book flashcards

1
Q

to what container should you set the base DN to in the search box of ldp.exe tool when performing tombstone reanimation of a user in test.com?

A

CN=Deleted Objects,DC=test,DC=com

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

what should you run from the command line to register SPN ‘http/srv55.nutex.com’ for a win2012R2 server named srv55?

A

> setspn -S http/srv55.nutex.com srv55

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

what service uses port 389?

A

LDAP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

what GUI tool will allow you to enable the Active Directory recycle bin?

A

ADAC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

when do you choose to import an object that has been exported from an Active Directory snapshot instead of retreiving an object form the Active Directory Recycle Bin?

A

when you want to reset the values of an objects attributes to a previous value

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

what parameter of the install-ADDSDomainController cmdlet is used to install and configure DNS on the DC?

A

-installDNS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

which parameter of the Move-ADDirectoryServerOperationMasterRole cmdlet will allow you to seize a master operations role?

A

-force

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

what setspn.exe command will list all SPN’s of services on the web server?

A

> setspn -l

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

what parameter of the install-ADDSDomainController cmdlet is used to prevent the replication of certain passwords to the DC

A

-DenyPasswordReplicationAccountName

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

which type of account in w2008R2 and above is a ‘managed local account’ that provides the ability to access the network with a computer identity in a domain environment with no password management required?

A

virtual account

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

what additional step is required to view deleted objects after setting the base DN to in the search box of ldp.exe tool when performing a tombstone reanimation of a user account?

A

use the ‘return deleted objects’ control to view deleted objects.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

to use kerberos authentication with SQL server, which two conditions are required?

A
  • the client and server computers must be part of the same windows domain, or in trusted domains.
  • ServicePrincipalNames (SPN) must be registered with AD
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

what are the four image types used in WDS?

A
  • boot images
  • install images
  • capture images
  • discover images
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

what are the prerequisites to install a WDS server in an Active Directory network?

A
  • ADDS Server
  • DHCP
  • DNS
  • NTFS Share
  • WDS Server needs GUI
  • WDS can be installed on member server
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

what are the three steps to create a Managed Service Account on Domains required 2008 R2?

A

on server

  1. > New-ADServiceAccount -Name -RestrictToSingleComputer -enabled $True
  2. > Add-ADComputerServiceAccount -Identity -serviceAccount

on target
3. > Install-ADServiceAccount -Identity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are the prerequisites for Active Directory MSA to work on a clint computer?

A
  • Active Directory Powershell Module

- .Net 3.5 Framework

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

what is the time period, in that managed service account renew their passowrds automaticaly?

A

30 Days

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

what tool is the only tool that can be used to create WSUS groups?

A

wsus.exe

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

what are the steps to update an offline image or vhd(x) with dism? with
security updates
hotfixes
drivers

A
  • set image to read-write (attrib -r)
  • mount the image on empty mount point
  • extract contents of update (winrar, etc)
  • inject .cab files into mounted image (add-windowsPackage)
  • commit changes and unmoute
    > Save-WindowsImage
    > Dismount-WindowsImage
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

in configuring WSUS, what does client side targeting mean?

A

to use GPOs to assign computers to WSUS groups

(used in lager organisations)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

DNS

which zone type can NOT be stored in Active Directory?

A

secondary zones

[secutity implications]

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

PS

what cmdlet is used to create a new conditional forwarder fot test.com

A

> Add-DnsServerConditionalZone -Name -masterServers -forwardertimeout -replicationscope

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

PS,DNS

which cmdlet is used to create an new stub zone ?

A

> Add-DnsServerStubZone -name -masterServers -replicationScope

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

PS,DNS

wich cmdlet is used to create a new secondary zone?

A

> Add-DnsServerSecondaryZone -name -zonefile -masterServers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

DNS

can secondary DNSserver be a master server in DNS?

A

yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

PS,DNS

which cmdlet can be used to create a primary zone?

