wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Active Directory Domain Services (AD DS) Fundamentals Quiz

Total questions: 109

Worksheet time: 55mins

Name
Class
Date
1.

Which of the following are defining characteristics of an AD DS forest? (Choose two)

a)

Each domain in a forest has its own unique schema and configuration partitions.

b)

Forests are security boundaries, restricting resource access to security principals within the forest.

c)

Forests are replicated between domain controllers in different forests.

d)

Forests are replication boundaries for the domain global catalog.

2.

What is the primary role of the Schema master in an Active Directory Domain Services (AD DS) forest?

a)

Managing changes to the AD DS configuration when domains are added or removed.

b)

Maintaining administrative privileges throughout the forest.

c)

Ensuring the availability of the global catalog across all domain controllers.

d)

Overseeing modifications to the AD DS schema.

3.

Which of the following best defines a characteristic of an Active Directory Domain Services (AD DS) domain?

a)

Each domain is an administrative boundary, allowing full administrative control only to the Domain Admins group.

b)

Domains are replication boundaries, with changes to domain objects replicated between domains.

c)

Each domain has its own unique schema and configuration partitions.

d)

Domains are high-level containers that store objects such as users, groups, computers, and other OUs.

4.

What is one purpose of Organizational Units (OUs) in Active Directory?

a)

To store user and computer account passwords.

b)

To host built-in domain local groups.

c)

To delegate administrative tasks to smaller teams or individuals at departmental levels.

d)

To manage domain controller replication.

5.

What does the Active Directory Domain Services (AD DS) schema define?

a)

The number of objects in a domain.

b)

The location of domain controllers within each site found in a forest.

c)

Types of objects, attributes of those objects, and the AD DS structure.

d)

The naming conventions for OUs.

6.

What is the purpose of the Active Directory Schema console?

a)

To create new user accounts in Active Directory.

b)

To manage the incoming trust relationships between domains in the same forest.

c)

To edit the schema directly and make changes to object classes and attributes.

d)

To manage domain controller replication.

7.

What is required to edit the schema directly and make changes to object classes and attributes in Active Directory?

a)

To edit the schema directly and make changes to object classes and attributes.

b)

To configure Group Policy Objects (GPOs) for domain-wide settings.

c)

To manage user accounts.

d)

To set up file sharing services.

8.

Which method is recommended for securing Domain Controllers (DCs) in branch offices where physical security is challenging?

a)

Deploying Read-only Domain Controllers (RODCs) and enabling BitLocker Drive Encryption.

b)

Configuring DCs to use single-factor authentication.

c)

Storing DC backups on unencrypted external hard drives.

d)

Disabling Lightweight Directory Access Protocol (LDAP) on DCs.

9.

What service does a Domain Controller (DC) advertise using SRV records in DNS?

a)

Active Directory services

b)

File sharing services

c)

Print services

d)

Domain Name System (DNS) services

10.

How can you designate a Domain Controller (DC) as a global catalog server in Active Directory?

a)

During AD DS promotion or using the Active Directory Sites and Services tool after promotion.

b)

By configuring it as the forest root domain controller.

c)

By promoting it to be a read-only Domain Controller (RODC).

d)

By adding it to the Enterprise Admins universal security group.

11.

In a multiple-domain environment, what is the recommendation regarding the deployment of global catalog servers?

a)

Ensure that DCs with the infrastructure operations master role are not global catalog servers.

b)

Make all DCs global catalog servers regardless of their roles.

c)

Deploy at least one global catalog server per domain.

d)

Deploy at least one global catalog server per physical AD DS site.

12.

The Kerberos authentication service is available on which port?

a)

88 over TCP and UDP.

b)

464 over TCP and UDP.

c)

TCP port 389.

d)

TCP port 3268.

13.

Which domain controller (DC) is selected when there is a tie in the lowest numerical priority value for a specific operation?

a)

The DC with the lowest numerical weight value.

b)

The DC with the highest numerical priority value.

c)

The DC with the highest numerical priority value, and if tied, the one with the highest weight value.

d)

The DC with the lowest numerical priority value, and if tied, the one with the highest weight value.

