wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

MOC 20742B - Identity with Windows Server 2016

Total questions: 74

Worksheet time: 37mins

Name
Class
Date
1.

What is an AD DS domain?

a)

A group of users/servers/groups that share a common Active Directory

b)

An Active Directory Domain Sharing service

c)

A logical Admin container for objects

d)

The Army Designated Duty Student for the week

2.

What is an AD DS domain tree?

a)

A collection of domains that share a contiguous namespace

b)

The separate Domain Names

c)

A domain consisting of Unique Principal Names

d)

I - G - DL - A

3.

What is an AD DS forest?

a)

A collection of domain trees that have built-in trust relationships

b)

A collection of domains that share a contiguous namespace

c)

An authentication pipeline between two objects

d)

A series of contiguous primary domain controllers

4.

What is a trust relationship?

a)

An authentication pipeline between two objects

b)

The connection between a parent and a child domain

c)

An example of Distributed File System Replication

d)

The set definitions between object types and attributes

5.

List Windows 2016 new features:

___ is a solution that helps organisations to restrict privileged access within an existing Active Directory environment.

a)

PAM

b)

PAN

c)

PAMN

d)

Pand...There's a D on the end.

e)

It's like "Comb" except P-A-N-M. N-N. There's two N's.

6.

List windows 2016 new features:

__________ is a feature that provides certificate authentication that can replace the use of passwords.

a)

MS Passport

b)

RFID

c)

Universal Group Scope

d)

SID

e)

Key Distribution Center

7.

List the Operations master roles at forest level.

(choose Two)

a)

Domain Naming Master

b)

Schema Master

c)

RID Master

d)

Infrastructure Master

e)

PDC emulator Master

8.

List the Operations master roles at Domain level

(choose Three)

a)

RID Master

b)

Infrastructure Master

c)

PDC Emulator Master

d)

Domain Naming Master

e)

Schema Master

9.

________ is a cloud-base service that provides identity management and access control for cloud-based applications.

a)

Azure AD

b)

Azura AD

c)

Web Application Proxy

d)

Connection Manager Administration Kit

10.

____________ is an easy and fast solution to deploy many virtual Domains Controllers in the private cloud environment.

a)

Cloning DC's

b)

Distributed File System Replication

c)

Flexible Single Master Operations

d)

In-place upgrading

11.

What are the two types of Group in Active Directory?

a)

Security Group

b)

Distribution Group

c)

Domain Local Group

d)

Universal Group

12.

Why is it better to reset the computer account rather than to disjoin and then rejoin it to the domain?

a)

Disjoin/Rejoin : New SID

b)

It doesn't lose it's group memberships

c)

Djinn

d)

Increased security

13.

The best practice for nesting groups is known as _________

a)

IGDLA

b)

IGUDLA

c)

Nested Virtulisation

d)

Hyper V Virtual Switch

14.

When importing user accounts from .csv file, you can use ________ (Syntax) loop to process each row in the file.

a)

Foreach

b)

NVGRE

c)

RSS

d)

RSC

15.

Compared to system container, what are the advantages of OU?

(Select Two)

a)

OU's can apply GPO's

b)

You can delegate admin

c)

OU's have Security Boundaries

d)

OU's can give IOUs

e)

OU's area part of SCHEMA

16.

Your company has purchased another company that also uses Windows Server 2016 and Active Directory. Both Companies need to be able to access each others forest resources. How can you achieve this goal with the least administrative effort?

a)

Short Cut trust

b)

Create a two way forest trust

c)

Configure a lower administrative distance

d)

Trust short cut

17.

You can have different domain functional levels within the forest, however, the lowest domain functional level determines the forest functional level. True or False?

a)

True

b)

False

18.

List the Three options that you can increase the security in forest trust.

a)

SID Filtering

b)

Selective authentication

c)

Name Suffix routing

d)

Unique Principal Names

e)

Disable Permissions

19.

_______ is used in each DC to generate IntraSite replication topology.

a)

KCC

b)

ISTG

c)

KC30

d)

IntraTopology

20.

_________ is used in each DC to generate InterSite replication topology

a)

ISTG

b)

KCC

c)

IGA

d)

InterTopology

21.

The bridgehead server is responsible for all replication into and out of the site. Instead of replication all domain controllers from one site with all domain controllers in another site. True or False?

a)

True

b)

False

22.

How to resolve replication conflict? (Choose Three)

a)

Version Number

b)

Times Stamp

c)

DCs GUID

d)

KCC

e)

Failover

23.

In windows 2008 or newer domain controllers, SYSVOL folder replication takes place by using _____________.

a)

DFS Rep

b)

NTFS Rep

c)

KCC Rep

d)

NFS Rep

24.

In a windows domain, sites are useful to quickly locate domain controllers and site-aware application and services. True or False?

a)

True

b)

False

25.

A GPO is stored in __________ and SYSVOL folder in the Domain Controller.

a)

AD DS

b)

AD FS

c)

AD HD

d)

\Sharefolder

26.

