Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Active Directory Quiz

Total questions: 78

Worksheet time: 13hrs 44mins

Name
Class
Date
1.

What allows administrators to grant users in one domain access to resources of another domain within the same domain tree?

a)

Bidirectional trust relationship between domains

b)

Permission inheritance between domains

c)

Access control list for users

d)

Domain isolation policy

2.

What special DNS resource record enables clients to locate domain controllers and other vital AD DS services?

a)

NSEC

b)

SPF

c)

SRV

d)

PTR

3.

What is a container object that functions in a subordinate capacity to a domain, and still inherits policies and permissions?

a)

Organizational unit

b)

Domain controller

c)

Leaf object

d)

Forest root domain

4.

What is the method for removing a domain controller in Windows Server 2012 R2?

a)

Using the Active Directory Users and Computers Console

b)

Manually Deleting the Domain Controller Files

c)

Using the Remove Roles and Features Wizard

d)

Reinstalling the Operating System

5.

In Active Directory Domain Services, an architectural element that consists of one or more domains that are part of the domain tree.

a)

domain controller

b)

domain tree

c)

domain clients

d)

forest root

6.

What is the PowerShell cmdlet for installing a domain controller to the domain 'adatum.com'?

a)

Install-ADDSDomainController -DomainName "adatum.com"

b)

Install-ADDSDomainController -DomainName "adatum.com" -LocalAdministratorPassword -Force

c)

Uninstall-ADDSDomainController -ForceRemoval

d)

Install-addsdomain -domainname "adatum.com"

7.

What can be used to add, delete, or modify objects in Active Directory, in addition to modifying the schema if necessary?

a)

DCPROMO

b)

LDIFDE

c)

CSVDE

d)

NSLOOKUP

8.

When using CSVDE, what is the first line of the text file that uses proper attribute names?

a)

header row

b)

header record

c)

name row

d)

name record

9.

Which of the following utilities do you use to perform an offline domain join?

a)

net join

b)

join

c)

djoin

d)

dconnect

10.

Which of the following is not a type of user account that can be configured in Windows Server 2012?

a)

local accounts

b)

domain accounts

c)

network accounts

d)

built-in accounts

11.

Which of the following are the two built-in user accounts created automatically on a computer running Windows Server 2012?

a)

Network

b)

Interactive

c)

Administrator

d)

Guest

12.

What is the PowerShell cmdlet syntax for creating a new user account?

a)

New-ADUser

b)

New-User

c)

New-SamAccountName

d)

There is no PowerShell cmdlet for user creation.

13.

What is the PowerShell cmdlet syntax for creating a new computer object?

a)

New-Computer -Name –path

b)

New-ADComputer -Name –path

c)

New-ComputerName –path

d)

There is no PowerShell cmdlet for creating computer objects.

14.

What is the PowerShell cmdlet and syntax for demoting a domain controller?

a)

Uninstall-ADDSDomainController -ForceRemoval

b)

Install-AddsForest -DomainName "adatum.com"

c)

Read-Only Domain Controller (RODC)

d)

A set of network resources available for a group of users who can authenticate to the network to gain access to those resources.

15.

What is the process of granting the user access only to the resources he or she is permitted to use?

a)

Replication

b)

Authentication

c)

Authorization

d)

Identification

16.

What is the command-line tool and syntax for determining whether a domain controller has been registered in DNS?

a)

nslookup /query: /server:

b)

dcdiag /test:registerindns /dnsdomain: /v

c)

ping

d)

tracert

17.

In AD DS, a domain controller that supports only incoming replication traffic.

a)

Read-Only Domain Controller (RODC)

b)

Active Directory Domain Services (AD DS)

c)

Directory Access Protocol (DAP)

d)

Primary domain controller (PDC) emulator

18.

In AD DS, the individual properties that combine to form an object.

a)

methods

b)

attributes

c)

values

d)

constraints

19.

If an admin creates two domain trees in an AD forest, what is the relationship between them?

a)

Completely separate security entities with no trust

b)

Hierarchical structure with no inter-domain trust

c)

Single domain tree with multiple forests

d)

Same security entity as one Active Directory forest, bidirectional trust

20.

