单选题Your company has an Active Directory domain. AlI servers run Windows Server 2008. Your company uses an Enterprise Root certificate authority (CA). You need to ensure that revoked certificate information is highly available. What should you do()AImplement an Online Certificate Status Protocol (OCSP) responder by using Network Load Balancing.BImplement an Online Certificate Status Protocol (OCSP) responder by using an Internet Security and Acceleration Server array.CPublish the trusted certificate authorities list to the domain by using a Group Policy Object (GPO).DCreate a new Group Policy Object (GPO) that allows users to trust peer certificates. Link the GPO to the domain.
单选题
Your company has an Active Directory domain. AlI servers run Windows Server 2008. Your company uses an Enterprise Root certificate authority (CA). You need to ensure that revoked certificate information is highly available. What should you do()
A
Implement an Online Certificate Status Protocol (OCSP) responder by using Network Load Balancing.
B
Implement an Online Certificate Status Protocol (OCSP) responder by using an Internet Security and Acceleration Server array.
C
Publish the trusted certificate authorities list to the domain by using a Group Policy Object (GPO).
D
Create a new Group Policy Object (GPO) that allows users to trust peer certificates. Link the GPO to the domain.
参考解析
解析:
暂无解析
相关考题:
Your company has an Active Directory domain. The company has purchased 100 new computers. You want to deploy the computers as members of the domain. You need to create the computer accounts in an organizational unit. What should you do()A、Run the csvde f computers.csv command.B、Run the ldifde f computers.ldf command.C、Run the dsadd computer command.D、Run the dsmod computer command.
Your company has a single Active Directory directory service domain. All servers in your environment run Windows Server 2003. Client computers run Windows XP or Windows Vista. You plan to create a security update scan procedure for client computers. You need to choose a security tool that supports all the client computers. Which tool should you choose? ()A、 UrlScan Security ToolB、 Enterprise Scan Tool (EST)C、 Malicious Removal Tool (MRT)D、 Microsoft Baseline Security Analyzer (MBSA)
Your company has an Active Directory forest. The corporate network uses DHCP to configure client computer IP addresses. The DHCP server has a DHCP client reservation for a portable computer named WKS1. You install asecond DHCP server on the network. You need to ensure that WKS1 receives the DHCP reservation from the DHCP service. What should you do?()A、Run the ipconfig /renew command on WKS1.B、Run the netsh add helper command on WKS1.C、Add the DHCP reservation for WKS1 to the second DHCP server.D、Add both DHCP servers to the RAS and IAS Servers group in the Active Directory domain.
Your company has an Active Directory domain. All servers run Windows Server 2008. You deploy a Certification Authority (CA) server. You create a new global security group named CertIssuers. You need to ensure that members of the CertIssuers group can issue, approve, and revoke certificates. What should you do()A、Assign the Certificate Manager role to the CertIssuers group.B、Place CertIssuers group in the Certificate Publisher groupC、Run the certsrv -add CertIssuers command promt of the certificate serverD、Run the add -member-membertype memberset CertIssuers command by using Microsoft WindowsPowershell
Your company has an Active Directory domain. You install a new domain controller in the domain. Twenty users report that they are unable to log on to the domain. You need to register the SRV records. Which command should you run on the new domain controller()A、Run the netsh interface reset command.B、Run the ipconfig /flushdns command.C、Run the dnscmd /EnlistDirectoryPartition command.D、Run the sc stop netlogon command followed by the sc start netlogon command.
Your company has an Active Directory domain. The company has a main office and a branch office. Both the offices have domain controllers that run Active Directory-integrated DNS zones. All client computers are configured to use the local domain controllers for DNS resolution. The domain controllers at the branch office location are configured as Read-Only Domain Controllers (RODC). You change the IP address of an exisiting server named SRV2 in the main office. You need the branch office DNS servers to reflect the change immediately. What should you do?() A、 Run the dnscmd /ZoneUpdateFromDs command on the branch office servers.B、 Run the dnscmd /ZoneUpdateFromDs command on a domain controller in the main office.C、 Change the domain controllers at the branch offices from RODCs to standard domain controllers.D、 Decrease the Minimum (default) TTL option to 15 minutes on the Start of Authority (SOA) record for thezone.
