/* */
SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
MCTS: Configuring A DNS Zone Infrastructure
Start Test
Study First
Subjects
:
certifications
,
mcts
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Public key cryptography provides ______ - which means that separate keys are used to encrypt and decrypt data.
request DNSSEC validation for specific queries
To All Domain Controllers In This Domain
disabled
asymmetric encryption
2. ______ in DNS refers to the process of using time stamps to track the age of dynamically registered resource records.
enable zone transfers
Aging
dnscmd servername /enlistdirectorypartition FQDN
standard
3. A ______ is a public key for a remote DNS server that is trusted and able to provide DNSSEC responses.
CNAME resource records
The Zone Aging/Scavenging Properties
trust anchor
1. Start of Authority (SOA) record that defines basic properties for the zone. 2. NS record signifying the name of the server or servers authoritative for the zone.
4. You must be a member of the ______ group to create an application directory partition.
use more than one name to point to
CNAME resource records
Service location (SRV)
Enterprise Admins
5. A ______ is a data structure in AD that distinguishes data for different replication purposes.
partition
Aging
Minimum (Default) TTL
Service location (SRV)
6. TTL values are not relevant for resource records within their authoritative zones. Instead - the TTL refers to ______ in nonauthoritative servers. A DNS server that has cached a resource record from a previous query discards the record when that reco
The DNS server needs to be a domain controller.
Host (A or AAAA) - Alias (CNAME) - Mail exchanger (MX) - Pointer (PTR) - Service location (SRV)
the cache life of a resource record
The Zone Aging/Scavenging Properties
7. ______ are public keys from other zones that are used to validate digitally signed records originating from those zones and from delegated subdomains that are also DNSSEC-compatible.
standard
Aging
Trust anchors
primary
8. What kind of zones do not automatically perform time stamping on dynamically created resource records?
parent zone to a child zone
dnscmd servername /enlistdirectorypartition FQDN
Standard zones
Service location (SRV)
9. The ______ partition is replicated among all DCs that are also DNS servers in every domain in an AD forest.
1. A SOA record 2. At least one NS record.
Minimum (Default) TTL
DNS server
ForestDnsZones
10. A ______ is a database containing records that associate names with addresses for a defined portion of a DNS namespace.
use more than one name to point to
dnscmd servername /enlistdirectorypartition FQDN
DNS zone
server level and at the zone level
11. A secondary zone will not be recognized as a valid name server until it contains a valid copy of zone data. For the secondary zone to obtain this data - you must first ______ to that server.
public key
enable zone transfers
request DNSSEC validation for specific queries
Notify
12. The ______ option stores the new zone in the Domain-DnsZones partition. Every DC in the local domain and on which the DNS Server role is installed will receive a copy of the zone.
1. Start of Authority (SOA) record that defines basic properties for the zone. 2. NS record signifying the name of the server or servers authoritative for the zone.
the cache life of a resource record
Netlogon
To All DNS Servers In This Domain
13. The first step in preparing a zone for DNSSEC is to back up the current zone data. To back up a zone - type the following command at an elevated command prompt: _______.
dnscmd /ZoneExport <zone name> <zone file name>
Enterprise Admins
The Zone Aging/Scavenging Properties
notification
14. To configure notifications - click ______ on the Zone Transfers tab when zone transfers are enabled.
Notify
Standard zones
A DS record
1. A SOA record 2. At least one NS record.
15. Manually created resource records for all zone types are assigned a time stamp of 0; this value indicates that they ______ be aged.
Group Policy
will not
decreases
delegate
16. You use Group Policy to configure DNS clients to _________________.
The Zone Aging/Scavenging Properties
Remove stale
To All DNS Servers In This Forest
request DNSSEC validation for specific queries
17. Active Directory-integrated zones perform time stamping for dynamically registered records by default - even before aging and scavenging are enabled. However - primary standard zones place time stamps on dynamically registered records in the zone onl
Win Srvr 2008 and Win Srvr 2008 R2
delegate
parent and child AD DS domains
aging
18. What is the name of the record that contains a hash of the public key in a delegated subdomain?
notification
A DS record
asymmetric encryption
Transfer New Copy Of Zone From Master
19. ______ refers to the process of deleting outdated resource records on which time stamps have been placed.
