单选题Your company has an Active Directory domain. All servers run Windows Server 2008 R2.  Your  company uses an Enterprise Root certification authority (CA) and an Enterprise Intermediate CA.  The Enterprise Intermediate CA certificate expires.    You need to deploy a new Enterprise Intermediate CA certificate to all computers in the domain. What should you do()AImport the new certificate into the Intermediate Certification Store on the Enterprise Root CA server.BImport the new certificate into the Intermediate Certification Store on the Enterprise Intermediate CA  server.CImport the new certificate into the Intermediate Certification Store in the Default Domain Controllers  group policy object.DImport the new certificate into the Intermediate Certification Store in the Default Domain group policy  object.

单选题
Your company has an Active Directory domain. All servers run Windows Server 2008 R2.  Your  company uses an Enterprise Root certification authority (CA) and an Enterprise Intermediate CA.  The Enterprise Intermediate CA certificate expires.    You need to deploy a new Enterprise Intermediate CA certificate to all computers in the domain. What should you do()
A

Import the new certificate into the Intermediate Certification Store on the Enterprise Root CA server.

B

Import the new certificate into the Intermediate Certification Store on the Enterprise Intermediate CA  server.

C

Import the new certificate into the Intermediate Certification Store in the Default Domain Controllers  group policy object.

D

Import the new certificate into the Intermediate Certification Store in the Default Domain group policy  object.


参考解析

解析: 暂无解析

相关考题:

Your company has an Active Directory domain. The company has purchased 100 new computers. You want to deploy the computers as members of the domain. You need to create the computer accounts in an organizational unit. What should you do()A、Run the csvde f computers.csv command.B、Run the ldifde f computers.ldf command.C、Run the dsadd computer  command.D、Run the dsmod computer  command.

Your company has a single Active Directory directory service domain. All servers in your environment run Windows Server 2003. Client computers run Windows XP or Windows Vista. You plan to create a security update scan procedure for client computers. You need to choose a security tool that supports all the client computers.  Which tool should you choose? ()A、 UrlScan Security ToolB、 Enterprise Scan Tool (EST)C、 Malicious Removal Tool (MRT)D、 Microsoft Baseline Security Analyzer (MBSA)

Your company has an Active Directory forest. The corporate network uses DHCP to configure client computer IP addresses. The DHCP server has a DHCP client reservation for a portable computer named WKS1. You install asecond DHCP server on the network. You need to ensure that WKS1 receives the DHCP reservation from the DHCP service. What should you do?()A、Run the ipconfig /renew command on WKS1.B、Run the netsh add helper command on WKS1.C、Add the DHCP reservation for WKS1 to the second DHCP server.D、Add both DHCP servers to the RAS and IAS Servers group in the Active Directory domain.

Your company has an Active Directory domain. All servers run Windows Server 2008. You deploy a Certification Authority (CA) server. You create a new global security group named CertIssuers. You need to ensure that members of the CertIssuers group can issue, approve, and revoke certificates. What should you do()A、Assign the Certificate Manager role to the CertIssuers group.B、Place CertIssuers group in the Certificate Publisher groupC、Run the certsrv -add CertIssuers command promt of the certificate serverD、Run the add -member-membertype memberset CertIssuers command by using Microsoft WindowsPowershell

ou are the network administrator for your company. The network consists of a single Active Directory domain. All servers run Windows Server 2003. All client computers run Windows XP Professional.Two of the servers on the network contain highly confidential documents. The company’s written security policy states that all network connections with these servers must be encrypted by using an IPSec policy.You place the two servers in an organizational unit (OU) named SecureServers. You configure a Group Policy object (GPO) that requires encryption for all connections. You assign the GPO to the SecureServers OU.  You need to verify that users are connecting to the two servers by using encrypted connections.   What should you do?()A、Run the net view command.B、Run the gpresult command.C、Use the IP Security Monitor console.D、Use the IPSec Policy Management console.

