单项选择题

You have a single Active Directory directory service domain. All client computers run either Windows Vista or Windows XP. You create and configure a Group Policy object (GPO) named Secure Client  Computer. You need to ensure that the Secure Client Computer GPO is automatically applied to current  and future Windows XP client computers. 
What should you do?()

A. Create a WMI filter that limits the scope of the Secure Client Computer GPO to the Windows XP operating system. Link the WMI filter to the GPO. Link the GPO to the domain.
B. Create a global security group that contains all of the Windows XP client computers. Edit the permissions of the Secure Client Computer GPO to allow the global security group the Read and Apply Group Policy permissions. Link the Secure Client Computer GPO to the domain.
C. Use the Delegation of Control Wizard at the domain level, and delegate the Generate Resultant Set of policy (Planning) right to the Windows XP client computers. Link the Secure Client Computer GPO to the domain.
D. Use the Delegation of Control Wizard at the domain level, and delegate the Generate Resultant Set of policy (Logging) right to the Windows XP client computers. Link the Secure Client Computer GPO to the domain.


您可能感兴趣的试卷

你可能感兴趣的试题

1.多项选择题

Your network consists of Windows XP computers in a single Active Directory directory service  
domain. All computers are located in a single Active Directory site. You need to design and deploy a new  Group Policy object (GPO) that automatically installs a custom application on computers. 
What are two possible ways to achieve this goal?()

A. Link the GPO to the domain and assign the application.
B. Link the GPO to the site and assign the application.
C. Link the GPO to the domain and publish the application.
D. Link the GPO to the site and publish the application.

2.单项选择题

Your company plans to distribute an application to all of its client computers by using GroupPolicy. You save a file named setup.msi to a local folder on the domain controller. You assign the Authenticated Users group the Read and Read & Execute permissions for the folder. You create a new Group Policy  object (GPO) and a new Computer Configuration software installation package, and you point the package to the setup.msi file in the local folder. You link the GPO to an organizational unit (OU) that contains a computer object for a test client computer. When you log on to the test client computer, you  notice that the application is not installed. You need to ensure that the application is installed on the test computer. 
What should you do?()

A. Modify the permissions on the folder that contains the setup.msi file so that authenticated users have the List Folder Contents permission. Log off the client computer and then log on.
B. Modify the permissions on the folder that contains the setup.msi file so that authenticated users have the List Folder Contents permission. Restart the client computer.
C. Place the setup.msi file into a shared folder. Modify the software installation package to point to the shared folder. Log off the client computer and then log on.
D. Place the setup.msi file into a shared folder. Modify the software installation package to point to the shared folder. Restart the client computer.

3.单项选择题

Your network consists of Windows XP computers. All computers are joined to a single Active  Directory directory service domain and located in a single Active Directory site. You create a new Group  Policy object (GPO) and link it to the site. The policy configures default screensaver settings. User  accounts of users in the research department are located in an organizational unit (OU) named Research.  You need to allow users in the research department to configure a different screensaver setting on their  computers. 
What should you do?()

A. Move the user accounts of users in the research department to the Users container.
B. Configure a local security policy on all computers in the research department to allow users to modify their screensaver settings.
C. Add users in the research department to a domain group. Allow the group the Apply Group Policy permission for the GPO.
D. Add users in the research department to a domain group. Deny the group the Apply Group Policy permission to the GPO.

4.单项选择题

You have a single Active Directory directory service domain. You create organizational units (OUs)  named Corporate and Support. You move the corporate user and computer accounts into the Corporate  OU. You move the accounts of computers in the support department into the Support OU. You need to ensure that users have one screensaver while using computers that are in the Corporate OU, and aseparate screensaver while using computers that are in the Support OU. 
What should you do?()

A. Create a new parent OU for the Corporate and Support OUs and name the parent OU Users. Move all user objects to the Users OU, and then create and link a Group Policy object (GPO) with the screensaver setting to the Users OU.
B. Create and link a Group Policy object (GPO) with the screensaver setting to the Support OU and select the Block Inheritance option.
C. Create and link a Group Policy object (GPO) with the screensaver setting to the Corporate OU, create and link a GPO with the screensaver setting to the Support OU, and then enable loopback processing in Replace mode on the Support OUs GPO.
D. Create and link a Group Policy object (GPO) with the screensaver setting to the Support OU and select the Enforced option.

