wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

20742 - Identity with Window Ser - Mod 10, 11, 12, and 13 quiz

Total questions: 33

Worksheet time: 19mins

Name
Class
Date
1.

You can access https://hostname/federationmetadata/2007-06/federationmetadata.xml on the AD FS server to test whether AD FS is functioning properly. True or false?

a)

True

b)

False

2.

A federated trust is the same as a forest trust that organizations can configure between AD DS forests.

a)

True

b)

False

3.

In Windows Server 2016, the federation server proxy functionality is part of the Web Application Proxy role.

a)

True

b)

False

4.

Which of the following you might need to prepare the before installing AD FS?

a)

SQL Server

b)

Service account

c)

Certificates

d)

DHCP

e)

All of them

5.

Which of the following statements about configuring the Web Application Proxy is true?

a)

To install the Web Application Proxy, you first must implement AD FS in your organization.

b)

For each application that you publish, you must configure an external URL and an internal server URL.

c)

  When you define the external URL, you must also select a certificate that contains the host name in the external URL.

d)

    All of the above

6.

Which of the following is a critical infrastructure for a successful AD FS deployment?

a)

AD DS    

b)

Operating system

c)

Web server

d)

  File server

7.

Expansion of SOAP?

a)

Simple Object Array Protocol 

b)

Sample Object Array Protocol

c)

Simple Object Access Protocol

d)

Sample Object Access Protocol

8.

The ____________ issues, manages, and validates requests involving identity claims. All implementations of AD FS require at least one Federation Service for each participating party.

a)

    Certificates   

b)

Relying parties

c)

Claims providers

d)

Federation server

9.

AD FS uses a ____________ to sign every token that a federation server issues. This certificate is critical in an AD FS deployment because the token signature indicates which federation server issued the token.

a)

Service communication certificates

    

b)

Token-decrypting certificates

c)

Token-signing certificates

d)

All of them

10.

Which of the following is a type of AD RMS exclusion policy?

(Choose TWO)

a)

User Exclusion

b)

Address Exclusion

c)

Lockbox Version Exclusion

d)

Machine Exclusion    

11.

The benefits of having an SSL certificate installed on the AD RMS server when you are performing AD RMS configuration that you cannot protect the connection between clients and the AD RMS server with SSL. True or false?

a)

True

b)

False

12.

Your company deals with highly confidential information, some of which is transmitted via email among employees. Some documents have been forwarded via email, making the documents more difficult to track. You want to be able to prevent employees from forwarding certain emails. What should you deploy?

a)

EFS

   

b)

Web SSO

c)

AD RMS

d)

AD CS

13.

Which of the following are the best practice before you deploy AD RMS?

a)

Not necessary to Analyze your organization’s business requirements

  

b)

create the necessary templates

c)

Strictly control membership of the Super Users

d)

All of the them

14.

Azure RMS is deployed locally on a server. True or False?

a)

True

b)

False

15.

To implement an AD RMS cluster, which components are necessary?

(Choose TWO)

a)

Office    

b)

A Secure Sockets Layer (SSL) certificate

c)

AD FS

d)

A database

e)

A service account

16.

When does a user receives a RAC?

a)

A RAC is issued the first time a user attempts to access AD RMS-protected content or to perform an AD RMS task, such as creating a protected document.    

b)

A RAC is issued the second time a user attempts to access AD RMS-protected content or to perform an AD RMS task.

c)

A RAC is issued the third time a user attempts to access AD RMS-protected content or to perform an AD RMS task.

d)

None of the above

17.

What kinds of permissions does a Super Users group have?

a)

Super Users group members are granted limited rights in all use licenses that are issued by the AD RMS cluster on which the Super Users group is configured.

b)

Super Users group members are granted full owner rights in all use licenses that are issued by the AD RMS cluster on which the Super Users group is configured.

c)

Super Users group members are granted Read/Write rights in all use licenses that are issued by the AD RMS cluster on which the Super Users group is configured.

d)

None of the above.

18.

You want to block users from protecting content by using specific version of Microsoft PowerPoint. What steps should you take to accomplish this goal?

a)

You should configure an application exclusion for the PowerPoint application

b)

Unaffiliated PowerPoint files 

c)

Lockdown the Windows Azure™ Rights Management

d)

Link the PowerPoint database to AD RMS 

19.

Which of the following scenarios you can deploy for AD RMS?

a)

Deployed in a single forest    

b)

Used on an extranet

c)

Integrated with AD FS

d)

All of the above

e)

Deployed in multiple forests

20.

When you implement directory synchronization, user accounts and groups move from your local AD DS to Azure AD. True or false?

a)

True

b)

False

21.

Which of the following are the key differences between Azure AD and AD DS?

a)

a) Azure AD is designed for Intranet-based applications

b)

b)  In Azure AD, there are no OUs or GPOs

c)        Azure AD cannot be queried through LDAP

c)

d) Azure AD does not use Kerberos authentication

e)       Azure AD includes federation services

d)

All of the above

22.

If you want to have SSO for both cloud-based and on-premises services, what do you need to deploy?

(Choose TWO)

a)

Azure AD Connect Health 

b)

Azure AD

c)

Office 365

d)

Azure AD Connect

e)

AD FS

23.

If you implement AD FS and federation between locally deployed AD DS and Azure AD, then you do not need to use Azure AD Connect. True or false?

a)

True

b)

False

24.

Which cmdlet should you use to change the synchronization schedule for Azure AD Connect?

a)

Set-ADSyncScheduler  

b)

Get-ADSyncSchedulerConnectorOverride

c)

Set-ADSyncSchedulerConnectorOverride

d)

Start-ADSyncSyncCycle

25.

What are the tools to monitor directory synchronization?

a)

a) Operations Manager

b) The Azure classic portal

 

b)

c) Windows PowerShell

c)

d) Synchronization Service Manager

e) Event logs

d)

  All of the above

26.

The cmdlet Initialize-ADSyncGroupWriteBack prepares AD DS automatically for group writeback. True or false?

a)

True

b)

False

27.

In Azure AD, there are no OUs or GPOs. True or False?

a)

True

b)

False

28.

You use ____________________ for directory synchronization between on-premises Active Directory and Azure AD.

a)

Active Directory sync tool  

b)

Dynamic Control Access

c)

Federation Service

d)

Azure AD connect

29.

When you identify the Azure AD Connect requirements, which of the following you should review?

a)

a)       Azure AD CS requirements

b)

b)       Domain and forest requirements

c)        Operating system and supporting software requirements

c)

d)       Permissions and accounts

e)       Database requirements

d)

All of the above

30.

What kind of restoration can you perform with AD DS?

a)

Authoritative restore

b)

non authoritative restore

c)

restoration of single onjects with AD recycle bin

d)

All of them

31.

In the lab, would it be possible to restore the deleted objects if they were deleted before you enabled AD recycle bin. Yes or No?

a)

Yes

b)

No

32.

You can use NTtdsUtil to: SELECT all that apply.

a)

Manage and control multi-master operations

b)

Perform AD database maintenance

c)

Clean Domain controller metadata

d)

Reset DSRM

33.

Data collector sets can contain the following types of data collectors: SELECT THREE

a)

Performance counters

b)

Event trace data

c)

System configuration information

d)

Task Manager

e)

Resource Monitor