Identify Infrastructure Flashcards

1
Q

What is Active Directory Domain Services?

A

A directory service that is the central store for all domain objects.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

(AD DS) Logical or physical?

Partition

A

Logical

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

(AD DS) Logical or physical?

Schema

A

Logical

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

(AD DS) Logical or physical?

Domain

A

Logical

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

(AD DS) Logical or physical?

Domain tree

A

Logical

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

(AD DS) Logical or physical?

Forest

A

Logical

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

(AD DS) Logical or physical?

OU

A

Logical

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

(AD DS) Logical or physical?

Container

A

Logical

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

(AD DS) Logical or physical?

Domain controller

A

Physical

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

(AD DS) Logical or physical?

Data store

A

Physical

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

(AD DS) Logical or physical?

Global catalog server

A

Physical

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

(AD DS) Logical or physical?

Read-only domain controller

A

Physical

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

(AD DS) Logical or physical?

Site

A

Physical

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

(AD DS) Logical or physical?

Subnet

A

Physical

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is an AD DS partition?

A

A portion (or naming context) of the AD DS database

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is the default Active Directory database file location?

A

C:\Windows\NTDS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What is the Active Directory database file name?

A

Ntds.dit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What is the AD DS schema?

A

A set of definitions of the object types and attributes that you use to define the objects created in AD

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What is an AD domain?

A

A logical administrative container for storing and managing objects

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What is an AD DS domain tree?

A

A hierarchical collection of domains sharing a common root domain and a contiguous DNS namespace

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What is an AD DS forest?

A

A collection of one or more domains with a common AD DS root, schema, and global catalog

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What is an AD DS OU?

A

A container object for users, groups, and computers that provides framework for assigning administrative rights and administration by linking Group Policy Objects (GPOs)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What is an AD DS container?

A

An object that provides an organization framework for use in AD DS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

What AD DS logical component cannot be linked to a container?

A

GPOs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

What is an AD domain controller?

A

A server that contains a copy of the AD DS database

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

What is an AD DS data store?

A

The data stored on each domain controller

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

What is an AD DS Global catalog server?

A

A domain controller that hosts the global catalog

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

What is the name of a partial, read-only copy of all of the objects in a multiple-domain forest?

A

AD DS global catalog

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

What purpose does a global catalog serve?

A

It speeds up searches for objects that might be stored on domain controllers in a different domain in the forest

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

What is a special, read-only installation of AD DS?

A

Read-only domain controller (RODC)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

Where are read-only domain controllers commonly found?

A

Branch offices lacking optimal physical security and IT support

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

What is an AD DS site?

A

A container for AD DS objects and services that are specific to a physical location

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

What is an AD DS subnet?

A

A portion of the network IP addresses

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

What is an AD DS managed service account (MSA)?

A

An object class used to facilitate service-account management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

What enables you to extend the capabilities of standard managed service accounts (MSA) to more than one server in your domain?

A

Group Managed Service Accounts (gMSA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

For what does the acronym SPN stand?

A

Service Principal Name

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

What is a managed domain account that provides provided automatic password management, simplified SPN management, and the ability to delegate this management to other admins?

A

Standalone Managed Service Account (sMSA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

What are the two group types in a Windows Server enterprise network?

A

Security and distribution

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

What are the four group scopes in Windows Server?

A

Local, domain-local, global, and universal

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
40
Q

What is a group object?

A

A representation of a group in AD DS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
41
Q

What is a group in AD DS?

A

A logical grouping of objects

42
Q

Which AD DS group type is security-enabled, and allows you to assign permissions to various resources?

A

Security group

43
Q

Which AD DS group type is not security-enabled?

A

Distribution group

44
Q

Which AD DS group type is commonly used by email applications?

A

Distribution group

45
Q

Based on scope, which Windows Server group is available only to the computer where they exist?

A

Local group

46
Q

Which Windows Server group scope only allows for the assignment of abilities and permissions for local resources?

A

Local group

47
Q

Which Windows Server group scope only allows for the assignment of abilities and permissions for domain-local resources?

A

Domain-local group

48
Q

Which Windows Server group scope is used for 1) standalone servers or workstations, 2) domain-member servers that are not domain controllers, or on 3) domain-member workstations?

A

Local group

49
Q

Which Windows Server group scope is used primarily for managing access to resources or to assign management rights and responsibilities?

A

Domain-local group

50
Q

Which Windows Server group scope is used primarily for consolidation of users who have similar characteristics?

A

Global group

51
Q

Which Windows Server group scope is used mostly in multidomain networks?

A

Universal group

52
Q

Which Windows Server group scope would you use to join users who are part of the same department or geographic location?

A

Global group

53
Q

What is a AD computer object?

A

A representation of a computer in AD

54
Q

Where is the default location for computers in AD?

A

The Computers container

55
Q

All the domains within a _____ share a contiguous namespace.

56
Q

All of the root domains within a _____ do not share a contiguous namespace.

57
Q

What four objects exist in the forest root domain?

A

The schema master role
The domain naming master role
The Enterprise Admins group
The Schema Admins group

58
Q

Which domain contains the schema master role, the domain naming master role, the Enterprise Admins group, and the Scheme Admins group?

