WorksheetsActive Directory and GPO Quiz
Total questions: 75
Worksheet time: 38mins
You have a GPO that should apply only to computers in the 'Laptops' security group. How do you achieve this?
Set 'Block Inheritance' for the GPO.
Create a new OU for Laptops and link the GPO there.
Use a WMI filter to query for laptop hardware.
This is not possible; GPOs can only be filtered by OU.
In the GPO's Scope tab, remove 'Authenticated Users' and add the 'Laptops' security group.
What is the effect of setting a GPO link to 'Enforced' (also known as 'No Override')?
It forces the GPO's settings to apply, even if a child container has 'Block Inheritance' enabled.
It applies the GPO only if a WMI filter evaluates to true.
It prevents the GPO from being applied to any users or computers.
It blocks GPOs from parent containers from being inherited.
It applies the GPO only to members of a specific security group.
WMI filtering allows a GPO to be applied conditionally based on what?
The user's group membership.
Properties of the target computer, such as OS version or free disk space.
The time of day.
The name of the GPO.
The link speed to the domain controller.
In Active Directory, what is the primary replication boundary for domain-specific information, such as user accounts and groups?
The Site
The Organizational Unit (OU)
The Domain
The Subnet
The Forest
What is the maximum amount of RAM supported by Windows Server 2008 R2 Standard Edition?
2 TB
32 GB
64 GB
128 GB
16 GB
Which security group scope can contain users and groups from any domain in the forest and can be used to assign permissions in any domain in the forest?
Universal
System
Global
Local
Domain Local
The process of moving roles and data from an old server to a new server installation of Windows Server is known as:
Cloning
Hot swap
Migration
In-place upgrade
Replication
What is the highest-level logical container in an Active Directory structure, providing the ultimate security boundary?
Tree
Domain
Forest
Organizational Unit (OU)
Site
Which of the following common tasks can be configured using Group Policy Preferences but NOT with traditional Group Policy Settings?
Mapping a network drive based on user group membership
Account Lockout Policy
Software Installation
Audit Policy
Password Policy
Which PowerShell cmdlet is used to add a new role or feature to Windows Server 2008 R2?
Install-Role
Enable-ServerRole
Set-WindowsRole
New-Feature
Add-WindowsFeature
What is a key characteristic of a Read-Only Domain Controller (RODC)?
It must hold the PDC Emulator FSMO role.
It holds a full, writable copy of the Active Directory database.
It does not replicate or cache user passwords by default.
It is typically deployed in a secure, central datacenter.
All directory changes must originate from the RODC.
Which FSMO role is responsible for processing RID pools' requests from all domain controllers in a particular domain?
PDC Emulator
RID Master
Schema Master
Infrastructure Master
Domain Naming Master
You need to grant a junior administrator the ability to reset passwords for all users in the 'Sales' OU, but no other administrative rights. How would you accomplish this?
Use the Delegation of Control Wizard on the Sales OU.
Grant them 'Domain Admins' group membership in the domain controller.
Make them a member of Domain Admins.
Create a 'Full Control' permission on the OU.
Create a new GPO linked to the OU.
When a client computer detects a slow network link to the domain controller, which GPO client-side extension's processing will be delayed or skipped to improve logon performance?
Security
Administrative Templates
Folder Redirection
Software Installation
Registry
Following the Microsoft best practice IGDLA, where do you assign permissions to resources (like a shared folder)?
To the computer account
To the Universal group
To the User Account
To the Global group
To the Domain Local group
In PowerShell, which character is used to pipe the output of one command as the input to another command?
|
#
;
&
?
What is the standard, recommended naming convention for PowerShell cmdlets?
Verb-Noun
Noun-Verb
Adjective-Noun
Action-Subject
Verb-Object
Which FSMO role is a forest-wide role, meaning only one exists in the entire Active Directory forest?
PDC Emulator
RID Master
Infrastructure Master
Global Catalog
Schema Master
What is the function of the Active Directory Schema?
It defines the structure of the Active Directory.
It defines the types of objects and attributes that can be created in the directory.
It manages the physical site topology.
It stores user passwords securely.
It contains a list of all domain controllers.
What is the main advantage of creating and using user templates
It simplifies and standardizes the creation of new user accounts with consistent properties
It automatically assigns new users to the Domain Admins group
It automatically assigns new users to the Domain Admins group
It automatically assigns new users to the Domain Admins group
It ensures all new users have the same password
What is the main advantage of creating and using user templates in Active Directory?
