Deck 4: Introduction to Active Directory and Account Management
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Question
Unlock Deck
Sign up to unlock the cards in this deck!
Unlock Deck
Unlock Deck
1/36
Play
Full screen (f)
Deck 4: Introduction to Active Directory and Account Management
1
If domain1.com is the forest root domain, you can use the command Set-ADForestMode Windows2012R2Domain to raise the forest functional level to Windows Server 2012 R2.
False
2
A user, Petra.T, is trying to access their system while the global catalog server for the domain is offline. What is the most likely outcome?
A) Petra.T will not be allowed to log in to the system because the global catalog server is not available.
B) Petra.T will be allowed to log in and access resources across the domain.
C) Petra.T will be locked out of their account until the domain controller can access the global catalog.
D) Petra.T will be allowed to log in to the system with cached credentials.
A) Petra.T will not be allowed to log in to the system because the global catalog server is not available.
B) Petra.T will be allowed to log in and access resources across the domain.
C) Petra.T will be locked out of their account until the domain controller can access the global catalog.
D) Petra.T will be allowed to log in to the system with cached credentials.
D
3
Ahmad, a system administrator in an organization, is setting up new Active Directory domains for the Marketing and Sales teams in the organization. Previously, all the marketing and sales employees worked as a single team. Recently, the employees in these teams were reorganized into two separate teams. He is setting up Active Directory domains on Windows 2019 Server to reflect the organizational structure. What is the minimum number of domain controllers that Ahmad should add to the Marketing domain?
A) Zero
B) One
C) Two
D) Three
A) Zero
B) One
C) Two
D) Three
C
4
Which of the following organizations should consider using Azure Active Directory?
A) An organization that subscribes to Office 365 services
B) An organization that has a substantially onsite workforce
C) An organization that uses IIS as a web server
D) An organization that deploys Internet accessible services, such as FTP or DNS
A) An organization that subscribes to Office 365 services
B) An organization that has a substantially onsite workforce
C) An organization that uses IIS as a web server
D) An organization that deploys Internet accessible services, such as FTP or DNS
Unlock Deck
Unlock for access to all 36 flashcards in this deck.
Unlock Deck
k this deck
5
Kettle Inc. from Florida merges with Blue Clu Networks from Minneapolis. Minisha, a system administrator, is granted the responsibility of configuring Active Directory across both locations to enable users from both locations to access common resources. If Minisha is able to accomplish this task successfully, which of the following must be true?
A) Minisha is a member of the Enterprise Admins group in both organizations.
B) Minisha is a member of the Domain Admins group in both organizations.
C) Minisha has run the following command: Get-ADForest | select SchemaMaster,DomainNamingMaster.
D) Minisha has run the following command: Set-ADDomainMode -Identity domainX.com -DomainMode Windows2012R2Domain.
A) Minisha is a member of the Enterprise Admins group in both organizations.
B) Minisha is a member of the Domain Admins group in both organizations.
C) Minisha has run the following command: Get-ADForest | select SchemaMaster,DomainNamingMaster.
D) Minisha has run the following command: Set-ADDomainMode -Identity domainX.com -DomainMode Windows2012R2Domain.
Unlock Deck
Unlock for access to all 36 flashcards in this deck.
Unlock Deck
k this deck
6
By default, a new domain has six organizational units: Domain Controllers, Builtin, Computers, ForeignSecurityPrincipals, Managed Service Accounts, and User.
Unlock Deck
Unlock for access to all 36 flashcards in this deck.
Unlock Deck
k this deck
7
You are the system administrator at an organization. Most of the servers in your organization, including domain controllers, are running Windows Server 2012 and above. Some servers, excluding domain controllers, are running Windows Server 2008 R2. Most of the clients are running Windows 10, but a few systems are running Windows 7. You have been tasked with improving the security measures of the Active Directory forest by restricting malicious access to Active Directory. You decide to use Privilege Access Management. What should you do next?