Your company has an Active Directory domain. AlI servers run Windows Server 2008. Your company uses an Enterprise Root certificate authority (CA). You need to ensure that revoked certificate information is highly available. What should you do()A、Implement an Online Certificate Status Protocol (OCSP) responder by using Network Load Balancing.B、Implement an Online Certificate Status Protocol (OCSP) responder by using an Internet Security and Acceleration Server array.C、Publish the trusted certificate authorities list to the domain by using a Group Policy Object (GPO).D、Create a new Group Policy Object (GPO) that allows users to trust peer certificates. Link the GPO to the domain.
Your company has an Active Directory forest. The company has servers that run Windows Server 2008 R2 and client computers that run Windows 7. The domain uses a set of GPO administrative templates that have been approved to support regulatory compliance requirements. Your partner company has an Active Directory forest that contains a single domain. The company has servers that run Windows Server 2008 R2 and client computers that run Windows 7. You need to configure your partner companys domain to use the approved set of administrative templates. What should you do()A、Use the Group Policy Management Console (GPMC) utility to back up the GPO to a file. In each site, import the GPO to the default domain policy.B、Copy the ADMX files from your companys PDC emulator to the PolicyDefinitions folder on the partner companys PDC emulator.C、Copy the ADML files from your companys PDC emulator to the PolicyDefinitions folder on thepartner companys PDC emulator.D、Download the conf.adm, system.adm, wuau.adm, and inetres.adm files from the Microsoft Updates Web site. Copy the ADM files to the PolicyDefinitions folder on the partner companys PDC emulator.
You have an Exchange Server 2010 organization. Your company has a relationship with another company. The partner company has an Exchange Server 2010 organization. You need to recommend a security solution to meet the following requirements: .Ensure that all e-mail delivery between your servers and the partner companys servers is encrypted .Ensure that all communication between your servers and the partner companys servers is authenticated What should you include in the solution?()A、Active Directory Rights Management Services (AD RMS)B、Domain SecurityC、Forms-based AuthenticationD、Secure/Multipurpose Internet Mail Extensions (S/MIME)
Your company has a main office and two branch offices.Domain controllers in the main office host an Active Directory-integrated zone.The DNS servers in the branch offices host a secondary zone for the domain and use the main office DNS servers as their DNS Master servers for the zone.The company adds a new branch office. You add a member server named Branch3 and install the DNS Server server role on the server. You configure a secondary zone for the domain. The zone transfer fails.You need to configure DNS to provide zone data to the DNS server in the new branch office.What should you do?()A、Run dnscmd by using the ZoneResetMasters option.B、Run dnscmd by using the ZoneResetSecondaries option.C、Add the new DNS server to the Zone Transfers tab on one of the DNS servers in the main office.D、Add the new DNS server to the DNSUpdateProxy Global security group in Active Directory Users and Computers.
Your company has a single Active Directory domain. All domain controllers run Windows Server 2003. You install Windows Server 2008 R2 on a server. You need to add the new server as a domain controller in your domain. What should you do first()A、On the new server, run dcpromo /adv.B、On the new server, run dcpromo /createdcaccount.C、On a domain controller run adprep /rodcprep.D、On a domain controller, run adprep /forestprep.
Your company has a single active directory domain. All servers run windows server 2008. You install an additional DNS server that runs windows server 2008. You need to delete the pointer record for the IP address 10.3.2.127. what should you do?()A、Use DNS manager to delete the 127.in-addr.arpa zone.B、Run the dnscmd /recordelte 10.3.2.127 command at the command prompty.C、Run the dnscmd /zonedelete 127.in-addr.apa command at the command prompt.D、Run the dnscmd /recorddelete 10.in-addr.arpa 172.2.3 PRT command at the command prompt.
