Chapter 1: Active Directory Fundamentals Flashcards

1
Q

What are 5 main concerns of implementing a hybrid identity infrastructure?

A
  1. Maintaining 1:1 identity between platforms (Federation)
  2. Enabling SSO
  3. How are identities protected externally (cloud, etc.)
  4. How is compliance maintained
  5. How are potential breaches detected/handled
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Define a “digital identity”

A

A user’s username, or devices, applications, services, groups,
and organizations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the modern approach to solving the issue of identities living outside of the corporate network (remote work, cloud, etc.)?

A

Zero trust

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the 3 main principles of “Zero Trust”?

A
  1. Verify explicitly
  2. Least privilege
  3. Assume breach
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What must be done to ensure the concept of “assume breach” is always constant in zero trust?

A

Collect logs, analyze logs, detect anomalies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Define the concept of “verify explicitly” in zero trust

A

Continuously monitor and verify user and device access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Where does AD store digital identities?

A

In a multi-master database file called ntds.dit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the two types of replication in Microsoft Active Directory?

A

Outbound replication and inbound replication

Outbound replication occurs when a domain controller advertises changes to neighboring domain controllers, while inbound replication occurs when a domain controller accepts changes from neighboring domain controllers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is outbound replication?

A

When a domain controller advertises changes made on itself to neighboring domain controllers

This type of replication ensures that changes are communicated to other domain controllers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is inbound replication?

A

When a domain controller accepts changes advertised by neighboring domain controllers

This allows a domain controller to update its data based on the changes made by others.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How does AD provide high availability by default?

A

A multi-master database and the replication of domain
controllers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the structure of any kind of database called?

A

Schema

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What type of database structure is applicable to an Active Directory database?

A

Schema

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are the two main types of information contained in the Active Directory schema?

A
  • A definition of every object class in Active Directory
  • A definition of every attribute in an Active Directory object
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the primary consideration when designing an Active Directory setup?

A

Matching it with the company hierarchical layout

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Why is it important to align Active Directory with company hierarchy?

A

To effectively manage resources and security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What are the two types of objects in the Active Directory logical structure?

A

Container objects and leaf objects

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What are container objects in the Active Directory logical structure?

A

Objects that can be associated with other objects in the logical structure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What are leaf objects in the Active Directory logical structure?

A

The smallest components that will not have any other child objects associated with them

20
Q

What are the 4 logical components of AD?

A
  1. Forests
  2. Domains
  3. Domain trees
  4. OUs
21
Q

Define an AD Forest

A

It represents a complete Active Directory instance made of one or more domains and domain trees.

22
Q

Describe the connection between two domains in a forest

A

Two-way trust relationship

23
Q

What is the significance of the first domain controller in Active Directory?

A

It is important for creating the first domain and forest.

24
What is created when you establish the first domain in Active Directory?
The forest is created.
25
What does the first domain become in the Active Directory structure?
The forest root domain.
26
What does a domain tree contain?
Its own root domain.
27
Can forests contain multiple root domains?
Yes, forests can contain multiple root domains.
28
What is two-way transitive trust (trust relationship)?
A logical link between domains where the trusting domain honors the logon authentication of the trusted domain.
29
How do domains in the same forest interact with a two way trust?
Inherently trusts other objects in other domains in the same forest.
30
Is two-way transitive trust within a forest the same as authentication between forests?
No, it is not the same.
31
31
What is the logical security boundary for objects in AD?
The domain
32
What is Active Directory divided into to improve efficiency?
Multiple partitions ## Footnote This structure helps manage data and replication more effectively.
33
What is a partition of Active Directory that contains domain information?
Domain ## Footnote The domain partition stores data about objects specific to that domain.
34
What do domain controllers have a copy of?
Domain partition ## Footnote Each domain controller within the same domain tree shares this copy.
35
Who shares the domain partition?
Domain controllers within the same domain tree ## Footnote This ensures consistency and availability of domain data.
36
What type of data is saved in the domain partition?
Information about objects in that particular domain ## Footnote This includes user accounts, groups, and other directory objects.
37
What does the partitioning of Active Directory ensure regarding data replication?
Only the required data is replicated across the domain trees and forests ## Footnote This optimizes network resources and improves performance.
38
What do the Active Directory domain's functional levels define?
The Active Directory capabilities ## Footnote This includes features and functionalities available within the domain.
39
What happens with each new version of the directory services?
New features are added to the domain's functional level ## Footnote These new features may require an upgrade to the functional level to be utilized.
40
What is required to use new features within the domain?
The domain functional level needs to be upgraded ## Footnote Upgrading allows access to the latest features introduced in newer versions.
41
What determines the version of the domain's functional level that can run on the domain?
The forest's functional level ## Footnote The forest's functional level sets an upper limit on the domain's functional level.
42
True or False: You can have a domain's functional level that is higher than the forest's functional level.
False ## Footnote The domain's functional level cannot exceed the forest's functional level.
43
Define a "Domain Tree"
A collection of domains that reflects the organization's structure.
44
Describe the relationship between the domains in a domain tree and the root/parent domain
A parent-child relationship
45
If two child domains on different domain trees want to authenticate, how is it performed?
Authenticated traffic must pass through the forest root domains.
46
Describe the role/function of a global catalog domain server
Holds the full writable copy of objects in its host domain, and the partial copy of the objects in child domain
47
Are all domain controllers in a domain a global catalog server?
No, by default the only global catalog server is the initial domain controller