wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Quiz6,7 COOS295

Total questions: 82

Worksheet time: 41mins

Name
Class
Date
1.

What is the primary function of administrative templates in Group Policy?

a)

Providing security patches

b)

Managing network protocols

c)

Configuring hardware settings

d)

Configuring user and computer settings

2.

Where are the user configuration settings of administrative templates stored in the registry?

a)

HKEY_LOCAL_MACHINE

b)

HKEY_CLASSES_ROOT

c)

HKEY_CURRENT_CONFIG

d)

HKEY_CURRENT_USER

3.

What is the purpose of ADMX files in Group Policy?

a)

To provide language-specific interface files

b)

To define the functionality and interface of administrative templates

c)

To store user-specific settings related to policies applied at log on and log off

d)

To manage printer configurations for departments required to share printers

4.

When do computers in an organization apply Group Policy changes made in the Group Policy Management Editor?

a)

Immediately upon closing the editor

b)

When the administrator forces a system restart

c)

During the next Group Policy refresh cycle

d)

After manually pushing updates to each computer

5.

What is the final step after making changes in the Group Policy Management Editor?

a)

Restarting the domain controller

b)

Reinstalling Group Policy

c)

Closing the editor to implement changes

d)

Disabling Group Policy enforcement

6.

What is the recommended domain controller to host the central store?

a)

The one containing the PDC Emulator operations primary role

b)

Any domain controller with sufficient storage

c)

The one with the least network traffic

d)

The one with the highest CPU power

7.

Where should the PolicyDefinitions folder be created to implement the central store?

a)

C:\Windows\System32

b)

C:\Program Files

c)

\<FQDN>\SYSVOL<FQDN>\Policies

d)

C:\Users\Documents

8.

Which section of a security template includes settings for the Password Policy?

a)

Account Policies

b)

Local Policies

c)

Restricted Groups

d)

Event Log

9.

How can you import security templates into Group Policy?

a)

By using the Group Policy Management Editor

b)

By restarting the domain controller

c)

By manually editing the registry

d)

By using a third-party application

10.

What tool can you use to compare current computer configuration to security templates?

a)

Secedit.exe

b)

Windows PowerShell

c)

Security Templates snap-in

d)

Group Policy Management Console

11.

What should you consider before making changes to GPO configuration after updating the central store?

a)

Restarting the domain controller

b)

Disabling DFS Replication

c)

Waiting for replication latency

d)

Modifying the DNS settings

12.

What is one of the primary benefits of using Folder Redirection?

a)

Enhanced graphical user interface

b)

Improved network speeds in branch locations

c)

Users access documents from any domain-joined computer

d)

Reduced administrator workload during normal working hours

13.

What does enabling the "Move the contents of to the new location" setting in Folder Redirection do?

a)

Deletes existing content in the local folder

b)

Leaves the content in the local folder untouched

c)

Prevents users from accessing the redirected folder

d)

Moves existing content in the local folder to the UNC-defined location

14.

Which security principal has Full Control for subfolders and files only in the root folder permissions for Folder Redirection?

a)

System

b)

Administrator

c)

Creator/Owner

d)

Security group of users that save data on the share

15.

What does Folder Redirection synchronize to a defined network location?

a)

User data

b)

User settings

c)

System registry

d)

Windows operating system files

16.

What must you do before configuring Folder Redirection in Group Policy?

a)

Configure the UNC path that hosts the redirected content

b)

Install additional software

c)

Perform a system reboot

d)

Disable user profiles

17.

Which tool provides a feature-limited means to deploy apps to Windows computers assuming those apps are installed by .msi files?

a)

Group Policy

b)

Microsoft Intune

c)

Endpoint Configuration Manager (ECM)

d)

Microsoft Deployment Toolkit (MDT)

18.

What is file extension activation in the context of Group Policy app deployment?

a)

A feature to disable certain file extensions

b)

Auto-installing an app if a user attempts to open a file with a defined file extension

c)

A method to restrict file access based on file types

d)

A security measure to prevent file corruption

19.

Which deployment method installs apps automatically without user intervention?

a)

Publish

b)

Assign

c)

Deploy

d)

Share

20.

Why might a user need to sign out and back in after an app is assigned to their user account via Group Policy?

a)

To uninstall the oldest version of the app prior to updating

b)

To refresh their desktop wallpaper to support the new app

c)

To make the assigned app effective

d)

To synchronize their system time with the server

21.

What is a characteristic of the "Publish" deployment mode when deploying apps via Group Policy?

a)

Apps are automatically installed without user intervention

b)

Apps are installed only if a user selects to install the published app

c)

Apps are installed based on file extensions opened by users

d)

Apps are deployed to specific computers based on organizational units

22.

