You are the network administrator for TestKing. The network consists of a single
Active Directory domain. All servers run Windows Server 2003.
The domain contains two domain controllers named Testking1 and Testking2. You
use a Windows XP Professional client computer named Client1.
In Active Directory, the domain administrator creates two new user accounts
named NetAdmin1 and AdminUser1. The NetAdmin1 account is a member of the
Domain Admins global group. The AdminUser1 account is a member of only the
Users local group. You assign the AdminUser1 logon account the Allow log on
locally user right in the Default Domain Controller Group Policy object (GPO).
A new written security policy states that user accounts that are member of the
Domain Admins global group should not be used to log on to the console of a
domain controller. It also states that administrative tasks should be performed by
using the Secondary Logon service.
You need to create a new computer account in Active Directory, and you must
comply with the new company security policy.
What should you do?()
A. Log on to Testking1 by using the AdminUser1 user account. Run the dsa.msc command.
B. Log on to Testking1 by using the NetAdmin1 user account. Run the dsa.msc command.
C. Log on to Client1 by using the AdminUser1 user account. Run the runas /user:netadmin1 dsa.msc
D. Log on to Client1 by using the NetAdmin1 user account. Run the runas /user:adminuser1 dsa.msc
您可能感兴趣的试卷
你可能感兴趣的试题
You are the network administrator for The network consists of a
single Active Directory domain named The domain contains Windows
Server 2003 computers and Windows XP Professional computers.
All confidential company files are stored on a file server named TestKing1. The
written company security states that all confidential data must be stored and
transmitted in a secure manner. To comply with the security policy, you enable
Encrypting File System (EFS) on the confidential files. You also add EFS
certificates to the data decryption field (DDF) of the confidential files for the users
who need to access them.
While performing network monitoring, you notice that the confidential files that are
stored on TestKing1 are being transmitted over the network without encryption.
You must ensure that encryption is always used when the confidential files on
TestKing1 are stored and transmitted over the network.
What are two possible ways to accomplish this goal?() (Each correct answer presents
a complete solution. Choose two)
A. Enable offline files for the confidential files that are stored on TestKing1, and select the Encrypt offline files to secure data check box on the client computers of the users who need to access the files.
B. Use IPSec encryption between TestKing1 and the client computers of the users who need to access the confidential files.
C. Use Server Message Block (SMB) signing between TestKing1 and the client computers of the users who need to access the confidential files.
D. Disable all LM and NTLM authentication methods on TestKing1.
E. Use IIS to publish the confidential files. Enable SSL on the IIS server. Open the files as a Web folder.
You are the network administrator for TestKing. The network consists of a single
Active Directory domain. All network servers run Windows Server 2003.
A member server named TestkingA has a locally attached tape device. TestkingA
contains several folders and files that are encrypted by using Encrypting File
System (EFS).
You create a new user account for a new employee named Victoria. Victoria's user
account is member of the Users group only.
You need to ensure that Victoria can back up the encrypted folders and files on
TestkingA. Victoria must be assigned the minimum administrative privileges
needed to complete this task.
What should you do?()
A. Add Victoria's domain user account to the Administrators group.
B. Add Victoria's user account to the Backup Operators group.
C. Assign the Allow - Full Control permission on the encrypted folders and files to Victoria.
D. Designate Victoria as a recovery agent for the encrypted files.
You are the network administrator for TestKing. The network consists of a single
Active Directory domain. All network servers run Windows Server 2003. Half of the
client computers run Windows XP Professional, and the other half run Windows
NT 4.0 Workstation.
You install Terminal Services on three member servers named Testking1,
Testking2, and Testking3. Each server has a single Pentium III 600-Mhz CPU with
512 MB of RAM and a single-channel EIDE disk subsystem. You place all three
terminal servers in an organizational unit (OU) named Terminal Server. You link a
Group Policy Object (GPO) to the Terminal Server OU.
Several days after the installation, users report that the performance of all three
terminal servers is unacceptably slow. You discover that each server has at least 50
active sessions at once.
You need to improve the performance of all three terminal servers. You must
achieve this goal by using the minimum amount of administrative effort, without
upgrading any hardware.