A

> Add-DnsServerPrimaryZone -name -replicationscope -dynamicupdate ‘secure’
(Active Directory integrated)
or
Add-DnsServerPrimaryZone -name -zonefile -dynamicupdate ‘none’
(file based)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

DNS

why can the two parameters -ReplicationScope and -ZoneFile not be used at the same time when creating a new DNS zone

A

one fits file based zones the other Active Directory integrated zones

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

DNS
is it possible to change the zone* type from file-based to Active Directory integrated or vice versa with powershell?

*or conditional forwarder

A

no

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

DNS

what tool do you use to change the type of zone from Active Directory integrated to file-based or voce versa?

A

use DNS management console

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

DNS

what are the four possible settings for zone transfers in DNS management?

A
  • noTransfer
  • TransferAnyServer
  • TrasnsferToZoneNameServer
  • TransferToSecureServers
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

DNS

what are the three possible notification settings for DNS zone changes?

A
  • NoNotify
  • Notify
  • NotifyServers
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

DNS

what is the possible alternative in Active Directory integrated DNS to file-based secondars servers?

A

stub-zones and conditional forwarders

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

DNS

what are conditional forwarders used for?

A

conditional forwarders provide a means to manage to which DNS server a DNS query is forwarded for specific zones.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

DNS

what is zone delegation used for?

A

use DNS zone delegation to delegate the administration of a portion of your DNS namespace.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

DNS

what is the default zone transfer setting?

A

zone transfers are disallowed unless explicitly allowed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

DNS

which DNS resource record type can NOT be created with PowerShell?

A

SOA* - Start Of Authority record.

* is a version number record identifying the number of the DNSZone

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

DNS

if DNS has two MX entries for a domain with different priority settings, which server ist receiving the SMTP traffic?

A

lowest value

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

what tool is used to perform a tombstone reanimation?

A

> ldp.exe

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

what tools can you use to view the contents of a mounted Active Directory snapshot?

A
  • ADUC (DSA.msc)
  • ADSIEDIT.msc
  • LDP.exe
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
40
Q

which cmdlet do you use to copy images between groups in WDS ?

A

> export-WDSInstallImage

> import-WDSInstallImage

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
41
Q

which cmdlet do you use to copy images inside a WDS group?

A

> copy-WDSInstallImage

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
42
Q

how do you enable client-side targeting in WSUS?

A

by selecting computers in the options section of the server update services and selecting “use group policy or registry settings on computers”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
43
Q

what is the minimum size of the local updates volume for WSUS?

A

6GB

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
44
Q

what form of credential does the -credential option expect?

A

a psCredential object. not a string “domain\user”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
45
Q

what cmdlet do you use to open an elevated PowerShell ?

A

> Start-Process Powershell.exe -verb RunAs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
46
Q

to install WDS via PowerShell including tools type..

A

> Install-windowsFeature -name WDS -cn -includemanagementtools

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
47
Q

before capturing an image from a template installation, what do you need to do?

A

> %windir”\system32\sysprep sysprep /oobe /generalize /reboot

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
48
Q

can you remove a driver-package from an image in WDS?

A

no

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
49
Q

can you use powershell to create or manage the properties of driver-groups in WDS?

A

no

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
50
Q

what are the steps to install or remove features in offline images?

A
  • set the image to read-write with : attrib -r
  • mount image on empty mountpoint
  • modify image > enable-windowsoptionalfeature
    > disable-windowsoptionalfeature
    -commit changes and unmount
    > save-windowsImage
    > dismount-windowsImage
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
51
Q

DA

what cmdlet do you use to install the direct access role on a server

A

> Install-WindowsFeature -name RemoteAccess -IncludeAllSubfeatures -IncludeManagementTools

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
52
Q

WDS

what can you do to maintain functionality in established boot images to support hardware compatibility?

A

inject vendor specific drivers into boot images.
cmdlets:
> Import-WDSDriverPackage
> Add-WDSDriverPackage

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
53
Q

WDS

what is the prerequisite to install the WDS role on a 2012 R2 server?

A

WDS is only supported on a full GUI installation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
54
Q

WDS

wich cmdlet is used to install the WDS role ?