A) Update the clients that are running Windows 7 to Windows 10
B) Update the servers running Windows Server 2008 R2 to Windows Server 2019
C) Update all the domain controllers running Windows Sever 2012 to Windows Server 2016
D) Revert the domain functional level of each domain in the forest to Windows Server 2016
A) Update the clients that are running Windows 7 to Windows 10
B) Update the servers running Windows Server 2008 R2 to Windows Server 2019
C) Update all the domain controllers running Windows Sever 2012 to Windows Server 2016
D) Revert the domain functional level of each domain in the forest to Windows Server 2016
Unlock Deck
Unlock for access to all 36 flashcards in this deck.
Unlock Deck
k this deck
8
By default, the only site created within a new forest does not contain any domain controller.
Unlock Deck
Unlock for access to all 36 flashcards in this deck.
Unlock Deck
k this deck
9
What is the term for domain and forest functions that must be coordinated from a single domain controller?
A) Universal Group Membership Caching
B) Flexible Single Master Operations
C) Role seizure
D) User Principle Name
A) Universal Group Membership Caching
B) Flexible Single Master Operations
C) Role seizure
D) User Principle Name
Unlock Deck
Unlock for access to all 36 flashcards in this deck.
Unlock Deck
k this deck
10
You are the system administrator tasked with raising the domain functional level of domainA.com from Windows Server 2008 to Windows Server 2012 R2. First, you upgrade the domain controllers running Windows Server 2008 to Windows Server 2012 R2. Which of the following commands must you run next in Windows PowerShell to complete your task?
A) Set-ADForestMode -Identity domainA.com -ForestMode Windows2012R2Domain
B) Get-ADDomain | select PDCEmulator,RIDMaster,InfrastructureMaster
C) netdom.exe
D) Set-ADDomainMode -Identity domainA.com -DomainMode Windows2012R2Domain
A) Set-ADForestMode -Identity domainA.com -ForestMode Windows2012R2Domain
B) Get-ADDomain | select PDCEmulator,RIDMaster,InfrastructureMaster
C) netdom.exe
D) Set-ADDomainMode -Identity domainA.com -DomainMode Windows2012R2Domain
Unlock Deck
Unlock for access to all 36 flashcards in this deck.
Unlock Deck
k this deck
11
Which of the following statements about directory partitions is true?
A) Changes to a domain partition on a domain controller are only replicated to domain controllers within the same domain.
B) The largest section of the Active Directory database is the configuration partition.
C) Schema partitions store the structure and layout of the forest, including the names of each domain and their trust relationships.
D) If any change is made to a configuration partition, the change is also replicated in the schema partition.
A) Changes to a domain partition on a domain controller are only replicated to domain controllers within the same domain.
B) The largest section of the Active Directory database is the configuration partition.
C) Schema partitions store the structure and layout of the forest, including the names of each domain and their trust relationships.
D) If any change is made to a configuration partition, the change is also replicated in the schema partition.
Unlock Deck
Unlock for access to all 36 flashcards in this deck.
Unlock Deck
k this deck
12
Alfons recently received a promotion to lead a team of 35 software engineers, testers, and business analysts. When he needs to send an email or meeting invite to his team, he realizes that he must type out the email IDs for all his team members. He approaches Priyanka from the IT team to help him make this process easier and more efficient. Which of the following features of Active Directory can Priyanka use to provide a solution?
A) Universal Group Membership Caching
B) User Principle Name
C) Selective authentication
D) Distribution groups
A) Universal Group Membership Caching
B) User Principle Name
C) Selective authentication
D) Distribution groups
Unlock Deck
Unlock for access to all 36 flashcards in this deck.
Unlock Deck
k this deck
13
Arpita is adding FSMO roles to domain controllers in the domainG.com forest. The forest contains other domains. domainG.com contains two domain controllers, DC1 and DC2. DC1 contains a copy of the global catalog. Which of the following is a best practice that Arpita should follow?
A) She should create the Domain Naming Master role on DC2.
B) She should create the Infrastructure Master role on DC1.
C) She does not need to create the Domain Master role because DC1 contains a copy of the global catalog.
D) She does not need to create the Infrastructure Master role because the forest contains multiple domains.
A) She should create the Domain Naming Master role on DC2.
B) She should create the Infrastructure Master role on DC1.
C) She does not need to create the Domain Master role because DC1 contains a copy of the global catalog.
D) She does not need to create the Infrastructure Master role because the forest contains multiple domains.
Unlock Deck
Unlock for access to all 36 flashcards in this deck.
