You are the administrator of an Active Directory domain named All servers run Windows Server 2003. All client computers run Windows 2000 Professional with Service Pack 2.You install Software Update Services (SUS) on a computer named Testking1, and you approve all downloaded updates. You apply the appropriate Group Policy object (GPO) settings to configure domain computers to download critical updates from Testking1.You discover that no updates were applied since you installed SUS on Testking1.You confirm that all the Windows Server 2003 computers receive updates from Testking1.You need to ensure that all client computers receive updates from Testking1.What are two possible ways to achieve this goal?() (Each correct answer presents a complete solution. Choose two)A. Install Service Pack 3 on all client computers.B. Move all client computers out of the Computers contain and into a new organizational unit (OU).C. Enable the No Override GPO setting.D. Install the Automatic Updates client on all client computers.E. Configure Testking1 to authenticate against a proxy server to receive updates from the Windows Update servers.

You are the administrator of an Active Directory domain named All servers run Windows Server 2003. All client computers run Windows 2000 Professional with Service Pack 2.You install Software Update Services (SUS) on a computer named Testking1, and you approve all downloaded updates. You apply the appropriate Group Policy object (GPO) settings to configure domain computers to download critical updates from Testking1.You discover that no updates were applied since you installed SUS on Testking1.You confirm that all the Windows Server 2003 computers receive updates from Testking1.You need to ensure that all client computers receive updates from Testking1.What are two possible ways to achieve this goal?() (Each correct answer presents a complete solution. Choose two)

A. Install Service Pack 3 on all client computers.

B. Move all client computers out of the Computers contain and into a new organizational unit (OU).

C. Enable the No Override GPO setting.

D. Install the Automatic Updates client on all client computers.

E. Configure Testking1 to authenticate against a proxy server to receive updates from the Windows Update servers.


相关考题:

You are the network administrator for your company. The network originally consists of a single Windows NT 4.0 domain.You upgrade the domain to a single Active Directory domain. All network servers now run Windows Server 2003, and all client computers run Windows XP Professional.Your staff provides technical support to the network. They frequently establish Remote Desktop connections with a domain controller named DC1.You hire 25 new support specialists for your staff. You use Csvde.exe to create Active Directory user accounts for all 25.A new support specialist named Paul reports that he cannot establish a Remote Desktop connection with DC1. He receives the message shown in the Logon Message exhibit. (Click the Exhibit button.)You open Gpedit.msc on DC1. You see the display shown in the Security Policy exhibit. (Click the Exhibit button.)You need to ensure that Paul can establish Remote Desktop connections with DC1.What should you do? ()

Your network consists of a single Active Directory domain. The functional level of the domain is Windows Server 2008 R2. All servers run Windows Server 2008 R2.   A corporate security policy requires complex passwords for user accounts that have administrator  privileges. You need to design a strategy that meets the following requirements: èEnsures that administrators use complex passwords   èMinimizes the number of servers required to support the solution What should you include in your design?()A、Implement Network Access Protection (NAP).B、Implement Active Directory Rights Management Services (AD RMS).C、Create a new Password Settings Object (PSO) for administrator accounts.D、Create a new child domain in the forest. Move all non-administrator accounts to the new domain.Configure a complex password policy in the root domain.

ou are the network administrator for your company. The network consists of a single Active Directory domain. All servers run Windows Server 2003. All client computers run Windows XP Professional.Two of the servers on the network contain highly confidential documents. The company’s written security policy states that all network connections with these servers must be encrypted by using an IPSec policy.You place the two servers in an organizational unit (OU) named SecureServers. You configure a Group Policy object (GPO) that requires encryption for all connections. You assign the GPO to the SecureServers OU.  You need to verify that users are connecting to the two servers by using encrypted connections.   What should you do?()A、Run the net view command.B、Run the gpresult command.C、Use the IP Security Monitor console.D、Use the IPSec Policy Management console.

