Chapter 1 Flashcards
Which are leaf objects? (Choose all that apply)
Computer account, Domain controller, Shared folder
Leaf objects don’t contain other AD objects. OU (Organizational Unit) is a container object.
Default folder object created when AD is installed?
Computers
Cannot have a GPO linked to it. Domain Controllers is an OU, Groups is an account object, Sites are physical AD components.
Which type of account is NOT in Active Directory?
Local user account
Stored in the SAM database on standalone Windows machines.
Which are directory partitions? (Choose all that apply)
Domain directory, Schema directory, Configuration partition
Group policy is NOT a partition.
Who manages adding, removing, renaming domains in a forest?
Domain Naming Master
What do all domains in a forest share? (Choose all that apply)
Schema, Global catalog
Schema defines object types. Global catalog holds partial lists of objects for searches.
Where is the schema master located?
First domain controller in the forest root domain
A forest-wide FSMO role.
Where can a GPO be linked? (Choose all that apply)
Domains, Sites
Which container has a default GPO linked to it?
Domain
Ensures a security baseline for objects and domain controllers.
When are User Configuration policies applied?
At user logon
Which are true about Organizational Units (OUs)?
OUs can be nested, A GPO can be linked to an OU.
OUs are not security principals and can’t be added to a DACL.
How do you view OU permissions in ADUC?
Enable ‘Advanced Features’ in the View menu.
How to delegate control of an OU?
Right-click the OU in ADUC → ‘Delegate Control’.
What are the user account categories?
Local, Domain.
What are the built-in user accounts?
Administrator, Guest.
What is an invalid user account name?
Sam*Snead35 (asterisks are not allowed).
Which are true for user accounts in a Windows Server domain?
1-20 character names, Unique in the domain.
Which account options can’t be set together?
User must change password at next logon & Password never expires.
Who can be in a global group?
User & Computer accounts (NOT universal or global groups from another domain).
What is the best way to transition Jada’s account for a new hire?
Disable & rename Jada’s account, assign a new password.
How to restrict Tom’s logon locations?
Use the ‘Log On To’ option in his account properties.
How to block after-hours logins?
Set Logon Hours for their accounts.
What is the best group scope for assigning permissions to resources?
Domain local (AGDLP best practice: Accounts → Global Groups → Domain Local Groups → Permissions).
What are security principals?
User accounts, Computer accounts.