单项选择题

You are the network administrator for your company. The network consists of a single Active Directory domain with three sites. There is a domain controller at each site. All servers run Windows Server 2003. Each client computer runs either Windows 2000 Professional or Windows XP Professional. The IT staff is organized into four groups. The IT staff works at the three different sites. The computers for the IT staff must be configured by using scripts. The script or scripts must run differently based on which site the IT staff user is logging on to and which of the four groups the IT staff user is a member of. You need toensure that the correct logon script is applied to the IT staff users based on group membership and site location. 
What should you do?()

A. Create four Group Policy objects (GPOs). Create a script in each GPO that corresponds to one of the four groups. Link the four new GPOs to all three sites. Grant each group permissions to apply only the GPO that was created for the group.
B. Create a single script that performs the appropriate configuration based on the user’s group membership. Place the script in the Netlogon shared folders on the domain controllers.
C. Configure a Group Policy object (GPO) with a startup script that configures computers based on IT staff group. Link the GPO to the three sites.
D. Create a script that configures the computers based on IT staff group membership and site. Create and link a GPO to the Domain Controllers OU to run the script.


您可能感兴趣的试卷

你可能感兴趣的试题

1.多项选择题

You have a single Active Directory directory service domain. All users are located in an organizational unit (OU) named ContosoUsers. All client computer accounts are located in an OU named ContosoComputers. You need to deploy a new application to all users. The application shortcut must be available the next time the users log on.
What are two possible ways to achieve this goal?()

A. Create a Group Policy object (GPO) to publish the application. Link the GPO to the ContosoComputers OU.
B. Create a Group Policy object (GPO) to assign the application. Link the GPO to the ContosoComputers OU.
C. Create a Group Policy object (GPO) to publish the application. Link the GPO to the ContosoUsers OU. 
D. Create a Group Policy object (GPO) to assign the application. Link the GPO to the ContosoUsers OU.

2.单项选择题

You are the network administrator for your company. The network consists of a single Active Directory domain. The domain includes an organizational unit (OU) named Processing. There are 100 computer accounts in the Processing OU. You create a Group Policy object (GPO) named NetworkSecurity and link it to the domain. You configure NetworkSecurity to enable security settings through the Computer Configuration section of the Group Policy settings. You need to ensure that NetworkSecurity will apply only to the computers in the Processing OU. You need to minimize the number of GPO links. 
What should you do?()

A. Link NetworkSecurity to the Processing OU. Disable the User Configuration section of NetworkSecurity.
B. Link NetworkSecurity to the Processing OU. Remove the link from NetworkSecurity to the domain.
C. Modify the discretionary access control list (DACL) for NetworkSecurity to assign all computer accounts in the Processing OU the Allow - Read and the Allow - Apply Group Policy permissions.
D. Modify the discretionary access control list (DACL) for NetworkSecurity to assign the Authenticated Users group the Deny - Apply Group Policy permission and to assign all of the computer accounts in the Processing OU the Allow - Read and the Allow - Apply Group Policy permissions.

3.多项选择题

You are the network administrator for your company. The network consists of a single Active Directory domain. All servers run Windows Server 2003. All client computers run either Windows XP Professional or Windows 2000 Professional. All client computer accounts are located in an organizational unit (OU) named Workstation. A written company policy states that the Windows 2000 Professional computers must not use offline folders. You create a Group Policy object (GPO) to enforce this requirement. The settings in the GPO exist for both Windows 2000 Professional computers and Windows XP Professional computers. You need to configure the GPO to apply only to Windows 2000 Professional computers. 
What are two possible ways to achieve this goal?()

A. Create a WMI filter that will apply the GPO to computers that are running Windows 2000 Professional. 
B. Create a WMI filter that will apply the GPO to computers that are not running Windows XP Professional.
C. Create two OUs under the Workstation OU. Place the computer accounts for the Windows XP Professional computers in one OU, and place the computer accounts for the Windows 2000 Professional computers in the other OU. Link the GPO to the Workstation OU.
D. Create a group that includes the Windows XP Professional computers. Assign the group the Deny - Generate Resultant Set of Policy(Logging) permission.
E. Create a group that includes the Windows 2000 Professional computers. Assign the group the Deny - Apply Group Policy permission.

4.单项选择题

You have a single Active Directory directory service domain. All servers run Windows Server 2003. You need to specify the list of applications that users are permitted to run. You create a new Group Policy object (GPO) and link it to the domain. 
What should you do next?()

A. Configure Software Restriction Policies Group Policy settings.
B. Configure the Enable user control over installs Group Policy setting.
C. Assign all approved applications.
D. Publish all approved applications.

