Review 70-640 Flashcards
Review terms and things from 70-640, server 2008 and R2. Google, technet, cert books, cbt nuggets, vtc :(,
What is the SOA
First record in any zone file, it identifies the primary name server within the domain. It also includes other properties such as an administrator email address and caching properties for the zone.
What is the A and AAAA (host)
Contains the computer name to IPv4 (A) or IPv6 (AAAA) address mappings for all hosts found in the domain, thereby identifying these hostnames.
NS (Name Server)
Contains the DNS servers that are authoritative in the domain. This includes both the primary DNS servers and any secondary DNS servers.
What does DSmod do?
Dsmod is a command-line tool that is built into Windows Server 2008. It is available if you have the Active Directory Domain Services (AD DS) server role installed. DSmod (commands) computer, contact, group, ou, server, user, quota, partition. Modifies attributes of one or more attributes in each of the above.
Auditpol
Displays information about and performs functions to manipulate audit policies.
/get, /set, /list, /backup, /restore, /clear, /remove, /resourceSACL
Certutil
Certutil.exe is a command-line program that is installed as part of Certificate Services. You can use Certutil.exe to dump and display certification authority (CA) configuration information, configure Certificate Services, backup and restore CA components, and verify certificates, key pairs, and certificate chains.
When certutil is run on a certification authority without additional parameters, it displays the current certification authority configuration. When cerutil is run on a non-certification authority, the command defaults to running the certutil -dump verb.
ntdsutil
Ntdsutil.exe is a command-line tool that provides management facilities for Active Directory Domain Services (AD DS) and Active Directory Lightweight Directory Services (AD LDS). You can use the ntdsutil commands to perform database maintenance of AD DS, manage and control single master operations, and remove metadata left behind by domain controllers that were removed from the network without being properly uninstalled. (authoritative restore, configurable settings, DS behavior, files, group membership evaluation, ifm, ldap policies, local roles, metadata cleanup, partition management, roles, security account management, semantic database analysis, set DSRM password, snapshot.
dsmgmt
Facilitates managing Active Directory Lightweight Directory Services (AD LDS) application partitions, managing and controlling flexible single master operations (FSMO), and cleaning up metadata that is left behind by abandoned Active Directory domain controllers and AD LDS instances. (Abandoned domain controllers and AD LDS instances are those that are removed from the network without being uninstalled.), set DSRM password, roles, metadata cleanup, ldap policies, ds behavior (AD DS and AD LDS)
gpfixup
Fix domain name dependencies in Group Policy Objects (GPOs) and Group Policy links after a domain rename operation
Which of the following are components of the DNS namespace? Root Domains, Top level domains, second level domains, host names, netbios names.
Root domains, top level domains, second level domains, host names.
Which of the following is most likely to cause a problem when installing a DNS server? The server is not configured as a domain controller; the server has only a single network adapter; the server is not configured with a static IP address, the server is not configured with the application server rol.
The server is not configured with a static IP address.
What tool do you use to install DNS on a windows server 2008 R2 computer? add roles wizard; add features wizard, dns manager, control panel add or remove programs.
Add roles wizard
What DNS zone type contains source information about authoritative name server for its zone only? primary zone, secondary zone, forwarding zone, stub zone, active directory-integrated zone.
Stub zone
You set up two windows server 2008 R2 servers as domain controllers and configured them with Active Directory-integrated DNS zones. You have configured another windows server 2008 R2 computer as a DNS server. You do not intend to promote this server to domain controller, but you want it to include a backup cop of the DNS zone data for your domain. What DNS zone type should you configure.
Secondary zone
Your network has several older servers that have static records with single-label names. Historically, you have used WINS for name resolution with these servers, but the WINS server is being removed as your network is being converted to IPv6. What zone type should you configure to support these servers.
primary zone
You are configuring a reverse lookup zone for you network, which uses the Class C network address range of 192.168.5.0/24. Which of the following addresses should you use for the reverse lookup zone?
5.168.192.in-addr.arpa
Which type of resource record would you use to specify a host name to IPv6 address mapping for a computer in your domain.
AAAA
Your AD DS network contains a Windows Server 2008 R2 machine that hosts both a web server and an FTP server, which are configured two different FQDNs. You want to ensure that clients are directed properly to this machine. What typ of resource record should you specify.
PTR (Pointer.
You are configuring DNS on your AD DS network and want to ensure that only computers with existing domain accounts can update DNS records. What option should you specify?
Make it an active directory integrated account.
Your network is experiencing heavy traffic to and from the DNS server because of large numbers of client requests. On examining DNS server logs and talking to users on the network, you discover that many users are repeatedly accessing the same FQDNs. What should you do to reduce the DNS network traffic in this situation.
Increase the minimum default TTL value (so the records hang around longer and they don’t have to keep asking for them)
You are configuring the properties of a secondary DNS server on your network. You want to ensure that the secondary DNS server is keptt up-to-date with respect to changes in resource records at the primary DNS server, so you access the Start of Authority (SOA) tab of your server’s Properties dialog box. What should you do?
Increase the refresh interval.
You are responsible for administering DNS on your company’s AD DS domain. All domain controllers are configured as DNS servers with an Active Directory-integrated zone. When checking the configuration of a DNS server, you notice that the zone includes resource records for computers that were removed from the network several weeks ago. What should you do to ensure that these records are removed immediately?
X
Which of the following are best practices that your should follow when planning an AD DS domain structure? Employ a test lab, prepare thorough documentation, keep everyone, including top managers, informed; understand toroughly the network’s TCP/IP infrastructure; develope and adhere to an adequate security policy, know the capabilities of your wan links
x
On which editions of Windows Server 2008 R2 can you install the AD DS role?
Foundation, standard, enterprise, datacenter.
Define “Publishing” software
Typically, after you publish a software package to users in a site, domain, or OU, the users can use Add or Remove Programs to install the software
Define “Assigning” software
The application is fully installed by the user from the Start menu, from Add or Remove Programs, from a desktop shortcut, or by opening a document (on demand) that has a file name extension that is associated with the application. Only the local or network administrator can remove the software, though a user can repair the software, •If you assign many applications instead of publishing them, you can cause congestion between client computers and the software distribution point servers. Use DFS to distribute the server load among multiple servers
Which of the following tools can you use to install AD DS on a server running Windows Server 2008 R2 (choose two): dcpromo.exe; manage your server tool; configure your server tool; add roles wizard; add features wizard.
dcpromo.exe, add roles wizard.
Which of the following conditions would represent a problem when you are attempting to install the first domain controller in your domain? a dhcp server is not present, dns server not present, hard disk formated to fat32, hard disk of only 10gb free space.
hard disk formatted to fat32
Which of the following is a new AD DS administrative tool included with Windows Server 2008 R2 and was not present in older versions.
ACtive directory administrative console. ADAC
Your computer is running the server core edition of windows server 2008 r2. you want to promote this server to domain controller, what should you do.
reload everything from scratch. no upgrade path.
What can a domain local group contain and how is it used
User account from any domain in forest; global or universal from any domain in forest; user accounts, global or universal groups from a trusted forest domain; other domain local groups from the same domain. Useage: Resources in local domain.
What can a global group contain and how is it used
User account n same domain, other global groups from the same domain. Useage: Any domain in forest or trusted forests
What can a universal group contain and how is it used
Users, global groups, or uniersal groups from any domain in forest. Useage: Any domain in forest or trusted forests.