What should you do?()
A. Log on to the console of each terminal server. In the RDP-Tcp connection properties, set the Maximum connections option to 35.
B. Edit the GPO to set the Limit number of connections policy to 35.
C. Modify all domain user accounts to set the When a session limit is reached or broken user property to End session.
D. Edit the GPO to enable the Remove Disconnected option from shutdown dialog policy
You are the administrator of a Windows Server 2003 computer named Testking1.
An application on Testking1 gradually uses more and more memory until it causes
Testking1 to stop responding. If you restart the application before it uses the
available memory, there is no interruption of user services.
You need to configure Testking1 to notify you when it encounters a low-memory
condition.
What should you do?()
A. Using Task Scheduler, schedule a repeating task that runs the tracert command.
B. Using Performance Logs and Alerts, configure an alert for the appropriate performance object.
C. Using System Monitor, configure the appropriate performance object to display.
D. Using Startup and Recovery Settings, configure Testking1 to send an Administrative Alert.
You are the network administrator for Test King. The network consists of a single
Active Directory domain named The domain contains Windows
Server 2003 computers and Windows XP Professional computers.
The Default Domain Policy has been modified by importing a security template file,
which contain several security settings.
A server named TestKing1 cannot run a program that us functioning on other
similarly configured servers. You need to find out whether additional security
settings have been added to the local security policy on TestKing1.
To troubleshoot, you want to use a tool to compare the current security settings on
TestKing1 against the security template file in order to automatically identify any
settings that might have been added to the local security policy.
Which tool should you run on TestKing1?()
A. Microsoft Baseline Security Analyzer (MBSA)
B. Security Configuration and Analysis console
C. gpresult.exe
D. Resultant Set of Policy console in planning mode
You are the network administrator for The network consists of a
single Active Directory domain named All network servers run
Windows Server 2003. Three thousand client computers run Windows 2000
Professional, and 1,500 client computers run Windows XP Professional.
A new employee named Dr King is hired to assist you in installing Windows XP
Professional on 150 new client computers.
You need to ensure that Dr King has only the minimum permissions required to add
new computer accounts to the domain and to own the accounts that he creates. Dr
King must not be able to delete computer accounts.
What should you do?()
A. Add Dr King's user account to the Server Operators group.
B. Add Dr King's user account to the Account Operators group.
C. Use the Delegation of Control Wizard to permit Dr King's user account to create new computer objects in the Computers container.
D. Create a Group Policy object (GPO) and link it to the domain. Configure the GPO to permit Dr King's user account to add client computers to the domain.
You are the network administrator for the Beijing office of TestKing. A branch
office is located in Cairo. The DNS servers in both locations run Windows Server
2003.
The network uses two DNS namespaces internally. They are named
publishing.testking.com and testking.com. The locations of the primary name
servers are shown in the following table.
The Beijing office contains some servers that are registered in the testking.com zone
and other that are registered in the publishing.testking.com zone. All computers in
the Beijing office are configured to use the local DNS server as their preferred DNS
server. The two offices are connected only by using a VPN through the Internet.
Various network problems occasionally result in loss of connectivity between the
two offices.
Firewalls prevent the DNS servers in both offices from receiving queries from the
Internet.
You need to configure the DNS server in the Beijing office to allow successful
resolution of all queries from the Beijing office for names in the
publishing.testking.com namespace, even when the VPN link between the Beijing
and Cairo offices fails.
What should you configure on the DNS server in the Beijing office?()
A. In the testking.com zone, create a delegated subdomain named publishing. Specify the DNS server in the Cairo office as a name server.
B. Create a secondary zone name publishing.testking.com. Specify the DNS server in the Cairo office as a master server.
C. Configure conditional forwarding for the publishing.testking.com namespace. Specify the DNS server in the Cairo office as a target server.
D. Create a stub zone named publishing.testking.com. Specify the DNS server in the Cairo office as a master server.
You are the network administrator for The network consists of a
single Active Directory domain named All network servers run
Windows Server 2003.