A

> Install-WindowsFeature -name WDS -includeManagementTools

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
55
Q

WDS

what is the initial configuration after installing the WDS role on a server?

A

set the location of the WDS image store.

NTFS, not on C:!

56
Q

WDS

what are capture images used for?

A

capture images are custom install images from a template computer.

57
Q

WDS

what are discover images?

A

discover images are use to deploy by using physical media rather than PXE boot.

58
Q

WDS

what are the two cmdlets to update images?

A

after mounting the offline image read-write on the local file system
> Add-WindowPackage
or
> Enable-WindowsOptionalFeature

don’t forget to commit changes and unmont the image.

59
Q

WDS

what is the only tool to create WDS driver groups?

A

WDS console

60
Q

WDS

what are two basic network requirements for WDS?

A
  • active DHCP server

- working and reachable DNS server

61
Q

WDS

what cmdlet is used to update an offline boot image file with a new driver?

A

> Add-WDSDriverPackage

62
Q

RA VPN

which ports are used for the PPTP VPN Protocol?

A

TCP 1723

GRE 47

63
Q

RA VPN

which ports are used for the L2TP VPN Protocol?

A

UDP 500
UDP 4500
UDP 1701
ESP 50

64
Q

RA VPN

which ports are used for the SSTP VPN Protocol?

A

TCP 443

65
Q

RA VPN

which ports are used for the IKEv2 VPN Protocol?

A

UDP 500
UDP 4500
UDP 1701
ESP 50

66
Q

IPv6

what is a global IPv6 prefix?

A

2000::/3

67
Q

IPv6

what is a link local IPv6 prefix?

A

FE80::/10

68
Q

IPv6

what is a multicast IPv6 prefix?

A

FF00::/8

69
Q

IPv6

what is a unique local IPv6 prefix

A

FC00::/7

70
Q

IPv6

what is the loopback IPv6 address?

A

::1

71
Q

what can be configured with the routing and remote access console?

A

routing
NAT
dial-up remote access
vpn remote access

72
Q
VPN
which module in PS provides cmdlets for VPN server support?
A

RemoteAccess module

73
Q

VPN

which are the four parts that construct the remote acces role?

A

routing
VPN
directAccess
web application proxy

74
Q

you need to configure VPN to only support clients using the SSTP protocol. What changes do you need to make to the default VPN config in w2012R2?

A

Clear remote access connections for the WAN Miniport (PPTP), WAN miniport (IKEv2), and WAN miniport (L2TP).

75
Q

you use DirectAccess for all Windows8 and later remote clients, but you use VPN to support windows 7 clients. you need to configure VPN to use IP addresses controlled by the remote access server. what settings do you need to make? (2)

A
  • in the DHCP management console, create a DHCP exclusion for the IP addresses assigned to VPN clients.
  • in the remote access management console, select assign addresses from a static address pool
76
Q

name three benifits of Direct Access compared with VPNs.

A
  • always-on (no need to initiate connection)
  • seamless (transparently connected if online)
  • security (managed connection + IPsec)
77
Q

which VPN protocols are supported in w2012 R2?

A

PPTP
L2TP
IKEv2
SSTP

78
Q

what command do you use to !only! install VPN and NAT and their management tools?

A

> Add-WindowsFeature DirectAccess-VPN,Routing -inludeManagementTools

79
Q

you need to configure VPN to only support clients using the SSTP protocol. What changes do you need to make to the default VPN config in w2012R2?

A

Clear remote access connections for the WAN Miniport (PPTP), WAN miniport (IKEv2), and WAN miniport (L2TP).

80
Q

you use DirectAccess for all Windows8 and later remote clients, but you use VPN to support windows 7 clients. you need to configure VPN to use IP addresses controlled by the remote access server. what settings do you need to make? (2)

A
  • in the DHCP management console, create a DHCP exclusion for the IP addresses assigned to VPN clients.
  • in the remote access management console, select assign addresses from a static address pool
81
Q

name three benifits of Direct Access compared with VPNs.

