多项选择题

You have two Active Directory directory service forests named contoso.com and fabrikam.com. All users log on to the contoso.com domain. All servers run Windows Server 2003 and are members of the fabrikam.com domain. You create a one-way forest trust in which fabrikam.com is trusting contoso.com. Forest-wide authentication is enabled. You need to provide only selected users with access to a server in the fabrikam.com domain.
Which two actions should you perform?()

A. Grant the users the Allowed to Authenticate permission on the computer object representing the server.
B. Grant the users the Modify permission on the computer object representing the server.
C. Change the one-way forest trust to a two-way forest trust.
D. Change the properties of the forest trust from Forest-wide authentication to Selective authentication.


您可能感兴趣的试卷

你可能感兴趣的试题

1.单项选择题

You are the network administrator for your company. Your network consists of a single Active Directory domain. The functional level of the domain is Windows Server 2003. You add eight servers for a new application. You create an organizational unit (OU) named Application to hold the servers and other resources for the application. Users and groups in the domain will need varied permissions on the application servers. The members of a global group named Server Access Team need to be able to grant access to the servers. The Server Access Team group does not need to be able to perform any other tasks on the servers. You need to allow the Server Access Team group to grant permissions for the application servers without granting the Server Access Team group unnecessary permissions. 
What should you do?()

A. Create a Group Policy object (GPO) for restricted groups. Configure the GPO to make the Server Access Team group a member of the Power Users group on each application server. Link the GPO to the Application OU.
B. Grant the Server Access Team group permissions to modify computer objects in the Application OU.
C. Move the Server Access Team group object into the Application OU.
D. Create domain local groups that grant access to the application servers. Grant the Server Access Team group permissions to modify the membership of the domain local groups.

2.多项选择题

You are the network administrator for your company. The network consists of a single Active Directory domain with three sites named Site1, Site2, and Site3. The sites and site links are configured to use Site2 to connect Site1 and Site3. Each site contains three Windows Server 2003 domain controllers. A domaincontroller in each site is configured as a preferred bridgehead server. All user and group accounts are created in Site1. Several new users start work in Site2. When they attempt to log on to the network, the logon fails. You confirm that the user accounts are created and are visible in Site1 and Site2. You discover that the preferred IP bridgehead server in Site2 failed. You repair the server and confirm that replication is successful to Site2. You need to ensure that the failure of a single domain controller in any site will not interfere with Active Directory replication between sites. 
What are two possible ways to achieve this goal?()

A. Configure an IP site link between Site1 and Site3.
B. Configure two domain controllers in each site as preferred IP bridgehead servers.
C. Configure two domain controllers in each site as preferred SMTP bridgehead servers.
D. Configure each site to have no preferred bridgehead servers.
E. Configure an SMTP site link between each of the sites. Assign a cost of 200 to the SMTP site link.

4.单项选择题

You have a single Active Directory directory service domain. You have an application that adds Active Directory Schema attributes during installation. The attributes replicate as part of global catalog replication. Your user account is a member of the Domain Admins, Schema Admins, and Enterprise Admins global groups. You test the application and decide not to deploy it to production.  You need to ensure that the attributes that are added by the application are no longer available in Active Directory. 
Using the Active Directory Schema snap-in,what should you do?()

A. Clear the Index this attribute in the Active Directory option for each attribute that is added by the application.
B. Clear the Attribute is active option for each attribute that is added by the application.
C. Clear the Replicate this attribute to the Global Catalog option for each attribute that is added by the application.
D. Clear the Allow this attribute to be shown in advanced view option for each attribute that is added by the application.

5.单项选择题

You are the network administrator for Northwind Traders. The network consists of a single Active Directory forest that contains one root domain and one child domain. The forest also contains three separate sites, as shown in the Network Diagram exhibit. (Click the Exhibit button.) The network is not fully routed and there is no direct physical connection between Site1 and Site3. Site links are not bridged. You discover that the domain controllers for namerica.northwindtraders.com located in Site1 have additional accounts that are not on the domain controllers for namerica.northwindtraders.com located in Site3. You examine the directory service log in Event Viewer on a domain controller for namerica.northwindtraders.com. You discover the error message shown in the Error Message exhibit. (Click the Exhibit button.) You need to resolve the condition that is causing this error. 
What should you do? ()

A. Add a domain controller for the namerica.northwindtraders.com domain to Site2.
B. Configure a site link bridge between the site links for Site1 and Site3.
C. Configure at least one domain controller in each site to be a global catalog server.
D. Create a site link between Site1 and Site3.

