问答题

You are the network administrator for A. Datum Corporation. The network consists of a single Active Directory forest that contains three domains named adatum.com, child1.adatum.com, and child2.adatum.com. The functional level of the forest is Windows Server 2003. The help desk department is responsible for resetting passwords for all user accounts in the forest except for accounts that have administrative privileges. There is an organizational unit (OU) named Corp_Users in each domain that contains the user accounts in that domain. All of the user accounts that have administrative privileges are in the default Users container in each domain. There is a universal group named HD_Users in the adatum.com domain. All user accounts for the help desk department users are members of the HD_Users group. You need to delegate the required authority for resetting passwords to the users in the help desk department. 
For which Active Directory component or components should you delegate control? To answer,select the appropriate component or components in the work area.
 


您可能感兴趣的试卷

你可能感兴趣的试题

4.单项选择题

Your company has a single Active Directory directory service forest with a forest root domain and a child domain. The child domain is set to the default domain functional level. You install a second domain controller in the child domain by promoting a server named SVR1. You need to rename SVR1 to DC2, and you must ensure that there will be no interruption in the ability of client computers to authenticate to DC2, except during reboot. 
What should you do?() 

A. Raise the domain functional level of the child domain to Windows 2000 native. Use System Properties on SVR1 to rename SVR1 to DC2.
B. Raise the domain functional level of the child domain to Windows Server 2003. Run the netdom command to rename SVR1 to DC2.
C. Raise the domain functional level of the child domain to Windows 2000 native. Run the dcpromo command on SVR1 to remove Active Directory directory service. Use System Properties to rename SVR1 to DC2. Run the dcpromo command to re-install Active Directory.
D. Raise the domain functional level of the child domain to Windows Server 2003. Create a DNS CNAME record for DC2.contoso.com that points to SVR1.contoso.com.

6.单项选择题

You have a single Active Directory directory service forest with two domains named contoso.com and corp.contoso.com. You need to grant a user in the contoso.com domain the permission to create Group Policy objects (GPOs) in the corp.contoso.com domain. 
What should you do?()

A. Delegate the Manage Group Policy links permission in the corp.contoso.com domain to the user.
B. Add the user to a domain local group in the corp.contoso.com domain, and grant the domain local group the permission to create GPOs in the corp.contoso.com domain.
C. Add the users user account to the Group Policy Creator Owners group in the contoso.com domain.
D. Grant the Group Policy Creator Owners group in the corp.contoso.com domain the Full Control permission for the GPOs in the corp.contoso.com domain.

7.多项选择题

You are the network administrator for your company. The network consists of a single Active Directory domain. All servers run Windows Server 2003. All client computers run Windows XP Professional with themost recent service pack. All client computers have computer accounts in an organizational unit (OU) named CompanyComputers. The company requires all computers to be kept up-to-date with service packs and hotfixes from Microsoft. Administrators will manually update servers as required. You need to configure the network so that client computers are automatically updated as new critical updates are issued. 
What are two possible ways to achieve this goal?()

A. Create a Group Policy object (GPO) linked to the domain. Configure the GPO so that client computers automatically download and install updates from Microsoft update servers from the Internet.
B. Create a Group Policy object (GPO) linked to the CompanyComputers OU. Configure the GPO so that client computers automatically download and install updates from Microsoft update servers from the Internet.
C. Create a Group Policy object (GPO) linked to the domain. Configure the GPO so that client computers automatically download and install updates from an internal server on which you install and configure Software Update Services.
D. Create a Group Policy object (GPO) linked to the CompanyComputers OU. Configure the GPO so that client computers automatically download and install updates from an internal server on which you install and configure Software Update Services.

8.单项选择题

You have a single Active Directory directory service domain. All domain controllers run Windows Server 2003. All client computers run Windows Vista. The computers in the sales department are located in an organizational unit (OU) named Sales. You use a Default Domain Policy to configure company user and computer settings. You configure a software restriction policy for the domain. The policy prevents users from running software that is not approved.  You need to allow computers in the Sales OU to run software that is not approved while maintaining other required settings. 
What should you do?()

A. Configure the Sales OU to block inheritance.
B. Create a new software restriction policy that reverses the settings in the Default Domain Policy. Link the new software restriction policy to the Sales OU.
C. Link the software restriction policy to the Sales OU. Disable the user configuration settings of this policy.
D. Link the software restriction policy to the Sales OU. Disable the computer configuration settings of this policy.

9.单项选择题

You are the network administrator for your company. The network consists of a single Active Directory domain with three sites. There is a domain controller at each site. All servers run Windows Server 2003. Each client computer runs either Windows 2000 Professional or Windows XP Professional. The IT staff is organized into four groups. The IT staff works at the three different sites. The computers for the IT staff must be configured by using scripts. The script or scripts must run differently based on which site the IT staff user is logging on to and which of the four groups the IT staff user is a member of. You need toensure that the correct logon script is applied to the IT staff users based on group membership and site location. 
What should you do?()

A. Create four Group Policy objects (GPOs). Create a script in each GPO that corresponds to one of the four groups. Link the four new GPOs to all three sites. Grant each group permissions to apply only the GPO that was created for the group.
B. Create a single script that performs the appropriate configuration based on the user’s group membership. Place the script in the Netlogon shared folders on the domain controllers.
C. Configure a Group Policy object (GPO) with a startup script that configures computers based on IT staff group. Link the GPO to the three sites.
D. Create a script that configures the computers based on IT staff group membership and site. Create and link a GPO to the Domain Controllers OU to run the script.