It simplifies and standardizes the creation of new user accounts with consistent properties.
It automatically assigns new users to the Domain Admins group.
It is the only way to create new user accounts.
It enforces a password history of 24 passwords for new users.
It ensures all new users have the same password.
What is the name of the main Active Directory database file located on a domain controller?
ntds.org
ntds.dat
registry.pol
ntds.dit
sam.dat
What is the primary difference between a 'Role' and a 'Feature' in Windows Server?
Roles provide primary functions (e.g., AD DS), while Features provide support functions (e.g., Failover Clustering).
Features provide primary functions, while Roles provide support functions.
There is no difference.
Roles are only for security, Features are only for networking.
Roles are installed via GUI, Features are installed via PowerShell.
What is the purpose of the Group Policy Loopback Processing feature in 'Replace' mode?
It reverses the normal processing order of GPOs (UUDSL).
It allows users to choose which GPOs they want to apply.
It applies only the User Configuration GPOs linked to the computer's OU, ignoring the GPOs linked to the user's OU.
It prevents GPOs from being applied over slow network links.
It forces an update of all GPO settings.
Which command-line tool is used on Server Core to perform initial configuration tasks like setting the IP address, computer name, and domain membership?
netsh.exe
sconfig.cmd
ipconfig.exe
servermanagercmd.exe
dcpromo.exe
Which Active Directory partition is replicated to all domain controllers in the entire forest?
Root Partition
Schema Partition
Configuration Partition
Domain Partition
Application Partition
What is the primary benefit of using the Install from Media (IFM) option when promoting a new domain controller in a remote site?
It reduces the amount of Active Directory data that needs to be replicated over the network.
It creates a new forest based on the media.
It allows installation without administrator privileges.
It is the only way to install an RODC.
It automatically installs all necessary FSMO roles on the new DC.
Which of the following is a primary advantage of performing a migration over an in-place upgrade?
It is a faster process.
It allows for a clean OS installation, avoiding legacy issues.
It requires less planning.
It requires no additional hardware.
It preserves all application settings perfectly.
By default, if a GPO setting is configured at the Domain level and a conflicting setting is configured at the OU level that contains a user object, which setting will be applied to the user?
The Domain level setting.
Neither setting will be applied due to the conflict.
The OU level setting, because it is processed last.
The settings will be merged together.
The setting from the GPO with the lower link order number.
What is a key difference between Group Policy Settings and Group Policy Preferences?
Settings can only be applied to users, Preferences only to computers.
Settings are enforced and re-applied periodically, while Preferences are typically applied once and can be changed by the user.
Preferences are enforced, while Settings are not.
There is no difference.
Preferences require WMI filters, while Settings do not.
In Active Directory, what construct is used to represent the physical topology of the network to manage replication traffic?
OUs
Subnets
Forests
Sites
Domains
What is the primary purpose of an Organizational Unit (OU)?
To define a boundary for security and other domains.
To mirror a company's physical locations.
To group and secure secondary objects in different OUs cannot access each other.
To control access to network resources.
To delegate administrative control and link Group Policy Objects.
What type of DNS resource record is essential for clients to locate Active Directory services, like domain controllers and Global Catalog servers?
PTR (Pointer)
CNAME (Alias)
A (Host)
SRV (Service Locator)
MX (Mail Exchanger)
What is a key feature of the PowerShell Integrated Scripting Environment (ISE) that is NOT available in the standard PowerShell console?
Tab completion
The ability to run PowerShell cmdlets
A multi-pane view with a script editor and command window
A blue background
Command history
A Global Catalog server holds a full, writable copy of all objects in its host domain and what kind of copy of objects from other domains in the forest?
A full, writable copy
No copy of objects from other domains
A partial, writable copy
A partial, read-only copy
A full, read-only copy
In Active Directory, what is the primary replication boundary for domain-specific information, such as user accounts and groups?
The Site
The Domain
The Forest
The Organizational Unit (OU)
The Schema
By default, if a GPO setting is configured at the Domain level and a conflicting setting is configured at the OU level that contains a user object, which setting will be applied to the user?
The setting from the GPO with the lower link order number.
The OU level setting, because it is processed last.
The Domain level setting.
Neither setting will be applied due to the conflict.
The settings will be merged together.
Which security group scope can contain users and groups from any domain in the forest and can be used to assign permissions in any domain in the forest?
Universal
System
Global
Domain Local
Local
The 'Block Inheritance' feature is configured at which level in the Active Directory hierarchy?
