(Anna Notes) SP TS667 CH 1-4:---------------------- [C1: Creating a SharePoint 2010 Intranet / C2: Administering and Automating SharePoint / C3: Managing Web Applications / CH4 : Administering and securing SharePoint Content ] Flashcards

Chapter 1: Creating a SharePoint 2010 Intranet Chapter 2: Administering and Automating SharePoint Chapter 3: Managing Web Applications Chapter 4: Administering and Securing SharePoint Content

1
Q

Hardware requirements for the web server and application server

A

64 bit, four core processor and an 80 GB hard drive
( free space should ideally be double amount of RAM used )</p>

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Small Farm deployment of servers needs what hardware requirements ?

A

64 but, four core processor and 8 GB of RAM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Hardware & Software Requirements

A

Hard Disk: 80 GB min.
Processor: 64 bit, four core processor
Memory: Production: 8 GB min per server
Development 4 GB per lab

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Medium-Farm deployment of servers needs what hardware requirements ?

A

64 bit, eight core processor and 16GB RAM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Command to run errors in pre-upgrade checker

A

STSADM.EXE -o preupgradechecker

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Large Farm deployment of servers needs what hardware requirements ?
@ 2 Terabytes

Beyond 2 within 5 terabytes?

A

32 GB RAM

64GB RAM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Microsoft Operating System requirements

A

4 GB Ram min
-Windows Vista with SP1 or later (64 bit)
-Windows 7 (64 bit): Should not be used for production

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

PowerShell CMD to attach database

A

<p>Mount-SPContentDatabase -Name</p>

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

PowerShell CMD verify additions to new DB setup / Test DB

A

Test-SPContentDatabase

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

service application group

A

The service application group is a collection of service applications in a farm. Other names for service
application group are proxy group or application proxy group. Every web application is assigned a serviceapplication group.
You can use the default service application group for this purpose. You can also customize the service
application group to choose service applications for a web application. However, you can’t use the same
service applications for service application groups of other web applications.

The service application group interacts with two service application components. First, it is accessed bythe web application through the service application connection. Second, it contains service applications
that interact with service application databases. These service applications create a service instance onthe application server. So the service application group also needs to interact with application servers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

service application connection

A

The service application connection component connects the web application with the service applicationgroup. Also known as a proxy or an application proxy, this connection is usually created with service
applications.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

harePoint 2010 is Supported on which Servers?

A

-SQL Server 2005 SP3 w/ Cumulative Update 3 (64 - bit)
-SQL Server 2008 SP1 w/ Cumulative Update 2 or, Update 5 and later (64 bit)
-SQL Server 2008 R2 (64 bit only)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are the two Methods to Disable Loopback?

A

Method 1: Specify all Sites hosted on the Server [hostfile]
Method 2 (Not recommended on production/live): reduces security, disable look back altogether programmatically.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What can be used for SharePoint Prerequisites

A

PrerequisiteInstaller.exe

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

User Accounts for SharePoint Administration and Services?

A

Top Three:
-SQL Server Service Account (SPSQL, SQL_Service)
-SharePoint Admin & Setup User (SP_Admin)
-SharePoint Farm Service Account / Database Account Access (SP_Farm)
Additional:
-SQL Server Administrator Account (SQL_Admin)
-Web & Service Application Pool (SPWebApps & SP Service Apps)
-Search Indexer (SPCrawl)
-User Profile Sunchronization (SPUserSync)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Preparation steps for Installation & Configuration (Summary)

A

-Install the prerequisites
-Install the SharePoint Binaries
-Configure the SharePoint Server
-Configure Services and Applications on the farm

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Install SharePoint Binaries Summary

A

-Log on as the Setup User Account
-Install SharePoint Server

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What is the Business Connectivity Service?

A

Enables SharePoint to connect to external data sources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

OOB Service Applications

A

-Search Service Application
-Business Connectivity Service
-Managed Metadata Service
-User Profile Service

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What is the Managed Metadata Service?

A

Provides taxonomy and managed content types

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Explain Proxy and Proxy Groups:

A

Proxy: service application connection, creates the connection point for the web applications
Proxy Groups: app connection groups, a virtual entity that creates the connection point for the web app.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What are Managed Accounts and their benefits?

A

Are service account that can be made in central Admin and updates to the accounts will be made to AD and Computers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Web Requests for HTTP and HTTPS use which ports?

