Font size
WorksheetsMOC 20742B - Identity with Windows Server 2016
Total questions: 74
Worksheet time: 37mins
What is an AD DS domain?
A group of users/servers/groups that share a common Active Directory
An Active Directory Domain Sharing service
A logical Admin container for objects
The Army Designated Duty Student for the week
What is an AD DS domain tree?
A collection of domains that share a contiguous namespace
The separate Domain Names
A domain consisting of Unique Principal Names
I - G - DL - A
What is an AD DS forest?
A collection of domain trees that have built-in trust relationships
A collection of domains that share a contiguous namespace
An authentication pipeline between two objects
A series of contiguous primary domain controllers
What is a trust relationship?
An authentication pipeline between two objects
The connection between a parent and a child domain
An example of Distributed File System Replication
The set definitions between object types and attributes
List Windows 2016 new features:
___ is a solution that helps organisations to restrict privileged access within an existing Active Directory environment.
PAM
PAN
PAMN
Pand...There's a D on the end.
It's like "Comb" except P-A-N-M. N-N. There's two N's.
List windows 2016 new features:
__________ is a feature that provides certificate authentication that can replace the use of passwords.
MS Passport
RFID
Universal Group Scope
SID
Key Distribution Center
List the Operations master roles at forest level.
(choose Two)
Domain Naming Master
Schema Master
RID Master
Infrastructure Master
PDC emulator Master
List the Operations master roles at Domain level
(choose Three)
RID Master
Infrastructure Master
PDC Emulator Master
Domain Naming Master
Schema Master
________ is a cloud-base service that provides identity management and access control for cloud-based applications.
Azure AD
Azura AD
Web Application Proxy
Connection Manager Administration Kit
____________ is an easy and fast solution to deploy many virtual Domains Controllers in the private cloud environment.
Cloning DC's
Distributed File System Replication
Flexible Single Master Operations
In-place upgrading
What are the two types of Group in Active Directory?
Security Group
Distribution Group
Domain Local Group
Universal Group
Why is it better to reset the computer account rather than to disjoin and then rejoin it to the domain?
Disjoin/Rejoin : New SID
It doesn't lose it's group memberships
Djinn
Increased security
The best practice for nesting groups is known as _________
IGDLA
IGUDLA
Nested Virtulisation
Hyper V Virtual Switch
When importing user accounts from .csv file, you can use ________ (Syntax) loop to process each row in the file.
Foreach
NVGRE
RSS
RSC
Compared to system container, what are the advantages of OU?
(Select Two)
OU's can apply GPO's
You can delegate admin
OU's have Security Boundaries
OU's can give IOUs
OU's area part of SCHEMA
Your company has purchased another company that also uses Windows Server 2016 and Active Directory. Both Companies need to be able to access each others forest resources. How can you achieve this goal with the least administrative effort?
Short Cut trust
Create a two way forest trust
Configure a lower administrative distance
Trust short cut
You can have different domain functional levels within the forest, however, the lowest domain functional level determines the forest functional level. True or False?
True
False
List the Three options that you can increase the security in forest trust.
SID Filtering
Selective authentication
Name Suffix routing
Unique Principal Names
Disable Permissions
_______ is used in each DC to generate IntraSite replication topology.
KCC
ISTG
KC30
IntraTopology
_________ is used in each DC to generate InterSite replication topology
ISTG
KCC
IGA
InterTopology
The bridgehead server is responsible for all replication into and out of the site. Instead of replication all domain controllers from one site with all domain controllers in another site. True or False?
True
False
How to resolve replication conflict? (Choose Three)
Version Number
Times Stamp
DCs GUID
KCC
Failover
In windows 2008 or newer domain controllers, SYSVOL folder replication takes place by using _____________.
DFS Rep
NTFS Rep
KCC Rep
NFS Rep
In a windows domain, sites are useful to quickly locate domain controllers and site-aware application and services. True or False?
True
False
A GPO is stored in __________ and SYSVOL folder in the Domain Controller.
AD DS
AD FS
AD HD
\Sharefolder
What is the default processing order that GPOs apply?