What is the default processing order that GPOs apply?

a)

1-Local

2-Site Level

3-Domain Level

4-OU GPOs

b)

1-Site Level

2-OU GPOs

3-Domain Level

4-Local Level

c)

1-Setting

2-Scope

3-Application

d)

1-IntraSite Level

2-InterSite Level

27.

How to refresh GPO in CLI?

a)

gpupdate/force

b)

gpupdate/enforce

c)

gpupdate/refresh

d)

gpupdate/generate

28.

When you delete a GPO link, you also delete the GPO as well. True or False?

a)

True

b)

False

29.

What is a starter GPO?

a)

GPO Template

b)

It stores administrative settings

c)

A Local Group

d)

A Computer Configuration Policy

30.

How do you exclude users/computers to be affected by a GPO?

a)

Configure "apply group policy" permission as deny for the specific users and computers

b)

Configure exclusions on the Delegation Tab

c)

Uncheck apply in the the administrative template settings

d)

Put the hosts in a different Subnet

31.

There is no difference between an ADMX and a ADMLfile. True or False?

a)

True

b)

False

32.

What is the difference between policies and preferences in a GPO?

a)

-Policy settings are compulsory, UI is inactive

-Preference settings are recommended, UI is active

b)

-Policy settings are recommended, UI is active

-Preference settings are compulsory, UI is inactive

33.

You have created Group Policy preferences to configure new power options. How can you make sure that they apply only to laptop computers?

a)

Configure item-level targeting in GPO preferences

b)

Configure with secpol.msc

c)

Configure Authentication Policy Silos

34.

Group policy can be used to install, maintain and remove software from organisation computers. When delivering software to client, admin has 2 deployment methods. (choose two)

a)

Assign software to computers/users

b)

Publish software to computers

c)

Designate Hardware to clients

d)

Delegate Software permissions to OUs

35.

Which technology allows you to use biometric functionality to sign in to Windows devices?

a)

Windows Hello

b)

Windows Sign in

c)

MS Passport

d)

Windows Hi

36.

When a user signs in to a domain controller, a logon event is generated in the DC. True or False?

a)

True

b)

False

37.

How are group MSAs different from standard MSAs?

a)

Can be shared by multiple servers

b)

Stored in AD

c)

Shared by App services

d)

Stored in AD DS

38.

In windows domain, administrator can create multiple ______________________ to specify multiple password policies to different users or groups within a single domain or single OU.

a)

Fine grained password policies

b)

MS Password accounts

c)

Multiple domain logins

d)

Authentication Policy Silos

e)

Organisation units

39.

________________ enable administrators to configure users, service accounts and computers within the same security scope to apply the same authentication policy.

a)

Authentication Policy Silo

b)

Fine grained password policies

c)

Multiple Servers

d)

Windows Hello

40.

Both user account names and passwords are case sensitive. True or False?

a)

True

b)

False

41.

Managed service accounts provide managed password changes that do not require administrator intervention. True or False?

a)

True

b)

False

42.

Certificate auto enrollment is an option only on enterprise CA's. True or False?

a)

True

b)

False

43.

Your company is currently acquiring another company. Both companies run their own PKI. What hierarchy could you create to minimize disruption and continue to provide PKI services seamlessly?

a)

Configure cross-certification between two companies

b)

Enroll a designated user for a KRA certificate

c)

Verify certificate validity and revocation

d)

Configure a constitutional hierarchy

44.

To recover private keys, you must configure CA to archive private keys for specific templates, and you must issue a Key Recovery Agent (KRA) certificate. True or False?

a)

True

b)

False

45.

Which of the following actions must you take to configure key archival on an AD CS CA? (choose four)

a)

Configure the KRA certificate template

b)

Enroll a designated user for a KRA certificate

c)

Publish the KRA public key by using Group Policy

d)

Configure a recovery agent on the CA

e)

Configure desired certificate templates for key archival

46.

AD FS is designed to work over the public internet with a Web Browser interface. True or False?

a)

True

b)

False

47.

Where do you deploy Application Proxy Server when deploying AD FS in a single organisation scenario?

a)

Perimeter network

b)

Boundary Network

c)

Internal Interface

d)

Active Directory Federation Service

48.

A federated trust is the same as a forest trust that organizations can configure between AD DS forests. True or False?

a)

True

b)

False

49.

In Windows Server 2016, the federation server proxy functionality is part of the Web Application Proxy role. True or False?

a)

True

b)

False

50.

How can you test whether AD FS is functioning properly?

a)

https://hostname/federationmetadata/2007-06/federationmetadata.xml

b)

https://hostname/federationmetadata/2007-06/federationmetadata.pdf

c)

www://hostname/federationmetadata/2007-06/federationmetadata.xml

d)

https://federationmetadata/hostname/2007-06/federationmetadata.xml

51.

When deploying AD FS server, the server will have 3 self-issued certificates, they are; server communication certificate (SSL), Token Signing certificate and Token-decrypting certificate. Which self-issued certificate need be replaced by an internalCA issued certificate or public-CA issued certificate, so that users can access web application from intranet/internet?

a)

communication certificate SSL

b)

Token-decrypting certificate

c)

Token-signing certificate

52.