14.

What is the impact of the PDC emulator operations master role becoming unavailable?

a)

Low impact, as it only prevents schema modifications.

b)

Medium impact, as it prevents the creation of new security principals.

c)

High impact, affecting password changes, GPO management, and time synchronization.

d)

No impact, as it does not affect directory functionality.

15.

When should you consider transferring or seizing an operations master role?

a)

When planning software updates for a domain controller.

b)

When deploying a new RODC in the forest.

c)

Prior to taking the role holder offline for planned maintenance.

d)

When adding a new user to the domain.

16.

Which tool would you use to determine the current holder of the RID master operations master role?

a)

Active Directory Users and Computers

b)

Active Directory Schema

c)

Active Directory Domains and Trusts

d)

Active Directory Sites and Services

17.

Which TWO methods can be used to install the Active Directory Domain Services role on a Server Core server? (Choose 2)

a)

Use Server Manager on the Server Core server to add the role.

b)

Open Server Manager on another computer and connect to the Server Core server to add the role.

c)

Use an elevated Windows PowerShell command prompt to run Install-WindowsFeature AD-Domain-Services.

d)

Use the Active Directory Domain Services Configuration Wizard on the Server Core server.

18.

What is the purpose of the "Install from media" option when deploying a Domain Controller (DC)?

a)

To synchronize time between DCs during the promotion process.

b)

To populate the AD DS database without needing to replicate from another DC.

c)

To verify the functionality of SRV records in DNS.

d)

To clone existing DCs for accelerated deployment.

19.

What is the first step in preparing the source virtual DC for cloning?

a)

Add the source DC to the Cloneable Domain Controllers group.

b)

Verify the functionality of SRV records in DNS.

c)

Run the Active Directory Domain Services Configuration Wizard.

d)

Install the DNS Server role on the source DC.

20.

What is a best practice for virtualizing Domain Controllers (DCs)?

a)

Synchronize time between virtualized DCs and physical computers.

b)

Use checkpoints to create backup copies of DCs for easy restoration.

c)

Deploy only one virtualized DC to minimize resource consumption.

d)

Use a hypervisor that does not support VM generation IDs.

21.

What is the primary purpose of Microsoft Entra ID?

a)

Providing authentication and authorization for cloud apps and services

b)

Managing on-premises infrastructure and apps

c)

Supporting directory-aware apps in on-premises environments

d)

Implementing role-based access control for on-premises resources

22.

Which feature is NOT characteristic of Microsoft Entra ID?

a)

Hierarchical structure

b)

Conditional access

c)

Multifactor authentication (MFA)

d)

Compliance with widely used authentication standards

23.

Which Microsoft Entra ID edition is included with Office 365 subscriptions?

a)

Office 365 apps

b)

Free

c)

Premium P1

d)

Premium P2

24.

What administration tools are used to manage Microsoft Entra ID?

a)

Using the Microsoft Entra admin center or Windows PowerShell

b)

The Microsoft Entra ID Domain Services command-line interface

c)

Exclusively through PowerShell scripts

d)

The Azure portal and navigating to the Microsoft Entra ID section

25.

What are objects in Active Directory?

a)

Types of records within the Active Directory database

b)

Different types of folders

c)

Types of databases within Active Directory

d)

Types of users within the network

26.

What type of information can be stored in user accounts in Active Directory?

a)

Only security-related information

b)

Only personal information

c)

Both security-related and personal information

d)

Only group membership information

27.

What is the purpose of the User Principal Name (UPN) in Active Directory?

a)

To provide a user's first name

b)

To display like an email address and must be unique in the forest

c)

To provide the user's last name

d)

To display the user's full name

28.

What is the purpose of enabling the "Store password using reversible encryption" setting in Active Directory?

a)

It allows users to sign in using smart cards

b)

It prevents users from changing their passwords

c)

It stores passwords in a less secure format for legacy protocols and applications

d)

It allows computers to impersonate users to access network resources

29.

