wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Identity with Windows Server Exam Revision

Total questions: 40

Worksheet time: 20mins

Name
Class
Date
1.

This best practice for nesting groups is known as

a)

IGDLA

b)

IDGLA

c)

IGLAD

d)

IAGDL

2.

__________________enable administrators con figure users, service accounts and computers within the same security scope to apply the same authentication policy

a)

Authentication policy container

b)

Authentication policy silo

c)

Authentication policy scope

d)

Authentication access control policy

3.

Which of the following statements are true regarding smart cards? (choose 3)

a)

Smart cards provide an option for multifactor authentication

b)

Smart cards cannot be used for interactive sign in

c)

Smart cards contain a certificate and private key that can only be accessed by using a PIN

d)

Smart cards provide enhanced security beyond a password

e)

Smart cards can only be used for digital signature and encryption

4.

TRUE OR FALSE?

An account lockout threshold setting ensures that users are allowed only that many invalid sign-inattempts

a)

True

b)

False

5.

You are the AD CS administrator for A. Datum. You want to enable your AD DS users to perform digital signature and encryption using certificates from your internal PKI. Which of the following steps are required?

a)

Enable a key recovery agent

b)

Enable a data recovery agent

c)

Publish the User certificate template and configure the desired groups of users for auto-enrollment

d)

Enable EFS on AD DS domain computers by using Group Policy

e)

Upgrade all AD DS domain computers to Windows Server 2016 or Windows 10

6.

TRUE OR FALSE

Managed service accounts provide managed password changes that do not require administrator intervention

a)

True

b)

False

7.

Which of the following are true statements regarding the use of certificates in a business environment? (Choose 3 )

a)

Certificates can be used to encrypt HTTP traffic between a web server and browser

b)

Certificates can be used to digitally sign documents

c)

Digitally signed documents are invalidated if the contents are modified

d)

To send encrypted e-mail to an external recipient who is not part of your internal PKI, you must use an encryption certificate issued by a public CA

e)

Files encrypted using Encrypting File System (EFS) can only be read by the individual who first encrypted the file

8.

TRUE OR FALSE

Both User account names and passwords are case sensitive

a)

True

b)

False

9.

Which of the following actions must you take to configure key archival on an AD CS CA? (Choose 4)

a)

Configure the KRA certificate template

b)

Enroll a designated user for a KRA certificate

c)

Publish the KRA public key by using Group Policy

d)

Configure a recovery agent on the CA

e)

Configure desired certificate templates for key archival

10.

When deploying AD FS SSO, where do you need deploy the application Proxy Server?

a)

Internal network

b)

External network

c)

Perimeter network

d)

Anywhere

11.

What Windows command can you use to force the immediate refresh of all GPOs on a client computer?

a)

Gpupdate /*

b)

Gpupdate /force

c)

Refresh /GPO

d)

GPO /now

12.

TRUE OR FALSE

There is no difference between ADMX and ADML files

a)

True

b)

False

13.

In what order are Group Policy Objects applied?

a)

Local policies, site-linked GPOs, domain-linked GPOs, OU-linked GPOs

b)

Site-linked GPOs, domain-linked GPOs, OU-linked GPOs, local policies

c)

Domain-linked GPOs, OU-linked GPOs, local policies, site-linked GPOs

d)

Site-linked GPOs, local policies, domain-linked GPOs, OU-linked GPOs

14.

What is the primary container object for organizing and managing resources in a domain?

a)

Groups

b)

Computer accounts

c)

OUs

d)

Security principals

15.

What are the two main purposes of OUs? (choose 2)

a)

to provide a framework for delegations of administration

b)

to provide a place to store files

c)

to provide a structure to enable the targeted GPO deployment

d)

to provide a structure to enable PowerShell commands

16.

Which of the following is a valid Group Type?

a)

Global

b)

Domain local

c)

Local

d)

Distribution

17.

What type of Active Directory accounts should we restrict password changes on?

a)

Managed Service accounts

b)

User accounts

c)

Computer accounts

d)

Bank accounts

18.

To implement an AD RMS cluster, which components are necessary? (choose 2)

a)

Office

b)

A service account

c)

A database

d)

AD FS

e)

A Secure Sockets Layer (SSL) certificate

19.

TRUE OR FALSE

Azure RMS is deployed locally on a server.

a)

True

b)

False

20.

you use ____________________ for directory synchronization between on-premises Active Directory and Azure AD

a)

Active Directory sync tool

b)

Azure AD connect

c)

Federation Service

d)

Dynamic Control Access

21.

