Maintain Active Directory Flashcards

1
Q

What are two ways to take AD offline?

A
  1. Directory Services Restore Mode

2. Restartable AD DS Service

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How do you take AD offline using DSRM?

A
  1. Open command prompt, type:
    bcdedit /set safeboot dsrepair
  2. shutdown -t 0 -r
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Within Safe Mode, how do you bring AD back online?

A
  1. Log in as local admin
  2. Open cmd prompt
  3. bcdedit /deletevalue safeboot
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How do you perform a defrag of an AD Database?

A
  1. Open cmd prompt
  2. ntdsutil > activate instance ntds
  3. files > compact to c:\
  4. integrity
  5. quit > quit
  6. copy c:\ntds.dit c:\windows\ntds\ntds.dit
  7. del c:\windows\ntds*.log
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the classic method of taking AD offline?

A

DSRM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How do you clean up metadata?

A

Within ADUC, delete the DC from the Domain Controllers OU.

Within ADSS, delete the DC from the Servers container within Sites

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How do you backup Active Directory?

A
  1. Install Windows Server Backup feature
  2. Create backup partition utilizing Disk Management
  3. Within Windows Server Backup, set schedule or run Backup Once, System State
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the difference between an authoritative and non-authoritative restore?

A

An authoritative restore performs the restore without receiving any updates from any DCs.

A non-authoritative restore performs the restore as well as accepts any updates from any DCs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

How do you perform a restore of AD?

A
1. Reboot the server in DSRM by typing:
bcdedit /set safeboot dsrepair
shutdown -t 0 -r
2. Within Safe Mode, open Windows Server Backup and select Recover and walk through Recovery Wizard
3. bcdedit /deletevalue safeboot
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

How do you restore objects in AD Recycle Bin?

A
  1. Enable AD Recycle Bin by going to AD Admin Center.

2. The objects can be restored within the Deleted Objects folder in AD Admin Center.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How long can objects last in the Deleted Objects folder in AD Admin Center?

A

180 days.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What tool is used to configure snapshots?

A

ntdsutil

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

How do you access the ntds snapshot utility?

A
  1. Open a command prompt

2. ntdsutil > activate ntds > snapshot

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Within the ntds snapshot utility, what command lists all available snapshots?

A

List all

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Within the ntds snapshot utility, what command is used to create a new snapshot?

A

Create

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

How do you mount an AD snapshot?

A

Within the ntds snapshot utility, type Mount .

Outside of the ntds snapshot utility, type dsamain -dbpath \windows\ntds\ntds.dit -ldapport

17
Q

How do you open a mounted AD snapshot?

A

Within ADUC, right click on top container and select Change Directory Server

Change to “This Domain Controller or AD LDS instance”

Enter :

18
Q

How do you unmount an AD snapshot?

A
  1. ntdsutil > activate instance ntds > snapshot
  2. List all
  3. Unmount
19
Q

How do you manually trigger replication between DCs?

A
  1. Within ADSS, navigate to the NTDS settings of the DC that needs replicating.
  2. Right click and select Replicate Now
20
Q

What command-line tool is used to manually trigger Active Directory replication?

A

repadmin

21
Q

Using the repadmin command-line tool, how do you trigger a manual replication?

A

repadmin /syncall dc=,dc=com /d /e /a

22
Q

How do you check whether replication is running successfully with your RODCs?

A

repadmin /kcc