单选题Your company has two Active Directory forests as shown in the following table: Forest name Forest functional level Domain(s) contoso.com Windows Server 2008 contoso.com fabrikam.com Windows Server 2008 fabrikam.com eng.fabrikam.com The forests are connected by using a two-way forest trust. Each trust direction is configured with forest-wide authentication. The new security policy of the company prohibits users from the eng.fabrikam.com domain to access resources in the contoso.com domain. You need to configure the forest trust to meet the new security policy requirement. What should you do()ADelete the outgoing forest trust in the contoso.com domain.BDelete the incoming forest trust in the contoso.com domain.CChange the properties of the existing incoming forest trust in the contoso.com domain from Forest-wide authenticatDChange the properties of the existing outgoing forest trust in the contoso.com domain to exclude *.eng.fabrikam.com
单选题
Your company has two Active Directory forests as shown in the following table: Forest name Forest functional level Domain(s) contoso.com Windows Server 2008 contoso.com fabrikam.com Windows Server 2008 fabrikam.com eng.fabrikam.com The forests are connected by using a two-way forest trust. Each trust direction is configured with forest-wide authentication. The new security policy of the company prohibits users from the eng.fabrikam.com domain to access resources in the contoso.com domain. You need to configure the forest trust to meet the new security policy requirement. What should you do()
A
Delete the outgoing forest trust in the contoso.com domain.
B
Delete the incoming forest trust in the contoso.com domain.
C
Change the properties of the existing incoming forest trust in the contoso.com domain from Forest-wide authenticat
D
Change the properties of the existing outgoing forest trust in the contoso.com domain to exclude *.eng.fabrikam.com
参考解析
解析:
暂无解析
相关考题:
Your network consists of a single Active Directory domain that has three Active Directory sites. Each site contains two Active Directory domain controllers. All domain controllers run Windows Server 2003 Service Pack 2 (SP2). All domain controllers have Windows Support Tools installed. You need to verify the replication status of Active Directory. Which tool should you use?()A、Active Directory Sites and ServicesB、Nltest.exeC、Network MonitorD、Replmon.exe
Your company has a branch office that is configured as a separate Active Directory site and has an Actrve Directory domain controller. The Active Directory site requires a local Global Catalog server to support a new application. You need to configure the domain controller as a Global Catalog server. Which tool should you use()A、The Dcpromo.exe utilityB、The Server Manager consoleC、The Computer Management consoleD、The Active Directory Sites and Services consoleE、The Actrve Directory Domains and Trusts console
Your company has a branch office that is configured as a separate Active Directory site and has an Active Directory domain controller. The Active Directory site requires a local Global Catalog server to support a new application. You need to configure the domain controller as a Global Catalog server. Which tool should you use()A、The Dcpromo.exe utilityB、The Server Manager consoleC、The Computer Management consoleD、The Active Directory Sites and Services consoleE、The Active Directory Domains and Trusts console
Your network consists of a single Active Directory domain. All domain controllers run Windows Server2008 R2. Your company and an external partner plan to collaborate on a project. The external partner has an Active Directory domain that contains Windows Server 2008 R2 domain controllers. You need to design a collaboration solution that meets the following requirements: èAllows users to prevent sensitive documents from being forwarded to untrusted recipients or from being printed. èAllows users in the external partner organization to access the protected content to which they have been granted rights. èSends all inter-organizational traffic over port 443. èMinimizes the administrative effort required to manage the external users. What should you include in your design?()A、Establish a federated trust between your company and the external partner. Deploy a Windows Server 2008 R2 server that has Microsoft SharePoint Foundation 2010 installed.B、Establish a federated trust between your company and the external partner. Deploy a Windows Server 2008 R2 server that runs Microsoft SharePoint 2010 and that has the Active Directory Rights Management Services (AD?RMS) role installed.C、Establish an external forest trust between your company and the external partner. Deploy a Windows Server 2008 R2 server that has the Active Directory Certificate Services server role installed. Implement Encrypting File System (EFS).D、Establish an external forest trust between your company and the external partner. Deploy a Windows Server 2008 R2 server that has the Active Directory Rights Management Service (AD?RMS)role installed and Microsoft SharePoint Foundation 2010 installed.