In AD DS, an object that has leaf objects or other container objects as subordinates.

a)

container object

b)

domain

c)

leaf object

d)

group object

21.

For Server Core installations, how does Windows Server 2012 R2 differ when installing AD DS role?

a)

Windows Server 2008 Has more installation options

b)

Windows Server 2012 R2 allows admins to use PowerShell

c)

Windows Server 2012 R2 does not support DCs

d)

Windows Server 2008 requires a GUI

22.

When is an Active Directory site topology created?

a)

Started upon initial installation of AD

b)

Starts when you finalize links and subnets config

c)

Manually configured depending on WAN bandwidth

d)

Depends on link costs

23.

A technique where duplicate copies of a file are updated regularly from one master copy.

a)

multi-master replication

b)

multiserver replication

c)

multiple-master replication

d)

single-master replication

24.

In AD DS, an object like a user or computer, incapable of containing any other object.

a)

group objects

b)

container object

c)

leaf object

d)

tree

25.

What is the global catalog?

a)

List of all users in the domain

b)

A security policy for the forest

c)

A backup of all domain controllers

26.

What does LDAP stand for?

a)

Local Data Access Protocol

b)

Link Directory Access Protocol

c)

Lightweight Directory Access Protocol

27.

What is an important difference between groups and OUs?

a)

OUs are always nested within groups.

b)

Group memberships are independent of the domain's tree structure.

c)

Groups are only for security purposes, while OUs are for organization.

d)

OUs can contain users but groups cannot.

28.

What is the next level of Active Directory container object within a domain?

a)

Organizational unit

b)

Global catalog

c)

Domain controller

d)

Directory schema

29.

What defines what objects exist as well as what attributes are associated with any object in the Active Directory?

a)

Schema master

b)

Active directory root user

c)

Active Directory schema

d)

Active directory global directory

30.

An Active Directory _____ consists of one or more separate domain trees.

a)

forest

b)

workgroup

c)

subnet

d)

tree

31.

What administrative division in Active Directory is defined as a collection of subnets with good connectivity?

a)

Forests

b)

Domains

c)

Sites

d)

Locations

32.

Which feature allows you to create virtual machines on a leased cloud resource?

a)

Platform as a Service (PaaS)

b)

Infrastructure as a Service (IaaS)

c)

Network as a Service (NaaS)

d)

Software as a Service (SaaS)

33.

What is the process by which domain controllers stay synchronized?

a)

Replication

b)

Recovery

c)

Authorization

d)

Transcription

34.

What determines the functional level of an Active Directory forest?

a)

Number of users in the domain

b)

Total number of DCs

c)

Number of DCs in the forest

d)

Lowest version of Windows Server on a DC

35.

What is not a container, nor full-fledged security division, and cannot have Group Policy settings applied?

a)

Group

b)

Policy

c)

Site

d)

User

36.

Which feature allows you to install AD DS on a virtual machine in the cloud?

a)

Windows Azure

b)

Sql Azure

c)

Windows Blob Storage

d)

Google App Engine

37.

What can be used to add, delete, or modify objects in Active Directory, in addition to modifying the schema if necessary?

a)

DCPROMO

b)

LDIFDE

c)

CSVDE

d)

NSLOOKUP

38.

When using CSVDE, what is the first line of the text file that uses proper attribute names?

a)

header row

b)

header record

c)

name row

d)

name record

39.

Which of the following utilities do you use to perform an offline domain join?

a)

net join

b)

join

c)

djoin

d)

dconnect

40.

Which of the following is not a type of user account that can be configured in Windows Server 2012?

a)

local accounts

b)

domain accounts

c)

network accounts

d)

built-in accounts

41.

Which of the following are the two built-in user accounts created automatically on a computer running Windows Server 2012?

a)

Network

b)

Interactive

c)

Administrator

d)

Guest

42.

What is the PowerShell cmdlet syntax for creating a new user account?

a)

New-ADUser

b)

New-User

c)

New-SamAccountName

d)

There is no PowerShell cmdlet for user creation.

43.

What is the PowerShell cmdlet syntax for creating a new computer object?

a)

New-Computer -Name –path

b)

New-ADComputer -Name –path

c)

New-ComputerName –path

d)

There is no PowerShell cmdlet for creating computer objects.