A

HTTP: 80 / HTTPS: 443

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

Configure Outgoing Email Settings:

A

Central Admin > System Settings > E-mail & Text(SMS)
-Ensure SMTP Server is up

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

What are the steps when a "Request a Page from a SharePoint Site?

A

1) user enters URI or URL = The request
-Protocol: the Uri includes a specified protocol as DNS (Domain Name System)
2)Browser sends request to Server Hosting the website
DNS name must be resolved to IP Address
3)DNS Server resolves the query and returns the IP Address
4)Client sends request to Web Server
Request sent to specific port on server
5) IIS receives the request based on site
Bindings: a site can be bound specific to an IP or port
6) If SharePoint Site retrieves content from content DB on SQL Server
7)Security an be placed at each point.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

What is also created when a new Web Application is added?

A

Content DB and IIS Site

In Addition:
SharePoint also creates the physical path \ web.config file, IIS Web Site, Several Vitual Directories

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

There is one IIS Site per web application but how many associations can an IIS Site have?

A

Five

28
Q

How many application pools can be supported per web server?

A

10 App Pools (depends on RAM allocated to front-end web servers)

29
Q

List SharePoint Administrative Roles:

A

-Farm Admins
-Windows Admins
-Service Application Admins
-Service Application Feature Admins
-Site Collection Owners
-Site Collection Admin
-Site Groups

30
Q

You must change a Port. You cannot change the port from..? Where can you change ports?

A

Central admin not supported
STSADM & Powershell can be used to change ports

31
Q

How to create an Intranet with PowerShell

A

New-SPWebApplication -Name -Port -HostHeader - URL -ApplicationPool -ApplicationPoolAccount -DatabaseName

32
Q

An IIS Site had Bindings, what does this include?

A

Unique IP Address, Host-Header or Port Binding

33
Q

What is the Root directory and where is it located?
(When creating a web app you must specify the physical path)

A

C:\intepub\wwwroot\wss\vitural Directories\sometimes_80</br>
(When binding an IIS to on IP Address repeat process on each server)

34
Q

App pools have an identity, which is a?

A
  • a domain user account
35
Q

Classic Mode Authentication?

A

Windows: NTLM or Negotiate (Kerberos), [relies on Active Directory]
Anonymous, Basic, Digest

36
Q

Claims Based Authentication?

A

Windows: NTLM or Negotiate (Kerberos), [relies on Active Directory]
Anonymous, Basic, Digest

FBA: LDAP, SWL DBS, other DB, Custom

SAML: ADFS 2.0, Windows Live ID, Third Party

37
Q

What are the steps to configure SSL (Summary)

A

Secure Sockets Layer

-Configure the SharePoint Web Application to use SSL
-Create a Certificate
-Bind the Cert to the IIS Website of the SharePoint Web App.

38
Q

If modifying an existing HTTP you must?

A

Modify the AAMs & Zones

39
Q

After SharePoint is configured for SSL, what else must be competed?

A

Manage Certs and bindings on each web application on server in farm

40
Q

Recycle Bin has two stages, what are they?

A

1st: End User, OOB 30 days then deleted cannot restore</br>
2nd: Site Collection Admin, then deleted permanently

41
Q

General Settings that can be set from General Settings Ribbon > Central Admin:

A

-Default Time Zone
-Default Quota Template
-Person Name Actions & Presence Settings
-Alerts
-RSS Settings
-Blog API Settings
-Browser File Handling
-Web Page Security Validation
-Send User Name and Password
-Maximum File Upload Size

42
Q

What is the Maximum file upload size?

A

2 GB also SQL record limit

43
Q

General Settings > Workflow Settings, what settings can be set?

A

-Enable User-Defined Workflows
-Alert Internal users Who Do Not have Access
-Allow External Users to Participate in Workflows

44
Q

General Settings > Outgoing Email Settings, what settings can be set? details

A

-Must Define SMTP Relay Server, From Address & Reply Address
-SMPT Must be accessible over TCP port 25(SharePoint does not support SMTP Authentication)

45
Q

General Settings > Text Message Service Settings , what settings can be set? details

A

-Must subscribe to a third-party SMS service provider
-SharePoint does not support SMS Throttling.

46
Q

General Settings > Self-Service Site Creation, what settings can be set?

A

allows user creation of site collections if enabled.

47
Q

Additional Web App Setting from Ribbon? what settings can be set?