Your Windows Server 2003 environment consists of a single Active Directory directory service forest with multiple domains. The forest functional level is set to Windows 2000 Server. Your company has a main office and four branch offices. Each office has two domain controllers. The domain controllers in the main office are global catalog servers. In the branch offices, searches for some printers in Active Directory are slow. You need to improve the performance of Active Directory printer searches in the four branch offices. What should you do?() A、 Enable universal group membership caching in each branch office.B、 Increase the number of domain controllers in each branch office.C、 Add global catalog services to each branch office.D、 Upgrade the forest functional level to Windows Server 2003.
Your company has an Active Directory forest that contains only Windows Server 2008 domain controllers. You need to prepare the Active Directory domain to install Windows Server 2008 R2 domain controllers. Which two tasks should you perform()A、Run the adprep /forestprep command.B、Run the adprep /domainprep command.C、Raise the forest functional level to Windows Server 2008.D、Raise the domain functional level to Windows Server 2008.
You are designing the Windows Server 2003 Active Directory forest structure to meet the business and technical requirements. Which forest structure should you use?()A、 One Active Directory forest with one domain.B、 One Active Directory forest with three domains.C、 One Active Directory forest with four domains.D、 Two Active Directory forests with one domain in each forest.E、 Three Active Directory forests with one domain in each forest.
Your company has an Active Directory domain. The company has two domain controllers named DC1 and DC2. DC1 holds the schema master role. DC1 fails. You log on to Active Directory by using the administrator account. You are not able to transfer the schema master role. You need to ensure that DC2 holds the schema master role. What should you do()A、Register the Schmmgmt.dll. Start the Active Directory Schema snap-in.B、Configure DC2 as a bridgehead server.C、On DC2, seize the schema master role.D、Log off and log on again to Active Directory by using an account that is a member of the Schema Admins group. St
Your company has three Active Directory domains in a single forest. You install a new Active Directory enabled application. The application ads new user attributes to the Active Directory schema. You discover that the Active Directory replication traffic to the Global Catalogs has increased. You need to prevent the new attributes from being replicated to the Global Catalog. You must achieve this goal without affecting application functionality. What should you do()A、Change the replication interval for the DEFAULTIPSITELINK object to 9990.B、Change the cost for the DEFAULTIPSITELINK object to 9990.C、Make the new attributes in the Active Directory as defunct.D、Modify the properties in the Active Directory schema for the new attributes.
Contoso Ltd. has a single Active Directory forest that has five domains. Each domain has two DNS servers. Each DNS server hosts Active Directory-integrated zones for all five domains. All domain controllers run windows server 2008. Contoso acquires a company names Tailspin Toys. Tailspin Toys has a single Active Directory forest that contains a single domain. You need to configure the DNS system in the Contoso forest to provide name resolution for resources in both forests. What should you do?()A、Configure client computers in the Contoso forest to use the Tailspin Toys DNS server as the alternate DNS serverB、Create a new conditional forwarder and store it in Active Directory. Replicate the new conditional forwarded to all DNS server in the Contoso forest.C、Create a new application directory partition in the Contoso forest. Enlist the directory partition for all DNS serversD、Create a new host (A) record in the GlobalNames folder on one of the DNS servers in the contoso forest. Configure the host (A) record by using the Tailspin Toys domain name and the ip address of the DNS server in the Tailspin Toys forest.
You are a security administrator for your company. The network consists of three Active Directory domains. All Active Directory domains are running at a Windows Server 2003 mode functionality level. Employees in the editorial department of your company need access to resources on file servers that are in each of the Active Directory domains. Each Active Directory domain in the company contains at least one editorial department employee user account. You need to create a single group named Company Editors that contains all editorial department employee user accounts and that has access to the resources on file server computers. What should you do?()A、 Create a global distribution group in the forest root domain and name it Company Editors.B、 Create a global security group in the forest root domain and name it Company Editors.C、 Create a universal distribution group in the forest root domain and name it Company Editors. D、 Create a universal security group in the forest root domain and name it Company Editors.