Confidential files are stored on a member server named TK1. The computer object
for TK1 resides in an organizational unit (OU) named Confidential. A Group Policy
object (GPO) named GPO1 is linked to the Confidential OU.
To audit access to the confidential files, you enable auditing on all private folders on
TK1.
Several days later, you review the audit logs. You discover that auditing is not
successful.
You need to ensure that auditing occurs successfully.
What should you do?()
A. Start the System Event Notification Service (SENS) on TK1.
B. Start the Error Reporting service on TK1.
C. Modify the Default Domain Controllers GPO by selecting Success and Failure as the Audit Object Access setting.
D. Modify GPO1 by selecting Success and Failure as the Audit Object Access setting.
You are the network administrator in the New York office of TestKing.
The company network consists of a single Active Directory domain The New York office currently contains one Windows Server 2003 file server named TestKingA.
All file servers in the New York office are in an organizational unit (OU) named
New York Servers. You have been assigned the Allow - Change permission for a
Group Policy object (GPO) named NYServersGPO, which is linked to the New
York Servers OU.
The written company security policy states that all new servers must be configured
with specified predefined security settings when the servers join the domain. These
settings differ slightly for the various company offices.
You plan to install Windows Sever 2003, on 15 new computers, which all functions
as file servers. You will need to configure the specified security settings on the new
file servers.
TestKingA currently has the specified security settings configured in its local
security policy. You need to ensure that the security configuration of the new file
servers is identical to that of TestKingA. You export a copy of TestKingA's local
security policy settings to a template file.
You need to configure the security settings of the new servers, and you want to use
the minimum amount of administrative effort.
What should you do?()
A. Use the Security Configuration and Analysis tool on one of the new servers to import the template file.
B. Use the default Domain Security Policy console on one of the new servers to import the template file.
C. Use the Group Policy Editor console to open NYServersGPO and import the template file.
D. Use the default Local Security Policy console on one of the new servers to import the template file.
You are the network administrator for The network consists of a single Active Directory domain named.
You configure a new Windows Server 2003 file server named TestKingSrv1.
You restore user files from a tape backup, and you create a logon script that maps drive
letters to shared files on TestKingSrv1.
Users report that they cannot access TestKingSrv1 through the drive mappings you
created. Users also report that TestKingSrv1 does not appear in My Network
Places.
You log on to TestKingSrv1 and confirm that the files are present and that the
NTFS permissions and share permissions are correct. You cannot access any
network resources. You run the ipconfig command and see the following output.
You need to configure the TCP/IP properties on TestKingSrv1 to resolve the
problem.
What should you do?()
A. Add testking.com to the DNS suffix for this connection field.
B. Configure the default gateway.
C. Configure the DNS server address.
D. Configure a static IP address.
最新试题
You are the network administrator for Active Directory domain. Thedomain includes Windows Server 2003 domain controllers and Windows XPProfessional client computers.A new administrator named Sandra is hired to assist you in deploying Windows XPProfessional to 100 new computers. Sandra installs the operating system on a newcomputer named TestKing11.However, when Sandra tries to log on to the domain from TestKing11, she isunsuccessful. The logon dialog box does now allow her to view and select the domainname.You need to ensure that Sandra can log on to the domain from TestKing11.What should you do?()
You are the network administrator for TestKing. Your network consists of a singleActive Directory domain. You manage a Terminal Server farm that includes fiveterminal servers and a Terminal Services Licensing server named testking9. Allservers run Windows 2000 Server. There are 2,500 users who log on to the terminalservers to access a custom human resource (HR) application.You install Windows Server 2003 on a new server named testking10. Testking10 isconfigured with all default settings enabled. You install Terminal Services and theHR application on testking10. You instruct some users to access the HR applicationon testking10.Four months later, users report that they can no longer establish Terminal Servicessessions to testking10. You verify that users can connect to the other terminalservers in your Terminal Server farm.You need to ensure that users can run the HR application on all terminal servers onthe network.What should you do?()