A

-SharePoint designer Governance
-Manage Features
-Web Port Security
-User Permissions
-User Policy
-Permission Policy
-Resource Throttling
-Manged Paths
-Service Connections
-Authentication Providers
-Anonymous Policy

48
Q

At what points can you configure Anonymous Access?

A

-Anonymous authentication for the web application
-Anonymous access restriction policies for the web app zones
-Permissions assigned to anonymous users for sites, lists & libraries

49
Q

Anonymous authentication for the web application configured where?

A

Central Admin > Application Management > Select Web App to enable/disable

50
Q

Who can enforce permissions across entire web-application for Anonymous Access Restrictions?

A

Farm Admin

51
Q

Where in Central Admin could you Edit Authentication?

A

Web Application or Authentication Providers

52
Q

Windows Authentication Methods:

A

-NT LAN Manger (NTLM) or Negotiate (Kerberos or NTLM)
-Basic
-Anonymous
-Digest
-Client Certificates

53
Q

NLTM authenticates in what method?

A

When a user logs onto their computer ask for username & password

54
Q

Kerberos method?

A

default windows client & servers in Active directory domain
-process that involves encrypted tickets
the domain controllers key distribution center (KDC)
issues a ticket gaining ticket (TGT)

55
Q

Why is Kerberos preferred to NTLM?

A

entire process encrypted (the client, the service, and the domain)
*does not have to do round trip like NTML
can also be proxied between tiers

Preferable:
-More secure / mutual authentication
-more scalable: supports authentication across trusted realms
-supports delegation: allows service to impersonate a user
-Reduced load on domain controllers.

56
Q

If Kerberos is not supported it fails back to NTLM, what causes this to fail?

A

The negotiate security headers lets clients switch between, Kerberos is selected unless one of the following is true:
-One of the systems that is involved in the authentication cannot use Kerberos authentication
-The calling application does not provide enough information to use Kerberos authentication

57
Q

Keberos Authentication Configuration:
SPNs(Service Principal Names) for SharePoint Services, Web Apps, and SQL Server. What is a SPN (provides what to the web app)?

A

-Serive Class: always HTTP, include both protocols
-Host Name
-Port: (80, if not) of the web application

58
Q

Keberos Authentication Configuration:
For each Web Application you must assign two SPNs, how is this done?

A

-one with the fully qualified domain name for the device
-one with the NetBIDS name of the service.

59
Q

Keberos Authentication Configuration:
How to configure Service Principal names for SQL server service account:

A

AD: An SPN must be added to the user account of the application pool identity

60
Q

One Difference between Classic Mode & Claims Based (token)?

A

Classic Mode relies on IIS to pass your windows security token
Claims Based, web app relies on farm’s security token service (STS)

61
Q

What is Trust?
Claims?

Claims Authentication is built on?

A

all web apps and services in the farm trust the security token service of the farm.

Claims? Contains assertions about the users identity.

Built on Windows Identity Foundation (WIF)

62
Q

Forms Based Authentication (FBA)?

A

based on ASP.NET membership & role provider authentication

63
Q

What are the steps to configure FBA (Forms Based Authentication)?

A

-The web app authentication mode
-The config file of the security token service(STS) application
the forms based authentication claims based authentication
-The web.config file of the web app’s IIS site
-The web.config file of the Central Administration IIS Site
-Access to the db against which users are authenticated

64
Q

SAML Token Authentication?

A

allows SharePoint Web Apps to accept claims of identity that are STS authenticated by other than SharePoints STS

65
Q

AAM (Alternate Access Mappings) can include how many zones?

What are the zones?

A

Can include Five zones
-Intranet
-Internet
-Extranet
-Custom
-Default

66
Q

What are the four things you must never do when creating AAMs?

A

-Do not add an Interal URL association with a zone that does not exist (Instead extend the web app)
-Do not add a Pulic URL to a zone that does not exist(Instead extend the web app)
-Do not delete the last internal URL associated to zone
-Do not remove the public URL associated with zone(Instead extend the web app)

67
Q

What can a Reverse Proxy Provide?

A

-can filter based on characteristics, then forward eligible requests to web server
-can change host name or port of the URL requested by user.
-can receive request using one port or protocol / can perform OFF-Box SSL Termination
-can forward from a different port as which is requested
can change HTTP host header field, thereby masking internal name of server or app