Your company network has an Active Directory forest that has one parent domain and one child domain. The child domain has two domain controllers that run Windows Server 2008. All user accounts from the child domain are migrated to the parent domain. The child domain is scheduled to be decommissioned. You need to remove the child domain from the Active Directory forest. What are two possible ways to achieve this goal()A、Delete the computer accounts for each domain controller in the child domain. Remove the trust relationship between the parent domain and the child domain.B、Run the Dcpromo tool that has individual answer files on each domain controller in the child domain.C、Run the Computer Management console to stop the Domain Controller service on both domain controllers in the child domain.D、Use Server Manager on both domain controllers in the child domain to uninstall the Active Directory domain services role.
Your company has a single Active Directory domain. AlI domain controllers run Windows Server 2003 You install Windows Server 2008 on a server. You need to add the new server as a domaincontroller in your domain.What should you do first()A、On the new server, run dcpromo /adv.B、On the new server, run dcpromo /createdcaccount.C、On a domain controller run adprep /rodcprep.D、On a domain controller, run adprep /forestprep.
Your company has an Active Directory domain. A user attempts to log on to a computer that was turned off for twelve weeks. The administrator receives an error message that authentication has failed. You need to ensure that the user is able to log on to the computer. What should you do()A、Run the netdom TRUST /reset command.B、Run the netsh command with the set and machine options.C、Run the Active Directory Users and Computers console to disable, and then enable the computer account.D、Reset the computer account. Disjoin the computer from the domain, and then rejoin the computer to the domain.
Certkiller has an Active Directory forest with six domains. The company has 5 sites. The company requires a new distributed application that uses a custom application directory partition named ResData for data replication. The application is installed on one member server in five sites. You need to configure the five member servers to receive the ResData application directory partition for data replication. What should you do()A、Run the Dcpromo utility on the five member servers.B、Run the Regsvr32 command on the five member serversC、Run the Webadmin command on the five member serversD、Run the RacAgent utility on the five member servers
单选题Your company has an Active Directory forest. The company has servers that run Windows Server 2008 amd client computers that run Windows Vista. The domain uses a set of GPO administrative templates that have been approved to support regulatory compliance requirements. Your partner company has an Active Directory forest that contains a single domain, The company has servers that run Windows Server 2008 and client computers that run Windows Vista. You need to configure your partner company’s domain to use the approved set of administrative templates. What should you do()AUse the Group Policy Management Console (GPMC) utility to back up the GPO to a file. In each site, import the GPO to the default domain policy.BCopy the ADMX files from your company’s PDC emulator to the PolicyDefinitions folder on the partner company’s PDC emulatorCCopy the ADML files from your company’s PDC emulator to the PolicyDefinitions folder on the partner company’s PDC emulatorDDownload the conf.adm, system.adm, wuau.adm, and inetres.adm files from the Microsoft Updates Web site. Copy the ADM files to the PolicyDefinitions folder on thr partner company’s emulator.
单选题Your network consists of a single Active Directory domain. All servers run Windows Server 2003 Service Pack 2 (SP2).You need to provide a user named User1 the required permissions to reset passwords in the domain. What should you do?()AInstall and run the Security Configuration Wizard (SCW).BFrom the Authorization Manager snap-in, modify the authorization store type.CFrom Active Directory Sites and Services, run the Delegation of Control Wizard.DFrom Active Directory Users and Computers, run the Delegation of Control Wizard.
单选题Your company has an Active Directory domain. All servers run Windows Server 2008 R2. Your company uses an Enterprise Root certificate authority (CA). You need to ensure that revoked certificate information is highly available. What should you do()AImplement an Online Certificate Status Protocol (OCSP) responder by using Network Load Balancing.BImplement an Online Certificate Status Protocol (OCSP) responder by using an Internet Security and Acceleration Server array.CPublish the trusted certificate authorities list to the domain by using a Group Policy Object (GPO).DCreate a new Group Policy Object (GPO) that allows users to trust peer certificates. Link the GPO to the domain.