A
  • always-on (no need to initiate connection)
  • seamless (transparently connected if online)
  • security (managed connection + IPsec)
82
Q

what is the default setting in the remote access quick start wizard to allow connectoins via DirectAccess?

A

mobile computers only

83
Q

radius

whitch settings can be configured in seperate templates each?

A
  • shared secret
  • radius clients
  • remote radius servers
  • IP filters
  • health policies
  • remediation server groups
84
Q

what are the four possible settings for RADUS logging

A

SQL logging only
Test logging only
Parallel logging
SQL logging with backup

85
Q

what are the possible settings that can be simplified by RADIUS templates

A
shared secrets
RADIUS clients
remote RADIUS servers
IP filters
health policies
remediation server groups
86
Q

with multiple RADIUS server infrastructure, you have three servers all with parity 1. server1 has weight 10, server2 has weight 15 and server3 has weight 25.
how are the next 100 messages processed.

A
server1  = 20
server2 = 30
server3 = 50
87
Q

in NPS which server is higher priorized.

server1 with priority 1 or server2 with priority 50?

A

the lower the number the higher the priority.

server1

88
Q

in NPS what ports are used for authentication and accounting?

A
1812 = authentication
1813 = accounting
89
Q

in NPS (RADIUS) if you have two servers. server1 with priority 1 and server2 with priority 2. how many messages does server2 recieve if 100 messages are sent by clients?

A

zero.

server2 is only accessed if server1 is unavailable.

90
Q

NPS / RADIUS certificates
in which policy do you set up the configuration for auto enrollment for clients and servers for certificate-based authentication?
what path ist used for the policy setting?

A

default domain policy

comp/policies/windows settings/security settings/public key policies

91
Q

NPS / RADIUS certificates

which purpose of a certificate does not work with client and server authentication?

A

the purpose “All” does not work wiht authentication.

92
Q

NPS templates

what does the abreviation SHV stand for?

A

system health validator

93
Q

NPS templates

what are the options for client SHV checks (7)?

A

client passes all SHV checks
client fails all SHV checks
client passes one or more SHV checks
client fails one or more SHV checks
client reported as transitionsl by one or more SHVs
client reported as infected by one or more SHVs
client reported as unknown by one or more SHVs

94
Q

what two options can be configured on an NPS?

A

RADIUS server

RADIUS proxy

95
Q

for whitch scenarios can RADIUS be used for?

A

VPN authentication and authorization

Dial-in authentication and authorization

96
Q

what does RADIUS client mean?

A

network access servers

other RADIUS servers

97
Q

when installing NPS as RADIUS proxy which NPS role services are required in win2012R2?

A

NPS

98
Q

what does it mean when a NPS is configured as a RADIUS proxy?

A

the server acts as a RADIUS client, forwarding connection requests to a RADIUS server group for authentication and authorization.

99
Q

certificates with which purposes can be used for mutual authentication of NPS and client computers?

A

server authentication certs

client authentication cerst

100
Q

which three kinds of policies are supported by NPS?

A

connection request policies
network policies
health plicies

101
Q

NPS

in older versions of windows server NPS policies were im- and exported. what technologies are used instead in win2012R2?

A

import and export templates

import and export NPS entire configuration

102
Q

NPS

which two policies control which clients are allowed to connect to the network?

A

client request policy and network policy

103
Q

NPS

what is the purpose of the connection request policy?

A

it handles the initial request by a client to connect and passes it to an appropriate network policy
connection request policies define which connections are processed on the NPS server and which are processed on remote RADIUS servers.

104
Q

NPS

what does a network policy do?

A

it determines how a client is authenticated and whether is authorized to connect.

105
Q

NPS

how can you manage nps templates?

A

export the templates to xml files.

import templates from a server or from a file.

106
Q

NPS configuration

what is the most important concern when exporting NPS configuration to a file.

A

the exported file includes policies, templates,clients, RADIUS server information and shared secrets. this is sensitive information that should be handled with security concerns in mind.
if accounting is set up to sql db - this info is not included in the exported file and has to be added manually after import.