Your company has a main office and 40 branch offices. Each branch office is configured as a separate Active Directory site that has a dedicated read-only domain controller (RODC). An RODC server is stolen from one of the branch offices. You need to identify the user accounts that were cached on the stolen RODC server. Which utility should you use()A、Dsmod.exeB、Ntdsutil.exeC、Active Directory Sites and ServicesD、Active Directory Users and Computers
Your company has a main office and a branch office. The company has a single-domain Active Directory forest. The main office has two domain controllers named DC1 and DC2 that run Windows Server 2008. The branch office has a Windows Server 2008 read-only domain controller (RODC) named DC3. All domain controllers hold the DNS Server role and are configured as Active Directory-integrated zones. The DNS zones only allow secure updates. You need to enable dynamic DNS updates on DC3. What should you do()A、Run the Ntdsutil.exe DS Behavior commands on DC3.B、Run the Dnscmd.exe /ZoneResetType command on DC3.C、Reinstall Active Directory Domain Services on DC3 as a writable domain controller.D、Create a custom application directory partition on DC1. Configure the partition to store Active Directory- integrated zones.
Your company has two Active Directory forests as shown in the following table: Forest name Forest functional level Domain(s) contoso.com Windows Server 2008 contoso.com fabrikam.com Windows Server 2008 fabrikam.com eng.fabrikam.com The forests are connected by using a two-way forest trust. Each trust direction is configured with forest-wide authentication. The new security policy of the company prohibits users from the eng.fabrikam.com domain to access resources in the contoso.com domain. You need to configure the forest trust to meet the new security policy requirement. What should you do()A、Delete the outgoing forest trust in the contoso.com domain.B、Delete the incoming forest trust in the contoso.com domain.C、Change the properties of the existing incoming forest trust in the contoso.com domain from Forest-wide authenticatD、Change the properties of the existing outgoing forest trust in the contoso.com domain to exclude *.eng.fabrikam.com
单选题Your company has a branch office that is configured as a separate Active Directory site and has an Actrve Directory domain controller. The Active Directory site requires a local Global Catalog server to support a new application. You need to configure the domain controller as a Global Catalog server. Which tool should you use()AThe Dcpromo.exe utilityBThe Server Manager consoleCThe Computer Management consoleDThe Active Directory Sites and Services consoleEThe Actrve Directory Domains and Trusts console
单选题Your company has an Active Directory forest. The company has servers that run Windows Server 2008 amd client computers that run Windows Vista. The domain uses a set of GPO administrative templates that have been approved to support regulatory compliance requirements. Your partner company has an Active Directory forest that contains a single domain, The company has servers that run Windows Server 2008 and client computers that run Windows Vista. You need to configure your partner company’s domain to use the approved set of administrative templates. What should you do()AUse the Group Policy Management Console (GPMC) utility to back up the GPO to a file. In each site, import the GPO to the default domain policy.BCopy the ADMX files from your company’s PDC emulator to the PolicyDefinitions folder on the partner company’s PDC emulatorCCopy the ADML files from your company’s PDC emulator to the PolicyDefinitions folder on the partner company’s PDC emulatorDDownload the conf.adm, system.adm, wuau.adm, and inetres.adm files from the Microsoft Updates Web site. Copy the ADM files to the PolicyDefinitions folder on thr partner company’s emulator.
单选题Your company has an Active Directory domain. The company has two domain controllers named DC1 and DC2. DC1 holds the schema master role. DC1 fails. You log on to Active Directory by using the administrator account. You are not able to transfer the schema master role. You need to ensure that DC2 holds the schema master role. What should you do()ARegister the Schmmgmt.dll. Start the Active Directory Schema snap-in.BConfigure DC2 as a bridgehead server.COn DC2, seize the schema master role.DLog off and log on again to Active Directory by using an account that is a member of the Schema Admins group. Start the Active Directory Schema snap-in.