You are the network administrator for TestKing. The network consists of a singleActive Directory domain. All network servers run Windows Server 2003 and allclient computers run Windows XP Professional.Terminal Services is installed on a member server named Testking1. Currently, 30active terminal server sessions are connected to Testking1. An unforeseen hardwareupgrade will require shutting down the server.You need to provide a two-minute warning about the shutdown to all activeterminal sessions.First, you log on to Testking1 as an administrator.What should you do next?()
You are the domain administrator for TestKing's Active Directory domain. Allservers run Windows Server 2003. All client computers run Windows XPProfessional.A newly installed server was added to your domain. You need to administer thisserver remotely from your client computer.You need to configure the new server to ensure that it can be administeredremotely.What should you do?()
You are the network administrator for TestKing. The network consists of a singleActive Directory domain. All network servers run Windows Server 2003.A member server named TestkingA has a locally attached tape device. TestkingAcontains several folders and files that are encrypted by using Encrypting FileSystem (EFS).You create a new user account for a new employee named Victoria. Victoria's useraccount is member of the Users group only.You need to ensure that Victoria can back up the encrypted folders and files onTestkingA. Victoria must be assigned the minimum administrative privilegesneeded to complete this task.What should you do?()
You are the network administrator in the New York office of TestKing.The company network consists of a single Active Directory domain The New York office currently contains one Windows Server 2003 file server named TestKingA.All file servers in the New York office are in an organizational unit (OU) namedNew York Servers. You have been assigned the Allow - Change permission for aGroup Policy object (GPO) named NYServersGPO, which is linked to the NewYork Servers OU.The written company security policy states that all new servers must be configuredwith specified predefined security settings when the servers join the domain. Thesesettings differ slightly for the various company offices.You plan to install Windows Sever 2003, on 15 new computers, which all functionsas file servers. You will need to configure the specified security settings on the newfile servers.TestKingA currently has the specified security settings configured in its localsecurity policy. You need to ensure that the security configuration of the new fileservers is identical to that of TestKingA. You export a copy of TestKingA's localsecurity policy settings to a template file.You need to configure the security settings of the new servers, and you want to usethe minimum amount of administrative effort.What should you do?()
You are the network administrator for TestKing. The network consists of a singleActive Directory domain. All network servers run Windows Server 2003. Half of theclient computers run Windows XP Professional, and the other half run WindowsNT 4.0 Workstation.You install Terminal Services on three member servers named Testking1,Testking2, and Testking3. Each server has a single Pentium III 600-Mhz CPU with512 MB of RAM and a single-channel EIDE disk subsystem. You place all threeterminal servers in an organizational unit (OU) named Terminal Server. You link aGroup Policy Object (GPO) to the Terminal Server OU.Several days after the installation, users report that the performance of all threeterminal servers is unacceptably slow. You discover that each server has at least 50active sessions at once.You need to improve the performance of all three terminal servers. You mustachieve this goal by using the minimum amount of administrative effort, withoutupgrading any hardware.What should you do?()
You are the network administrator for The network consists of asingle Active Directory domain named All domain controllers runWindows Server 2003, and all client computers run Windows XP Professional. Eachdomain server has a locally attached tape device.You need to back up each domain controller. Your backup process must fulfil thefollowing requirements:a. System recovery must be possible in the event of server failure.b. The system configuration and all current dynamic disk configurations must bebacked up.c. Other data partitions do not need to be backed up.What should you do?()
You are the network administrator for All network servers run Windows Server 2003.A member server named TESTKING1 hosts several hundred folders, which residein various locations on the server. TESTKING1 is configured to run a normalbackup of the folder every Saturday at 1:00 A.M.You discover that users edit the contents of the folders on Saturday and Sunday.You need to use the Backup utility to reschedule the backup job so that it runs everyMonday at 1:00 A.M. instead of every Saturday at 1:00 A.M. You must achieve thisgoal by using the minimum amount of administrative effort.What should you do?()
You are the network administrator for TestKing. All servers run Windows 2003. Allclient computers run Windows XP Professional.You log on to a server named Testking15 by using the local Administrator account.You start the installation of a new server application. After you start theinstallation, you return to your office, which is located in another building.You need to find out the status of the installation that is in progress on Testking15.What should you do?()