44.

When using Netdom.exe without [/OU:OUDN], where is the computer object placed?

a)

In the same organizational unit as the administrator running Netdom.exe

b)

In the Users container

c)

In the Computers container

d)

Without the OU specified, the program will fail.

45.

Who may join a computer to the domain?

a)

No one, the computer does this itself when authenticating.

b)

The computer joins the domain as part of the object creation process.

c)

Only the domain administrator may join the computer to the domain.

d)

Local admins can join the computer to the domain.

46.

What is the primary means by which people access resources on an AD DS network?

a)

By having a computer account

b)

Being within the proper site and domain

c)

By having elevated privileges

d)

By having a user account

47.

What differences matter most in creating a single user versus multiple users?

a)

Single user: GUI; multiple users: command-line tools.

b)

Creating a single user is simple, but manual work.

c)

Time does not permit automating the creation of a single user.

d)

When creating multiple users, not as many parameters are involved.

48.

What two graphical tools help create user or computer objects?

a)

ADAC and ADUC tools

b)

Server Core and PowerShell

c)

LDIFDE.exe and CSVDE.exe

49.

What is a key benefit of using ADAC or ADUC?

a)

ADAC can edit properties of many users and computers.

b)

ADAC allows you to import multiple objects at once.

c)

ADAC can change many user or computer settings at once.

d)

ADAC creates and joins users/computers to the domain.

50.

when is an active directory site topology created?

a)


a. Creation of sites and its topology is dependent on link costs.

b)


b. Site topology is manually configured dependent on WAN bandwidth and transmission speed.

c)

c. Site topology is started upon initial installation of the Active Directory

d)

d. Site topology starts when you finalize the links and subnets configuration.

51.

What defines what objects exist as well as what attributes are associated with any object in the Active Directory?

a)

Active Directory root user

b)

Active Directory administrator

c)

Active Directory global directory

d)

Active Directory schema

52.

Resource access for individuals takes place through their _____

a)

a. computer accounts

b)

b. shared folders

c)

user accounts

d)

authentication

53.

What command-line utility requires you know the SAM account name as well as the Distinguished Name before creating user?

a)

a.
CSVDE exe

b)

b. Active Directory Administrative Center

c)

c. Dsadd.exe

d)

d. New-ADUser

54.

To perform an offline domain join, how many times would an administrator run the Djoin.exe command?

a)

a. twice

b)

b. Djoin exe cannot perform this task

c)

c. once

d)

d. as many times as necessary

55.

Active directory keeps a naming convention for the domain that mirrors _____

a)


DNS

b)

WINS

c)

Files & Folders

d)

DHCP

56.

Using File and Storage Services in Server Manager, you will create a new share. The New Share Wizard prompts you for a profile. You need a profile for basic SMB sharing with full permissions. Which do you choose?

a)

a, NFS Share-Advanced

b)

b. NFS Share-Quick

c)

c. SMB-share- quick

d)

D. SMB Share-Advanced

57.

What is not a container, nor full-fledged security division and cannot have Group Policy settings applied directly to them?

a)

a. Forest

b)

Organizational unit

c)

Domain

d)

Group

58.

Which of the following is a PowerShell cmdlet for creating user objects?

a)


a. New-ADUser

b)

b. CSVDE.exe

c)

Active Directory Administrative Center

d)


Dsadd.exe

59.

Which of the following is the best description of a security principal?

a)

the person granting permissions to network users

b)

the network resource receiving permissions

c)

a collection of individual special permissions

d)

an object that assigns permissions

60.

Which of the following statements about effective access is not true?

a)

Inherited permissions take precedence over explicit permissions.

b)

Deny permissions always override Allow permissions.

c)

When a security principal receives Allow permissions from multiple groups, the per missions are combined to form the effective access permissions.

d)

Effective access includes both permissions inherited from parents and permissions derived from group memberships.

61.