Your company has an Active Directory domain. The company has a main office and a branch office. Both the offices have domain controllers that run Active Directory-integrated DNS zones. All client computers are configured to use the local domain controllers for DNS resolution. The domain controllers at the branch office location are configured as Read-Only Domain Controllers (RODC). You change the IP address of an exisiting server named SRV2 in the main office. You need the branch office DNS servers to reflect the change immediately. What should you do?() A、 Run the dnscmd /ZoneUpdateFromDs command on the branch office servers.B、 Run the dnscmd /ZoneUpdateFromDs command on a domain controller in the main office.C、 Change the domain controllers at the branch offices from RODCs to standard domain controllers.D、 Decrease the Minimum (default) TTL option to 15 minutes on the Start of Authority (SOA) record for thezone.

Your company has an Active Directory forest. The company has servers that run Windows Server   2008 R2 and client computers that run Windows 7. The domain uses a set of GPO administrative  templates that have been approved to support regulatory compliance requirements.   Your partner company has an Active Directory forest that contains a single domain. The company has  servers that run Windows Server 2008 R2 and client computers that run Windows 7.   You need to configure your partner companys domain to use the approved set of administrative  templates.   What should you do()A、Use the Group Policy Management Console (GPMC) utility to back up the GPO to a file. In each site,  import the GPO to the default domain policy.B、Copy the ADMX files from your companys PDC emulator to the PolicyDefinitions folder on the partner  companys PDC emulator.C、Copy the ADML files from your companys PDC emulator to the PolicyDefinitions folder on thepartner  companys PDC emulator.D、Download the conf.adm, system.adm, wuau.adm, and inetres.adm files from the Microsoft Updates  Web site. Copy the ADM files to the PolicyDefinitions folder on the partner companys PDC emulator.

You have an Exchange Server 2010 organization.  Your company has a relationship with another company.  The partner company has an Exchange Server 2010 organization.  You need to recommend a security solution to meet the following requirements:  .Ensure that all e-mail delivery between your servers and the partner companys servers is encrypted .Ensure that all communication between your servers and the partner companys servers is authenticated What should you include in the solution?()A、Active Directory Rights Management Services (AD RMS)B、Domain SecurityC、Forms-based AuthenticationD、Secure/Multipurpose Internet Mail Extensions (S/MIME)

Your company has a single Active Directory domain. All domain controllers run Windows Server  2003.     You install Windows Server 2008 R2 on a server.     You need to add the new server as a domain controller in your domain.     What should you do first()A、On the new server, run dcpromo /adv.B、On the new server, run dcpromo /createdcaccount.C、On a domain controller run adprep /rodcprep.D、On a domain controller, run adprep /forestprep.

All client computers on your company network run Windows 7 and are members of an Active Directory Domain Services domain. Your company policy requires that all unnecessary services be disabled on the computers. The Sales department staff has been provided with new mobile broadband adapters that use the Global System for Mobile Communications (GSM) technology. You need to ensure that portable computers can connect to the broadband GSM network. Which service should be enabled on the portable computers?()A、WLAN AutoConfigB、WWAN AutoConfigC、Computer BrowserD、Portable Device Enumerator Service

Your company has an Active Directory domain. All servers run Windows Server 2008 R2. Your  company uses an Enterprise Root certification authority (CA) and an Enterprise Intermediate CA.     The Enterprise Intermediate CA certificate expires.     You need to deploy a new Enterprise Intermediate CA certificate to all computers in the domain.     What should you do()A、Import the new certificate into the Intermediate Certification Store on the Enterprise Root CA server.B、Import the new certificate into the Intermediate Certification Store on the Enterprise Intermediate CA server.C、Import the new certificate into the Intermediate Certification Store in the Default Domain Controllers group policy obD、Import the new certificate into the Intermediate Certification Store in the Default Domain group policy object.

Your company has a single Active Directory directory service domain. Servers in your environment run Windows Server 2003. Client computers run Windows XP or Windows Vista. You plan to create an internal centrally managed security update infrastructure for client computers. You need to choose a security update management tool that supports all the client computers.  Which tool should you choose? ()A、 Microsoft Assessment and Planning (MAP) ToolkitB、 Microsoft Baseline Security AnalyzerC、 Microsoft System Center Operations ManagerD、 Windows Server Update Services (WSUS)