Where can Fine Grained Password Policies be created?

a)

Active Directory Users and Computers

b)

Group Policy Management Console

c)

AD Administrative Center

d)

Active Directory Sites and Services

30.

Which tab in Active Directory includes attributes for configuring information such as job title, department, and manager?

a)

Profile tab

b)

General tab

c)

Member of tab

d)

Organization tab

31.

What problem with roaming profiles led Microsoft to consider them a legacy feature?

a)

Profiles can become extremely large, leading to delays and network traffic

b)

Users cannot access their profiles from different computers

c)

Roaming profiles do not replicate changes back to the server

d)

Roaming profiles are not compatible with modern applications

32.

What happens to the security identifier (SID) of a user account when it is deleted?

a)

The SID is reused for new accounts.

b)

The SID is temporarily disabled.

c)

The SID is permanently deleted and cannot be reused.

d)

The SID is transferred to another user account.

33.

What is the recommended best practice regarding user account management to avoid SID-related issues?

a)

Regularly delete unused accounts to prevent SID conflicts.

b)

Disable accounts instead of deleting them when they are not needed.

c)

Reuse SIDs to minimize the number of unique identifiers in the system.

d)

Use a third-party tool to manage user accounts more effectively.

34.

Which command-line tool can be used to create computer, user, group, and other types of objects in Active Directory?

a)

dsmod

b)

csvde

c)

ldifde

d)

dsadd

35.

What is a template account used for in Active Directory?

a)

To disable user accounts

b)

To create multiple similar user accounts

c)

To delete user accounts

d)

To manage group membership

36.

Which attributes of a user account are typically not copied from a template account when creating a new user account?

a)

First name and last name

b)

Account expiration date

c)

Group membership

d)

Logon hours and department

37.

What environment variable can be used in UNC paths to indicate that a folder should be created matching the user's name?

a)

%username%

b)

%profile%

38.

Which of the following is NOT a method for managing objects in Azure AD?

a)

Using AD Users and Computers

b)

Using AD Administrative Center

c)

Using PowerShell scripts

d)

Using the Azure portal as a Guest Account

39.

What advantage does using groups offer in terms of administration?

a)

Groups allow for easier management of user profiles.

b)

Groups simplify administration by allowing for the assignment of permissions and rights to multiple users in a single operation.

c)

Groups eliminate the need for individual user accounts.

d)

Groups ensure compatibility with legacy systems.

40.

What is the major difference between security groups and distribution groups in Active Directory?

a)

Security groups are primarily used for email distribution, while distribution groups are used to assign rights and permissions.

b)

Security groups have SIDs and can be used to assign rights and permissions, while distribution groups do not have SIDs and cannot be used for this purpose.

c)

Distribution groups have SIDs and can be used to assign rights and permissions, while security groups do not have SIDs and cannot be used for this purpose.

d)

Security groups are used for both email distribution and assigning rights and permissions, while distribution groups are used only for email distribution.

41.

What consequence does converting a security group to a distribution group have?

a)

The group gains a SID, allowing assignment of rights and permissions.

b)

The group loses all permissions and rights assigned to it.

c)

The group retains its permissions but gains email distribution capabilities.

d)

The group loses its email distribution capabilities but retains its permissions.

42.

Which group scope allows for the assignment of rights and permissions within the domain they were created in, but cannot be used in other domains in the forest?

a)

Local group

b)

Domain Local group

c)

Global group

d)

Universal group

43.

Which statement accurately describes the nesting rules for group types in Active Directory?

a)

Local groups can contain other local groups, but cannot contain global or universal groups.

b)

Domain Local groups can contain only global groups from the local domain.

c)

Universal groups can only contain global groups from the local domain.

d)

Universal groups can contain global and universal groups from any domain in the forest.

44.

