Midterm Flashcards

1
Q

Which functional level only allows Windows Server 2003 and Windows 2008 domain controllers?

A

Windows Server 2003

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What type of trust relationship allows you to create two-way transitive trusts between separate forests?

A

cross-forest

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What type of trust is new to Windows Server 2008 and is only available when the forest functionality is set to Windows Server 2008?

A

cross-forest trust

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What type of zone is necessary for computer hostname-to-IP address mappings which are used for name resolution by a variety of services?

A

forward lookup

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Active Directory uses __________ relationships to allow access between multiple domains and/or forests either within a single forest or across multiple enterprise networks

A

trust

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

When configuring a site link object which attribute allows the administrator to define the path that replication will take?

A

cost

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Domain controllers located in different sites will participate in __________ replication

A

intersite

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the minimum amount of storage space required for the Active Directory installation files?

A

200 MB

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Read-Only Domain Controllers provide added security in the way passwords are stored through what feature?

A

Password Replication Policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What holds a subset of forest-wide Active Directory objects and acts as a central repository by holding a complete copy of all objects from the host servers local domain with a partial copy of all objects from other domains within the same forest?

A

global catalog

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What new Windows Server 2008 feature is a special installation option that creates a minimal environment for running only specific services and roles?

A

Server Core

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What tool is used to seize a FSMO role?

A

ntdsutil

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

The RID Master FSMO role distributes RIDs to domain controllers in what increments?

A

500

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Active Directory __________ provide the means by which administrators can control replication traffic

A

sites

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What process is used when you move a FSMO role gracefully from one domain controller to another?

A

role transfer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Replication within Active Directory will occur when which of the following conditions is met?

A

Replication within Active Directory will occur when an object is added or removed from Active Directory the value of an attribute has changed or the name of an object has changed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Which FSMO role has the authority to manage the creation and deletion of domains domain trees and application data partitions in the forest?

A

Domain Naming Master

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

A __________ is defined as one or more IP subnets that are connected by fast links

A

Site

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What SRV record information serves as a mechanism to set up load balancing between multiple servers that are advertising the same SRV records?

A

priority

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

The ISTG automatically assigns one server in each site as the bridgehead server unless you override this by establishing a list of __________ bridgehead servers

A

preferred

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What console must be used to move the Domain Naming Master FSMO role?

A

Active Directory Domains and Trusts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

When replicating information between sites Active Directory will designate a __________ server in each site to act as a gatekeeper in managing site-to-site replication

A

bridgehead

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

All default groups are __________ groups

A

security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

If the domains within a forest are separated by slow WAN links and the tree-walking process takes an exceedingly long time to allow user authentication across domains you can configure a __________ trust

A

shortcut

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

The largest container object within Active Directory is a(n) __________

A

forest

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

For both intrasite and intersite replication what protocol does Active Directory use for all replication traffic?

A

RPC over IP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What allows a user to be able to log on using a cached copy of his or her logon credentials that have been stored on his or her local workstation?

A

cached credentials

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

When a child domain is created it automatically receives a __________ trust with its parent domain

A

two-way transitive

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

A __________ name references an object in the Active Directory directory structure by using its entire hierarchical path starting with the object itself and including all parent objects up to the root of the domain

A

distinguished

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Which FSMO role is responsible for reference updates from its domain objects to other domains?

A

Infrastructure Master

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Which of the following is not a benefit of Active Directory Domain Services?

A

personalized desktops

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

What shared folder exists on all domain controllers and is used to store Group Policy objects login scripts and other files that are replicated domain-wide?

A

SYSVOL

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

__________ partitions are used to separate forest-wide DNS information from domain-wide DNS information to control the scope of replication of different types of DNS data

A

Application Directory

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

The KCC is responsible for calculating intrasite replication partners. During this process what is the maximum number of hops that the KCC will allow between domain controllers?

A

3

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

What role provides developers with the ability to store data for directory-enabled applications without incurring the overhead of extending the Active Directory schema to support their applications?

A

AD LDS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

What is an alternative solution for intersite replication when a direct or reliable IP connection is not available?

A

SMTP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

What master database contains definitions of all objects in the Active Directory?

A

schema

28
Q

What feature makes it possible to configure a user as the local administrator of a specific RODC without making the user a Domain Admins with far-reaching authority over all domain controllers in your entire domain and full access to your Active Directory domain data?

A

Admin Role Separation

30
Q

A Windows Server 2008 computer that has been configured with the Active Directory DS role is referred to as a __________

A

domain controller

31
Q

How often does intersite replication occur by default?

A

15 minutes

31
Q

Each objects SID consists of two components: the domain portion and the __________

A

relative identifier

32
Q

__________ roles work together to enable the multimaster functionality of Active Directory

A

FSMO

33
Q

Certain operations such as a password change or an account lockout will be transmitted by using __________ replication which means that the change will be placed at the beginning of the line and applied before any other changes that are waiting to be replicated

A

urgent

35
Q

When modifying the schema Microsoft recommends adding administrators to what group only for the duration of the task?

A

Schema Admins

37
Q

What contains the rules and definitions that are used for creating and modifying object classes and attributes within Active Directory?