Your network consists of a single Active Directory domain named contoso.com. All servers run Windows Server 2003 Service Pack 2 (SP2).You plan to deploy a new DNS zone named adatum.com. You need to ensure that only computers in the contoso.com domain can update host records in the new DNS zone. What should you do?()A、Create a new Active Directory forest named adatum.com. B、Create a new Active Directory-integrated zone named adatum.com. C、Create a new standard primary zone named adatum.com. Disable round robin. D、Create a new standard primary zone named adatum.com. Disable netmask ordering.

Your network contains an Active Directory domain named contoso.com. All domain controllers  and member servers run Windows Server 2008. All client computer run Windows 7.  From a client computer, you create an audit policy by using the Advanced Audit Policy  Configuration settings in the Default Domain Policy Group Policy object (GPO).   You discover that the audit policy is not applied to the member servers.    The audit policy is  applied to the client computers.   You need to ensure that the audit policy is applied to all member servers and all client computers.     What should you do()A、Add a WMI filter to the Default Domain Policy GPOB、Modify the security settings of the Default Domain Policy GPOC、Configure a startup script that runs auditpol.exe on the member servers.D、Configure a startup script that runs auditpol.exe on the domain controllers.

You are the network administrator for TestKing.com. The network consists of a single Active Directory domain named testking.com. All network servers run Windows Server 2003. You place computer accounts for servers in OUs that are organized by server roles. You apply GPOs to these servers at the OU level. You need to add a new server to the domain. You need to ensure that the appropriate GPOs are applied to this server. What should you do?()A、Prestage a domain computer account for the new server in the appropriate OU. Join the server to the domain by using the prestaged computer account.B、On the server, add the domain name for the Active Directory domain to the DNS suffix setting. Join the server to the domain.C、Assign a user account the Allow - Create permission for the appropriate OU. Join the new server to the domain by using the user account.D、Join the new server to the Active Directory domain. On the new server, run the gpupdate /force command.

You are the network administrator for . The network consists of a single Active Directory domain named All network servers run Windows Server 2003. Half of the client computers run Windows XP Professional and the other half run Windows NT 4.0 Workstation. You install Terminal Server on five member servers named TestKingSrvC through TestKingSrvG. You place all five servers in an organizational unit (OU) named Terminal Server. You link a group Policy object (GPO) to the Terminal Server OU. Two days later, users notify you, that the performance of TestKingSrvF is unacceptable slow. You discover that TestKingSrvF has 75 disconnected Terminal Server sessions.You need to configure all five terminal servers to end disconnected sessions after 15 minutes of inactivity. You must achieve this goal by using the minimum amount of administrative effort. What should you do?()A、Log on the console of each terminal server. In the RDP-Tcp connection properties, set the End a disconnected session option to 15 minutes.B、Edit the GPO to set the time limit for disconnected sessions to 15 minutes.C、On TestKingSrvC, run the tsdiscon] command to disconnect all 75 users from TestKingSrvFD、In Active Directory Users and Computers, set the End a disconnected session option for all domain user accounts to 15 minutes.

You are the network administrator for The network consists of a single Active Directory domain named All network servers run Windows Server 2003. The domain contains three domain controllers: DC1, DC2, and DC3. Each one hosts user data. DC1 experiences hard disk failure. You need to temporary restore the user data to DC2. Which type of restoration should you perform?()A、Automated System Recovery (ASR)B、NormalC、PrimaryD、Authoritative

Your network contains a single Active Directory domain. The functional level of the forest is  Windows Server 2008. The functional level of the domain is Windows Server 2008 R2. All DNS servers run Windows Server 2008. All domain controllers run Windows Server 2008 R2. You need to ensure that you can enable the Active Directory Recycle Bin. What should you do()A、Change the functional level of the forest.B、Change the functional level of the domain.C、Modify the Active Directory schema.D、Modify the Universal Group Membership Caching settings.

You are the network administrator for your company. Your network consists of a single Active Directory domain named All network servers run Windows Server 2003. A total of three servers are configured as domain controllers. You need to restore a failed domain controller named DC3. The last backup for any domain controller on the network occurred one week ago. First, you reinstall Windows Server 2003 on DC3. What should you do next?()A、Start DC3 and select Directory Services Restore Mode. Perform a nonauthoriative restoration.B、Start DC3 and select the Recovery Console. Perform a nonauthoriative restoration.C、Run Ntbackup.exe on DC3 to restore the System State data.D、Run the Active Directory Installation Wizard on DC3.