How can you manage group membership across multiple computers using Group Policy in Active Directory?

a)

By configuring permissions through the Group Policy Management Console.

b)

By creating a custom administrative role through PowerShell scripting.

c)

By adding users individually to each computer's local Administrators group.

d)

By using the Restricted Groups node in Group Policy to automatically assign membership to a specified group.

45.

What privileges does the Administrators group in the forest root domain have?

a)

Full administrative rights only on member servers.

b)

Full administrative rights on all domain controllers in the forest.

c)

Limited administrative rights restricted to specific OU.

d)

No administrative rights within the forest.

46.

True or False: Ordinary users have the right to sign in locally at DCs.

a)

True

b)

False

47.

What is a characteristic of protected groups in Active Directory?

a)

Protected group members inherit ACLs from the protected group, rather than the OU in which the user account is located.

b)

Adding a user to a protected group prevents them from accessing resources in the network.

c)

Members of protected groups inherit permissions from the organizational unit (OU) where their user account is located.

d)

Protected groups can be modified by any user with administrative privileges.

48.

Which of the following statements about special identities is true?

a)

Special identities cannot be assigned permissions or rights.

b)

Special identities are managed manually by administrators.

c)

Special identities can be deleted by domain admins.

d)

Special identities are only available in workgroup environments.

49.

Which of the following statements about special identities in Active Directory is correct?

a)

Special identities can be managed and assigned permissions and rights.

b)

Special identities cannot be managed but can be assigned permissions and rights.

c)

Special identities can be deleted by administrators.

d)

Special identities are only available to domain administrators.

50.

Which of the following are options available for populating group members when creating groups in the Azure portal? (Choose three.)

a)

Assigned, Dynamic Computer, Dynamic User

b)

Static User, Static Computer, Dynamic User

c)

Assigned, Static Computer, Dynamic User

d)

Assigned, Dynamic Computer, Static User

51.

What validates a computer as a legitimate member of the domain when it starts?

a)

Providing its IP address to the DC.

b)

Providing its secret password to the DC.

c)

Providing its hostname to the DC.

d)

Providing its MAC address to the DC.

52.

What is the main difference between a default container and an Organizational Unit (OU) in Active Directory?

a)

Default containers allow group policies to be linked, while OUs do not.

b)

OUs can only contain user objects, while default containers can contain both user and computer objects.

c)

Default containers support LDAP queries, while OUs do not.

d)

OUs can be nested within other OUs, while default containers cannot.

53.

Which command can be used to change the default location for computer objects in Active Directory?

a)

redirusr

b)

rediobj

c)

redircmp

d)

redirgrp

54.

What is the LDAP distinguished name for the default Computers container in the Contoso.com domain?

a)

OU=Computers,DC=Contoso,DC=com

b)

CN=Computers,DC=Contoso,DC=com

c)

DC=Computers,OU=Contoso,DC=com

d)

CN=Contoso,OU=Computers,DC=com

55.

Which group is typically given the permission to create and manage computer objects in Active Directory by default?

a)

Authenticated Users

b)

Backup Operators

c)

Domain Guests

d)

Domain Admins

56.

What is the main difference between creating a computer object using user rights and using permissions in Active Directory?

a)

User rights allow unlimited computer creations, while permissions are limited.

b)

User rights set the owner of the computer object to Domain Admins, while permissions set the owner to the creator.

c)

User rights can only be assigned to specific users, while permissions can be assigned to groups.

d)

User rights require administrative approval, while permissions do not.

57.

What is the purpose of the offline domain join file created using djoin.exe?

a)

It contains the computer's current password.

b)

It enables the computer to communicate with the domain controller in real-time.

c)

It provides a backup of the computer's configuration.

d)

It allows a computer to be joined to the domain without real-time connectivity.

58.

What is the purpose of providing credentials when joining a computer to the domain?

a)

To perform a system backup

b)

To enable remote desktop access

c)

To authenticate the computer to the domain

d)

To install additional software packages

59.

What prompt will appear after successfully joining a computer to the domain?

a)

Configure network settings

b)

Restart the computer

c)

Install Windows updates

d)

Set up a user account

60.