Which setting on the Common tab of Group Policy preferences allows you to determine whether a preference is applied based on the characteristics of the objects being configured?

a)

Stop processing items in this extension if an error occurs

b)

Item-level targeting

c)

Remove this item when it is no longer applied

d)

Apply one time and do not reapply

23.

In Group Policy preferences, what is the default behavior for preferences regarding reapplication?

a)

Preferences are applied only one time and not refreshed

b)

Can be configured to apply only one time, or at the same intervals as Policy settings.

c)

Preferences are removed when the GPO that applied them is no longer applying

d)

Preferences do not reapply unless manually refreshed by the user

24.

What feature of Group Policy preferences allows you to control the application of specific preferences within a given GPO?

a)

Link Order

b)

Enforced

c)

Block Inheritance

d)

Item-level targeting

25.

How can you be more specific when using item-level targeting in Group Policy preferences?

a)

By selecting the "Apply one time and do not reapply" setting

b)

By removing preferences when they are no longer applied

c)

By combining categories using Boolean logic and operators such as AND, OR

d)

By defining various options based on the type of preference being configured

26.

When using Group Policy preferences, what is the impact if a setting is configured by both policies and preferences?

a)

Preferences take precedence over policies

b)

Both policies and preferences are disregarded

c)

Policies and preferences are applied simultaneously

d)

The policy setting takes precedence over the preference setting

27.

What is a primary reason why protecting Domain Controllers (DCs) is crucial?

a)

To enhance network connectivity to branch office locations

b)

To prevent unauthorized access to AD DS authentication information

c)

To facilitate remote access for users working from home

d)

To increasing on site server capacity in company data centres

28.

Which of the following is NOT a security risk that can affect DCs?

a)

Operating system, service, or app attack

b)

Physical security threats

c)

Private network accessibility

d)

Denial of service attack (DoS)

29.

The settings in the Default Domain Controllers Policy provide optimal security.

a)

True

b)

False

30.

Which tool can be used to compare the configuration of DCs to security baselines?

a)

Domain Controller Analyzer

b)

Security Policy Editor

c)

Policy Analyzer

d)

Security Configuration Wizard

31.

What does the Center for Internet Security (CIS) provide?

a)

Hardware maintenance services

b)

Software development kits (SDKs)

c)

Security benchmarks for various software

d)

Cloud computing solutions

32.

How can you mitigate the risk of deploying DCs to less secure locations?

a)

By deploying additional DCs without encryption

b)

By disabling network firewalls

c)

By implementing an RODC

d)

By allowing open access to DC hardware

33.

What is the purpose of segmenting network activity ?

a)

To increase network speed

b)

To encourage collaboration among all users

c)

To limit access to resources

d)

To centralize data storage

34.

Which of the following statements regarding RODCs is FALSE?

a)

They provide local administrator access without administrative permissions to AD DS.

b)

They can initiate updates to AD DS objects.

c)

All passwords are cached on an RODC by default

d)

They forward authentication requests to a full DC by default.

35.

How can you pre-stage an RODC computer account?

a)

Use PowerShell to install Active Directory Domain Services.

b)

Use Active Directory Users and Computers to pre-create the account.

c)

Leave the server in a workgroup until installation.

d)

Promote the server to be a DC in an existing domain immediately.

36.

How can you support authentication in a site with intermittent network connectivity?

a)

By installing additional RODCs

b)

By configuring RODCs to deny all password caching

c)

By allowing branch office computer accounts to cache passwords on RODCs

d)

By promoting regular DCs to RODCs temporarily

37.

Which group controls password replication to all RODCs in the domain?

a)

Enterprise Admins

b)

Allowed RODC Password Replication Group

c)

Domain Users

d)

Denied RODC Password Replication Group

38.

What is a potential consequence of allowing many users to have passwords cached on all RODCs?

a)

Improved network performance

b)

Reduced security

c)

Enhanced authentication speed

d)

Increased fault tolerance

39.

What is NOT a task that a delegated administrator for an RODC can perform?

a)

Managing hardware devices

b)

Accessing the local copy of the AD DS database

c)

Installing and removing server roles and features

d)

Reviewing event logs

40.

Which feature mitigates the risk of automated password guessing attacks?

a)

Fine-grained policies

b)

Windows Hello

c)

Account lockout policies

d)

Kerberos authentication policies

41.