107
Q

NPS export

what is the cmdlet to export the NPS configuration?

A

> export-NPSConfiguration -path “… path\filename.xml”

108
Q

NPS export

can you use netsh to export the NPS configuration?

A

yes.

> netsh nps export filename=path\filename.xml exportpsk=yes

109
Q

NPS

what does the term 2FA mean?

A

two-factor authentication

110
Q

NPS export

how can you mitigate security implications when exporting a NPS configuration file.

A

store the file in an encrypted location, or an encrypted usb device.

111
Q

NPS

what is it that controls whether a NPS acts as a RADIUS server or a RADIUS proxy?

A

the connection request policy

112
Q

NPS

which condition sets the allowed protocols for a RADIUS connection?

A

the tunnel type condition

113
Q

NPS

can you set a condition for connection request policies for user names?

A

yes

114
Q

NPS

can you set a condition for connection request policies for user groups?

A

no

115
Q

NPS

can you set a condition for connection request policies for NAS port types?

A

yes

116
Q

NPS

can you set a condition for connection request policies for MS service classes?

A

no

117
Q

NAP DHCP

why is NAP enforcement using DHCP not a secure enforcement method?

A

a knowlegable user can assign a fixed IP address and bypass the restciction.

118
Q

NAP DHCP

what are the prerequsites for using NAP enforcement using DHCP?

A

either the NPS is the DHCP server

or the DHCP server has a NPS role installed as RADIUS proxy

119
Q

NAP

what are the four possible options for a NAP enforcement policy?

A
  • non-enforcement (monitoring)
  • limited enforcement (limited acces)
  • full enforcement (blocking)
  • full enforcement with remediation (acces to remediation servers)
120
Q

NAP

in network policy for remediation for noncompiant clients, should the clients be granted access or not?

A

yes - to enable access to remediation servers

121
Q

NAP

to implement NAP on your network, what steps do you need to take?

A

enable NAP on RADIUS servers
implement health policy that requires client computers to have firewall turned on, have all current updates, be free of infection.
implement remediation servers

122
Q

how often do you have to create a KDSRootkey if you want to use gMSAs?

A

once for each domain

123
Q

how long does it take to create a KDS-rootkey with the cmdlet
add-KDSRootKey -effectiveImmediately?

A

10 hours

124
Q

what is the prerequisite to use gMSAs?

A

the cration of the KDS-rootkey

125
Q

what are the steps to remove a MSA from a computer

A

> uninstall-ADServiceAccount on local comp
remove-ADComputerServiceAccount to unassign the account f comp
if you do not want to reuse account:
remove-ADServiceAccount

126
Q

what are the prerequsites on a client computer to use MSAs?

A

win 7 , Active Directory ps module, dotnet framewrk 3.5 or later

127
Q

what are the cmdlets to create a managed service account?

A

on server:
> new-ADServiceAccount -name -restrictToSingleComputer -enabled $true
> add-ADComputerServiceAccount -idntity -serviceAccount
on local computer:
> install-ADServiceAccount -identity

128
Q

when were MSAs introduced?

A

win srv 2008 R2

129
Q

when were gMSAs introduced?

A

win srv 2012 R2

130
Q

what tool or command do you use to create a MSA?

A

> New-ADServiceAccount

with the -standalone paramater

131
Q

what command should you use to add a gMSA on a computer?

A

> Install-ADComputerServiceAccount

132
Q

you want to use a virtual account for the testService on computer server1. what commands or tools would you use?

A

> services.msc

133
Q

what are the FSMO operations master roles and which are forest or domain wide roles?

A
once per forest:
schema master 
domain naming master 
once per domain:
RID master 
PDC emulador
infrastructure master
134
Q

who has rights to seize or transfer the schema master role?

A

schema administrators group

135
Q

who has the rights to tansfer or seize the domain naming master?

A

the enterprise administrators group

136
Q

who has the rights to seize or transfer the RID master, PDC emulator, or infrastructure master role?

A

domain administrators group