What is the term used for creating the computer account in Active Directory before joining the computer to the domain?

a)

Preconfiguration

b)

Prerendering

c)

Prestaging

d)

Preinstallation

61.

What is required to perform a hybrid join for a computer?

a)

Install a third-party antivirus software

b)

Deploy the Azure AD connector on-premises

c)

Use a cloud-based management tool

d)

Activate Windows Defender Firewall

62.

How can you verify if a hybrid join was successful from the target computer?

a)

Run the command dsregcmd /status in an administrator command prompt

b)

Check the System Properties window

c)

Open the Event Viewer and search for hybrid join events

d)

Review the Computer Management console

63.

What is the consequence of reinstalling an operating system on a computer that retains its previous name, but has a new SID?

a)

The computer automatically authenticates with the domain using its previous password.

b)

The computer's secret password is reset to its initial value.

c)

The computer cannot authenticate with the domain due to the new SID.

d)

The computer connects to the domain using its old SID.

64.

What command can you use to repair the secure channel of a computer with the domain using PowerShell?

a)

Reset-ComputerSecureChannel -Repair

b)

Repair-ADComputerSecureChannel

c)

Repair-SecureChannel -Computer

d)

Test-ComputerSecureChannel -Repair

65.

Which PowerShell cmdlet is used to modify properties of a user account?

a)

Set-ADUserModifies

b)

Update-ADUser

c)

Change-ADUserAttributes

d)

Set-ADUser

66.

True or False: If the AccountPassword parameter is not provided during account creation the user account is created in a disabled state.

a)

True

b)

False

67.

How would you specify that a newly created group named "MarketingTeam" should be a security group with a global scope?

a)

New-ADGroup -Name "MarketingTeam" -GroupScope DomainLocal -GroupCategory Security

b)

New-ADGroup -Name "MarketingTeam" -GroupScope Universal -GroupCategory Distribution

c)

New-ADGroup -Name "MarketingTeam" -GroupScope Global -GroupCategory Distribution

d)

New-ADGroup -Name "MarketingTeam" -GroupScope Global -GroupCategory Security

68.

If you want to modify properties of a computer account in Active Directory, which cmdlet would you use?

a)

Modify-ADComputer

b)

Edit-ADComputer

c)

Update-ADComputer

d)

Set-ADComputer

69.

Which cmdlet is used to create a new organizational unit (OU) in Active Directory?

a)

Create-ADOrganizationalUnit

b)

New-ADOU

c)

New-OrganizationalUnit

d)

New-ADOrganizationalUnit

70.

What is a common example of using PowerShell for bulk operations in Active Directory?

a)

Deleting individual user accounts

b)

Modifying the properties of an existing user account

c)

Creating users from a list of accounts in a CSV file

d)

Resetting the password for a user account

71.

Which parameter of the Get-AD* cmdlets defines the AD DS path to begin searching?

a)

StartPath

b)

BasePath

c)

SearchBase

d)

SearchPath

72.

Which symbols are used to surround the query in PowerShell when using the Filter parameter?

a)

( and )

b)

{ and }

c)

[ and ]

d)

< and >

73.

What is the purpose of using the Properties parameter in the Get-AD* cmdlets?

a)

To specify the type of object to retrieve

b)

To define the scope of the search

c)

To retrieve specific attributes of the objects

d)

To filter the results based on specified criteria

74.

Which parameter of the Search-ADAccount cmdlet retrieves a list of accounts that have passwords that will expire within a specified period?

a)

PasswordExpired

b)

PasswordExpiring

c)

AccountExpiring

d)

TimeSpan

75.

What character is used to connect the output of one cmdlet to the input of another cmdlet in PowerShell?

a)

>

b)

|

c)

<

d)

/

76.

What cmdlet is used to read the information in a text file in PowerShell?

a)

Read-File

b)

Get-Content

c)

Read-Content

d)

Import-File

77.