Your company deals with highly confidential information, some of which is transmitted via email among company employess. Some documents have been forwarded via email, making the documents more difficult to track. You want to be able to prevent employes from forwarding certain emails. What should you deploy?

a)

Deploy RMS Infrastructure

b)

Deploy Todd

c)

Certification Authority

d)

Line-of-business

53.

RMS Servers provide 3 types of exclusion policies. What are they?

a)

User Exclusion

b)

Application exclusion

c)

Lockbox version exclusion

d)

Public key infrastructure exclusion

e)

Single sign on exclusion

54.

You want to block uses from protecting content by using specific versions of Microsoft PowerPoint. Which exclusion policy should you create?

a)

Application exclusion

b)

User exclusion

c)

Lockbox version exclusion

d)

Line-of-business exclusion

55.

You can install an SSL certificate on the AD RMS configuration, the benefit is that you can protect the connection between clients and the AD RMS server with SSL. True or False?

a)

True

b)

False

56.

Azure RMS is deployed locally on a server. True or False?

a)

True

b)

False

57.

To implement an AD RMS cluster, which components are necessary? (choose two)

a)

Office

b)

A service account

c)

A database

d)

AD FS

e)

A Secure Sockets Layer (SSL) certificate

58.

When you decide to remove your AD RMS cluster from AD DS, what should you do first?

a)

Decommission

b)

Commission

c)

Configure Cluster Exclusion

d)

Remove multi factor authentication

59.

When you decide to remove your AD RMS cluster from AD DS, what should you do first?

a)

Decommission

b)

Commission

c)

Configure Cluster Exclusion

d)

Remove multi factor authentication

60.

Which of the following are true statements regarding the use of certificates in a business environment? (choose three)

a)

Certificates can be used to encrypt HTTP traffic between a web server and browser

b)

Certificates can be used to digitally sign documents

c)

Digitally signed documents are invalidated if the contents are modified

d)

files encrypted using Encrypting File System (EFS) can only be read by the individual who first encrypted the file

e)

To send encrypted e-mail to an external recipient who is not a part of your internal PKI, you must use an encryption certificate issued by public CA.

61.

You are the AD CS administrator for A. Datum. You want to enable your AD DS users to perform digital signature and encryption using certificates from your internal PKI. Which step is required?

a)

Enable a key recovery agent

b)

enable a data recovery agent

c)

Publish the user certificate template and configure the desired groups of users for autoenrollment

d)

Enable EFS on AD DS domain computers by using Group Policy

e)

Upgragde all AD DS domain computers to Windows Server 2016 or Windows 10

62.

Select reasons that an organization would use a PKI? (choose 3 options)

a)

Improve Security

b)

Identity Control

c)

Account Control

d)

Digital signing of code

e)

Group Control

63.

Which of the following statements are true regarding smart cards? (choose three options)

a)

Smart cards provide an option for multifactor authentication

b)

Smart cards cannot be used for interactive sign in

c)

Smart cards contain a certificate and private key that can only be accessed by using a PIN

d)

Smart cards provide enhanced security beyond a password

e)

Smart Cards can only be used for digital signature and encryption

64.

You use __________________________ for directory synchronization between on-premises Active Directory and Azure AD.

a)

Azure AD connect

b)

Directory synchronization with SSO

c)

Azure AD Connect Health

d)

AD DS Preperation

65.

When you implement directory synchronization, user accounts and groups move from your local AD DS to Azure AD. True or False?

a)

True

b)

False

66.

If you implement AD FS and federation between locally deployed AD DS and Azure AD AD, then you do not need to use Azure AD Connect

a)

True

b)

False

67.

If you want to have SSO for both cloud-based and on-premises services, what do you need to deploy? (Choose two)

a)

Azure AD Connect Health

b)

AD FS

c)

Azure AD Connect

d)

Office 265

e)

Azure AD

68.

In Azure AD, there are no OUs or GPOs. True or False?

a)

True

b)

False

69.

By using Azure AD ___________________, you can limit standard administrator access to privileged roles, discover who can access and review privileged access.

a)

PIM

b)

PIN

c)

PAM

d)

Connect

70.

List all monitoring tools tht can be used to monitor AD DS? (5)

a)

Task Manager

b)

Resource Monitor

c)

Event Viewer

d)

Performance Monitor

e)

Windows Powershell

71.

_________________ is a command line tool which can be used to perform AD database maintenance, such as creating snapshots, performing offline defragmentation.

a)

ntdsutil.exe

b)

Data Protection Manager

c)

Windows Server Backup

d)

Azure backup

72.

AD DS has 3 states, what are they?

a)

Start

b)

Stop

c)

DSRM

d)

Go

e)

Pause

73.

____________ is a microsoft system center tool that can manage data backup/restore centrally

a)

DPM

b)

DTM

c)

Windows server backup

d)

Azure Backup

74.

You restore a Domain Controller from backup file, then restored domain controller recieve all of the recent updates from the running Domain Controllers, this restore mode is called ____________.

a)

Non-authorative Restore

b)

Authorative Restore

c)

Full Restore

d)

Update Restore