Final Theory Flashcards
Two components of a GPO
Group Policy Container (GPC), Group Policy Template (GPT).
Group Policy Container (GPC)
An AD object stored in the GPO container with the domain naming content. It defines basic attributes of the GPO but does not contain any settings.
Group Policy Template (GPT)
Contains the settings of a GPO which is stored in the SYSVOL of each domain controller.
GPO Backups
You can back up all or individual GPOs in GPMC. Each time a backup is performed a new backup version of the GPO is created.
Importing GPOs
Only imports the GPO settings, no links or security principals assigned to it. Imported settings overwrite existing settings.
Copying GPOs
Can be same or different domain. When pasted, becomes ‘copy of old_name’. If copied between, security principals need to be redefined.
Migration Table
File that maps references to users, groups, computers, and UNC paths in source GPO to new values in destination GPO. Consists of one or more mapping entries. When importing with migration table, each reference in source is replaced with a target reference.
How to restore either or both Default Domain Policy or Default Domain Controllers Policy?
DCGPOFix.exe (DcGPOFix command in command prompt).
Group Policy Preferences (GPP)
Made up of more than 20 new GP client-side extensions (CSEs), expands range of configurable settings in a GPO. Refreshes at the same interval as GP settings.
Preferences that support editing states
Start Menu, Regional and Language, Internet options, Folder options, Power options
How to toggle editing states?
F5: Enable all, F6: Enable current, F7: Disable current, F8: Disable all
Preference action options
Create, Replace, Update, Delete
Create (Preference action options)
Create new preference setting for user/computer
Replace (Preference action options)
Delete and recreate preference setting for the user/computer
Update (Preference action options)
Modify an existing preference setting for user/computer
Delete (Preference action options)
Remove an existing preference setting for the user/computer
Create (File Preference action options)
Copy a file/files from source to destination if it doesn’t exist and configure attributes
Replace (File Preference action options)
Delete a file/files, replace with another file/files, and configure attributes
Update (File Preference action options)
Modify settings of existing file/files
Delete (File Preference action options)
Remove a file/files for computers/users
Folder Preference action options
Same as File preference action options
Item-Level Targeting
Used to change the scope of individual preference items so that the preference items apply to only selected users/computers.
Windows Deployment Services (WDS)
Software based platform and technology allowing automated network-based installations based on network-based boot and installation media. Includes two services: Deployment/Transport Server.
Image File
Snapshot of a computer’s hard drive taken at a particular moment in time. Contains all operating system files, any updates and drivers, any applications, any configuration changes.
Preboot Execution Environment (PXE)
A technology that boots computers using the network interface without a data storage device. Needed for client computers to communicate with a WDS server without an OS. Must be configured in BIOS.
Windows Preinstallation Environment (Windows PE)
Loaded from boot image downloaded when PXE is used with WDS. WPE is a minimal WinOS with limited services which is then used to install the OS.
WDS Requirements
Member of AD domain/domain controller for domain, active DHCP and DNS present, WDS server has NTFS partition to store images.
Two Types of Image Formats
Sector-based/File-based image formats
Sector-Based Image Formats
Each sector is stored within the file and each sector is the smallest unit
File-Based Image Formats
Each file is the smallest unit. Advantage: hardware-independent and files can be referenced multiple times
Windows Imaging Format (WIM)
Used by boot and install images, is a file format that allows a file structure to be stored inside a single WIM database.
Windows Server boot image file
Named boot.wim, located in \sources. Can be used in deployment of any OS without modification.
res.rwm
The resource .wim file, contains file resources for all of the images in an image group.
Windows Deployment Services Capture Utility
Used to create image files which can be deployed to other computers.
System Preparation Utility (Sysprep.exe)
Prepares Windows computer for cloning by removing specific computer information. On 2012 R2 is located in C:\Windows\System32\Sysprep.
Discover Image
Image file that can be burned to a CD-ROM or other boot medium and used to network boot a PC that doesn’t support PXE boot.
Answer Files
Provide responses to prompts during Windows installation, used to automate this process.
System Image Manager (SIM)
A tool used to create and manage unattended answer files using a GUI, is a part of Windows Assessment and Deployment Kit.
What are the seven configuration passes in an answer file?
Windows PE, offlineServicing, generalize, specialize, auditSystem, auditUser, oobeSystem
Deployment Image Servicing and Management (Dism.exe)
A command-line tool used to service a Windows Image or prepare a Windows PE image.
Dynamic Driver Provisioning
Included with WDS starting with 2008 R2, allows to add driver packages to WDS and deploy when you deploy an image. Requires boot image from Windows 7+, Windows server 2008 R2+ and install images from Windows Vista Sp1+ including windows server +
Out-of-band Patches
Released at other times besides Patch Tuesday when the patches are critical or time-sensitive.
Out-of-band Updates
Updates released as needed
Update Classifications
Important, Recommended, Optional
Windows Update update types
Security Update, Critical Update, Service Pack
Hotfix
A single cumulative package that includes one or more files that are used to address a problem in a software product.
Cumulative Patch
Multiple hotfixes combined into a single package.
Windows Server Update Services (WSUS)
A program that allows admins to manage the distribution of updates and other patches to computers within an organization.
WSUS Modes
Autonomous Mode, Replica Mode
Minimum Requirements for WSUS
1.4 GHz x64 bit processor, 2GB (Windows Server) + 1.5 GB RAM, 10 GB disk space, 100Mbps network adapter, .NET Framework 4.0 etc.
Methods for assigning WSUS computer groups
Server-side targeting (manual), Client-side targeting (auto assigned by GP)
WSUSutil.exe
Located in %drive%\Program Files\Update Services\Tools folder, allows to manage the WSUS from command line.
Service Account general rule
Use the account with minimum rights and permissions for the service to operate.