Which of the following statements is not true in reference to resource ownership?

a)

One of the purposes for file and folder ownership is to calculate disk quotas.

b)

Every file and folder on an NTFS driver has an owner.

c)

It is possible for any user possessing the Take Ownership special permission to assume the ownership of a file or folder.

d)

It is possible to lock out a file or folder by assigning a combination of permissions that permits access to no one at all, including the owner of the file or folder.

62.

Which of the following statements about permissions are true?

a)

a. ACLs are composed of ACEs.

b)

b. Basic permissions are composed of advanced permissions.

c)

All permissions are stored as part of the protected resource.

d)

d. All of the above

63.

What is the maximum number of shadow copies that a Windows Server 2012 system can maintain for each volume?

a)

8

b)

16

c)

64

d)

128

64.

Which of the following terms describes the process of granting users access to file server shares by reading their permissions?

a)

a. authentication

b)

authorization

c)

enumeration

d)

assignment

65.

Which of the following are tasks that you can perform using the quotas in File Server Resource Manager but you can’t perform with NTFS quotas?

a)

a. Send an email message to an administrator when users exceed their limits.

b)

b. Specify different storage limits for each user.

c)

c. Prevent users from consuming any storage space on a volume beyond their allotted limit.

d)

d. Generate warnings to users when they approach their allotted storage limi

66.

In the NTFS permission system, combinations of advanced permissions are also known as __________ permissions.

a)

a. special

b)

b. basic

c)

c. share

d)

d. standard

67.

What is a key reason for assigning permissions when configuring file and share access?

a)

a. Creates redundancy for file storage, providing a fault-tolerant file archive.

b)

b. Enables configuring offline files, improving performance.

c)

c. Improves data security, granting file and share access only to the users who need it.

d)

d. Assigns ownership to specific users, instilling responsibility and personal accountability.

68.

You are deciding which file system to use. You need NTFS permission system support. You don’t presently need encryption or compression, but might at a later date. What file system is your best choice?

a)

a. The traditional NTFS file system

b)

b. The new ReFS file system introduced in Windows Server 2012

c)

c. The FAT file system

d)

d. The NFS file system

69.

f massive shares were split across multiple servers, what is the best way to make them appear as a single, unified directory tree?

a)

a. Windows Server 2012 Distributed File System

b)

b. Volume Shadow Copy Service

c)

c. Large volume split across multiple drives, attached to multiple servers

d)

d. Volumes created on a single Virtual Hard Disk (VHD)

70.

Which of the following sets of permissions is responsible for controlling access to files and folders stored on a local disk volume?

a)

a. Share permissions

b)

b. NTFS permissions

c)

c. Registry permissions

d)

d. Active Directory permissions

71.

Knowing how permissions can be cumulative or override each other is an important factor in understanding what?

a)

a. Permission inheritance

b)

b. Explicitly assigned permissions

c)

c. Permission precedence

d)

d. Effective access

72.

1. What does SMB in file sharing stand for?

a)

A) Server Message Block

b)

B) Secure Message Broadcast

c)

C) System Managed Backup

d)

D) Simple Mail Bridge

73.

Which SMB share type is optimized for applications like Hyper-V?

a)

A) SMB Share – Quick

b)

B) SMB Share – Advanced

c)

C) SMB Share – Applications

d)

D) NFS Share – Quick

74.

Which file system provides full share and NTFS permissions?

a)

A) SMB Share – Quick

b)

B) NFS Share – Advanced

c)

C) SMB Share – Applications

d)

D) Both A and C

75.

Which of the following shares provides access to File Server Resource Manager services?

a)

A) SMB Share – Quick

b)

B) SMB Share – Advanced

c)

C) NFS Share – Quick

d)

D) SMB Share – Applications

76.

What does NFS stand for?

a)

A) Network File System

b)

B) New File Server

c)

C) Network File Sharing

d)

D) Node File System

77.

Which NFS share type provides basic sharing with authentication and permissions?

a)

A) NFS Share – Quick

b)

B) NFS Share – Advanced

c)

C) SMB Share – Quick

d)

D) SMB Share – Advanced

78.

What extra feature does NFS Share – Advanced provide over NFS Share – Quick?

a)

A) Faster file transfers

b)

B) Access to File Server Resource Manager services

c)

C) Application optimized settings

d)

D) No authentication required