Your network contains an Active Directory domain named contoso.com. The contoso.com DNS  zone is stored in Active Directory. All domain controllers run Windows Server 2008 R2.     You need to identify if all of the DNS records used for Active Directory replication are correctly  registered.     What should you do()A、From the command prompt, use netsh.exe.B、From the command prompt, use dnslint.exe.C、From the Active Directory Module for Windows PowerShell, run the Get-ADRootDSE cmdlet.D、From the Active Directory Module for Windows PowerShell, run the Get-ADDomainController cmdlet.

You are the network administrator for . The network consists of a single Active Directory domain named . All servers run Windows Server 2003. All client computers run Windows XP Professional. The network contains a domain controller named TestKing3. You create a preconfigured user profile on a client computer named TKClient1. You need to ensure that all users receive the preconfigured user profile when they log on to the network for the first time. All users must still be able to personalize their desktop environments. What should you do?()A、From TKClient1, copy the user profile to //TestKing3/netlogon/Default User.B、From TKClient1, copy the user profile to //TestKing3/netlogon/Default User. Change the User Profile path for all users in the Active Directory to //TestKing3/netlogon/Default. User.C、From TKClient1, copy the user profile to the C:/Documents and Settings/Default User folder. Share the Default User profile on the network.D、Create a Folder Redirection policy in Active Directory.

You are the network administrator for The network consists of a single Active Directory domain named All servers run Windows Server 2003, and all client computers run Windows XP Professional. A user named Lilli receives a new computer named Client223. She successfully logs on to the domain. The next day, she tries to log on again. The domain name appears in the domain dropdown list in the dialog box. However, Lilli cannot log on. You try to log on by using Client223, but you are also unsuccessful. Then you use a local Administrator account to log on. You read the following error message in the system event log. "NETLOGON Event ID 3210: Failed to authenticate with //Server5, a Windows NT domain controller for domain TestKing". You search the computer account for Client223 in Active Directory Users and Computers, but the account does not appear. You need to ensure that Lilli can log on to the domain successfully. What should you do?()A、Recreate the user account for Lilli and add her to all appropriate security groups.B、Run the netdom reset 'Client223' /domain:'testking' command and then restart Client223.C、Add Client223 to a workgroup. Then join Client223 to the domain.D、Reset the computer account for Server5 in Active Directory Users and Computers.

Your network consists of a single Active Directory domain. All servers run Windows Server 2003Service Pack 2 (SP2). All client computers run Windows XP Professional Service Pack 3 (SP3).You need to ensure that locked out user accounts remain locked out until an administrator unlocks theaccounts.What should you do? ()A、In the Default Domain Policy, set the Account lockout duration to 0.B、In the Default Domain Policy, set the Account lockout duration to 99999.C、From Active Directory Users and Computers, select the Account is trusted for delegation option for all user accounts.D、From Active Directory Users and Computers, select the Account is sensitive and cannot be delegated option for all user accounts.

Your network consists of a single Active Directory domain. All domain controllers run Windows Server 2003 You upgrade all domain controllers to Windows Server 2008 You need to configure the Active Directory environment to support the application of multiple password policies What should you do()A、Create multiple Active Directory sites.B、On all domain controllers, run dcpromo /adv.C、On one domain controller, run dcpromo /adv.D、Raise the functional level of the domain to Windows Server 2008.

You are the network administrator for The network consists of a single Active Directory domain named All network servers run Windows Server 2003, and all client computers run Windows XP Professional. You use the Backup utility to schedule a full backup of TESTKINGDC1 every night. You ensure that the Active Directory configuration is also backed up. One week later, TESTKINGDC1 stops accepting logon requests. On investigation, you discover that the Active Directory configuration is corrupt. You need to restore TESTKINGDC1 as a functioning domain controller. Which two actions should you perform? ()(Each correct answer presents part of the solution. Choose two)A、Restart TESTKINGDC1 in Directory Services Restore Mode.B、Demote TESTKINGDC1 to a member server.C、Run the ntbackup systemstate command on TESTKINGDC1.D、Run the Backup utility and select the option to restore the System State data.E、Run the ntdsutil command on TESTKINGDC1.