How are attributes represented in the first row of a CSV file?

a)

In parentheses

b)

In square brackets

c)

As column names

d)

As row numbers

78.

What character is used to indicate a blank attribute for a particular user in a CSV file?

a)

-

b)

/

c)

:

d)

,,

79.

What PowerShell construct is used to iterate over the list of objects in the CSV file in the provided code snippet?

a)

For loop

b)

While loop

c)

Do-While loop

d)

Foreach loop

80.

What is one benefit of carefully planning the Organizational Unit (OU) structure?

a)

Facilitating user authentication

b)

Improving network security

c)

Efficiently delegating administrative rights and applying Group Policy

d)

Reducing the number of objects in the Active Directory domain

81.

What is a benefit of using a location-based OU planning strategy?

a)

Facilitating centralized administration

b)

Ensuring frequent reorganization of locations

c)

Decentralizing administration to various levels

d)

Making user and computer movements between locations easier

82.

What would be good advice regarding the complexity of the OU structure in a resource-based strategy?

a)

Keep it simple and avoid unnecessary complications

b)

Expand the structure to include as many OUs as possible

c)

Create separate OUs for every individual object

d)

Prioritize detailed hierarchy over simplicity

83.

What is a potential limitation of the organization-based OU planning strategy?

a)

It is not suited for organizations with stable structures

b)

It is not suited for organizations with fluid job roles

c)

It is not suited for organizations with multiple locations

d)

It is not suited for organizations with limited resources

84.

What is a common approach used by most organizations when structuring their OUs?

a)

Utilizing a single, overarching strategy for all OUs

b)

Employing a combination of strategies, with high-level OUs representing either locations or departments

c)

Creating separate OUs for each individual object

d)

Assigning distinct policies for each OU based on its function

85.

How can administrative control be delegated in Active Directory?

a)

By setting permissions on individual objects within the domain

b)

By creating a new domain for each user

c)

By assigning all rights to a single administrator

d)

By disabling user accounts

86.

Which of the following is a method for setting which administrator has what permissions for an Organizational Unit (OU) and its contents in Active Directory?

a)

By setting permissions on OUs to indicate which administrator has what permissions for that OU and its contents

b)

By deleting unused OUs regularly

c)

By renaming OUs frequently

d)

By disabling all permissions on OUs

87.

Why is it important to consider the ability to block permissions and policy inheritance when designing the OU structure in Active Directory?

a)

To allow for selective control over which OUs inherit permissions and policies from parent OUs

b)

To ensure all OUs have the same permissions

c)

To prevent OUs from being deleted

d)

To make the domain slower

88.

Which two command line tools can be used to create OUs in Active Directory? (Choose two.)

a)

Command-line tools like dsadd OU

b)

PowerShell cmdlets such as New-ADOrganizationalUnit

c)

Active Directory Administrative Center

d)

LDAP distinguished name

89.

What features introduced with Windows Server 2008 R2 help prevent the unintentional removal of Organizational Units (OUs) and their contents? (Choose two.)

a)

AD recycle bin

b)

Prevent Accidental Deletion attribute

c)

Active Directory Administrative Center

d)

LDAP distinguished name

90.

Where can you access advanced settings for setting granular permissions in Active Directory?

a)

From the Advanced settings in the Security tab of the OU or object

b)

From the Command Prompt

c)

From the Group Policy Management Console

d)

From the Active Directory Administrative Center

91.

What level of permissions allows an administrator to apply changes to an OU and all objects within it?

a)

This object and all descendent objects

b)

This object only

c)

This object and all sibling objects

d)

This object and all parent objects

92.

Which of the following is a reason for creating exceptions within the hierarchy in Active Directory?

a)

To create exceptions within the hierarchy

b)

To enforce default security settings

c)

To simplify permissions management

d)

To grant full control permissions to all objects

93.

What are the individual entries in the Discretionary Access Control List (DACL) referred to as?

a)

Access Control Entries (ACEs)

b)

Security Principals

c)

System Access Control Entries (SACEs)

d)

Discretionary Access Control Entries (DACEs)

94.