单选题Your company has an Active Directory domain. The company has two domain controllers named DC1 and DC2. DC1 holds the Schema Master role DC1 fails You log on to Actrve Directory by using the administrator account. You are not able to transfer the Schema Master operations role. You need to ensure that DC2 holds the Schema Master role. What should you do()ARegister the Schmmgmt.dll. Start the Active Directory Schema snap-in.BConfigure DC2 as a bridgehead serverCOn DC2, seize the Schema Master roleDLog off and log on again to Active Directory by using an account that is a member of the Schema Administrators group. Start the Actrve Directory Schema snap-in.
单选题You are a security administrator for your company. The network consists of three Active Directory domains. All Active Directory domains are running at a Windows Server 2003 mode functionality level. Employees in the editorial department of your company need access to resources on file servers that are in each of the Active Directory domains. Each Active Directory domain in the company contains at least one editorial department employee user account. You need to create a single group named Company Editors that contains all editorial department employee user accounts and that has access to the resources on file server computers. What should you do?()A Create a global distribution group in the forest root domain and name it Company Editors.B Create a global security group in the forest root domain and name it Company Editors.C Create a universal distribution group in the forest root domain and name it Company Editors. D Create a universal security group in the forest root domain and name it Company Editors.
单选题You are designing the Windows Server 2003 Active Directory forest structure to meet the business and technical requirements. Which forest structure should you use?()A One Active Directory forest with one domain.B One Active Directory forest with three domains.C One Active Directory forest with four domains.D Two Active Directory forests with one domain in each forest.E Three Active Directory forests with one domain in each forest.
单选题Your company has an Active Directory forest. The company has servers that run Windows Server 2008 R2 and client computers that run Windows 7. The domain uses a set of GPO administrative templates that have been approved to support regulatory compliance requirements. Your partner company has an Active Directory forest that contains a single domain. The company has servers that run Windows Server 2008 R2 and client computers that run Windows 7. You need to configure your partner company’s domain to use the approved set of administrative templates. What should you do()AUse the Group Policy Management Console (GPMC) utility to back up the GPO to a file. In each site, import the GPBCopy the ADMX files from your company’s PDC emulator to the PolicyDefinitions folder on the partner company’s PDCCCopy the ADML files from your company’s PDC emulator to the PolicyDefinitions folder on the partner company’s PDC DDownload the conf.adm, system.adm, wuau.adm, and inetres.adm files from the Microsoft Updates Web site.
单选题Your company has a branch office that is configured as a separate Active Directory site and has an Active Directory domain controller. The Active Directory site requires a local Global Catalog server to support a new application. You need to configure the domain controller as a Global Catalog server. Which tool should you use()AThe Dcpromo.exe utilityBThe Server Manager consoleCThe Computer Management consoleDThe Active Directory Sites and Services consoleEThe Active Directory Domains and Trusts console
多选题Your company has an Active Directory forest that contains only Windows Server 2003 domain controllers. You need to prepare the Active Directory domain to install Windows Server 2008 domain controllers. Which two tasks should you perform()ARun the adprep /forestprep command.BRun the adprep /domainprep command.CRaise the forest functional level to Windows Server 2008.DRaise the domain functional level to Windows Server 2008.
单选题Your company has a single Active Directory directory service forest with multiple domains. The company has a main office with 1,000 users and a single branch office with 500 users. Each office is aseparate Active Directory site. The main office Active Directory site has two domain controllers with Global Catalog services. Company employees must be able to work in both offices. You need to plan the placement and configuration of domain controllers. What should you do?()A Deploy two additional domain controllers in the main office Active Directory site.B Deploy global catalog servers in the branch office Active Directory site.C Enable change notification on the site link between the main office Active Directory site and the branch office Active Directory site.D Disable change notification on the site link between the main office Active Directory site and the branch office Active Directory site.
多选题Your company has a single Active Directory directory service forest. All user accounts are located in the Users container. You need to create a number of organizational units (OUs) that will be used to store user accounts. What are two possible ways to achieve this goal?()AUse the Active Directory Sites and Services snap-in.BUse the Active Directory Users and Computers snap-in.CUse the Dsadd command-line tool with the OU parameter.DUse the Dsmod command-line tool with the OU parameter.