On a Domain, Site, or OU container
On a security group
On a specific user account
On a WMI filter
On a specific GPO's properties
During a standard, default domain join process, what is required for the client computer?
The Active Directory Administrative Center must be installed.
Physical access to a domain controller.
A pre-staged computer account must exist.
Network connectivity to a DNS server that can resolve AD service records.
The computer must be running a Server Core installation.
What is the purpose of the Group Policy Loopback Processing feature in 'Replace' mode?
It reverses the normal processing order of GPOs (UUDSL).
It forces an update of all GPO settings.
It prevents GPOs from being applied over slow network links.
It allows users to choose which GPOs they want to apply.
It applies only the User Configuration GPOs linked to the computer's OU, ignoring the GPOs linked to the user's OU.
When a client computer detects a slow network link to the domain controller, which GPO client-side extension's processing is disabled by default to improve logon performance?
Administrative Templates
Security
Folder Redirection
Software Installation
Registry
Following the Microsoft best practice IGDLA, where do you assign permissions to resources (like a shared folder)?
To the Domain Local group
To the Global group
To the computer account
To the Universal group
To the User Account
Which FSMO role is responsible for processing RID pools' requests from all domain controllers in a particular domain?
Infrastructure Master
Domain Naming Master
PDC Emulator
Schema Master
RID Master
What is a key difference between Group Policy Settings and Group Policy Preferences?
Preferences are enforced, while Settings are not.
Settings are enforced and re-applied periodically, while Preferences are typically applied once and can be changed by the user.
There is no difference.
Preferences are applied only to specific users.
Which Active Directory partition is replicated to all domain controllers in the entire forest?
Schema Partition
Configuration Partition
Root Partition
Domain Partition
Application Partition
What type of DNS resource record is essential for clients to locate Active Directory services, like domain controllers and global catalog servers?
SRV (Service Locator)
MX (Mail Exchanger)
A (Host)
CNAME (Alias)
PTR (Pointer)
What does the PDC Emulator FSMO role provide in a modern Windows domain?
It manages the schema across all domains.
It handles DNS zone transfers.
It synchronizes time across the domain, manages password changes, and serves as a fallback for authentication.
It replicates Group Policy Objects.
It authorizes DHCP servers.
If a user is a member of multiple security groups that have different permissions to a file, what determines the effective access?
The permissions of the first group the user joined.
The most restrictive permission among all groups.
The permissions are averaged across all groups.
The cumulative (combined) permissions from all groups.
The permissions inherited from the user's OU.
What does the 'Enforce' option on a Group Policy Object do?
Prevents changes to the GPO.
Applies the GPO to computers even if they are not in the correct OU.
Makes the GPO apply last.
Forces the GPO to override child OUs that use 'Block Inheritance'.
Makes the GPO read-only for administrators.
Which tool is best used to create and link GPOs to OUs?
Active Directory Users and Computers
DNS Manager
ADSI Edit
Group Policy Management Console (GPMC)
Active Directory Sites and Services
What happens if two GPOs linked to the same OU configure the same setting, but in opposite ways (e.g., one enables and one disables)?
Neither setting applies.
The one processed first takes effect.
The one with the higher link order number takes effect.
The one with the lower link order number takes effect.
The setting is applied randomly.
A user can successfully log in with an old password but not with the new one. What is the most likely explanation?
The user is logged in with a cached credential and not contacting a domain controller.
The DNS record for the domain controller is incorrect.
There is no global catalog server in the domain.
The computer is joined to a workgroup.
The user account is locked.
In Active Directory, what does a Universal group allow that Global and Domain Local groups do not?
Assign permissions to computers
Be nested within Domain Local groups
Contain users from any domain and be granted permissions in any domain
Be created by any domain user
Apply GPOs directly
What is required for time synchronization in an Active Directory domain?
All clients must be manually configured with the same NTP server.
Clients must synchronize with the Schema Master.
Clients and member servers synchronize time with the domain controller holding the PDC Emulator role.
Only the domain controllers must synchronize time.
Group Policy must be disabled for time to sync.
You’ve linked a GPO to an OU, but the settings are not applying to users within that OU. What’s the first thing you should check?
Whether the GPO is enforced
If Block Inheritance is enabled on the domain
That the users have administrative rights
That the GPO is linked and enabled
Whether the computer account is in the OU
What happens if the Infrastructure Master is hosted on a Global Catalog server in a multi-domain forest?