6.单项选择题

You have a single Active Directory directory service domain. You back up your domain controllers on a nightly basis. An organizational unit (OU) is accidently deleted. You need to restore the objects that were located in the OU. 
What should you do?()

A. Perform a nonauthoritative restore of the domain controller.
B. Perform an authoritative restore of the domain controller.
C. Restore the system state data on the domain controller.
D. Restore the system volume on the domain controller.

7.单项选择题

Your company has a main office in Chicago and a branch office in New York. The company has a singleActive Directory directory service forest with four domains. Two of the domain controllers are described in the following table.  
An application has a server component and a client component. When the server component is installed, several schema classes and attributes are added. A user in the ne.sales.contoso.com domain installs the client component on his client computer. You then install the server component. Thirty minutes after you install the server component, the user attempts to run the client component, but receives an error message stating that the schema objects cannot be found. You verify that the objects are present on DC1. The users logon server is DC4. You need to ensure that the user can immediately run the client component. 
What should you do?()

A. Open the Active Directory Domains and Trusts snap-in on DC1. Create a shortcut trust between contoso.com and ne.sales.contoso.com.
B. Open the Active Directory Users and Computers snap-in on DC1. Create a new computer object named DC4 in the Domain Controllers organizational unit (OU). Add a Kerberos name mapping named DC1 in the properties of DC4.
C. Open the Active Directory Sites and Services snap-in on DC1. Create a connection object between DC1 and DC4. Manually initiate replication from DC1 to DC4.
D. Open ADSIEDIT.msc. Modify CN=NTFRS Subscriptions,CN=DC1,OU=DomainControllers,DC=contoso,DC=com to include DC4 in the repsTo and repsFrom attributes.

8.单项选择题

You have a single Active Directory directory service domain. You back up your domain controllers on a nightly basis. You perform Group Policy backups on a nightly basis. A Group Policy object (GPO) is accidentally deleted. You need to restore the GPO. 
What should you do?()

A. Perform a nonauthoritative restore of the Active Directory database.
B. Perform an authoritative restore of the Active Directory database.
C. Select the Import Policy option in the Group Policy Object Editor.
D. Restore the GPO by using the Group Policy Management Console.

9.单项选择题

You are the network administrator for Contoso, Ltd. The network consists of a single Active Directory forest that contains a single domain named contoso.com. You have a user account named CONTOSO\admin that is a member of the Domain Admins global group. You need to create a new child domain named NA.contoso.com in the forest. You install a stand-alone Windows Server 2003 computer named DC3. You use the Active Directory Installation Wizard to promote DC3 to a domain controller in the new domain. You choose to create a domain controller for a new child domain in an existing domain tree. You enter the user name and password for CONTOSO\admin. You choose contoso.com as the parent domain, and you type NA as the name of the child domain. You receive the error message shown in the exhibit. (Click the Exhibit button.) You need to be able to create the new child domain. 
What should you do?()

A. Enter the network credentials for a member of the local Administrators group.
B. Add DC3 to the contoso.com domain and then run the Active Directory Installation Wizard.
C. Enter the network credentials for a member of the Enterprise Admins group for the contoso.com forest.
D. Enter the network credentials for a member of the Schema Admins group for the contoso.com forest.

10.单项选择题

You have a single Active Directory directory service domain. You use Group Policy to assign applications. A computer named Desktop1 must be moved to a different organizational unit (OU). Youneed to ascertain the effect that the move will have on the applications that are assigned to the computer account. 
What should you do?()

A. Use the RSoP tool in logging mode on Desktop1.
B. Use the RSoP tool in planning mode on Desktop1.
C. Use the RSoP tool in logging mode on a domain controller.
D. Use the RSoP tool in planning mode on a domain controller.

