WorksheetsActive Directory / IDA — Practice MCQs
Total questions: 30
Worksheet time: 15mins
An identity in Active Directory represents what?
A. A shared network folder
B. Any entity that performs actions on a system
C. Only human users
D. Only application services
Which database file stores Active Directory data?
ActiveDB.sys
ADStore.ini
Ntds.dit
Schema.db
What is the main role of a Domain Controller?
Host databases
Provide file sharing
Authenticate and authorize identities
Install applications
Which authentication protocol does AD primarily use?
RADIUS
Kerberos
PAP
NTLM-Only
A group of domains that share a common schema and configuration is called a:
Tree
Site
Workgroup
Forest
The first domain created in a forest is called:
Primary Domain
Root Domain
Core Domain
Master Domain
What defines the classes and attributes allowed in Active Directory?
Catalog
Schema
Policy
Domain table
Which feature allows a single login across trusted organizations?
AD RMS
AD LDS
AD FS
AD CS
Which AD technology issues digital certificates?
AD RMS
AD DS
AD FS
AD CS
Which service controls what users are allowed to do with documents (like blocking printing)?
AD DS
AD FS
AD RMS
AD LDS
What is the purpose of the Global Catalog?
Backup AD data
Speed up logon only
Store DNS records only
Provide searchable directory information about all objects
Which of the following best describes an AD Site?
A logical grouping of users
A physical network boundary with good connectivity
A file storage unit
A different domain
What is stored inside Organizational Units (OUs)?
Only computers
Only users
Objects such as users and computers
Only Global Catalogs
Which component replicates AD data between Domain Controllers?
Kerberos
Replication Service
DNS
DHCP
A tree in Active Directory is formed when:
Domains share a contiguous DNS namespace
Two forests connect
No OUs exist
Sites overlap
Which of the following determines AD feature availability based on Windows Server version?
Schema level
Domain structure
Forest role
Functional level
Which AD technology is used mainly by applications needing a directory without full AD DS?
AD FS
AD LDS
AD CS
AD RMS
Which object uniquely identifies each security principal?
SID
UID
DNS name
IP address
What does an Access Control List (ACL) define?
Application restrictions
Password rules
Permissions on resources
Network addressing
What is TRUE about a forest?
It is not a security boundary
It contains multiple DNS servers only
Data never replicates outside forest boundaries
Forests cannot contain multiple domains
Which AD service supports secure document usage monitoring?
AD LDS
AD CS
AD RMS
AD FS
Which protocol is commonly used to query directory information?
FTP
SMTP
LDAP
RDP
Group Policy is mainly used for:
Encrypting data
Applying configuration settings across systems
Controlling DNS lookup
Configuring routing tables
Which of the following best describes replication within a site?
Manual
Slow
Occurs instantly or very frequently
Disabled
Clients generally prefer to authenticate with:
The furthest DC
Any random DC
The closest site’s Domain Controller
DNS server
Which of the following is NOT stored in AD DS?
User accounts
Computer accounts
Group objects
IP routing tables
Which technology helps enforce persistent document protection even outside the network?
AD CS
AD RMS
AD FS
DNS
Which directory service feature lets organizations apply settings from one place to many systems?
Schema
Audit policy
Policy-based administration
Replication tuning
A domain requires at least:
Zero domain controllers
One domain controller
Two domain controllers
Three servers
Which of the following BEST defines Identity and Access (IDA)?
Manages user logins only
Controls identity storage and access to resources
Stores network routes
Controls only application security