What does the Enforce user logon restrictions setting in the Kerberos Policy control?

a)

Password history requirements

b)

Maximum lifetime for service tickets

c)

Verification of user rights for session tickets

d)

Maximum tolerance for computer clock synchronization

42.

Which of the following is a sign-in option in Windows?

a)

Kerberos authentication policies

b)

Restricted groups

c)

Windows Hello

d)

Fine-grained policies

43.

How can you ensure that users are not accidentally added to certain groups?

a)

By configuring fine-grained policies

b)

By enforcing account lockout policies

c)

By using restricted groups

d)

By joining the Protected Users group

44.

Which group prevents devices from caching credentials for its members?

a)

Restricted Users group

b)

Protected Users group

c)

Domain Users group

d)

Authentication Policies group

45.

How can you configure rules for authentication to specific devices?

a)

By configuring fine-grained policies

b)

By enabling Windows Hello

c)

By using authentication policies

d)

By joining the Protected Users group

46.

Where can you configure Restricted Groups for member servers and workstations in Group Policy?

a)

User Configuration\Policies\Windows Settings\Security Settings\Restricted Groups

b)

Computer Configuration\Policies\Windows Settings\Security Settings\Restricted Group

c)

Computer Configuration\Preferences\Windows Settings\Security Settings\Restricted Groups

d)

User Configuration\Preferences\Control Panel Settings\Security Settings\Restricted Groups

47.

What applies when evaluating multiple PSOs for a user account?

a)

PSOs linked to groups have higher priority than PSOs linked to users

b)

PSOs with higher precedence value have higher priority

c)

PSOs linked to the user have higher priority than PSOs linked to groups

d)

For two PSOs with the same precedence the PSO with the higher object GUID will have higher priority

48.

How can you determine the effective PSO for a user?

a)

By reviewing the msDS-PSOApplied attribute of the user

b)

By using Windows Management Instrumentation filtering

c)

By reviewing the msDS-ResultantPSO attribute of the user

d)

By querying Active Directory Administrative Center

49.

How can you create a new PSO using Active Directory Administrative Center?

a)

By navigating to Domain Controllers and selecting New Password Policy

b)

By navigating to System and selecting New Password Settings

c)

By navigating to System\Password Settings Container and selecting New Password Settings

d)

By navigating to Users and Computers and selecting New Fine-Grained Password Policy

50.

Which PowerShell cmdlet is used to link a PSO to a user or group?

a)

Get-ADFineGrainedPasswordPolicy

b)

Add-ADFineGrainedPasswordPolicy

c)

Add-ADFineGrainedPasswordPolicySubject

d)

Remove-ADFineGrainedPasswordPolicySubject

51.

What is one of the security risks organizations face that Windows Hello helps prevent?

a)

Virus infections

b)

Malware attacks

c)

Credential theft

d)

Phishing scams

52.

What does Windows Hello for Business use for authentication instead of caching credentials?

a)

Biometrics

b)

Security tokens

c)

Certificate-based authentication

d)

OAuth tokens

53.

Which option is NOT a method of Azure AD MFA?

a)

Phone call acknowledgment

b)

Text message with password code

c)

Smart card authentication

d)

One-time password code

54.

Which characteristic can be evaluated by Azure AD conditional access policies?

a)

Browser type

b)

Printer model

c)

IP address location

d)

Monitor resolution

55.

How does PIM help reduce security risks associated with administrative accounts?

a)

By limiting access to specific apps

b)

By requiring additional authentication factors

c)

By automating permissions assignment and removal

d)

By encrypting administrative credentials

56.

Where is a logon event generated when a user accesses a file share from a workstation?

a)

Domain Controller

b)

Domain-connected server

c)

File server

d)

Workstation

57.

When does an account logon event occur on a Domain Controller?

a)

When a user accesses a file share

b)

When a user signs in to a workstation

c)

When a user signs in using a domain account

d)

When a user signs in using a local user account

58.

How can you ensure consistent application of audit policy settings to large groups of computers?

a)

Manually configure each computer

b)

Use local group policy settings

c)

Use GPOs in a domain

d)

Apply settings individually to each OU

59.

How can you apply a GPO to only some computers in an OU?

a)

Apply the GPO to all computers in the OU

b)

Use security filtering on the user accounts

c)

Make computer accounts members of a group and use security filtering

d)

Manually configure each computer individually

60.

What do advanced audit policies allow you to configure?

a)

Network bandwidth usage

b)

Fine-grained authentication information

c)

Application performance metrics

d)

System resource utilization

61.

What defines the security context in which services operate on Windows Server?

a)

User permissions

b)

Group policies

c)

Service account

d)

Network configuration

62.