5.单项选择题

You have a single Active Directory directory service domain. All servers run Windows Server 2003. You create several new Group Policies. You need to determine the end result of these Group Policies before applying the settings. 
What should you do?()

A. Use Resultant Set of Policy (RSoP) in Planning mode.
B. Use Resultant Set of Policy (RSoP) in Logging mode.
C. Use Event Viewer to view the system log.
D. Use Event Viewer to view the application log.

6.单项选择题

Your company has a single Active Directory directory service forest with multiple domains. The  company has a main office with 1,000 users and a single branch office with 500 users. Each office is aseparate Active Directory site. The main office Active Directory site has two domain controllers with Global  Catalog services. Company employees must be able to work in both offices. You need to plan the  placement and configuration of domain controllers. 
What should you do?()

A. Deploy two additional domain controllers in the main office Active Directory site.
B. Deploy global catalog servers in the branch office Active Directory site.
C. Enable change notification on the site link between the main office Active Directory site and the branch office Active Directory site.
D. Disable change notification on the site link between the main office Active Directory site and the branch office Active Directory site.

7.单项选择题

You have a single Active Directory directory service domain with three sites named Site1,Site2,and  Site3. There are site links between all three sites,and replication between sites occurs every 30 minutes. You need to ensure that all replication traffic is routed through Site2. 
What should you do?()  

A. Define a preferred bridgehead server for Site2.
B. Reduce the interval between replications between Site1 and Site2 and between Site2 and Site3.
C. Decrease the cost of the site link between Site1 and Site3.
D. Increase the cost of the site link between Site1 and Site3.

8.单项选择题

Your company has a single Active Directory directory service forest named contoso.com. A partner organization has a forest named fabrikam.com. Both forests are set to the Windows 2000 forest functional  level. Domains named contoso.com and fabrikam.com are set to Windows 2000 Native Mode. You plan to create a forest trust relationship between contoso.com and fabrikam.com. You need to be able to configure selective authentication for the trust relationship.
What should you do?()

A. Raise the forest functional level on contoso.com and fabrikam.com to Windows Server 2003.
B. Raise the domain functional level on contoso.com and fabrikam.com to Windows Server 2003.
C. Raise the domain functional level and the forest functional level on contoso.com to Windows Server 2003.
D. Raise the domain functional level and the forest functional level on fabrikam.com to Windows Server 2003.

10.单项选择题

You are the network administrator for Fabrikam, Inc. Your network consists of a single Active  Directory forest that contains one domain named fabrikam.com. The functional level of the forest is  Windows Server 2003. Fabrikam, Inc., acquires a company named Contoso, Ltd. The Contoso, Ltd., network consists of a single Active Directory forest that contains a root domain named contoso.com and a  child domain named usa.contoso.com. The functional level of the forest is Windows 2000. The functional level of the usa.contoso.com domain is Windows 2000 native. A business decision by the company requires the usa.contoso.com domain to be removed. You need to move all user accounts from the  usa.contoso.com domain to the fabrikam.com domain by using the Active Directory Migration Tool. You  need to accomplish this task without changing the logon rights and permissions for all other users. You  need to ensure that users in usa.contoso.com can log on to fabrikam.com by using their current user names and passwords. 
What should you do?()

A. Create a two-way Windows Server 2003 external trust relationship between the fabrikam.com domainand the contoso.com domain.
B. Create a one-way Windows Server 2003 external trust relationship in which the fabrikam.com domain trusts the contoso.com domain.
C. Create a temporary two-way external trust relationship between the fabrikam.com domain and the usa.contoso.com domain.
D. Create a temporary one-way external trust relationship in which the usa.contoso.com domain trusts the fabrikam.com domain.

最新试题

You are the network administrator for Contoso Pharmaceuticals. Your network consists of a single  Active Directory forest that contains three domains. The forest root domain is named contoso.com. The domain contains two child domains named usa.contoso.com and europe.contoso.com. The functional level of the forest is Windows Server 2003. Each domain contains two Windows Server 2003 domain controllers named DC1 and DC2. DC1 in the contoso.com domain performs the following two operations master roles: schema master and domain naming master. DC1 in each child domain performs the following three operations master roles: PDC emulator master, relative ID (RID) master, and infrastructure master. DC1 in each domain is also a global catalog server. The user account for Nancy Buchanan in the europe.contoso.com domain is a member of the Medicine Students security group. Because of a name change, the domain administrator of europe.contoso.com changes the Last name field of Nancy’s user account from Buchanan to Anderson. The domain administrator of usa.contoso.com discovers that the user account for Nancy is still listed as Nancy Buchanan. You need to ensure that the user account for Nancy Anderson is correctly listed in the Medicine Students group. What should you do?()

