Module1 Intro Active Directory Domain Services Flashcards

0
Q

What does AAA stand for?

A

Authentication
Authorization
Accounting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
1
Q

What does IDA stand for?

A

Identity and access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does CIA stand for?

A

Confidentiality
Integrity
Availability
Authenticity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is another name for identity store?

A

Directory database

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Another word for Identity in AD.

A

Security principal

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What does SID stand for?

A

Security identifier

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What does DACL stand for?

A

Discretionary access control list

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What Does ACE stand for?

A

Access control entry (allow or deny)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What does LSA stand for?

A

Local security authority

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

User’s access token require?

A

User SID
Member Group SIDs
Privileges “user rights”
Other access info

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Are access tokens ever transmitted over a network?

A

No LSAs generate local tokens for local access and server side tokens for file access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Another name for Privileges in AD.

A

User Rights

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is SACL?

A

System access control list

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is authorization?

A

The process that determines whether to grant or deny a user access to a requested level of access to a resource

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What does SAM stand for?

A

Security Accounts Manager database

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

3 components of authorization are?

A

Resource
Access Request
Security token

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is pass through authentication?

A

Transparent authentication, when the local workgroup user name and password are I debit all to the server or machine being accessed remotely

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Kerberos is?

A

The AD Authenticator and TGT issuer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What is TGT?

A

Ticket Granting Ticket

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What is AD LDS?

A

AD LIGHTWEIGHT DS

A standalone version of AD used with LDAP AND REPLACED ADAM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What is AD CS?

A

AD CERTIFICATE SERVICE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What is AD RMS?

A

AD RIGHTS MANAGEMENT SERVICES

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What is inetOrgPerson?

A

An object class used to support interoperability with a handful of third-party DSs, it is a security principal and is similar to a user account.

23
Q

What is AD FS?

A

AD FEDERATION SERVICES

25
Q

What is API?

A

Application Programming Interfaces aka LDAP

25
Q

NTDS.DIT databases are?

A
Schematic
Configuration
Domains
DNS
PAS
26
Q

What is Ntds.dit?

A

Where AD DS stored it’s identities. Usually in C:\ntds\

27
Q

What is Schema?

A

Defines the attributes and types of objects that can be stored in the directory.

29
Q

What is a Domain naming context (domain NC)?

A

Contains the data about the objects within a domain. Users groups and computers.

30
Q

What is Configuration (ntds.dit) in AD?

A

Contains info about domains, services and topology.

31
Q

What is DNS in (AD)?

A

In AD integrated DNS, the DNS zones and resource records are stored in a partition.

32
Q

What is PAS (Partial Attribute Set)?

A

This partition is used by global catalog,

33
Q

What is SYSVOL?

A

In c:\windows used by AD to store info such as login scripts and files related to GPOs

34
Q

What is KDC SERVICE?

A

Kerberos Key Distribution Center

35
Q

What is a Server core?

A

Command Prompt version of Windows Server 2008 r2 with no Windows Explorer.

36
Q

What is RODCs?

A

Read-only DC that caches credentials only, no changes to AD, no passwords are replicated to it

37
Q

What is ObjectSID (Schema)?

A

Security identifier

38
Q

What is sAMAccountName (Schema)?

A

The pre-windows 2000 server login name aka Username

39
Q

What is unicodePwd (Schema)?

A

This attribute stores a password as a hashtag code, only a brute force dictionary attack can derive the password.

40
Q

What is member (Schema?

A

The attribute that stores the membership list for a group object.

41
Q

What is Classes (Schema)?

A

This container defines the type of objects that can be created in the directory, including user and group.

42
Q

What is a Forrest?

A

Is a collection of one or more AD domains. The first is called the Forrest root domain. Only one Schema for all other domains.

43
Q

What is DNS?

A

Domain Name System

44
Q

What is Replication?

A

Replication services distribute directory data across a network

45
Q

What is Multimaster Replication?

A

No DC is a single master, the replicate to each other

45
Q

A zone in AD DS is?

A

DNS data stored in AD

46
Q

What is Sites in (AD)?

A

An AD site is an object that represents a portion of the enterprise within which network connectivity is good, it creates a boundary of replication and service utilization

48
Q

What is Global catalog?

A

A partition of the data store also known as PAS contains info about every object in the directory.

49
Q

What is an INTEGRATED ZONE?

A

A database within AD used to store data from other applications and replicated using AD replication services.

49
Q

Where do you edit GPO settings?

A

Group Policy Manager

50
Q

What are Trust Relationships?

A

When a trusting domain extends it’s realm of trust so that it trusts the identity store and authentication services of the trusting domain

51
Q

Where do you install AD DS roles?

A

In Server Manager

52
Q

What are the steps for Installing and Configuring a DC

A

Configure Time Zone
Install AD DS role in Server Manager
Run the ADDS Install Wizard
Choose Deployment Configuration
Select the additional domain controller Features
Select the location for database, log files and Sysvol
Configure the DS Restore Mode Administrator Password

53
Q

Information need to create a Domain Controller.

A
Domain Name
DNS Name
NetrBios Name (Short Name)
Function Level (OS Functionality Level)
DNS Implementation for SD Support
IP Configuration for Domain Controller (Static IP)
DNS Server Address for name resolution
Admin Username and Password for Admin Group
Data Store Location
54
Q

What must the first domain controller in a forest be?

A

A Global Catalog Server, and cannot be an RODC