Font size
WorksheetsIdentity with Windows Server Exam Revision
Total questions: 40
Worksheet time: 20mins
This best practice for nesting groups is known as
IGDLA
IDGLA
IGLAD
IAGDL
__________________enable administrators con figure users, service accounts and computers within the same security scope to apply the same authentication policy
Authentication policy container
Authentication policy silo
Authentication policy scope
Authentication access control policy
Which of the following statements are true regarding smart cards? (choose 3)
Smart cards provide an option for multifactor authentication
Smart cards cannot be used for interactive sign in
Smart cards contain a certificate and private key that can only be accessed by using a PIN
Smart cards provide enhanced security beyond a password
Smart cards can only be used for digital signature and encryption
TRUE OR FALSE?
An account lockout threshold setting ensures that users are allowed only that many invalid sign-inattempts
True
False
You are the AD CS administrator for A. Datum. You want to enable your AD DS users to perform digital signature and encryption using certificates from your internal PKI. Which of the following steps are required?
Enable a key recovery agent
Enable a data recovery agent
Publish the User certificate template and configure the desired groups of users for auto-enrollment
Enable EFS on AD DS domain computers by using Group Policy
Upgrade all AD DS domain computers to Windows Server 2016 or Windows 10
TRUE OR FALSE
Managed service accounts provide managed password changes that do not require administrator intervention
True
False
Which of the following are true statements regarding the use of certificates in a business environment? (Choose 3 )
Certificates can be used to encrypt HTTP traffic between a web server and browser
Certificates can be used to digitally sign documents
Digitally signed documents are invalidated if the contents are modified
To send encrypted e-mail to an external recipient who is not part of your internal PKI, you must use an encryption certificate issued by a public CA
Files encrypted using Encrypting File System (EFS) can only be read by the individual who first encrypted the file
TRUE OR FALSE
Both User account names and passwords are case sensitive
True
False
Which of the following actions must you take to configure key archival on an AD CS CA? (Choose 4)
Configure the KRA certificate template
Enroll a designated user for a KRA certificate
Publish the KRA public key by using Group Policy
Configure a recovery agent on the CA
Configure desired certificate templates for key archival
When deploying AD FS SSO, where do you need deploy the application Proxy Server?
Internal network
External network
Perimeter network
Anywhere
What Windows command can you use to force the immediate refresh of all GPOs on a client computer?
Gpupdate /*
Gpupdate /force
Refresh /GPO
GPO /now
TRUE OR FALSE
There is no difference between ADMX and ADML files
True
False
In what order are Group Policy Objects applied?
Local policies, site-linked GPOs, domain-linked GPOs, OU-linked GPOs
Site-linked GPOs, domain-linked GPOs, OU-linked GPOs, local policies
Domain-linked GPOs, OU-linked GPOs, local policies, site-linked GPOs
Site-linked GPOs, local policies, domain-linked GPOs, OU-linked GPOs
What is the primary container object for organizing and managing resources in a domain?
Groups
Computer accounts
OUs
Security principals
What are the two main purposes of OUs? (choose 2)
to provide a framework for delegations of administration
to provide a place to store files
to provide a structure to enable the targeted GPO deployment
to provide a structure to enable PowerShell commands
Which of the following is a valid Group Type?
Global
Domain local
Local
Distribution
What type of Active Directory accounts should we restrict password changes on?
Managed Service accounts
User accounts
Computer accounts
Bank accounts
To implement an AD RMS cluster, which components are necessary? (choose 2)
Office
A service account
A database
AD FS
A Secure Sockets Layer (SSL) certificate
TRUE OR FALSE
Azure RMS is deployed locally on a server.
True
False
you use ____________________ for directory synchronization between on-premises Active Directory and Azure AD
Active Directory sync tool
Azure AD connect
Federation Service
Dynamic Control Access
TRUE OR FALSE
If you implement AD FS and federation between locally deployed AD DS and Azure AD, then youdo not need to use Azure AD Connect.
True
False
If you want to have SSO for both cloud-based and on-premises services, what do you need to deploy? Choose all that apply. (choose 2)
Azure AD Connect Health
AD FS
Azure AD Connect
Office 365
Azure AD
TRUE OR FALSE
In Azure AD, there are no OUs or GPOs.
True
False
_______________ is a command line tool which can used to performance AD databasemaintenance, such as creating snapshots, perform offline defragmentation.
adprep
certutil
ntdsutil
adutil
TRUE OR FALSE
Creating a connection object manually between Domain Controllers with in a site is not typically required or recommended because the KCC does not verify or use the manual connection object for failover.
True
False
Before you deploy AD RMS it is best practice to:
Analyise your organization’s business requirements
create the necessary templates
Strictly control membership of the Super Users
All of the above
TRUE OR FALSE
You can access https://hostname/federationmetadata/2007-06/federationmetadata.xml on theAD FS server to test whether AD FS is functioning properly
True
False
TRUE OR FALSE
AD FS is designed to work over the public Internet with a Web browser interface.
True
False
Your company deals with highly confidential information, some of which is transmitted via email among employees. Some documents have been forwarded via email, making the documents more difficult to track. You want to be able to prevent employees from forwarding certain emails. What should you deploy?
EFS
Web SSO
AD RMS
AD CS
TRUE OR FALSE
To recover private keys, you must configure CA to archive private keys for specific templates, and you must issue a Key Recovery Agent (KRA) certificate.
True
False
You want to block users from protecting content by using specific version of MicrosoftPowerPoint . What steps should you take to accomplish this goal?
You should configure an application exclusion for the PowerPoint application
Unaffiliated PowerPoint files
Lockdown the Windows Azure™ Rights Management
Link the PowerPoint database to AD RMS
TRUE OR FALSE
The benefits of having an SSL certificate installed on the AD RMS server when you are performingAD RMS configuration that you can protect the connection between clients and the AD RMSserver with SSL.
True
False
Which of the following is a type of AD RMS exclusion policy? (Choose 2)
User Exclusion
Machine Exclusion
Lockbox Version Exclusion
Address Exclusion
What are not reasons that an organization would utilize PKI for? (Choose 2)
Improve security
Identity control
Account control
Digital signing of code
Group control
TRUE OR FALSE
Certificate auto enrolment is an option only on enterprise CAs.
True
False
What is an advantage of reducing the intersite replication interval?
Reducing the intersite replication interval decreases convergence
Reducing the intersite replication interval allows Group policy to converge quicker
Reducing the intersite replication interval improves convergence
Reducing the intersite replication interval allows new users to log on faster
What is the purpose of a bridgehead server?
The bridgehead server is responsible for only some replication into and out of the site
you can use bridgehead servers to manage internal replication
The bridgehead server is responsible for all replication into and out of the site. Insteadof replicating all domain controllers from one site with all domain controllers in another site
You can use bridgehead servers to manage intersite replication as long as all theservers are set to be a bridgehead server
Which of the following is true about the domain functional level?
All DCs and member servers must be running the Windows version that supports the functional level
You must raise the functional level on all DCs
You can have different domain functional levels within the forest
The domain and forest functional level must be the same
our company has purchased another company that also uses Windows Server 2012 R2 and Active Directory. Both companies need to be able to access each other's forest resources. How can you achieve this goal with the least administrative effort?
Share the global catalog for both companies
Create a two-way forest trust
Configure an external trust
Configure selective authentication
Which technology allows you to use biometric functionality to sign in to Windows devices?
Windows Hello
Microsoft Passport
TMP integration
Bio-Tech