Unlock Deck
k this deck
14
If a site cannot hold a copy of the global catalog, which of the following features can be enabled on the site to provide fast authentication?
A) Universal Group Membership Caching
B) Flexible Single Master Operations
C) Role seizure
D) User Principle Name
A) Universal Group Membership Caching
B) Flexible Single Master Operations
C) Role seizure
D) User Principle Name
Unlock Deck
Unlock for access to all 36 flashcards in this deck.
Unlock Deck
k this deck
15
Anahira is the system administrator at an organization that has offices in two different locations, New York and Sao Paulo. She decides to create sites for each location, NewYorkSite and SaoPauloSite, to improve Active Directory replication. Once she creates the sites, she associates NewYorkSite with the IP address 10.1.0.0/16. Which of the following is true of this scenario?
A) When new domain controllers are added to this network, they will be added to NewYorkSite by default.
B) Assigning an IP address to a site indicates that domain controllers within this site contain the global catalog.
C) Anahira will not be able to install or use Simple Mail Transfer Protocol (SMTP) to perform Active Directory replication.
D) This restricts the creation of bridgehead servers, and only NewYorkSite will contain bridgehead servers.
A) When new domain controllers are added to this network, they will be added to NewYorkSite by default.
B) Assigning an IP address to a site indicates that domain controllers within this site contain the global catalog.
C) Anahira will not be able to install or use Simple Mail Transfer Protocol (SMTP) to perform Active Directory replication.
D) This restricts the creation of bridgehead servers, and only NewYorkSite will contain bridgehead servers.
Unlock Deck
Unlock for access to all 36 flashcards in this deck.
Unlock Deck
k this deck
16
Which of the following statements regarding a domain functional level is accurate?
A) Unlike forest functional levels, you can revert to a previous domain functional level after it has been raised.
B) It represents the oldest Windows Server version that can be used on a domain controller.
C) A server containing Windows Server 2016 cannot run on a domain at the Windows Server 2019 functional level.
D) It applies to domain controllers, clients, and other servers that are present in the domain.
A) Unlike forest functional levels, you can revert to a previous domain functional level after it has been raised.
B) It represents the oldest Windows Server version that can be used on a domain controller.
C) A server containing Windows Server 2016 cannot run on a domain at the Windows Server 2019 functional level.
D) It applies to domain controllers, clients, and other servers that are present in the domain.
Unlock Deck
Unlock for access to all 36 flashcards in this deck.
Unlock Deck
k this deck
17
Hiroshi is the system administrator at an organization that has offices spread across three locations, Boston, London, and Paris. The organization has an Active Directory domain, domainA.com, with two domain controllers in each location for the marketing business unit. The company expanded recently and added over 3000 new users across these locations. Hiroshi notices that this surge in users is causing Internet congestion because of the Active Directory replication. What is a cost-effective method of dealing with this issue?
A) Hiroshi should create separate domains for each location to avoid the need for replication.
B) Hiroshi should create site objects and specify timed intervals for replication using site link objects.
C) Hiroshi should reduce the number of domain controllers to just one per physical location.
D) Hiroshi should remove all domain controllers and have only one domain controller for the domain.
A) Hiroshi should create separate domains for each location to avoid the need for replication.
B) Hiroshi should create site objects and specify timed intervals for replication using site link objects.
C) Hiroshi should reduce the number of domain controllers to just one per physical location.
D) Hiroshi should remove all domain controllers and have only one domain controller for the domain.
Unlock Deck
Unlock for access to all 36 flashcards in this deck.
Unlock Deck
k this deck
18
Azure Active Directory can be configured to trust an organization's Active Directory forest, or mirror it using a synchronization service.
Unlock Deck
Unlock for access to all 36 flashcards in this deck.
Unlock Deck
k this deck
19
Sanya, an IT administrator for an organization, installs a new application on 150 computers used by programmers in the organization. She does this with a few clicks only for this specific set of users without impacting the rest of the organization. Which of the following features of Active Directory is exemplified by Sanya's actions in this scenario?
A) A member server
B) Group Policy
C) A standalone server
D) Access Control List
A) A member server
B) Group Policy
C) A standalone server
D) Access Control List
Unlock Deck
Unlock for access to all 36 flashcards in this deck.
