Font size
WorksheetsQuiz6,7 COOS295
Total questions: 82
Worksheet time: 41mins
What is the primary function of administrative templates in Group Policy?
Providing security patches
Managing network protocols
Configuring hardware settings
Configuring user and computer settings
Where are the user configuration settings of administrative templates stored in the registry?
HKEY_LOCAL_MACHINE
HKEY_CLASSES_ROOT
HKEY_CURRENT_CONFIG
HKEY_CURRENT_USER
What is the purpose of ADMX files in Group Policy?
To provide language-specific interface files
To define the functionality and interface of administrative templates
To store user-specific settings related to policies applied at log on and log off
To manage printer configurations for departments required to share printers
When do computers in an organization apply Group Policy changes made in the Group Policy Management Editor?
Immediately upon closing the editor
When the administrator forces a system restart
During the next Group Policy refresh cycle
After manually pushing updates to each computer
What is the final step after making changes in the Group Policy Management Editor?
Restarting the domain controller
Reinstalling Group Policy
Closing the editor to implement changes
Disabling Group Policy enforcement
What is the recommended domain controller to host the central store?
The one containing the PDC Emulator operations primary role
Any domain controller with sufficient storage
The one with the least network traffic
The one with the highest CPU power
Where should the PolicyDefinitions folder be created to implement the central store?
C:\Windows\System32
C:\Program Files
\<FQDN>\SYSVOL<FQDN>\Policies
C:\Users
Which section of a security template includes settings for the Password Policy?
Account Policies
Local Policies
Restricted Groups
Event Log
How can you import security templates into Group Policy?
By using the Group Policy Management Editor
By restarting the domain controller
By manually editing the registry
By using a third-party application
What tool can you use to compare current computer configuration to security templates?
Secedit.exe
Windows PowerShell
Security Templates snap-in
Group Policy Management Console
What should you consider before making changes to GPO configuration after updating the central store?
Restarting the domain controller
Disabling DFS Replication
Waiting for replication latency
Modifying the DNS settings
What is one of the primary benefits of using Folder Redirection?
Enhanced graphical user interface
Improved network speeds in branch locations
Users access documents from any domain-joined computer
Reduced administrator workload during normal working hours
What does enabling the "Move the contents of to the new location" setting in Folder Redirection do?
Deletes existing content in the local folder
Leaves the content in the local folder untouched
Prevents users from accessing the redirected folder
Moves existing content in the local folder to the UNC-defined location
Which security principal has Full Control for subfolders and files only in the root folder permissions for Folder Redirection?
System
Administrator
Creator/Owner
Security group of users that save data on the share
What does Folder Redirection synchronize to a defined network location?
User data
User settings
System registry
Windows operating system files
What must you do before configuring Folder Redirection in Group Policy?
Configure the UNC path that hosts the redirected content
Install additional software
Perform a system reboot
Disable user profiles
Which tool provides a feature-limited means to deploy apps to Windows computers assuming those apps are installed by .msi files?
Group Policy
Microsoft Intune
Endpoint Configuration Manager (ECM)
Microsoft Deployment Toolkit (MDT)
What is file extension activation in the context of Group Policy app deployment?
A feature to disable certain file extensions
Auto-installing an app if a user attempts to open a file with a defined file extension
A method to restrict file access based on file types
A security measure to prevent file corruption
Which deployment method installs apps automatically without user intervention?
Publish
Assign
Deploy
Share
Why might a user need to sign out and back in after an app is assigned to their user account via Group Policy?
To uninstall the oldest version of the app prior to updating
To refresh their desktop wallpaper to support the new app
To make the assigned app effective
To synchronize their system time with the server
What is a characteristic of the "Publish" deployment mode when deploying apps via Group Policy?
Apps are automatically installed without user intervention
Apps are installed only if a user selects to install the published app
Apps are installed based on file extensions opened by users
Apps are deployed to specific computers based on organizational units
Which setting on the Common tab of Group Policy preferences allows you to determine whether a preference is applied based on the characteristics of the objects being configured?
Stop processing items in this extension if an error occurs
Item-level targeting
Remove this item when it is no longer applied
Apply one time and do not reapply
In Group Policy preferences, what is the default behavior for preferences regarding reapplication?
Preferences are applied only one time and not refreshed
Can be configured to apply only one time, or at the same intervals as Policy settings.
Preferences are removed when the GPO that applied them is no longer applying
Preferences do not reapply unless manually refreshed by the user
What feature of Group Policy preferences allows you to control the application of specific preferences within a given GPO?
Link Order
Enforced
Block Inheritance
Item-level targeting
How can you be more specific when using item-level targeting in Group Policy preferences?
By selecting the "Apply one time and do not reapply" setting
By removing preferences when they are no longer applied
By combining categories using Boolean logic and operators such as AND, OR
By defining various options based on the type of preference being configured
When using Group Policy preferences, what is the impact if a setting is configured by both policies and preferences?