A

Schema NC

38
Q

What types of memberships are stored in the global catalog?

A

universal

39
Q

What special identity group is used by the system to allow permission to protected system files for services to function properly?

A

Service

40
Q

What Windows Server 2008 feature stores universal group memberships on a local domain controller that can be used for logon to the domain eliminating the need for frequent access to a global catalog server?

A

universal group membership caching

41
Q

How many FSMO roles does Active Directory support?

A

5

43
Q

The primary goal of intersite replication is to minimize the usage of __________

A

bandwidth

44
Q

What can be defined as a password that follows guidelines that make it difficult for a potential hacker to determine the users password?

A

strong password

46
Q

What utility is used to manually create trust relationships?

A

Active Directory Domains and Trusts MMC snap-in

47
Q

What is the process of confirming that an authenticated user has the correct permissions to access one or more network resources?

A

authorization

48
Q

What command-line utility is used to import or export Active Directory information from a comma-separated value (.csv) file?

A

CSVDE

49
Q

The __________ Domain Controller contains a copy of the ntds.dit file that cannot be modified and does not replicate its changes to other domain controllers within Active Directory

A

Read-Only

50
Q

What process is responsible for selecting a bridgehead server and mapping the topology to be used for replication between sites?

A

Intersite Topology Generator

51
Q

What command can you use to run the Active Directory Installation Wizard?

A

dcpromo

52
Q

What is used to uniquely identify an object throughout the Active Directory domain?

A

security identifier

53
Q

As a rule of thumb you should estimate __________ percent of the size of the ntds.dit file of every other domain in the forest when sizing hardware for a global catalog server

A

50

54
Q

Which of these design aspects should you consider when planning the appropriate location of FSMO role holders?

A
  1. Number of domains that are or will be part of the forest
  2. Physical structure of the network
  3. Number of domain controllers that will be available in each domain
56
Q

__________ is the highest available forest functional level

A

Windows Server 2008

57
Q

What locator records within DNS allow clients to locate an Active Directory domain controller or global catalog?

A

SRV records

59
Q

The process of keeping each domain controller in synch with changes that have been made elsewhere on the network is called __________

A

replication

60
Q

What processes can be used by Windows Server 2008 DNS to clean up the DNS database after DNS records become stale or out of date?

A

aging and scavenging

61
Q

Interoperability with prior versions of Microsoft Windows is available in Windows Server 2008 through the use of __________

A

functional levels

62
Q

What signifies an objects relative location within an Active Directory OU structure?

A

distinguished name

63
Q

What command-line tool can be used to manually create a replication topology if site link bridging is disabled if the network is not fully routed?

A

Repadmin

64
Q

When you install the forest root domain controller in an Active Directory forest the Active Directory Installation Wizard creates a single site named __________

A

Default-First-Site-Name

65
Q

What command-line tool is used to create delete verify and reset trust relationships from the Windows Server 2008 command line?

A

netdom

67
Q

What procedure is used only when you have experienced a catastrophic failure of a domain controller that holds a FSMO role and you need to recover that role?

A

role seizure

68
Q

What is the process of confirming a users identity by using a known value such as a password pin number on a smart card or users fingerprint or handprint in the case of biometric authentication?

A

authentication

69
Q

Each class or attribute that you add to the schema should have a valid __________

A

OID

70
Q

What command-line tool used for monitoring Active Directory provides functionality that includes performing connectivity and replication tests?

A

dcdiag

71
Q

How many RID Masters can a domain have?

A

1

72
Q

What special identity group contains all authenticated users and domain guests?

A

Everyone

73
Q

Active Directory creates a __________ with the idea that all writeable domain controllers in a domain should communicate Active Directory information to each other in addition to communicating forest-wide information with other domains

A

replication topology

74
Q

What type of trust allows you to configure trust relationships between Windows Server 2008 Active Directory and a UNIX MIT Kerberos realm?

A

realm

75
Q

What allows businesses to define manage access and secure network resources including files printers people and applications?

A

Directory service

76
Q

What port is used by Active Directory to direct search requests to a global catalog server?

A

3268

77
Q

How often does replication occur in intersite replication?

A

180 minutes

79
Q

To raise the functional level of a forest you must be logged on as a member of the __________ group

A

Enterprise Admins

81
Q

Which of the following is not a function performed by a global catalog server?

A

maintaining a backup of all data stored on a domain controller

82
Q

How many FSMO roles does Active Directory support?

A

5

83
Q

What protocol has become an industry standard that enables data exchange between directory services and applications?

A

LDAP

84
Q

What is the process of replicating DNS information from one DNS server to another?

A

zone transfer

85
Q

What is a partial copy of all objects from other domains within the same forest that is held on a global catalog server?

A

partial attribute set

86
Q

When a user logs on what is created that identifies the user and all of the users group memberships?

A

access token

88
Q

What DLL must be registered to use the Schema Management snap-in?

A

schmmgmt.dll

89
Q

What describes the amount of time that it takes for all domain controllers in the environment to contain the most up-to-date information?

A

convergence

90
Q

What defines a chain of site links by which domain controllers from different sites can communicate?

A

site link bridge