Unlock Deck
k this deck
20
Raven is adding FSMO roles to domain controllers in the domain1.com forest. The forest contains a single domain and three domain controllers, DC1, DC2, and DC3. DC1 contains a copy of the global catalog, and all three domain controllers have the latest version of Windows Server 2019 installed. Which of the following is a best practice that Raven should follow?
A) She should create the Domain Naming Master role on DC1.
B) She should use DC2 or DC3 as the Domain Naming Master.
C) She does not need to create the Domain Master role because DC1 contains a copy of the global catalog.
D) She should create three Domain Naming Master roles, one for each domain controller.
A) She should create the Domain Naming Master role on DC1.
B) She should use DC2 or DC3 as the Domain Naming Master.
C) She does not need to create the Domain Master role because DC1 contains a copy of the global catalog.
D) She should create three Domain Naming Master roles, one for each domain controller.
Unlock Deck
Unlock for access to all 36 flashcards in this deck.
Unlock Deck
k this deck
21
What are the necessary conditions and permissions required to raise domain or forest functional levels?
Unlock Deck
Unlock for access to all 36 flashcards in this deck.
Unlock Deck
k this deck
22
Keplez Informatics is headquartered in Sydney, Australia, and has smaller branch offices spread across the world. The RODC in one of the branch offices gets stolen. Shannon is the system administrator at Keplez Informatics. What is the appropriate security measure that Shannon should take?
A) Shut down all RODCs
B) Create a new RODC
C) Disable user accounts in the branch office
D) Delete the RODC computer account
A) Shut down all RODCs
B) Create a new RODC
C) Disable user accounts in the branch office
D) Delete the RODC computer account
Unlock Deck
Unlock for access to all 36 flashcards in this deck.
Unlock Deck
k this deck
23
What happens when you join a computer to an Active Directory domain?
Unlock Deck
Unlock for access to all 36 flashcards in this deck.
Unlock Deck
k this deck
24
Latanya, a system administrator, is creating computer objects. She uses the Active Directory Users and Computers tool instead of the Active Directory Administrative Center. What is the most likely reason for not using the Active Directory Administrative Center?
A) It does not support features introduced within Windows Server 2008 R2 and later functional levels.
B) It uses a minimal color interface that is similar to the one provided by Server Manager.
C) It can only be used to manage OU, user, group, and computer objects, but not to create these objects.
D) It is a command line tool similar to Windows PowerShell that requires the use of cmdlets.
A) It does not support features introduced within Windows Server 2008 R2 and later functional levels.
B) It uses a minimal color interface that is similar to the one provided by Server Manager.
C) It can only be used to manage OU, user, group, and computer objects, but not to create these objects.
D) It is a command line tool similar to Windows PowerShell that requires the use of cmdlets.
Unlock Deck
Unlock for access to all 36 flashcards in this deck.
Unlock Deck
k this deck
25
Kiora is setting up an RODC for the first time at one of her organization's branch offices. She creates a prestaged RODC computer account. Next, she installs a Windows Server 2019 system that will function as the RODC. What is the most appropriate step that Kiora should take next?
A) Run the Active Directory Domain Services Installation Wizard
B) Add branch office user accounts to the Allowed RODC Password Replication Group
C) Create new user accounts for the branch office users
D) Use the Active Directory Domain Services Configuration Wizard to configure the RODC
A) Run the Active Directory Domain Services Installation Wizard
B) Add branch office user accounts to the Allowed RODC Password Replication Group
C) Create new user accounts for the branch office users
D) Use the Active Directory Domain Services Configuration Wizard to configure the RODC
Unlock Deck
Unlock for access to all 36 flashcards in this deck.
Unlock Deck
k this deck
26
What are the three Active Directory group scopes and their restrictions regarding the objects that the groups can contain and the domains within the forest that can access them?
Unlock Deck
Unlock for access to all 36 flashcards in this deck.
Unlock Deck
k this deck
27
What is the purpose of a Read-only Domain Controller?
Unlock Deck
Unlock for access to all 36 flashcards in this deck.
Unlock Deck
k this deck
28
Explain the use of prestaging.
Unlock Deck
Unlock for access to all 36 flashcards in this deck.