1-Local
2-Site Level
3-Domain Level
4-OU GPOs
1-Site Level
2-OU GPOs
3-Domain Level
4-Local Level
1-Setting
2-Scope
3-Application
1-IntraSite Level
2-InterSite Level
How to refresh GPO in CLI?
gpupdate/force
gpupdate/enforce
gpupdate/refresh
gpupdate/generate
When you delete a GPO link, you also delete the GPO as well. True or False?
True
False
What is a starter GPO?
GPO Template
It stores administrative settings
A Local Group
A Computer Configuration Policy
How do you exclude users/computers to be affected by a GPO?
Configure "apply group policy" permission as deny for the specific users and computers
Configure exclusions on the Delegation Tab
Uncheck apply in the the administrative template settings
Put the hosts in a different Subnet
There is no difference between an ADMX and a ADMLfile. True or False?
True
False
What is the difference between policies and preferences in a GPO?
-Policy settings are compulsory, UI is inactive
-Preference settings are recommended, UI is active
-Policy settings are recommended, UI is active
-Preference settings are compulsory, UI is inactive
You have created Group Policy preferences to configure new power options. How can you make sure that they apply only to laptop computers?
Configure item-level targeting in GPO preferences
Configure with secpol.msc
Configure Authentication Policy Silos
Group policy can be used to install, maintain and remove software from organisation computers. When delivering software to client, admin has 2 deployment methods. (choose two)
Assign software to computers/users
Publish software to computers
Designate Hardware to clients
Delegate Software permissions to OUs
Which technology allows you to use biometric functionality to sign in to Windows devices?
Windows Hello
Windows Sign in
MS Passport
Windows Hi
When a user signs in to a domain controller, a logon event is generated in the DC. True or False?
True
False
How are group MSAs different from standard MSAs?
Can be shared by multiple servers
Stored in AD
Shared by App services
Stored in AD DS
In windows domain, administrator can create multiple ______________________ to specify multiple password policies to different users or groups within a single domain or single OU.
Fine grained password policies
MS Password accounts
Multiple domain logins
Authentication Policy Silos
Organisation units
________________ enable administrators to configure users, service accounts and computers within the same security scope to apply the same authentication policy.
Authentication Policy Silo
Fine grained password policies
Multiple Servers
Windows Hello
Both user account names and passwords are case sensitive. True or False?
True
False
Managed service accounts provide managed password changes that do not require administrator intervention. True or False?
True
False
Certificate auto enrollment is an option only on enterprise CA's. True or False?
True
False
Your company is currently acquiring another company. Both companies run their own PKI. What hierarchy could you create to minimize disruption and continue to provide PKI services seamlessly?
Configure cross-certification between two companies
Enroll a designated user for a KRA certificate
Verify certificate validity and revocation
Configure a constitutional hierarchy
To recover private keys, you must configure CA to archive private keys for specific templates, and you must issue a Key Recovery Agent (KRA) certificate. True or False?
True
False
Which of the following actions must you take to configure key archival on an AD CS CA? (choose four)
Configure the KRA certificate template
Enroll a designated user for a KRA certificate
Publish the KRA public key by using Group Policy
Configure a recovery agent on the CA
Configure desired certificate templates for key archival
AD FS is designed to work over the public internet with a Web Browser interface. True or False?
True
False
Where do you deploy Application Proxy Server when deploying AD FS in a single organisation scenario?
Perimeter network
Boundary Network
Internal Interface
Active Directory Federation Service
A federated trust is the same as a forest trust that organizations can configure between AD DS forests. True or False?
True
False
In Windows Server 2016, the federation server proxy functionality is part of the Web Application Proxy role. True or False?
True
False
How can you test whether AD FS is functioning properly?
https://hostname/federationmetadata/2007-06/federationmetadata.xml
https://hostname/federationmetadata/2007-06/federationmetadata.pdf
www://hostname/federationmetadata/2007-06/federationmetadata.xml
https://federationmetadata/hostname/2007-06/federationmetadata.xml
When deploying AD FS server, the server will have 3 self-issued certificates, they are; server communication certificate (SSL), Token Signing certificate and Token-decrypting certificate. Which self-issued certificate need be replaced by an internalCA issued certificate or public-CA issued certificate, so that users can access web application from intranet/internet?
communication certificate SSL
Token-decrypting certificate
Token-signing certificate
Your company deals with highly confidential information, some of which is transmitted via email among company employess. Some documents have been forwarded via email, making the documents more difficult to track. You want to be able to prevent employes from forwarding certain emails. What should you deploy?