Your company has a single Active Directory forest that has six domains. All DNS servers in the forest run Windows Server 2008. You need to ensure that all public DNS quieries are channeled through a singlecahing- only DNS server. Which two actions should you perform?() A、Disable the root hintsB、Enable BIND secondariesC、Configure a forwarder to the caching DNS serverD、Configure a GlobalNames host (A) record for the hostname of the caching DNS server

Your company has a single active directory domain. All servers run windows server 2008. You install an additional DNS server that runs windows server 2008. You need to delete the pointer record for the IP address 10.3.2.127. what should you do?()A、Use DNS manager to delete the 127.in-addr.arpa zone.B、Run the dnscmd /recordelte 10.3.2.127 command at the command prompty.C、Run the dnscmd /zonedelete 127.in-addr.apa command at the command prompt.D、Run the dnscmd /recorddelete 10.in-addr.arpa 172.2.3 PRT command at the command prompt.

Your company has an Active Directory Domain Services (AD DS) domain. All servers run Windows Server 2008 R2. All client computers run Windows 7. You use Microsoft Enterprise Desktop Virtualization (MED-V) to support client virtualization requirements. You need to ensure that all MED-V virtual machine (VM) images can be centrally stored and are available to all client computers. What should you do?()A、Install and configure IIS on a member server.B、Configure a shared folder on a member server.C、Create a single workspace for all client computers.D、Install and configure Microsoft SQL Server 2008 on a member server.

Your company network has an Active Directory forest that has one parent domain and one child domain. The child domain has two domain controllers that run Windows Server 2008. All user accounts from the child domain are migrated to the parent domain. The child domain is scheduled to be decommissioned. You need to remove the child domain from the Active Directory forest. What are two possible ways to achieve this goal()A、Delete the computer accounts for each domain controller in the child domain. Remove the trust relationship between the parent domain and the child domain.B、Run the Dcpromo tool that has individual answer files on each domain controller in the child domain.C、Run the Computer Management console to stop the Domain Controller service on both domain controllers in the child domain.D、Use Server Manager on both domain controllers in the child domain to uninstall the Active Directory domain services role.

Your company has an Active Directory domain. A user attempts to log on to a computer that was turned off for twelve weeks. The administrator receives an error message that authentication has failed. You need to ensure that the user is able to log on to the computer. What should you do()A、Run the netdom TRUST /reset command.B、Run the netsh command with the set and machine options.C、Run the Active Directory Users and Computers console to disable, and then enable the computer account.D、Reset the computer account. Disjoin the computer from the domain, and then rejoin the computer to the domain.

单选题Your company has an Active Directory forest. The company has servers that run Windows Server 2008 amd client computers that run Windows Vista. The domain uses a set of GPO administrative templates that have been approved to support regulatory compliance requirements. Your partner company has an Active Directory forest that contains a single domain, The company has servers that run Windows Server 2008 and client computers that run Windows Vista. You need to configure your partner company’s domain to use the approved set of administrative templates. What should you do()AUse the Group Policy Management Console (GPMC) utility to back up the GPO to a file. In each site, import the GPO to the default domain policy.BCopy the ADMX files from your company’s PDC emulator to the PolicyDefinitions folder on the partner company’s PDC emulatorCCopy the ADML files from your company’s PDC emulator to the PolicyDefinitions folder on the partner company’s PDC emulatorDDownload the conf.adm, system.adm, wuau.adm, and inetres.adm files from the Microsoft Updates Web site. Copy the ADM files to the PolicyDefinitions folder on thr partner company’s emulator.

单选题Contoso Ltd. has a single Active Directory forest that has five domains. Each domain has two DNS servers. Each DNS server hosts Active Directory-integrated zones for all five domains. All domain controllers run Windows Server 2008 R2.Contoso acquires a company named Tailspin Toys. Tailspin Toys has a single Active Directory forest that contains a single domain. You need to configure the DNS system in the Contoso forest to provide name resolution for resources in both forests. What should you do?()AConfigure client computers in the Contoso forest to use the Tailspin Toys DNS server as the alternate DNS server.BCreate a new conditional forwarder and store it in Active Directory. Replicate the new conditional forwarder to all DNS servers in the Contoso forest.CCreate a new application directory partition in the Contoso forest. Enlist the directory partition for all DNS servers.DCreate a new host (A) record in the GlobalNames folder on one of the DNS servers in the Contoso forest. Configure the host (A) record by using the Tailspin Toys domain name and the IP address of the DNS server in the Tailspin Toys forest.