5.多项选择题

You have two Active Directory directory service forests named contoso.com and fabrikam.com. All users log on to the contoso.com domain. All servers run Windows Server 2003 and are members of the fabrikam.com domain. You create a one-way forest trust in which fabrikam.com is trusting contoso.com. Forest-wide authentication is enabled. You need to provide only selected users with access to a server in the fabrikam.com domain.
Which two actions should you perform?()

A. Grant the users the Allowed to Authenticate permission on the computer object representing the server.
B. Grant the users the Modify permission on the computer object representing the server.
C. Change the one-way forest trust to a two-way forest trust.
D. Change the properties of the forest trust from Forest-wide authentication to Selective authentication.

6.单项选择题

You are the network administrator for your company. Your network consists of a single Active Directory domain. The functional level of the domain is Windows Server 2003. You add eight servers for a new application. You create an organizational unit (OU) named Application to hold the servers and other resources for the application. Users and groups in the domain will need varied permissions on the application servers. The members of a global group named Server Access Team need to be able to grant access to the servers. The Server Access Team group does not need to be able to perform any other tasks on the servers. You need to allow the Server Access Team group to grant permissions for the application servers without granting the Server Access Team group unnecessary permissions. 
What should you do?()

A. Create a Group Policy object (GPO) for restricted groups. Configure the GPO to make the Server Access Team group a member of the Power Users group on each application server. Link the GPO to the Application OU.
B. Grant the Server Access Team group permissions to modify computer objects in the Application OU.
C. Move the Server Access Team group object into the Application OU.
D. Create domain local groups that grant access to the application servers. Grant the Server Access Team group permissions to modify the membership of the domain local groups.

7.多项选择题

You are the network administrator for your company. The network consists of a single Active Directory domain with three sites named Site1, Site2, and Site3. The sites and site links are configured to use Site2 to connect Site1 and Site3. Each site contains three Windows Server 2003 domain controllers. A domaincontroller in each site is configured as a preferred bridgehead server. All user and group accounts are created in Site1. Several new users start work in Site2. When they attempt to log on to the network, the logon fails. You confirm that the user accounts are created and are visible in Site1 and Site2. You discover that the preferred IP bridgehead server in Site2 failed. You repair the server and confirm that replication is successful to Site2. You need to ensure that the failure of a single domain controller in any site will not interfere with Active Directory replication between sites. 
What are two possible ways to achieve this goal?()

A. Configure an IP site link between Site1 and Site3.
B. Configure two domain controllers in each site as preferred IP bridgehead servers.
C. Configure two domain controllers in each site as preferred SMTP bridgehead servers.
D. Configure each site to have no preferred bridgehead servers.
E. Configure an SMTP site link between each of the sites. Assign a cost of 200 to the SMTP site link.

9.单项选择题

You have a single Active Directory directory service domain. You have an application that adds Active Directory Schema attributes during installation. The attributes replicate as part of global catalog replication. Your user account is a member of the Domain Admins, Schema Admins, and Enterprise Admins global groups. You test the application and decide not to deploy it to production.  You need to ensure that the attributes that are added by the application are no longer available in Active Directory. 
Using the Active Directory Schema snap-in,what should you do?()

A. Clear the Index this attribute in the Active Directory option for each attribute that is added by the application.
B. Clear the Attribute is active option for each attribute that is added by the application.
C. Clear the Replicate this attribute to the Global Catalog option for each attribute that is added by the application.
D. Clear the Allow this attribute to be shown in advanced view option for each attribute that is added by the application.

10.单项选择题

You are the network administrator for Northwind Traders. The network consists of a single Active Directory forest that contains one root domain and one child domain. The forest also contains three separate sites, as shown in the Network Diagram exhibit. (Click the Exhibit button.) The network is not fully routed and there is no direct physical connection between Site1 and Site3. Site links are not bridged. You discover that the domain controllers for namerica.northwindtraders.com located in Site1 have additional accounts that are not on the domain controllers for namerica.northwindtraders.com located in Site3. You examine the directory service log in Event Viewer on a domain controller for namerica.northwindtraders.com. You discover the error message shown in the Error Message exhibit. (Click the Exhibit button.) You need to resolve the condition that is causing this error. 
What should you do? ()

A. Add a domain controller for the namerica.northwindtraders.com domain to Site2.
B. Configure a site link bridge between the site links for Site1 and Site3.
C. Configure at least one domain controller in each site to be a global catalog server.
D. Create a site link between Site1 and Site3.