最新试题

You have a single Active Directory directory service domain. You back up your domain controllers on a nightly basis. An organizational unit (OU) is accidently deleted. You need to restore the objects that were located in the OU. What should you do?()

题型:单项选择题

You are the network administrator for your company. The network consists of a single Active Directory domain. The domain includes an organizational unit (OU) named Processing. There are 100 computer accounts in the Processing OU. You create a Group Policy object (GPO) named NetworkSecurity and link it to the domain. You configure NetworkSecurity to enable security settings through the Computer Configuration section of the Group Policy settings. You need to ensure that NetworkSecurity will apply only to the computers in the Processing OU. You need to minimize the number of GPO links. What should you do?()

题型:单项选择题

Your company has a single Active Directory directory service domain that includes a main office and two branch offices. Each branch office has its own Active Directory site. All user accounts are placed into organizational units (OUs) based on department. Multiple Group Policy objects (GPOs) are linked at the domain, the site, and the OU levels. A user in Atlanta transfers to a different branch office and joins a different department. You move her user account into the corresponding OU. After logging on to her new client computer, the user notices that the desktop settings are different from the settings she had in her previous location. You need to find out the effect of all GPOs on the user. What should you do?()

题型:单项选择题

You are the network administrator for your company. Your network consists of a single Active Directory domain. The functional level of the domain is Windows Server 2003. You add eight servers for a new application. You create an organizational unit (OU) named Application to hold the servers and other resources for the application. Users and groups in the domain will need varied permissions on the application servers. The members of a global group named Server Access Team need to be able to grant access to the servers. The Server Access Team group does not need to be able to perform any other tasks on the servers. You need to allow the Server Access Team group to grant permissions for the application servers without granting the Server Access Team group unnecessary permissions. What should you do?()

题型:单项选择题

You are the network administrator for your company. The network consists of a single Active Directory domain. All servers run Windows Server 2003. All client computers run Windows XP Professional with themost recent service pack. All client computers have computer accounts in an organizational unit (OU) named CompanyComputers. The company requires all computers to be kept up-to-date with service packs and hotfixes from Microsoft. Administrators will manually update servers as required. You need to configure the network so that client computers are automatically updated as new critical updates are issued. What are two possible ways to achieve this goal?()

题型:多项选择题

You are the network administrator for Contoso, Ltd. The network consists of a single Active Directory forest that contains a single domain named contoso.com. You have a user account named CONTOSO\admin that is a member of the Domain Admins global group. You need to create a new child domain named NA.contoso.com in the forest. You install a stand-alone Windows Server 2003 computer named DC3. You use the Active Directory Installation Wizard to promote DC3 to a domain controller in the new domain. You choose to create a domain controller for a new child domain in an existing domain tree. You enter the user name and password for CONTOSO\admin. You choose contoso.com as the parent domain, and you type NA as the name of the child domain. You receive the error message shown in the exhibit. (Click the Exhibit button.) You need to be able to create the new child domain. What should you do?()

题型:单项选择题

You are the network administrator for your company. Your network consists of a single Active Directory domain. All servers run Windows Server 2003. All user accounts in your domain are located in an organizational unit (OU) named User Accounts. User accounts are separated into two types: accounts for users who use portable computers and accounts for users who use desktop computers. The accounts for the users who use portable computers are in an OU named Portable, and the accounts for the users who use desktop computers are in an OU named Desktop. The OU structure is shown in the work area. Users who use portable computers often travel with them, but they do not connect to the network when they are out of the office. You need to install an application on all client computers. Users must be able to run the application even if the client computer is not connected to the network. You need to perform the installation in a way that reduces network load on the installation source. All software installed by using a Group Policy object (GPO) must require as little support as possible. You need to configure Group Policy to install the application. You also need to link any GPO to the appropriate OU. What should you do? To answer,drag the appropriate action or actions for a GPO to perform to the correct OU or OUs in the work area. 

题型:问答题

You are the network administrator for your company. Your network consists of a single Active  Directory domain. Three security groups named Accountants, Processors, and Management are located in an organizational unit (OU) named Accounting. All of the user accounts that belong to these three  groups are also in the Accounting OU. You create a Group Policy object (GPO) and link it to the  Accounting OU. You configure the GPO to disable the display options under the User Configuration  section of the GPO. You need to achieve the following goals: You need to ensure that the GPO applies to  all user accounts that are members of the Processors group. You need to prevent the GPO fromapplying  to any user account that is a member of the Accountants group. You need to prevent the GPO from  applying to any user account that is a member of the Management group, unless the user account is also  a member of the Processors group.What should you do?()

题型:单项选择题

Why is a data source required?()

题型:单项选择题

Your Windows Server 2003 environment consists of a single Active Directory directory service forest with multiple domains. The forest functional level is set to Windows 2000 Server. Your company has a main office and four branch offices. Each office has two domain controllers. The domain controllers in the main office are global catalog servers.  In the branch offices, searches for some printers in Active Directory are slow. You need to improve the performance of Active Directory printer searches in the four branch offices. What should you do?() 

题型:单项选择题