单选题You are the network administrator for The network consists of a single Active Directory domain named All 40 network servers run Windows Server 2003, and all 1,500 client computers run Windows XP Professional. The servers are located in seven different buildings. All are configured to allow Remote Desktop connections. A new administrator named Tess King is hired to help you configure applications and perform disk defragmentation on all 40 servers. You need to enable Tess King to manage the servers remotely by using Remote Desktop for Administration. What should you do?()AAdd Tess King to the Administrators group.BAdd Tess King to the Power Users group.CAdd Tess King to the Remote Desktop Users group.DDelegate control of the Domain Controllers organizational unit (OU) to Tess King.EDelegate control of the Computers organizational unit (OU) to Tess King.

单选题You are the network administrator for The network consists of a single Active Directory domain named All servers run Windows Server 2003, and all client computers run Windows XP Professional. A user named Lilli receives a new computer named Client223. She successfully logs on to the domain. The next day, she tries to log on again. The domain name appears in the domain dropdown list in the dialog box. However, Lilli cannot log on. You try to log on by using Client223, but you are also unsuccessful. Then you use a local Administrator account to log on. You read the following error message in the system event log. "NETLOGON Event ID 3210: Failed to authenticate with //Server5, a Windows NT domain controller for domain TestKing". You search the computer account for Client223 in Active Directory Users and Computers, but the account does not appear. You need to ensure that Lilli can log on to the domain successfully. What should you do?()ARecreate the user account for Lilli and add her to all appropriate security groups.BRun the netdom reset 'Client223' /domain:'testking' command and then restart Client223.CAdd Client223 to a workgroup. Then join Client223 to the domain.DReset the computer account for Server5 in Active Directory Users and Computers.

单选题You are the network administrator for The network consists of a single Active Directory domain named All network servers run Windows Server 2003. You are responsible for defining the procedures for backing up and restoring all servers. TestKing uses the Backup utility. To enhance security, The IT department deploys certificates to all network users. Smart cards will be required to log on to the domain. A domain controller named TestKingDC1 is configured as the certificate server. You need to create a backup plan for TestKingDC1. The backup must include only the minimum amount of data needed to restore Active Directory and the certificate server. Which action or actions should you perform? ()(Choose all that apply)ABack up the System State data.BBack up C:/windows/ntds.CBack up C:/windows/sysvol.DBack up C:/windows/system32/certsrv.

单选题You are the network administrator for your company. Your network consists of a single Active Directory domain named All network servers run Windows Server 2003. A total of three servers are configured as domain controllers. You need to restore a failed domain controller named DC3. The last backup for any domain controller on the network occurred one week ago. First, you reinstall Windows Server 2003 on DC3. What should you do next?()AStart DC3 and select Directory Services Restore Mode. Perform a nonauthoriative restoration.BStart DC3 and select the Recovery Console. Perform a nonauthoriative restoration.CRun Ntbackup.exe on DC3 to restore the System State data.DRun the Active Directory Installation Wizard on DC3.

单选题Your network consists of a single Active Directory domain. All servers run Windows Server 2003 Service Pack 2 (SP2).You need to provide a user named User1 the required permissions to reset passwords in the domain. What should you do?()AInstall and run the Security Configuration Wizard (SCW).BFrom the Authorization Manager snap-in, modify the authorization store type.CFrom Active Directory Sites and Services, run the Delegation of Control Wizard.DFrom Active Directory Users and Computers, run the Delegation of Control Wizard.

单选题You are the network administrator for . The network consists of a single Active Directory domain named All network servers run Windows Server 2003. Half of the client computers run Windows XP Professional and the other half run Windows NT 4.0 Workstation. You install Terminal Server on five member servers named TestKingSrvC through TestKingSrvG. You place all five servers in an organizational unit (OU) named Terminal Server. You link a group Policy object (GPO) to the Terminal Server OU. Two days later, users notify you, that the performance of TestKingSrvF is unacceptable slow. You discover that TestKingSrvF has 75 disconnected Terminal Server sessions.You need to configure all five terminal servers to end disconnected sessions after 15 minutes of inactivity. You must achieve this goal by using the minimum amount of administrative effort. What should you do?()ALog on the console of each terminal server. In the RDP-Tcp connection properties, set the End a disconnected session option to 15 minutes.BEdit the GPO to set the time limit for disconnected sessions to 15 minutes.COn TestKingSrvC, run the tsdiscon] command to disconnect all 75 users from TestKingSrvFDIn Active Directory Users and Computers, set the End a disconnected session option for all domain user accounts to 15 minutes.