最新试题

Your company has a single Active Directory directory service forest. All user accounts are located in  the Users container. You need to create a number of organizational units (OUs) that will be used to store  user accounts. What are two possible ways to achieve this goal?()

题型:多项选择题

You are the network administrator for your company. The network consists of a single Active Directory domain with three sites named Site1, Site2, and Site3. The sites and site links are configured to use Site2 to connect Site1 and Site3. Each site contains three Windows Server 2003 domain controllers. A domaincontroller in each site is configured as a preferred bridgehead server. All user and group accounts are created in Site1. Several new users start work in Site2. When they attempt to log on to the network, the logon fails. You confirm that the user accounts are created and are visible in Site1 and Site2. You discover that the preferred IP bridgehead server in Site2 failed. You repair the server and confirm that replication is successful to Site2. You need to ensure that the failure of a single domain controller in any site will not interfere with Active Directory replication between sites. What are two possible ways to achieve this goal?()

题型:多项选择题

You are a network administrator for your company. The network consists of a single Active Directory domain. The company has offices in 25 cities. Each office is configured as a single site. You are responsible for one site that is configured as shown in the exhibit. (Click the Exhibit button.) An IP site link connects your site and the site at the company’s main office. The company replaces your router with a firewall device. The firewall is configured to allow HTTP, SMTP, FTP, NNTP, global catalog queries, and VPN packets to pass. You discover that replication with other sites is not occurring. You need to ensure that you can replicate with other sites. You need to achieve this goal without removing or reconfiguring the firewall. What should you do? ()

题型:单项选择题

You have two Active Directory directory service forests named contoso.com and fabrikam.com. All users log on to the contoso.com domain. All servers run Windows Server 2003 and are members of the fabrikam.com domain. You create a one-way forest trust in which fabrikam.com is trusting contoso.com. Forest-wide authentication is enabled. You need to provide only selected users with access to a server in the fabrikam.com domain.Which two actions should you perform?()

题型:多项选择题

Your company has a single Active Directory directory service forest with a forest root domain and a child domain. The child domain is set to the default domain functional level. You install a second domain controller in the child domain by promoting a server named SVR1. You need to rename SVR1 to DC2, and you must ensure that there will be no interruption in the ability of client computers to authenticate to DC2, except during reboot. What should you do?() 

题型:单项选择题

Why is a data source required?()

题型:单项选择题

You are the network administrator for your company. Your network consists of a single Active  Directory domain. Three security groups named Accountants, Processors, and Management are located in an organizational unit (OU) named Accounting. All of the user accounts that belong to these three  groups are also in the Accounting OU. You create a Group Policy object (GPO) and link it to the  Accounting OU. You configure the GPO to disable the display options under the User Configuration  section of the GPO. You need to achieve the following goals: You need to ensure that the GPO applies to  all user accounts that are members of the Processors group. You need to prevent the GPO fromapplying  to any user account that is a member of the Accountants group. You need to prevent the GPO from  applying to any user account that is a member of the Management group, unless the user account is also  a member of the Processors group.What should you do?()

题型:单项选择题

You are the network administrator for your company. The network consists of a single Active Directory domain. All servers run Windows Server 2003. All client computers run Windows XP Professional with themost recent service pack. All client computers have computer accounts in an organizational unit (OU) named CompanyComputers. The company requires all computers to be kept up-to-date with service packs and hotfixes from Microsoft. Administrators will manually update servers as required. You need to configure the network so that client computers are automatically updated as new critical updates are issued. What are two possible ways to achieve this goal?()

题型:多项选择题

You are the network administrator for Northwind Traders. The network consists of a single Active Directory forest that contains one root domain and one child domain. The forest also contains three separate sites, as shown in the Network Diagram exhibit. (Click the Exhibit button.) The network is not fully routed and there is no direct physical connection between Site1 and Site3. Site links are not bridged. You discover that the domain controllers for namerica.northwindtraders.com located in Site1 have additional accounts that are not on the domain controllers for namerica.northwindtraders.com located in Site3. You examine the directory service log in Event Viewer on a domain controller for namerica.northwindtraders.com. You discover the error message shown in the Error Message exhibit. (Click the Exhibit button.) You need to resolve the condition that is causing this error. What should you do? ()

题型:单项选择题

You have a single Active Directory directory service forest named contoso.com. You create baseline security settings for a group of computers, and you store the settings in a database. You deploy the baseline security settings. You need to confirm that the security settings on one of the computers are applied correctly. What are two possible commands that you can run to achieve this goal?()

题型:多项选择题