manager - select raise domain functional level ,

43
Q

How do you determine the highest Functional Level For a Forrest?

A

The highest level is based upon the lowest level Domain Controller

44
Q

What is Linked Value Replication?

A

It picks out the new objects inside of the security group and replicates only the new objects instated of replicating all the memberships in that group

45
Q

How to raise the Function Level for Forest?

A

Active Directory Domains and Trust - right click on active directory domains and trust - raise forest functional level

46
Q

How to make a user account?

A

Go to the users folder - right click - select user -

47
Q

What trick should you use for creating Template accounts?

A

create it with a _ in front of the name to make it appear at the top and disable the user account

48
Q

How to change the hours someone can login?

A

click the account - go to account settings tab - select logon hours

49
Q

How to make a new user from a template account?

A

right click on the template account - select copy - fill in the persons information.

50
Q

What is DSADD?

A

is the primary tool you can use to add new accounts

51
Q

What is DSRM?

A

Allows you to remove ou and all of the content in it.

52
Q

What is DSmove?

A

Allows you to move and rename groups

53
Q

What is LDIFDE?

A

Used to improt and export from a plane text file

54
Q

What is CSDE?

A

Used to work with CSV files to automatically import & export accounts.

55
Q

How do you get assistance with powershell cmdlets?

A

get-help (then the task you want to preform) get-service

56
Q

What are variables in PowerShell?

A

Its an abbreviation that reduces the amount of typing and they start with $
These changes are only temporary

example: $wmi=Get-WmiObject Win32_Service - computername dci

will run complete cmdlet in full when you now type $wmi

57
Q

What is PowerShell?

A

is a command line that uses Verb-Noun Syntax (CMDLET) example Get-Service
It is backwards compatible with cmd commands
**

58
Q

What is a Alias in PowerShell?

A

a shortened cmdlet
These changes are only temporary

example: get-ChildItem
Alias: Dir

59
Q

How do you make a Alias in PowerShell?

A

new-alias np (desired abbreviation) notepad (name of task)

60
Q

How do you assign or limit someone to the computers they can access.

A

Right click on the account - account tab - select logon - and you can assign the computer the user can access.

61
Q

How do you make an account profile?

A

account preferences - profile - \servername\profiles\%username%

62
Q

How do you access GPO passwords settings?

A

server manager - features - Group policy management - forest - domain - right click on default domain policy edit -

computer configurations - security settings - account policy

63
Q

How to access the Audit account login settings?

A

server manager - features - Group policy management - forest - domain - right click on default domain policy edit -

computer configurations -windows settings - security settings - local policies

64
Q

How to enable or disable an account?

A

Right click on the account and select disable / enable

65
Q

How to rename an account?

A

Right click on the account and select rename

66
Q

What are the 3 group scope?

A

Domain Local, Global, Universal

67
Q

What kind of memberships can be added to a Domain local group?

A

Can accept any membership ( Global , Universal ) but cant accept other Domain Local groups form another domain’s local group

User account from any domain in forest
 Global or universal from any domain in forest
 User accounts, global or universal groups from a
trusted forest domain
 Other domain local groups from the same domain

Recourse access

68
Q

What kind of memberships can be added to a Global group?

A

User account in same domain
Other global groups from same domain

for users of common type. example Department users

69
Q

What is a Tree?

A

A collection of domains that share a common DNS namespace ( Patent -Technet.vn) ( child (video.technet.vn)

70
Q

What is a Domain?

A

The core administrative unit of AD DS ( Address

)

71
Q

What is a Orgnizational Unit? (OU)

A

Containers in AD DS which provide a framework for administrator and Group Policy Links.

72
Q

What is a Site?

A

A collection of AD objects defined by their physical location

73
Q

What is a Partition?

A

Logical section of actual AD DS Database.

74
Q

What is a Domain Controller?

A

Contain copiesof the ad ds database

75
Q

What is a data store?

A

The file on each domain controller that stores the AD DS information

76
Q

What is Global Catalog servers

A

Domain Controllers which host global catalog which is partial read only copy of all the objects in the forrest

77
Q

Read-Only Domain Controllers ?

A

Contain a special read only copy of the AD DS Database

78
Q

What is Forest and Domain function level?

A

It is configured based on the older OS you will be supporting.