单选题Your company has a single Active Directory directory service domain. All servers in your environment run Windows Server 2003. All domain controllers run Active DirectoryCintegrated DNS. You create several static host (A) resource records. You need to verify that the DNS server is sending the correct host records to all client computers.  Which command-line tool should you use?()A netshB tracertC ntdsutilD nslookup

单选题You are the network administrator for . The network consists of a single Active Directory domain. All domain controllers run Windows Server 2003, and all client computers run Windows XP Professional. TestKing acquires a subsidiary. You receive a comma delimited file that contains the names of all user accounts at the subsidiary. You need to import these accounts into your domain. Which command should you use?()AldifdeBcsvdeCntdsutil with the authoritative restore optionDdsadd user

多选题You are the network administrator for The network consists of a single Active Directory domain named All network servers run Windows Server 2003, and all client computers run Windows XP Professional. You are required to implement a backup strategy for all five servers on the network. You use the Backup Utility to schedule nightly backup jobs. You create a domain user account named BackupSvc, and add it to the local Backup Operators group on all file servers. The scheduled backup jobs will use BackupSvc to log on to the network Nightly backups occur successfully for six weeks. Then, nightly backups fail on all servers. When you examine the event log of one server, you discover that the password for BackupSvc is expired. You reset the password and select the Password never expires option for BackupSvc. The next day, you discover that the previous night's backup failed on all file servers. You need to ensure that the next night's backup is successful. Which two actions should you perform? (Each correct answer presents part of the solution.() Choose two)AStop and restart every file server.BStop and restart the backup application on every file server.CChange the password for the backup job on every file server.DIn Active Directory Users and Computers, increase the value of the Account lockout threshold option.EUnlock the BackupSvc account.

单选题You are the network administrator for Your network consists of a single Active Directory domain named All network servers run Windows Server 2003, and all client computers run Windows XP Professional. TestKing has 16 different office locations. Each office is a separate Active Directory site. You work in the main office. A user named Anne works in a branch office. Every morning for one week, Anne reports that her user account is locked out. Each time, you are obliged to unlock her account. You suspect that Anne's account is being misused or attacked outside of regular business hours. You need to investigate the cause of the account lockout. Where should you search for security events?()AOnly in the event log of a domain controller in your site.BOnly in the event logs of the domain controllers in Anne's site.CIn the event logs of all domain controllers in all sites.DOnly in the event log of Anne's computer.

单选题Your network consists of a single Active Directory domain. All servers run Windows Server 2003Service Pack 2 (SP2). All client computers run Windows XP Professional Service Pack 3 (SP3).You need to ensure that locked out user accounts remain locked out until an administrator unlocks theaccounts.What should you do? ()AIn the Default Domain Policy, set the Account lockout duration to 0.BIn the Default Domain Policy, set the Account lockout duration to 99999.CFrom Active Directory Users and Computers, select the Account is trusted for delegation option for all user accounts.DFrom Active Directory Users and Computers, select the Account is sensitive and cannot be delegated option for all user accounts.

单选题You are the network administrator for The network consists of a single Active Directory domain The functional level of the domain is Windows 2000 native. All network servers run Windows Server 2003, and all client computers run Windows XP Professional. The network includes a shared folder named TestKingInfo. Your boss Dr. King reports that he is often unable to access this folder. You discover that the problem occurs whenever more than 10 users try to connect to the folder. You need to ensure that all appropriate users can access TestKingInfo. What should you do?()ADecrease the default user quota limit.BRaise the functional level of the domain to Windows Server 2003.CPurchase additional client access licenses.DMove TestKingInfo to one of the servers.