单选题Your network consists of a single Active Directory domain. All servers run Windows Server 2003 Service Pack 2 (SP2).You need to provide a user named User1 the required permissions to reset passwords in the domain. What should you do?()AInstall and run the Security Configuration Wizard (SCW).BFrom the Authorization Manager snap-in, modify the authorization store type.CFrom Active Directory Sites and Services, run the Delegation of Control Wizard.DFrom Active Directory Users and Computers, run the Delegation of Control Wizard.

单选题Your company has an Active Directory domain. All servers run Windows Server 2008 R2. Your   company uses an Enterprise Root certificate authority (CA).    You need to ensure that revoked certificate information is highly available.    What should you do()AImplement an Online Certificate Status Protocol (OCSP) responder by using Network Load Balancing.BImplement an Online Certificate Status Protocol (OCSP) responder by using an Internet Security and  Acceleration Server array.CPublish the trusted certificate authorities list to the domain by using a Group Policy Object (GPO).DCreate a new Group Policy Object (GPO) that allows users to trust peer certificates. Link the GPO to  the domain.

单选题Your company has an Active Directory forest. The company has servers that run Windows Server  2008 R2 and client computers that run Windows 7. The domain uses a set of GPO administrative  templates that have been approved to support regulatory compliance requirements.     Your partner company has an Active Directory forest that contains a single domain. The company  has servers that run Windows Server 2008 R2 and client computers that run Windows 7.     You need to configure your partner company’s domain to use the approved set of administrative  templates.   What should you do()AUse the Group Policy Management Console (GPMC) utility to back up the GPO to a file. In each site, import the GPBCopy the ADMX files from your company’s PDC emulator to the PolicyDefinitions folder on the partner company’s PDCCCopy the ADML files from your company’s PDC emulator to the PolicyDefinitions folder on the partner company’s PDC DDownload the conf.adm, system.adm, wuau.adm, and inetres.adm files from the Microsoft Updates Web site.

单选题Your company has a single Active Directory directory service domain. All servers in your environment run Windows Server 2003. All domain controllers run Active DirectoryCintegrated DNS. You create several static host (A) resource records. You need to verify that the DNS server is sending the correct host records to all client computers.  Which command-line tool should you use?()A netshB tracertC ntdsutilD nslookup

单选题Your company has a single Active Directory directory service domain. All servers in your environment run Windows Server 2003. Client computers run Windows XP or Windows Vista. You plan to create a security update scan procedure for client computers. You need to choose a security tool that supports all the client computers.  Which tool should you choose? ()A UrlScan Security ToolB Enterprise Scan Tool (EST)C Malicious Removal Tool (MRT)D Microsoft Baseline Security Analyzer (MBSA)

单选题Your company has a single Active Directory domain. All domain controllers run Windows Server 2003.    You install Windows Server 2008 R2 on a server.    You need to add the new server as a domain controller in your domain.    What should you do first()AOn the new server, run dcpromo /adv.BOn the new server, run dcpromo /createdcaccount.COn a domain controller run adprep /rodcprep.DOn a domain controller, run adprep /forestprep.

单选题Your company has a single Active Directory directory service domain. Servers in your environment run Windows Server 2003. Client computers run Windows XP or Windows Vista. You plan to create an internal centrally managed security update infrastructure for client computers. You need to choose a security update management tool that supports all the client computers.  Which tool should you choose? ()A Microsoft Assessment and Planning (MAP) ToolkitB Microsoft Baseline Security AnalyzerC Microsoft System Center Operations ManagerD Windows Server Update Services (WSUS)

多选题Your company has an Active Directory Domain Services (AD DS) domain. All servers run Windows Server 2008 R2. All client computers run Windows 7. Your environment includes Microsoft Enterprise Desktop Virtualization (MED-V). You use MED-V to support temporary test environments. You need to ensure that the disk space used by obsolete Workspaces is automatically minimized. Which two actions should you perform?()AConfigure the Workspace as revertible.BSet an expiration date for the Workspace.CSpecify the number of image versions to keep.DConfigure automatic deletion of the Workspace.