A

Forest root domain

59
Q

An AD DS forest in often described to be serving as what two boundaries?

A

Security boundary and replication boundary

60
Q

Which objects exist in each domain (including the forest root)?

A

The RID master role
The Infrastructure master role
The PDC emulator master role
The Domain Admins group

61
Q

Which type of trust relationship is automatically generated between domains within a multiple-domain AD DS forest?

A

Two-way transitive trust

62
Q

Where does Windows Server store the trusted domain objects in AD DS?

A

The System container

63
Q

For what does the acronym “RSAT” stand?

A

Remote Server Administration Tools

64
Q

_______ ________ authenticate all users and computers in a domain.

A

Domain controllers

65
Q

For what does the acronym “FQDN” stand?

A

Fully Qualified Domain Name

66
Q

What is the default Active Directory SYSVOL folder location?

A

C:\Windows\SYSVOL

67
Q

This physical component of AD DS does not cache any user passwords by default.

A

Read-Only Domain Controller (RODC)

68
Q

_____ ______ is a collection of critical OS and server role files that include AD DS database and registry.

A

System state

69
Q

For what does the acronym “DSRM” stand?

A

Directory Services Restore Mode

70
Q

What is Directory Services Restore Mode (DSRM)?

A

A special boot mode for repairing or recovering Active Directory

71
Q

An operations master role is also known as a _____ ______ ______ ______ role.

A

Flexible Single Master Operation (FSMO) role

72
Q

Regarding operations master roles, which two roles does each forest have?

A

Schema master

Domain naming master

73
Q

Regarding operations master roles, which three roles does each AD DS domain have?

A
Relative ID (RID) master
Infrastructure master
Primary domain controller (PDC) emulator master
74
Q

Which domain controller do is contacted to add or remove a domain, or make domain name changes?

A

Domain naming master

75
Q

Which domain controller is contacted to make schema changes?

A

Schema master

76
Q

Which domain controller allocates blocks of relative IDs (RIDs) to each domain controller within a domain to use when building security IDs (SIDs)

A

RID master

77
Q

What is an AD DS security ID (SID)?

A

A unique identifying number assigned by the domain controller to a security principal object

78
Q

Which domain controller maintains interdomain object refernces?

A

Infrastructure master

79
Q

Which domain controller serves as the time source for the domain, as well as receives any urgent password changes?

A

Primary domain controller (PDC) emulator master

80
Q

A planned move of a DC role between two online domain controllers is known as _____ ___ ____.

A

“Transferring the role”

81
Q

A emergency move of a DC role from one domain controller to another is known as

A

“Seizing the role”

82
Q

Should you need to seize a DC role, which two tools can you use?

A

ntdsutil.exe CLI tool or Windows PowerShell

83
Q

What result will running “netdom query fsmo” yield?

A

A list of where the FSMO roles reside

84
Q

An AD DS _____ is the component that defines all the object classes and attributes that AD DS uses to store data.

85
Q

Any changes to the AD DS schema originate at the schema ______.

86
Q

You define Group Policy settings within a ____ _____ _____.

A

Group Policy Object (GPO)

87
Q

______ _______ is a framework in Windows OSs that allow you to manage configurations in an AD DS domain.

A

Group Policy

88
Q

What are the two main nodes in the Group Policy Management Editor?

A

Computer Configuration

User Configuration

89
Q

The _____ of a GPO is the collection of users and computers that will apply the settings in the GPO.

90
Q

To what three things can you link a GPO?

A

Sites

Domains

OUs

91
Q

You can further narrow the scope of a GPO with these two filter types:

A

Security

Windows Management Instrumentation (WMI)

92
Q

Arrange the following GPOs in the correct processing order:

Domain-linked GPOs
Local GPOs
Site-linked GPOs
Child OU-linked GPOs
OU-linked GPOs
A
  1. Local GPOs
  2. Site-linked GPOs
  3. Domain-linked GPOs
  4. OU-linked GPOs
  5. Child OU-linked GPOs

Remember: “LSD, oh see!”

93
Q

In regards to GPO inheritance, the (higher/lower) the number, the (higher/lower) the precedence.

A

Lower, higher

94
Q

You can configure a domain or OU to prevent the inheritance of policy settings, which is known as ______ __________.

A

Block inheritance

95
Q

To evaluate the GPO precedence for an OU or domain, which tab would you select?

A

Group Policy Inheritence

96
Q

When AD DS is installed, which two default GPOs does Windows Server create?

A

Default Domain Policy GPO

Default Domain Controllers Policy GPO

97
Q

Which default GPO specifies password settings, account lockout settings, and Kerberos v5 authentication protocol policies?

A

Default Domain Policy GPO

98
Q

Which default GPO would you modify to implement auditing policies and to assign user rights that are required on domain controllers?

A

Default Domain Controllers Policy GPO

99
Q

Within both the Computer Configuration and User Configuration nodes are the ______ and __________ nodes.

A

Policy

Preference

100
Q

For what does the acronym “RSoP” stand?

A

Resultant Set of Policy

101
Q

In AD DS, it is best practice in a multi-domain enterprise to create a _____ _____ for .admx files.

A

Central Store