10.多项选择题

You have a single Active Directory directory service domain. All users are located in an organizational unit (OU) named ContosoUsers. All client computer accounts are located in an OU named ContosoComputers. You need to deploy a new application to all users. The application shortcut must be available the next time the users log on.
What are two possible ways to achieve this goal?()

A. Create a Group Policy object (GPO) to publish the application. Link the GPO to the ContosoComputers OU.
B. Create a Group Policy object (GPO) to assign the application. Link the GPO to the ContosoComputers OU.
C. Create a Group Policy object (GPO) to publish the application. Link the GPO to the ContosoUsers OU. 
D. Create a Group Policy object (GPO) to assign the application. Link the GPO to the ContosoUsers OU.

最新试题

Your company has a single Active Directory directory service domain that includes a main office and two branch offices. Each branch office has its own Active Directory site. All user accounts are placed into organizational units (OUs) based on department. Multiple Group Policy objects (GPOs) are linked at the domain, the site, and the OU levels. A user in Atlanta transfers to a different branch office and joins a different department. You move her user account into the corresponding OU. After logging on to her new client computer, the user notices that the desktop settings are different from the settings she had in her previous location. You need to find out the effect of all GPOs on the user. What should you do?()

题型:单项选择题

You are the network administrator for your company. The network consists of a single Active Directory domain. All servers run Windows Server 2003. All client computers run either Windows XP Professional or Windows 2000 Professional. All client computer accounts are located in an organizational unit (OU) named Workstation. A written company policy states that the Windows 2000 Professional computers must not use offline folders. You create a Group Policy object (GPO) to enforce this requirement. The settings in the GPO exist for both Windows 2000 Professional computers and Windows XP Professional computers. You need to configure the GPO to apply only to Windows 2000 Professional computers. What are two possible ways to achieve this goal?()

题型:多项选择题

Your companys Windows Server 2003 environment consists of a single Active Directory directory service forest. The forest has multiple domains and three sites named Site1, Site2, and Site3. Site1 is the main office and has four domain controllers. Two of the domain controllers are global catalog servers. Site2 is a branch office with two domain controllers. Site3 is a branch office with a slow and unreliable WAN link and two domain controllers.  You need to improve user logon performance for users in Site2 and Site3. Which two actions should you perform?()

题型:多项选择题

Why is a data source required?()

题型:单项选择题

You are the network administrator for your company. The network consists of a single Active Directory domain. The domain includes an organizational unit (OU) named Processing. There are 100 computer accounts in the Processing OU. You create a Group Policy object (GPO) named NetworkSecurity and link it to the domain. You configure NetworkSecurity to enable security settings through the Computer Configuration section of the Group Policy settings. You need to ensure that NetworkSecurity will apply only to the computers in the Processing OU. You need to minimize the number of GPO links. What should you do?()

题型:单项选择题

You are the network administrator for your company. Your network consists of a single Active Directory domain. The functional level of the domain is Windows Server 2003. You add eight servers for a new application. You create an organizational unit (OU) named Application to hold the servers and other resources for the application. Users and groups in the domain will need varied permissions on the application servers. The members of a global group named Server Access Team need to be able to grant access to the servers. The Server Access Team group does not need to be able to perform any other tasks on the servers. You need to allow the Server Access Team group to grant permissions for the application servers without granting the Server Access Team group unnecessary permissions. What should you do?()

题型:单项选择题

You are the network administrator for your company. The network consists of a single Active Directory domain with three sites. There is a domain controller at each site. All servers run Windows Server 2003. Each client computer runs either Windows 2000 Professional or Windows XP Professional. The IT staff is organized into four groups. The IT staff works at the three different sites. The computers for the IT staff must be configured by using scripts. The script or scripts must run differently based on which site the IT staff user is logging on to and which of the four groups the IT staff user is a member of. You need toensure that the correct logon script is applied to the IT staff users based on group membership and site location. What should you do?()

题型:单项选择题

You have a single Active Directory directory service domain. All domain controllers run Windows Server 2003. All client computers run Windows Vista. The computers in the sales department are located in an organizational unit (OU) named Sales. You use a Default Domain Policy to configure company user and computer settings. You configure a software restriction policy for the domain. The policy prevents users from running software that is not approved.  You need to allow computers in the Sales OU to run software that is not approved while maintaining other required settings. What should you do?()

题型:单项选择题

You are the network administrator for Northwind Traders. The network consists of a single Active Directory forest that contains one root domain and one child domain. The forest also contains three separate sites, as shown in the Network Diagram exhibit. (Click the Exhibit button.) The network is not fully routed and there is no direct physical connection between Site1 and Site3. Site links are not bridged. You discover that the domain controllers for namerica.northwindtraders.com located in Site1 have additional accounts that are not on the domain controllers for namerica.northwindtraders.com located in Site3. You examine the directory service log in Event Viewer on a domain controller for namerica.northwindtraders.com. You discover the error message shown in the Error Message exhibit. (Click the Exhibit button.) You need to resolve the condition that is causing this error. What should you do? ()

题型:单项选择题

You are the network administrator for A. Datum Corporation. The network consists of a single Active Directory forest that contains three domains named adatum.com, child1.adatum.com, and child2.adatum.com. The functional level of the forest is Windows Server 2003. The help desk department is responsible for resetting passwords for all user accounts in the forest except for accounts that have administrative privileges. There is an organizational unit (OU) named Corp_Users in each domain that contains the user accounts in that domain. All of the user accounts that have administrative privileges are in the default Users container in each domain. There is a universal group named HD_Users in the adatum.com domain. All user accounts for the help desk department users are members of the HD_Users group. You need to delegate the required authority for resetting passwords to the users in the help desk department. For which Active Directory component or components should you delegate control? To answer,select the appropriate component or components in the work area. 

题型:问答题