Chapter 1 Flashcards

1
Q

Which are leaf objects? (Choose all that apply)

A

Computer account, Domain controller, Shared folder

Leaf objects don’t contain other AD objects. OU (Organizational Unit) is a container object.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Default folder object created when AD is installed?

A

Computers

Cannot have a GPO linked to it. Domain Controllers is an OU, Groups is an account object, Sites are physical AD components.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which type of account is NOT in Active Directory?

A

Local user account

Stored in the SAM database on standalone Windows machines.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which are directory partitions? (Choose all that apply)

A

Domain directory, Schema directory, Configuration partition

Group policy is NOT a partition.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Who manages adding, removing, renaming domains in a forest?

A

Domain Naming Master

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What do all domains in a forest share? (Choose all that apply)

A

Schema, Global catalog

Schema defines object types. Global catalog holds partial lists of objects for searches.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Where is the schema master located?

A

First domain controller in the forest root domain

A forest-wide FSMO role.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Where can a GPO be linked? (Choose all that apply)

A

Domains, Sites

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which container has a default GPO linked to it?

A

Domain

Ensures a security baseline for objects and domain controllers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

When are User Configuration policies applied?

A

At user logon

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Which are true about Organizational Units (OUs)?

A

OUs can be nested, A GPO can be linked to an OU.

OUs are not security principals and can’t be added to a DACL.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

How do you view OU permissions in ADUC?

A

Enable ‘Advanced Features’ in the View menu.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

How to delegate control of an OU?

A

Right-click the OU in ADUC → ‘Delegate Control’.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are the user account categories?

A

Local, Domain.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are the built-in user accounts?

A

Administrator, Guest.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is an invalid user account name?

A

Sam*Snead35 (asterisks are not allowed).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Which are true for user accounts in a Windows Server domain?

A

1-20 character names, Unique in the domain.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Which account options can’t be set together?

A

User must change password at next logon & Password never expires.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Who can be in a global group?

A

User & Computer accounts (NOT universal or global groups from another domain).

20
Q

What is the best way to transition Jada’s account for a new hire?

A

Disable & rename Jada’s account, assign a new password.

21
Q

How to restrict Tom’s logon locations?

A

Use the ‘Log On To’ option in his account properties.

22
Q

How to block after-hours logins?

A

Set Logon Hours for their accounts.

23
Q

What is the best group scope for assigning permissions to resources?

A

Domain local (AGDLP best practice: Accounts → Global Groups → Domain Local Groups → Permissions).

24
Q

What are security principals?

A

User accounts, Computer accounts.

25
What are valid group scopes?
Global, Domain local.
26
What happens if a security group is converted to a distribution group?
It remains in the DACL but has no effect on permissions.
27
Who can be in a universal group?
Global groups (any domain), Other universal groups.
28
What is an allowed direct group scope conversion?
Domain local → Universal (if no domain local groups are members).
29
What does a domain local group include?
Domain Users (default membership in AD).
30
A domain user signing in belongs to which special identity group?
Authenticated Users (auto-assigned when logged in).
31
What to do if a computer can’t sign in after months of inactivity?
Reset computer account, remove from domain, rejoin domain.
32
What is a service account managed across multiple servers?
Group Managed Service Account (gMSA).
33
What are the built-in service accounts?
Local System, Network Service.
34
What are the benefits of managed service accounts?
System-managed passwords, No lockouts.
35
What uniquely identifies a service instance to a client?
Service Principal Name (SPN).
36
Before configuring a service to use an MSA, what must be done?
Run Install-ADServiceAccount on the target server.
37
How to configure multiple servers to use the same service account?
Create a group, add servers to it, run New-ADServiceAccount.
38
What is the simplest way to authenticate a local service without creating an account?
Use NT Service\ServiceName virtual account.
39
What provides Azure AD integration with on-prem AD for seamless sign-in?
Azure AD, Cloud Sync, SSO.
40
What allows users to sign in once and access multiple services?
Single Sign-On (SSO).
41
What is a characteristic of Azure AD?
Multitenant.
42
What to do if users can’t sign in to on-prem AD after changing their cloud password?
Configure password writeback.
43
What Azure AD sign-in option requires an on-prem agent?
Pass-through authentication.
44
Which Azure AD DS forest type syncs all objects and on-prem user accounts?
User forest.
45
What provides a secure web-based connection to an Azure VM?
Bastion host.