Deploy RMS Infrastructure
Deploy Todd
Certification Authority
Line-of-business
RMS Servers provide 3 types of exclusion policies. What are they?
User Exclusion
Application exclusion
Lockbox version exclusion
Public key infrastructure exclusion
Single sign on exclusion
You want to block uses from protecting content by using specific versions of Microsoft PowerPoint. Which exclusion policy should you create?
Application exclusion
User exclusion
Lockbox version exclusion
Line-of-business exclusion
You can install an SSL certificate on the AD RMS configuration, the benefit is that you can protect the connection between clients and the AD RMS server with SSL. True or False?
True
False
Azure RMS is deployed locally on a server. True or False?
True
False
To implement an AD RMS cluster, which components are necessary? (choose two)
Office
A service account
A database
AD FS
A Secure Sockets Layer (SSL) certificate
When you decide to remove your AD RMS cluster from AD DS, what should you do first?
Decommission
Commission
Configure Cluster Exclusion
Remove multi factor authentication
When you decide to remove your AD RMS cluster from AD DS, what should you do first?
Decommission
Commission
Configure Cluster Exclusion
Remove multi factor authentication
Which of the following are true statements regarding the use of certificates in a business environment? (choose three)
Certificates can be used to encrypt HTTP traffic between a web server and browser
Certificates can be used to digitally sign documents
Digitally signed documents are invalidated if the contents are modified
files encrypted using Encrypting File System (EFS) can only be read by the individual who first encrypted the file
To send encrypted e-mail to an external recipient who is not a part of your internal PKI, you must use an encryption certificate issued by public CA.
You are the AD CS administrator for A. Datum. You want to enable your AD DS users to perform digital signature and encryption using certificates from your internal PKI. Which step is required?
Enable a key recovery agent
enable a data recovery agent
Publish the user certificate template and configure the desired groups of users for autoenrollment
Enable EFS on AD DS domain computers by using Group Policy
Upgragde all AD DS domain computers to Windows Server 2016 or Windows 10
Select reasons that an organization would use a PKI? (choose 3 options)
Improve Security
Identity Control
Account Control
Digital signing of code
Group Control
Which of the following statements are true regarding smart cards? (choose three options)
Smart cards provide an option for multifactor authentication
Smart cards cannot be used for interactive sign in
Smart cards contain a certificate and private key that can only be accessed by using a PIN
Smart cards provide enhanced security beyond a password
Smart Cards can only be used for digital signature and encryption
You use __________________________ for directory synchronization between on-premises Active Directory and Azure AD.
Azure AD connect
Directory synchronization with SSO
Azure AD Connect Health
AD DS Preperation
When you implement directory synchronization, user accounts and groups move from your local AD DS to Azure AD. True or False?
True
False
If you implement AD FS and federation between locally deployed AD DS and Azure AD AD, then you do not need to use Azure AD Connect
True
False
If you want to have SSO for both cloud-based and on-premises services, what do you need to deploy? (Choose two)
Azure AD Connect Health
AD FS
Azure AD Connect
Office 265
Azure AD
In Azure AD, there are no OUs or GPOs. True or False?
True
False
By using Azure AD ___________________, you can limit standard administrator access to privileged roles, discover who can access and review privileged access.
PIM
PIN
PAM
Connect
List all monitoring tools tht can be used to monitor AD DS? (5)
Task Manager
Resource Monitor
Event Viewer
Performance Monitor
Windows Powershell
_________________ is a command line tool which can be used to perform AD database maintenance, such as creating snapshots, performing offline defragmentation.
ntdsutil.exe
Data Protection Manager
Windows Server Backup
Azure backup
AD DS has 3 states, what are they?
Start
Stop
DSRM
Go
Pause
____________ is a microsoft system center tool that can manage data backup/restore centrally
DPM
DTM
Windows server backup
Azure Backup
You restore a Domain Controller from backup file, then restored domain controller recieve all of the recent updates from the running Domain Controllers, this restore mode is called ____________.
Non-authorative Restore
Authorative Restore
Full Restore
Update Restore