题型:单项选择题

You are the network administrator for your company. The network consists of a single Active Directory domain. The domain includes an organizational unit (OU) named Processing. There are 100 computer accounts in the Processing OU. You create a Group Policy object (GPO) named NetworkSecurity and link it to the domain. You configure NetworkSecurity to enable security settings through the Computer Configuration section of the Group Policy settings. You need to ensure that NetworkSecurity will apply only to the computers in the Processing OU. You need to minimize the number of GPO links. What should you do?()

题型:单项选择题

You are the network administrator for your company. The network consists of a single Active  Directory forest. The forest consists of 19 Active Directory domains. Fifteen of the domains contain  Windows Server 2003 domain controllers. The functional level of all the domains is Windows 2000 native.  The network also consists of a single Microsoft Exchange 2000 Server organization. You need to create  groups that can be used only to send e-mail messages to user accounts throughout the company. You  want to achieve this goal by using the minimum amount of replication traffic and minimizing the size of the  Active Directory database. You need to create a plan for creating e-mail groups for your company. What should you do?()

题型:单项选择题

You have a single Active Directory directory service domain. You use Group Policy to assign applications. A computer named Desktop1 must be moved to a different organizational unit (OU). Youneed to ascertain the effect that the move will have on the applications that are assigned to the computer account. What should you do?()

题型:单项选择题

Your company has a main office in Chicago and a branch office in New York. The company has a singleActive Directory directory service forest with four domains. Two of the domain controllers are described in the following table.  An application has a server component and a client component. When the server component is installed, several schema classes and attributes are added. A user in the ne.sales.contoso.com domain installs the client component on his client computer. You then install the server component. Thirty minutes after you install the server component, the user attempts to run the client component, but receives an error message stating that the schema objects cannot be found. You verify that the objects are present on DC1. The users logon server is DC4. You need to ensure that the user can immediately run the client component. What should you do?()

题型:单项选择题

You are the network administrator for your company. Your network consists of a single Active Directory domain. The functional level of the domain is Windows Server 2003. You add eight servers for a new application. You create an organizational unit (OU) named Application to hold the servers and other resources for the application. Users and groups in the domain will need varied permissions on the application servers. The members of a global group named Server Access Team need to be able to grant access to the servers. The Server Access Team group does not need to be able to perform any other tasks on the servers. You need to allow the Server Access Team group to grant permissions for the application servers without granting the Server Access Team group unnecessary permissions. What should you do?()

题型:单项选择题

Your company has a single Active Directory directory service forest with multiple domains. The Schema FSMO role is held by one of the domain controllers in the forest root domain. The DomainThe safer , easier way to help you pass any IT exams. Naming Master FSMO role is held by one of the domain controllers in a child domain. All domain controllers have Windows Server 2003 installed.  You need to upgrade all domain controllers to Windows Server 2003 R2. Which two actions should you perform?()

题型:多项选择题

You have a single Active Directory directory service domain. You use a Group Policy object (GPO) to apply security settings to your client computers. You configure the startup type for system services settings in a new GPO, and you link the GPO to an organizational unit (OU).  You discover that the startup type for system services on one of the client computers has not been updated. You need to ensure that the Group Policy settings are applied to the client computer.What should you do?()

题型:单项选择题

You are the network administrator for A. Datum Corporation. The network consists of a single Active Directory forest that contains three domains named adatum.com, child1.adatum.com, and child2.adatum.com. The functional level of the forest is Windows Server 2003. The help desk department is responsible for resetting passwords for all user accounts in the forest except for accounts that have administrative privileges. There is an organizational unit (OU) named Corp_Users in each domain that contains the user accounts in that domain. All of the user accounts that have administrative privileges are in the default Users container in each domain. There is a universal group named HD_Users in the adatum.com domain. All user accounts for the help desk department users are members of the HD_Users group. You need to delegate the required authority for resetting passwords to the users in the help desk department. For which Active Directory component or components should you delegate control? To answer,select the appropriate component or components in the work area. 

题型:问答题

You have a single Active Directory directory service domain. All servers run Windows Server 2003. You need to specify the list of applications that users are permitted to run. You create a new Group Policy object (GPO) and link it to the domain. What should you do next?()

题型:单项选择题