Preferences take precedence over policies
Both policies and preferences are disregarded
Policies and preferences are applied simultaneously
The policy setting takes precedence over the preference setting
What is a primary reason why protecting Domain Controllers (DCs) is crucial?
To enhance network connectivity to branch office locations
To prevent unauthorized access to AD DS authentication information
To facilitate remote access for users working from home
To increasing on site server capacity in company data centres
Which of the following is NOT a security risk that can affect DCs?
Operating system, service, or app attack
Physical security threats
Private network accessibility
Denial of service attack (DoS)
The settings in the Default Domain Controllers Policy provide optimal security.
True
False
Which tool can be used to compare the configuration of DCs to security baselines?
Domain Controller Analyzer
Security Policy Editor
Policy Analyzer
Security Configuration Wizard
What does the Center for Internet Security (CIS) provide?
Hardware maintenance services
Software development kits (SDKs)
Security benchmarks for various software
Cloud computing solutions
How can you mitigate the risk of deploying DCs to less secure locations?
By deploying additional DCs without encryption
By disabling network firewalls
By implementing an RODC
By allowing open access to DC hardware
What is the purpose of segmenting network activity ?
To increase network speed
To encourage collaboration among all users
To limit access to resources
To centralize data storage
Which of the following statements regarding RODCs is FALSE?
They provide local administrator access without administrative permissions to AD DS.
They can initiate updates to AD DS objects.
All passwords are cached on an RODC by default
They forward authentication requests to a full DC by default.
How can you pre-stage an RODC computer account?
Use PowerShell to install Active Directory Domain Services.
Use Active Directory Users and Computers to pre-create the account.
Leave the server in a workgroup until installation.
Promote the server to be a DC in an existing domain immediately.
How can you support authentication in a site with intermittent network connectivity?
By installing additional RODCs
By configuring RODCs to deny all password caching
By allowing branch office computer accounts to cache passwords on RODCs
By promoting regular DCs to RODCs temporarily
Which group controls password replication to all RODCs in the domain?
Enterprise Admins
Allowed RODC Password Replication Group
Domain Users
Denied RODC Password Replication Group
What is a potential consequence of allowing many users to have passwords cached on all RODCs?
Improved network performance
Reduced security
Enhanced authentication speed
Increased fault tolerance
What is NOT a task that a delegated administrator for an RODC can perform?
Managing hardware devices
Accessing the local copy of the AD DS database
Installing and removing server roles and features
Reviewing event logs
Which feature mitigates the risk of automated password guessing attacks?
Fine-grained policies
Windows Hello
Account lockout policies
Kerberos authentication policies
What does the Enforce user logon restrictions setting in the Kerberos Policy control?
Password history requirements
Maximum lifetime for service tickets
Verification of user rights for session tickets
Maximum tolerance for computer clock synchronization
Which of the following is a sign-in option in Windows?
Kerberos authentication policies
Restricted groups
Windows Hello
Fine-grained policies
How can you ensure that users are not accidentally added to certain groups?
By configuring fine-grained policies
By enforcing account lockout policies
By using restricted groups
By joining the Protected Users group
Which group prevents devices from caching credentials for its members?
Restricted Users group
Protected Users group
Domain Users group
Authentication Policies group
How can you configure rules for authentication to specific devices?
By configuring fine-grained policies
By enabling Windows Hello
By using authentication policies
By joining the Protected Users group
Where can you configure Restricted Groups for member servers and workstations in Group Policy?
User Configuration\Policies\Windows Settings\Security Settings\Restricted Groups
Computer Configuration\Policies\Windows Settings\Security Settings\Restricted Group
Computer Configuration\Preferences\Windows Settings\Security Settings\Restricted Groups
User Configuration\Preferences\Control Panel Settings\Security Settings\Restricted Groups
What applies when evaluating multiple PSOs for a user account?
PSOs linked to groups have higher priority than PSOs linked to users
PSOs with higher precedence value have higher priority
PSOs linked to the user have higher priority than PSOs linked to groups
For two PSOs with the same precedence the PSO with the higher object GUID will have higher priority
How can you determine the effective PSO for a user?
By reviewing the msDS-PSOApplied attribute of the user
By using Windows Management Instrumentation filtering
By reviewing the msDS-ResultantPSO attribute of the user
By querying Active Directory Administrative Center
How can you create a new PSO using Active Directory Administrative Center?
By navigating to Domain Controllers and selecting New Password Policy
By navigating to System and selecting New Password Settings
By navigating to System\Password Settings Container and selecting New Password Settings
By navigating to Users and Computers and selecting New Fine-Grained Password Policy
Which PowerShell cmdlet is used to link a PSO to a user or group?
Get-ADFineGrainedPasswordPolicy
Add-ADFineGrainedPasswordPolicy
Add-ADFineGrainedPasswordPolicySubject
Remove-ADFineGrainedPasswordPolicySubject
What is one of the security risks organizations face that Windows Hello helps prevent?
Virus infections
Malware attacks
Credential theft
Phishing scams
What does Windows Hello for Business use for authentication instead of caching credentials?
Biometrics
Security tokens
Certificate-based authentication
OAuth tokens
Which option is NOT a method of Azure AD MFA?
