Font size
Worksheets20742B: Identity with Windows Server (Part B)
Total questions: 52
Worksheet time: 31mins
All new GPO's are automatically linked to the local domain. True or false?
True
False
What is the order in which GPO'S are processed on a client computer
Child OU, OU, Domain, Site, Local
Local, Site, Domain, OU, Child OU
Site, Domain, Local, Child OU, OU
Domain, Site, OU, Child OU, Local
Administrative templates modify registry keys. Select the two hives in the registry.
HKEY_CURRENT_CONFIG
HKEY_LOCAL_MACHINE
HKEY_USERS\.DEFAULT
HKEY_CURRENT_USER
Select the registry based policy from the list
Starter Group Policy
Local Group Policy
Administrative Template
What are the two types of files used to store in Administrative Templates
.XML files
.ADM files
.ACL files
.ADMX files
.ADMX files are copied into every GPO in SYSVOL folder. True or False?
True
False
.ADM are language neutral. True or False?
True
False
Create a folder as a common place at SYSVOL folder to store .admx files is called as
External Drive
Central Store
Shared Folder
Options available in folder redirection
Active
None
Basic
Disabled
Advanced
Group policy preferences are set of extensions that expand the functionality of GPO’s, True or False?
True
False
What are scripting language used in group policy scripts? Select 2 from the list
Pearl script
VB script
PHP
Jscript
In-regards to Fine-grained polices, select one option from the list.
Provide the ability to specify different password policies and account lockouts
Provide the ability to specify single password policy and account lockout
Provide the ability to eliminate password polices
From the list select the Multi-factor bio-metric method authentication
Finger print
Digital signature
Voice recognition
User ID and password
What's the default maximum password age?
32
44
42
46
Account lock down durations are calculated in
Days
Seconds
Hours
Minutes
A value of '0' is set in Account Lockout Threshold, which means ...
The account is never locked out
The account is locked out and you must contact administrator
The account will wait for 1 hour and then user can try to login
Managed service account. Select one correct answer from the list
MSA user must change his password to gain access to a service
MSA can provide a program with its own unique account
MSA defines a contract between IT vendor and a client
What's the default settings for enforce password history?
14
24
34
ADCS is one of the following. Select one correct answer from the following list:
Active Directory Computer Services
Active Directory Certificate services
Active Directory Corporate services
CA issues certificate to entities, choose 2 entities
Users
Computers
Public key
Private key
What are the 2 parts in a digital certificate?
Public key
Private key
Customer address
Provider address
Select 2 correct answers about a CA
CA is a computer in ADCS server role installed
CA is a user or administrator in ADCS
CA can sign and revoke certificates
CA is a router in ADCS
Root CA certificates are issued by another CA, True or False?
True
False
Select 1 correct answer about Subordinate CA from the list of options
Is the most trusted type of CA hierarchy
has a self-signed certificate
there could be 1 or many in a certificate hierarchy
mandatory in a CA hierarchy
Select 2 certificate templates from the list
Folder
Computer
User
File
Select the tool to manage certificates. Select all the correct answers
PKI view
Certutil.exe
Online Responder
ADprep
In RODC, by default, user credentials are replicated, True or False?
True
False
________________ allows you to implement a PKI for your organisation
ADFS
ADDS
ADCS
Certificate enrollment methods includes the following, select the missing one
Auto enrollment
Manual enrollment
CA web enrollment
Advanced enrollment
Private enrollment
Enroll on Behalf
Basic enrollment
KRA refers to (a)
Revocation is the process in which you enable the validity of one or more certificates, True or False?
True
False
What's AIA in deploying certificates?
Authority Information Access
Authority Information Administration
Administrator Internal Access
Certificate enrollment methods includes the following, select 2 methods
Public enrollment
Private enrollment
CA web enrollment
Enrollment on behalf
Configuration management is:
Are used by system objects as the default location for new objects
Is the user account that is authenticated to the domain controller
A centralised approach to applying one or more changes to more than one computer or user
Is a role performed only on a specific computer in a domain controller
What's VSC in security and identification? Select one answer from the list
Volume Shadow Copy
Virtual Shared Computer
Virtual Smart Card
Visual Studio Computer
What are the two types of CA's in two-tier CA hierarchy?
Root
Forest
Domain
Subordinate
In configuring certificate template permissions, fill in the missing permissions
Read, Write, Full Control, Enroll, (a)
The claims provider is the server that issues claims and authenticates users, True or False?
True
False
Select 2 ADFS components
Attribute store
Key Recovery Agent
Online Responder service
Endpoints
Profile
In a federated trust, the ______________ servers in 2 organisations never have to communicate directly with each other. All communications happens over HTTPS.
ADDS Servers
ADCS
ADFS
DNS
ADRMS is used to ...
Backup and recover
safeguard digital information
replicate user information
communicate with ADFS server
Select ADRMS-aware applications
Exchange
SharePoint server
Office 365
All of the above
In ADRMS, every entity that interacts with the system is represented by a certificate, True or False?
True
False
Dfsrmig is tool to perform migration from FRS to DFS, True or False?
True
False
You should create additional sites in AD for the following reasons:
(Select 2 from the correct answers from the following)
A connection between your HO and branch office location is less than 512kb/s
To create a subnet in the network
Clients use domain controllers that are nearest to them for authentication
To have a different website in IIS
Creates the replication topology for Sites. Select 1 correct answer from the following
DCdiag.exe
ISTG
Repadmin.exe
To implement in AD RMS cluster, which components are necessary?
Office
A Service Account
A Database
ADFS
A Secure Sockets Layer (SSL) certificate
What's the information that's not contained in the physical certificate when you compare it with a digital certificate?
Public Key
Email Address
Private Key
User ID
Certificate is a ______________
Command
File
Database
Schema
Version 1 templates can be duplicated to create version 2 or 3 templates, True or False?
True
False
Information protection technology to safeguard digital information that works with _________ enabled applications
RSAT
ADRMS
ADIMS
ADFS
When you install ADDS, a default site named "Default First-site-Name" is created, True or False?
True
False