Who initially owns an object in Active Directory, and what control do they have over it?

a)

The user who created the object, with full control.

b)

The domain administrator, with read-only control.

c)

The group with the highest permissions, with write control.

d)

The system administrator, with modify permissions.

95.

What is the risk associated with giving an administrator full control over an OU?

a)

Accidental or malicious deletion of objects

b)

Overwriting existing permissions

c)

Inability to modify objects within the OU

d)

Limited visibility into object properties

96.

How can you access the Delegation of Control Wizard in Active Directory?

a)

Right-clicking on the container and choosing "Delegate Control"

b)

Through PowerShell commands

c)

Via the Active Directory Administrative Center

d)

By modifying the registry settings

97.

What permissions are required, at minimum, to move an object in Active Directory?

a)

Delete all child objects permission on the source OU, Write permission for the object, and Create all child objects permission on the destination OU

b)

Read permission on the source OU and Write permission on the destination OU

c)

Full control permission on the source OU and Read permission on the destination OU

d)

Modify permission on the source OU and Create permission on the destination OU

98.

What forms the security boundary in an AD DS forest by default?

a)

The schema naming context

b)

The forest itself

c)

The Global Catalog servers

d)

The configuration naming context

99.

What is a characteristic of the replication boundary for DCs designated as Global Catalog servers?

a)

It contains full copies of objects only within their own domain

b)

It contains full copies of objects from all domains within the forest

c)

It restricts access to security principals within the forest

d)

It shares a subset of attributes with DCs serving as Global Catalogs in other forests

100.

What does the creation of multiple domains within the same forest not provide from a security standpoint?

a)

Administrative autonomy

b)

Full isolation

c)

Centralized administration

d)

Segregation of administrative duties

101.

What might be a reason for configuring separate domains in an AD DS environment based on bandwidth limitations?

a)
  • To achieve administrative autonomy

b)

To centralize administration of forest-level operations

c)
  • To facilitate strict oversight over changes

d)
  • To minimize replication traffic volume

102.

What is a common reason for implementing multiple forests in an AD DS environment to address regulatory and compliance dependencies?

a)

To achieve administrative autonomy

b)

To minimize replication traffic volume

c)

To eliminate replication traffic entirely

d)

To comply with data residency requirements

103.

What option involves the cloud provider managing the Domain Controllers (DCs) in a public cloud environment?

a)
  • Infrastructure as a service (IaaS)

b)
  • Platform as a service (PaaS)

c)

On-premises deployment

d)

Hybrid cloud deployment

104.

What IP configuration method is recommended for Azure VMs hosting AD DS Domain Controllers?

a)

Static IP configuration

b)

DHCP

c)

IPv6 only

d)

Manual IP configuration

105.

What is a common task in the implementation of self-service in Active Directory Domain Services (AD DS) environments?

a)

Delegating user management tasks to IT administrators

b)
  • Allowing users to unlock their accounts or reset their passwords

c)

Restricting users from creating groups or managing their membership

d)
  • Disabling self-service options for users

106.

What feature of Microsoft Identity Manager (MIM) allows users to unlock their accounts or reset their passwords?

a)

Multifactor authentication (MFA) support

b)

Group maintenance via approval-based workflows

c)

Certificate management

d)

Privileged Access Management (PAM)

107.

What do functional levels determine in Active Directory Domain Services (AD DS) environments?

a)

The number of domains allowed in a forest

b)

The number of Group Policy Objects (GPOs) that can be linked to a domain

c)
  • The supported operating systems for domain-joined computers

d)

The capabilities available in domains and forests

108.

What is the minimum forest and domain-functional level required to host Windows Server 2022 Domain Controllers (DCs)?

a)

Windows Server 2003

b)

Windows Server 2008

c)

Windows Server 2012

d)
  • Windows Server 2016

109.

True or False: The domain-functional levels can be less than the level assigned to the forest-functional level.

a)
  • True

b)
  • False