Phone call acknowledgment
Text message with password code
Smart card authentication
One-time password code
Which characteristic can be evaluated by Azure AD conditional access policies?
Browser type
Printer model
IP address location
Monitor resolution
How does PIM help reduce security risks associated with administrative accounts?
By limiting access to specific apps
By requiring additional authentication factors
By automating permissions assignment and removal
By encrypting administrative credentials
Where is a logon event generated when a user accesses a file share from a workstation?
Domain Controller
Domain-connected server
File server
Workstation
When does an account logon event occur on a Domain Controller?
When a user accesses a file share
When a user signs in to a workstation
When a user signs in using a domain account
When a user signs in using a local user account
How can you ensure consistent application of audit policy settings to large groups of computers?
Manually configure each computer
Use local group policy settings
Use GPOs in a domain
Apply settings individually to each OU
How can you apply a GPO to only some computers in an OU?
Apply the GPO to all computers in the OU
Use security filtering on the user accounts
Make computer accounts members of a group and use security filtering
Manually configure each computer individually
What do advanced audit policies allow you to configure?
Network bandwidth usage
Fine-grained authentication information
Application performance metrics
System resource utilization
What defines the security context in which services operate on Windows Server?
User permissions
Group policies
Service account
Network configuration
Why should you avoid using Local System for services on Domain Controllers (DCs)?
It lacks network access.
It has restricted permissions.
It has full access to AD DS.
It requires frequent password changes.
Why is correct documentation maintenance essential for service accounts used on multiple servers?
To improve network performance
To increase user satisfaction
To ensure proper password updates
To reduce server downtime
What is a common requirement when creating a service account for an app installed on Windows Server?
Assigning Domain Admins membership
Configuring network protocols
Defining permissions required
Disabling user access control
Which of the following is a potential risk if service accounts are misconfigured?
Decreased network security
Enhanced server performance
Service outage
Increased user productivity
What is the purpose of Service Principal Names (SPNs) for service accounts?
Assigning group memberships
Enabling remote desktop access
Facilitating Kerberos authentication
Configuring network protocols
How are SPNs formatted in Kerberos authentication?
servicename\host
servicename@host
servicename/host
servicename:port
How can you identify duplicate SPNs in a domain?
Running ipconfig /all
Using ping to check network connectivity
Running setspn.exe -X
Reviewing event logs
In what scenario is Kerberos authentication delegation useful?
Server downtime management
User authentication monitoring
When a service needs to access another service on behalf of users
Network bandwidth optimization
What is the primary advantage of group managed service accounts (MSAs) over regular MSAs?
They can run on multiple servers
They have shorter replication times
They require fewer permissions
They provide stronger encryption
In what scenarios are group MSAs particularly useful?
Local development environments
Single-server setups
High-availability scenarios
Non-networked environments
How can you create a group MSA named "SQLCluster" and allow specific servers to use it?
Using the Group Policy Management Console
Through the Active Directory Users and Computers interface
With the New-ADServiceAccount cmdlet
Manually editing the registry
How can you simplify management of computer accounts that can use a group MSA?
By configuring group policies
Through manual registry edits
By defining a group of computer accounts
By altering firewall settings
Which scenario is NOT appropriate for an RODC?
Branch offices
Company Data Centres
Public locations
Perimeter Networks
Why would you use fine-grained password policies?
To ensure low value users have the highest password complexity.
To apply the same account lockout policies across all employees.
To apply password and account lockout policies to specific groups.
To ensure everyone in the organization has the same password and account lockout policies.
Where are logon events recorded?
Logon events are recorded on the computer that is authoritative for the account.
Logon events are recorded on the computer where the resource is being accessed.
Logon events are recorded when signing in to a workstation.
Logon events are recorded on domain partition of the local file server.
Where are account logon events recorded? (Choose three)
Select all answers that apply
Account logon events are recorded on the computer that is authoritative for the account.
Account logon events are recorded on the computer where the resource is being accessed.
Account logon events are generated on the DC that performs the authentication.
Account logon events are generated on the workstation when logging in with a local user account.
When configuring a service account, what are TWO key benefits of using group MSAs instead of a domain user account?
Password management
User rights management
SPN Management
Ease of auditing
Which registry hive are settings configured in Computer Configuration
\Policies\Administrative Templates written to?
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_USERS
HKEY_CURRENT_CONFIG
When considering updating your administrative templates, which collection of files contains the settings?
ADMX
ADML
ADM
.XML
Where must you create the central store for managing administrative templates?
\\<FQDN>\SYSVOL\<FQDN>\Policies\PolicyDefinitions
C:\SYSVOL\Policies\PolicyDefinitions
C:\Policies\Administrative_Templates
C:\PolicyDefinitions
There are four options for configuring the Folder Redirection setting for Pictures. What are they?
None, Basic, Advanced, Follow the Documents
Move, Copy, Remove, Keep on Device
Read, Write, Execute, Copy
Desktop, Documents, Remote Server, Local Machine