It works normally
It causes replication delays
It fails to update references to objects in other domains
It promotes all users to domain admins
It prevents domain joins
Which feature allows administrators to apply Group Policy settings based on criteria such as the computer's CPU architecture or available RAM?
WMI Filtering
Block Inheritance
Group Policy Loopback
Enforced GPOs
Group Policy Templates
You have set a GPO at the domain level, and another GPO at an OU level. The OU GPO disables USB ports; the domain GPO enables them. What setting is applied?
The domain GPO because it’s higher
The OU GPO because it’s processed later
Neither will apply
Both settings will conflict and cancel
The setting is inherited from the forest root
WMI filtering allows a GPO to be applied conditionally based on what?
The user's group membership.
Properties of the target computer, such as OS version or free disk space.
The time of day.
The name of the GPO.
The link speed to the domain controller.
What is a key characteristic of a Read-Only Domain Controller (RODC)?
It holds a full, writable copy of the Active Directory database.
It does not replicate or cache user passwords by default.
It must hold the PDC Emulator FSMO role.
It is typically deployed in a secure, central datacenter.
It must hold the PDC Emulator FSMO role.
What is the effect of setting a GPO link to 'Enforced' (also known as 'No Override')?
It forces the GPO's settings to apply, even if a child container has 'Block Inheritance' enabled.
It blocks GPOs from parent containers from being inherited.
It prevents the GPO from being applied to any users or computers.
It applies the GPO only if a WMI filter evaluates to true.
It applies the GPO only to members of a specific security group.
A Global Catalog server holds a full, writable copy of all objects in its host domain and what kind of copy of objects from other domains in the forest?
A full, writable copy
A partial, read-only copy
No copy of objects from other domains
A full, read-only copy
A partial copy
What is the function of the Active Directory Schema?
It defines the rules for GPO processing.
It manages user password hashes.
It defines the types of objects and attributes that can be created in the directory.
It manages the physical site topology.
It contains a list of all domain controllers.
When you 'Publish' a software package to a user via Group Policy, what is the user experience?
The software is installed automatically at the next logon.
The software is installed, but the user must be a local administrator to run it.
A shortcut is placed on the user's desktop, and it installs on first use.
The software becomes available for the user to optionally install from 'Programs and Features' in the Control Panel.
An email is sent to the user with installation instructions.
What does the acronym LSDOU represent in the context of Group Policy processing order?
Local, Site, Domain, OU, User
Least, Specific, Default, Overridden
Left, Site, Domain, Organizational Unit
Local, Site, Domain, Organizational Unit
Link, Site, Domain, OU
Which command-line utility is used to perform an offline domain join, allowing a computer to join a domain without direct network connectivity to a domain controller?
netdom.exe
join.exe
djoin.exe
dsadd.exe
djoin.exe
What is the primary benefit of using the Install from Media (IFM) option when promoting a new domain controller in a remote site?
It allows installation without administrator privileges.
It creates a new forest based on the media.
It automatically installs all necessary FSMO roles on the new DC.
It is the only way to install an RODC.
It reduces the amount of Active Directory data that needs to be replicated over the network.
Which of the following is a primary advantage of performing a migration over an in-place upgrade?
It preserves all application settings perfectly.
It requires no additional hardware.
It is a faster process.
It requires less planning.
It results in a clean OS installation, avoiding legacy issues.
What is a key feature of the PowerShell Integrated Scripting Environment (ISE) that is NOT available in the standard PowerShell console?
The ability to run PowerShell cmdlets
A multi-pane view with a script editor and command window
Tab completion
Command history
A blue background
What is the maximum amount of RAM supported by Windows Server 2008 R2 Standard Edition?
16 GB
64 GB
32 GB
128 GB
2 TB
In Active Directory, what construct is used to represent the physical topology of the network to manage replication traffic?
OUs
Subnets
Forests
Domains
Sites
The process of creating a computer account in Active Directory using the Active Directory Users and Computers console before the computer is physically joined to the domain is known as:
Pre-staging
Default domain join
Remote domain join
Offline domain join
Default domain join
Which command-line tool is used on Server Core to perform initial configuration tasks like setting the IP address, computer name, and domain membership?
dcpromo.exe
servermanagercmd.exe
netsh.exe
ipconfig.exe
sconfig.cmd
Which of the following common tasks can be configured using Group Policy Preferences but NOT with traditional Group Policy Settings?
Password Policy
Account Lockout Policy
Software Installation
Mapping a network drive based on user group membership
Audit Policy