TRUE OR FALSE

If you implement AD FS and federation between locally deployed AD DS and Azure AD, then youdo not need to use Azure AD Connect.

a)

True

b)

False

22.

If you want to have SSO for both cloud-based and on-premises services, what do you need to deploy? Choose all that apply. (choose 2)

a)

Azure AD Connect Health

b)

AD FS

c)

Azure AD Connect

d)

Office 365

e)

Azure AD

23.

TRUE OR FALSE

In Azure AD, there are no OUs or GPOs.

a)

True

b)

False

24.

_______________ is a command line tool which can used to performance AD databasemaintenance, such as creating snapshots, perform offline defragmentation.

a)

adprep

b)

certutil

c)

ntdsutil

d)

adutil

25.

TRUE OR FALSE

Creating a connection object manually between Domain Controllers with in a site is not typically required or recommended because the KCC does not verify or use the manual connection object for failover.

a)

True

b)

False

26.

Before you deploy AD RMS it is best practice to:

a)

Analyise your organization’s business requirements

b)

create the necessary templates

c)

Strictly control membership of the Super Users

d)

All of the above

27.

TRUE OR FALSE

You can access https://hostname/federationmetadata/2007-06/federationmetadata.xml on theAD FS server to test whether AD FS is functioning properly

a)

True

b)

False

28.

TRUE OR FALSE

AD FS is designed to work over the public Internet with a Web browser interface.

a)

True

b)

False

29.

Your company deals with highly confidential information, some of which is transmitted via email among employees. Some documents have been forwarded via email, making the documents more difficult to track. You want to be able to prevent employees from forwarding certain emails. What should you deploy?

a)

EFS

b)

Web SSO

c)

AD RMS

d)

AD CS

30.

TRUE OR FALSE

To recover private keys, you must configure CA to archive private keys for specific templates, and you must issue a Key Recovery Agent (KRA) certificate.

a)

True

b)

False

31.

You want to block users from protecting content by using specific version of MicrosoftPowerPoint . What steps should you take to accomplish this goal?

a)

You should configure an application exclusion for the PowerPoint application

b)

Unaffiliated PowerPoint files

c)

Lockdown the Windows Azure™ Rights Management

d)

Link the PowerPoint database to AD RMS

32.

TRUE OR FALSE

The benefits of having an SSL certificate installed on the AD RMS server when you are performingAD RMS configuration that you can protect the connection between clients and the AD RMSserver with SSL.

a)

True

b)

False

33.

Which of the following is a type of AD RMS exclusion policy? (Choose 2)

a)

User Exclusion

b)

Machine Exclusion

c)

Lockbox Version Exclusion

d)

Address Exclusion

34.

What are not reasons that an organization would utilize PKI for? (Choose 2)

a)

Improve security

b)

Identity control

c)

Account control

d)

Digital signing of code

e)

Group control

35.

TRUE OR FALSE

Certificate auto enrolment is an option only on enterprise CAs.

a)

True

b)

False

36.

What is an advantage of reducing the intersite replication interval?

a)

Reducing the intersite replication interval decreases convergence

b)

Reducing the intersite replication interval allows Group policy to converge quicker

c)

Reducing the intersite replication interval improves convergence

d)

Reducing the intersite replication interval allows new users to log on faster

37.

What is the purpose of a bridgehead server?

a)

The bridgehead server is responsible for only some replication into and out of the site

b)

you can use bridgehead servers to manage internal replication

c)

The bridgehead server is responsible for all replication into and out of the site. Insteadof replicating all domain controllers from one site with all domain controllers in another site

d)

You can use bridgehead servers to manage intersite replication as long as all theservers are set to be a bridgehead server

38.

Which of the following is true about the domain functional level?

a)

All DCs and member servers must be running the Windows version that supports the functional level

b)

You must raise the functional level on all DCs

c)

You can have different domain functional levels within the forest

d)

The domain and forest functional level must be the same

39.

our company has purchased another company that also uses Windows Server 2012 R2 and Active Directory. Both companies need to be able to access each other's forest resources. How can you achieve this goal with the least administrative effort?

a)

Share the global catalog for both companies

b)

Create a two-way forest trust

c)

Configure an external trust

d)

Configure selective authentication

40.

Which technology allows you to use biometric functionality to sign in to Windows devices?

a)

Windows Hello

b)

Microsoft Passport

c)

TMP integration

d)

Bio-Tech