Unlock Deck
k this deck
29
Describe the three main container objects within an Active Directory database.
Unlock Deck
Unlock for access to all 36 flashcards in this deck.
Unlock Deck
k this deck
30
Censu Technologies wants to enforce a strict timings policy such that users are able to log into their systems only during specific time slots on weekdays. The company also wants to restrict access on weekends. Glenna, a system administrator at Censu, is tasked with enforcing this change. What tab under a user object's properties will allow Glenna to make this change?
A) Profile
B) General
C) Account
D) Organization
A) Profile
B) General
C) Account
D) Organization
Unlock Deck
Unlock for access to all 36 flashcards in this deck.
Unlock Deck
k this deck
31
Faustino is the system administrator at an organization that has offices in multiple locations. The domain controllers in each location are within location-specific sites to improve Active Directory replication. Faustino notices performance issues in the Active Directory replication across sites. Which of the following measures can Faustino use to improve the performance?
A) He can restrict the number of domain controllers to one per site.
B) He can increase the number of domain controllers to spread the replication load.
C) He change the bridgehead server to one with a faster network interface.
D) He can use SMTP instead of IP to improve performance.
A) He can restrict the number of domain controllers to one per site.
B) He can increase the number of domain controllers to spread the replication load.
C) He change the bridgehead server to one with a faster network interface.
D) He can use SMTP instead of IP to improve performance.
Unlock Deck
Unlock for access to all 36 flashcards in this deck.
Unlock Deck
k this deck
32
What is the use of the New-ADReplicationSite Windows PowerShell cmdlet?
A) It can be used configure the replication settings within a site link object.
B) It can be used to create a new site object.
C) It can be used to change the bridgehead server in a site.
D) It can be used to launch the Active Directory Sites and Services tool.
A) It can be used configure the replication settings within a site link object.
B) It can be used to create a new site object.
C) It can be used to change the bridgehead server in a site.
D) It can be used to launch the Active Directory Sites and Services tool.
Unlock Deck
Unlock for access to all 36 flashcards in this deck.
Unlock Deck
k this deck
33
A recently promoted employee at your company has called you because they attempted to log in to their computer several times with a password created after a password expiry notice, but the attempts made were unsuccessful. You have reset the user's account password, but the user is still unable to log in. What is most likely the cause of the failure?
A) The user is in a new OU and lacks permission to log into the computer used.
B) The user's account has been locked because of frequent failed password attempts.
C) The computer is having issues communicating with the domain and is attempting to use cached credentials.
D) The global catalog server has not replicated the user's account information to the rest of the domain.
A) The user is in a new OU and lacks permission to log into the computer used.
B) The user's account has been locked because of frequent failed password attempts.
C) The computer is having issues communicating with the domain and is attempting to use cached credentials.
D) The global catalog server has not replicated the user's account information to the rest of the domain.
Unlock Deck
Unlock for access to all 36 flashcards in this deck.
Unlock Deck
k this deck
34
Explain the process of restoring a deleted user account object using the Active Directory Administrative Center.
Unlock Deck
Unlock for access to all 36 flashcards in this deck.
Unlock Deck
k this deck
35
What are the Windows Server 2019 default password requirements?
Unlock Deck
Unlock for access to all 36 flashcards in this deck.
Unlock Deck
k this deck
36
After an RODC gets stolen along with a few other computers, Shania, the system administrator, resets the computer accounts of the stolen computers that were cached on the RODC. She accomplishes this task by using the Reset all passwords for computer accounts that were cached on this Read-only Domain Controller option. Which of the following is true of this scenario?
A) The stolen computers can rejoin the domain after resetting their passwords.
B) Any computers that were not stolen will need to rejoin the domain.
C) Shania does not need to delete the stolen RODC computer account if the other computer accounts are reset.
D) The Active Directory database on the stolen RODC is deleted automatically.
A) The stolen computers can rejoin the domain after resetting their passwords.
B) Any computers that were not stolen will need to rejoin the domain.
C) Shania does not need to delete the stolen RODC computer account if the other computer accounts are reset.
D) The Active Directory database on the stolen RODC is deleted automatically.
Unlock Deck
Unlock for access to all 36 flashcards in this deck.
Unlock Deck
k this deck