Font size
Worksheets20742 - Identity with Window Ser - Mod 10, 11, 12, and 13 quiz
Total questions: 33
Worksheet time: 19mins
You can access https://hostname/federationmetadata/2007-06/federationmetadata.xml on the AD FS server to test whether AD FS is functioning properly. True or false?
True
False
A federated trust is the same as a forest trust that organizations can configure between AD DS forests.
True
False
In Windows Server 2016, the federation server proxy functionality is part of the Web Application Proxy role.
True
False
Which of the following you might need to prepare the before installing AD FS?
SQL Server
Service account
Certificates
DHCP
All of them
Which of the following statements about configuring the Web Application Proxy is true?
To install the Web Application Proxy, you first must implement AD FS in your organization.
For each application that you publish, you must configure an external URL and an internal server URL.
When you define the external URL, you must also select a certificate that contains the host name in the external URL.
All of the above
Which of the following is a critical infrastructure for a successful AD FS deployment?
AD DS
Operating system
Web server
File server
Expansion of SOAP?
Simple Object Array Protocol
Sample Object Array Protocol
Simple Object Access Protocol
Sample Object Access Protocol
The ____________ issues, manages, and validates requests involving identity claims. All implementations of AD FS require at least one Federation Service for each participating party.
Certificates
Relying parties
Claims providers
Federation server
AD FS uses a ____________ to sign every token that a federation server issues. This certificate is critical in an AD FS deployment because the token signature indicates which federation server issued the token.
Service communication certificates
Token-decrypting certificates
Token-signing certificates
All of them
Which of the following is a type of AD RMS exclusion policy?
(Choose TWO)
User Exclusion
Address Exclusion
Lockbox Version Exclusion
Machine Exclusion
The benefits of having an SSL certificate installed on the AD RMS server when you are performing AD RMS configuration that you cannot protect the connection between clients and the AD RMS server with SSL. True or false?
True
False
Your company deals with highly confidential information, some of which is transmitted via email among employees. Some documents have been forwarded via email, making the documents more difficult to track. You want to be able to prevent employees from forwarding certain emails. What should you deploy?
EFS
Web SSO
AD RMS
AD CS
Which of the following are the best practice before you deploy AD RMS?
Not necessary to Analyze your organization’s business requirements
create the necessary templates
Strictly control membership of the Super Users
All of the them
Azure RMS is deployed locally on a server. True or False?
True
False
To implement an AD RMS cluster, which components are necessary?
(Choose TWO)
Office
A Secure Sockets Layer (SSL) certificate
AD FS
A database
A service account
When does a user receives a RAC?
A RAC is issued the first time a user attempts to access AD RMS-protected content or to perform an AD RMS task, such as creating a protected document.
A RAC is issued the second time a user attempts to access AD RMS-protected content or to perform an AD RMS task.
A RAC is issued the third time a user attempts to access AD RMS-protected content or to perform an AD RMS task.
None of the above
What kinds of permissions does a Super Users group have?
Super Users group members are granted limited rights in all use licenses that are issued by the AD RMS cluster on which the Super Users group is configured.
Super Users group members are granted full owner rights in all use licenses that are issued by the AD RMS cluster on which the Super Users group is configured.
Super Users group members are granted Read/Write rights in all use licenses that are issued by the AD RMS cluster on which the Super Users group is configured.
None of the above.
You want to block users from protecting content by using specific version of Microsoft PowerPoint. What steps should you take to accomplish this goal?
You should configure an application exclusion for the PowerPoint application
Unaffiliated PowerPoint files
Lockdown the Windows Azure™ Rights Management
Link the PowerPoint database to AD RMS
Which of the following scenarios you can deploy for AD RMS?
Deployed in a single forest
Used on an extranet
Integrated with AD FS
All of the above
Deployed in multiple forests
When you implement directory synchronization, user accounts and groups move from your local AD DS to Azure AD. True or false?
True
False
Which of the following are the key differences between Azure AD and AD DS?
a) Azure AD is designed for Intranet-based applications
b) In Azure AD, there are no OUs or GPOs
c) Azure AD cannot be queried through LDAP
d) Azure AD does not use Kerberos authentication
e) Azure AD includes federation services
All of the above
If you want to have SSO for both cloud-based and on-premises services, what do you need to deploy?
(Choose TWO)
Azure AD Connect Health
Azure AD
Office 365
Azure AD Connect
AD FS
If you implement AD FS and federation between locally deployed AD DS and Azure AD, then you do not need to use Azure AD Connect. True or false?
True
False
Which cmdlet should you use to change the synchronization schedule for Azure AD Connect?
Set-ADSyncScheduler
Get-ADSyncSchedulerConnectorOverride
Set-ADSyncSchedulerConnectorOverride
Start-ADSyncSyncCycle
What are the tools to monitor directory synchronization?
a) Operations Manager
b) The Azure classic portal
c) Windows PowerShell
d) Synchronization Service Manager
e) Event logs
All of the above
The cmdlet Initialize-ADSyncGroupWriteBack prepares AD DS automatically for group writeback. True or false?
True
False
In Azure AD, there are no OUs or GPOs. True or False?
True
False
You use ____________________ for directory synchronization between on-premises Active Directory and Azure AD.
Active Directory sync tool
Dynamic Control Access
Federation Service
Azure AD connect
When you identify the Azure AD Connect requirements, which of the following you should review?
a) Azure AD CS requirements
b) Domain and forest requirements
c) Operating system and supporting software requirements
d) Permissions and accounts
e) Database requirements
All of the above
What kind of restoration can you perform with AD DS?
Authoritative restore
non authoritative restore
restoration of single onjects with AD recycle bin
All of them
In the lab, would it be possible to restore the deleted objects if they were deleted before you enabled AD recycle bin. Yes or No?
Yes
No
You can use NTtdsUtil to: SELECT all that apply.
Manage and control multi-master operations
Perform AD database maintenance
Clean Domain controller metadata
Reset DSRM
Data collector sets can contain the following types of data collectors: SELECT THREE
Performance counters
Event trace data
System configuration information
Task Manager
Resource Monitor