单选题Your company has an Active Directory forest. The company has servers that run Windows Server 2008 R2 and client computers that run Windows 7. The domain uses a set of GPO administrative templates that have been approved to support regulatory compliance requirements. Your partner company has an Active Directory forest that contains a single domain. The company has servers that run Windows Server 2008 R2 and client computers that run Windows 7. You need to configure your partner company’s domain to use the approved set of administrative templates. What should you do()AUse the Group Policy Management Console (GPMC) utility to back up the GPO to a file. In each site, import the GPBCopy the ADMX files from your company’s PDC emulator to the PolicyDefinitions folder on the partner company’s PDCCCopy the ADML files from your company’s PDC emulator to the PolicyDefinitions folder on the partner company’s PDC DDownload the conf.adm, system.adm, wuau.adm, and inetres.adm files from the Microsoft Updates Web site.
单选题Your company has a single Active Directory directory service domain. All servers in your environment run Windows Server 2003. All domain controllers run Active DirectoryCintegrated DNS. You create several static host (A) resource records. You need to verify that the DNS server is sending the correct host records to all client computers. Which command-line tool should you use?()A netshB tracertC ntdsutilD nslookup
单选题Your company has an Active Directory forest. The corporate network uses DHCP to configure client computer IP addresses. The DHCP server has a DHCP client reservation for a portable computer named WKS1. You install a second DHCP server on the network. You need to ensure that WKS1 receives the DHCP reservation from the DHCP service. What should you do?()A Run the ipconfig /renew command on WKS1B Run the netsh add helper command on WKS1C Add the DHCP reservation for WKS1 to the second DHCP serverD Add both DHCP servers to the RAS and IAS Servers group in the Active Directory domain
单选题Your company has a single Active Directory directory service domain. All servers in your environment run Windows Server 2003. Client computers run Windows XP or Windows Vista. You plan to create a security update scan procedure for client computers. You need to choose a security tool that supports all the client computers. Which tool should you choose? ()A UrlScan Security ToolB Enterprise Scan Tool (EST)C Malicious Removal Tool (MRT)D Microsoft Baseline Security Analyzer (MBSA)
单选题Your company has an Active Directory forest that contains a single domain. The domain member server has an Active Directory Federation Services (AD FS) server role installed. You need to configure AD FS to ensure that AD FS tokens contain information from the Active Directory domain. What should you do()AAdd and configure a new account store.BAdd and configure a new account partner.CAdd and configure a new resource partner.DAdd and configure a Claims-aware application.
单选题Your company has a single Active Directory domain. AlI domain controllers run Windows Server 2003 You install Windows Server 2008 on a server. You need to add the new server as a domaincontroller in your domain.What should you do first()AOn the new server, run dcpromo /adv.BOn the new server, run dcpromo /createdcaccount.COn a domain controller run adprep /rodcprep.DOn a domain controller, run adprep /forestprep.
单选题Your company has a single Active Directory directory service forest with multiple domains. The company has a main office with 1,000 users and a single branch office with 500 users. Each office is aseparate Active Directory site. The main office Active Directory site has two domain controllers with Global Catalog services. Company employees must be able to work in both offices. You need to plan the placement and configuration of domain controllers. What should you do?()A Deploy two additional domain controllers in the main office Active Directory site.B Deploy global catalog servers in the branch office Active Directory site.C Enable change notification on the site link between the main office Active Directory site and the branch office Active Directory site.D Disable change notification on the site link between the main office Active Directory site and the branch office Active Directory site.
单选题Your company has a single Active Directory domain. All domain controllers run Windows Server 2003. You install Windows Server 2008 R2 on a server. You need to add the new server as a domain controller in your domain. What should you do first()AOn the new server, run dcpromo /adv.BOn the new server, run dcpromo /createdcaccount.COn a domain controller run adprep /rodcprep.DOn a domain controller, run adprep /forestprep.
单选题Your company has a single Active Directory directory service domain. Servers in your environment run Windows Server 2003. Client computers run Windows XP or Windows Vista. You plan to create an internal centrally managed security update infrastructure for client computers. You need to choose a security update management tool that supports all the client computers. Which tool should you choose? ()A Microsoft Assessment and Planning (MAP) ToolkitB Microsoft Baseline Security AnalyzerC Microsoft System Center Operations ManagerD Windows Server Update Services (WSUS)