Why should you avoid using Local System for services on Domain Controllers (DCs)?

a)

It lacks network access.

b)

It has restricted permissions.

c)

It has full access to AD DS.

d)

It requires frequent password changes.

63.

Why is correct documentation maintenance essential for service accounts used on multiple servers?

a)

To improve network performance

b)

To increase user satisfaction

c)

To ensure proper password updates

d)

To reduce server downtime

64.

What is a common requirement when creating a service account for an app installed on Windows Server?

a)

Assigning Domain Admins membership

b)

Configuring network protocols

c)

Defining permissions required

d)

Disabling user access control

65.

Which of the following is a potential risk if service accounts are misconfigured?

a)

Decreased network security

b)

Enhanced server performance

c)

Service outage

d)

Increased user productivity

66.

What is the purpose of Service Principal Names (SPNs) for service accounts?

a)

Assigning group memberships

b)

Enabling remote desktop access

c)

Facilitating Kerberos authentication

d)

Configuring network protocols

67.

How are SPNs formatted in Kerberos authentication?

a)

servicename\host

b)

servicename@host

c)

servicename/host

d)

servicename:port

68.

How can you identify duplicate SPNs in a domain?

a)

Running ipconfig /all

b)

Using ping to check network connectivity

c)

Running setspn.exe -X

d)

Reviewing event logs

69.

In what scenario is Kerberos authentication delegation useful?

a)

Server downtime management

b)

User authentication monitoring

c)

When a service needs to access another service on behalf of users

d)

Network bandwidth optimization

70.

What is the primary advantage of group managed service accounts (MSAs) over regular MSAs?

a)

They can run on multiple servers

b)

They have shorter replication times

c)

They require fewer permissions

d)

They provide stronger encryption

71.

In what scenarios are group MSAs particularly useful?

a)

Local development environments

b)

Single-server setups

c)

High-availability scenarios

d)

Non-networked environments

72.

How can you create a group MSA named "SQLCluster" and allow specific servers to use it?

a)

Using the Group Policy Management Console

b)

Through the Active Directory Users and Computers interface

c)

With the New-ADServiceAccount cmdlet

d)

Manually editing the registry

73.

How can you simplify management of computer accounts that can use a group MSA?

a)

By configuring group policies

b)

Through manual registry edits

c)

By defining a group of computer accounts

d)

By altering firewall settings

74.

Which scenario is NOT appropriate for an RODC?

a)

Branch offices

b)

Company Data Centres

c)

Public locations

d)

Perimeter Networks

75.

Why would you use fine-grained password policies?

a)

To ensure low value users have the highest password complexity.

b)

To apply the same account lockout policies across all employees.

c)

To apply password and account lockout policies to specific groups.

d)

To ensure everyone in the organization has the same password and account lockout policies.

76.

Where are logon events recorded?

a)

Logon events are recorded on the computer that is authoritative for the account.

b)

Logon events are recorded on the computer where the resource is being accessed.

c)

Logon events are recorded when signing in to a workstation.

d)

Logon events are recorded on domain partition of the local file server.

77.

Where are account logon events recorded? (Choose three)

Select all answers that apply

a)

Account logon events are recorded on the computer that is authoritative for the account.

b)

Account logon events are recorded on the computer where the resource is being accessed.

c)

Account logon events are generated on the DC that performs the authentication.

d)

Account logon events are generated on the workstation when logging in with a local user account.

78.

When configuring a service account, what are TWO key benefits of using group MSAs instead of a domain user account?

a)

Password management

b)

User rights management

c)

SPN Management

d)

Ease of auditing

79.

Which registry hive are settings configured in Computer Configuration
\Policies\Administrative Templates written to?

a)

HKEY_CURRENT_USER

b)

HKEY_LOCAL_MACHINE

c)

HKEY_USERS

d)

HKEY_CURRENT_CONFIG

80.

When considering updating your administrative templates, which collection of files contains the settings?

a)

ADMX

b)

ADML

c)

ADM

d)

.XML

81.

Where must you create the central store for managing administrative templates?

a)

\\<FQDN>\SYSVOL\<FQDN>\Policies\PolicyDefinitions

b)

C:\SYSVOL\Policies\PolicyDefinitions

c)

C:\Policies\Administrative_Templates

d)

C:\PolicyDefinitions

82.

There are four options for configuring the Folder Redirection setting for Pictures. What are they?

a)

None, Basic, Advanced, Follow the Documents

b)

Move, Copy, Remove, Keep on Device

c)

Read, Write, Execute, Copy

d)

Desktop, Documents, Remote Server, Local Machine