Transfer From Master
To All Domain Controllers In This Domain
GlobalNames zone
Scavenging
20. The refresh interval is the time after the no-refresh interval during which time stamp refreshes are ______ and resource records are not scavenged. The default refresh interval is 7 days.
dnscmd servername /createdirectorypartition FQDN
DomainDnsZones
Notify
accepted
21. The ______ partition is replicated among all DCs that are also DNS servers in a particular domain
aging
Reload - Transfer From Master - Transfer New Copy Of Zone From Master
DomainDnsZones
request DNSSEC validation for specific queries
22. The GlobalNames zone is compatible only with DNS servers running ______. Therefore - it cannot replicate to servers running earlier versions of Windows Server.
primary
Win Srvr 2008 and Win Srvr 2008 R2
stub
disabled
23. When the zone is stored in a file instead of AD - by default the primary zone file is named zone_name.dns - and this file is located in the ______ folder on the server.
Expires After
%systemroot%System32Dns
Transfer New Copy Of Zone From Master
Remove stale
24. During this operation - the server hosting the local secondary zone determines whether the serial number in the secondary zone's SOA resource record has expired and then pulls a zone transfer from the master server.
Expires After
Minimum (Default) TTL
The DNS server needs to be a domain controller.
Transfer From Master
25. Scavenging can occur only when ______ is enabled.
aging
NS record and an associated A record
trigger zone transfers on secondary zones
GlobalNames zone
26. Consequently - when aging is enabled - dynamically registered resource records can be scavenged after ___ days by default.
14
ForestDnsZones
notification
Service location (SRV)
27. The ______ option stores the zone in the user-created application directory partition specified in the associated drop-down list box.
To All Domain Controllers Specified In The Scope Of This Directory Partition
Group Policy
digitally sign
Secondary
28. For a delegation to be implemented - the parent zone must contain a _____ and an _____ (called a glue record) pointing to each authoritative server of the delegated domain.
the cache life of a resource record
dnscmd . /config /enableglobalnamessupport 1
AD Zone Replication Scope page
NS record and an associated A record
29. When you create a new zone - two types of records required for the zone are automatically created. List them.
Service location (SRV)
parent zone to a child zone
Notify
1. Start of Authority (SOA) record that defines basic properties for the zone. 2. NS record signifying the name of the server or servers authoritative for the zone.
30. Win 7 clients can be configured to request DNSSEC through the Name Resolution Policy Table (NRPT) in ______.
The Zone Aging/Scavenging Properties
will not
Group Policy
digitally sign
31. When you do not store a zone in AD - the zone is called a ______ zone - and zone data is stored in text files on the DNS server.
will not
standard
Scavenging
digitally sign
32. The ______ option stores the new zone in the ForestDnsZones partition. Every DC in the entire forest and on which the DNS Server role is installed will receive a copy of the zone.
AD Zone Replication Scope page
To All Domain Controllers In This Domain
delegate
To All DNS Servers In This Forest
33. By default - zone transfers are ______ from any zone.
AD Zone Replication Scope page
DNS server
Aging
disabled
34. Used to facilitate the resolution of single-label computer names in a large network.
partition
DNS zone
Enterprise Admins
GlobalNames zone
35. The value you configure in the ______ text box determines how long a secondary server waits before retrying a failed zone transfer. Normally - this time is less than the refresh interval. The default value is 10 minutes.
1. DomainDnsZones and - 2. ForestDnsZones
trust anchor
masters
Retry Interval
36. A ______ zone is similar to a secondary zone - but it contains only those resource records necessary to identify the authoritative DNS servers for the master zone.
Trust anchors
stub
notification
Scavenging
37. This operation performs a zone transfer from the secondary zone's master server regardless of the serial number in the secondary zone's SOA resource record.
notification
use more than one name to point to
Transfer New Copy Of Zone From Master
deploying a GlobalNames zone
38. The Zone Transfers tab also allows you to configure ______ to secondary servers whenever a change occurs at the primary zone.
Group Policy
notification
request DNSSEC validation for specific queries
enable zone transfers
39. By right-clicking a secondary zone in the DNS Manager console tree - you can use the shortcut menu to perform the following secondary zone update operations:
Reload - Transfer From Master - Transfer New Copy Of Zone From Master
partition
NS record and an associated A record
Scavenging
40. ______ zones provide a means to offload DNS query traffic in areas of the network where a zone is heavily queried and used.
NRPT
delegate
Secondary
standard
41. Any of three events can ________________: When the refresh interval of the primary zone's SOA resource record expires - When a server hosting a secondary zone boots up - When a change occurs in the configuration of the primary zone and this primary
deploying a GlobalNames zone
Scavenge Stale Resource Records
trigger zone transfers on secondary zones
CNAME resource records
42. The ___________________ dialog box enables you to modify two key settings related to aging and scavenging: 1. the no-refresh interval 2. and the refresh interval
deploying a GlobalNames zone
The Zone Aging/Scavenging Properties
server level and at the zone level
Notify
43. The value you configure in the ______ text box determines the length of time that a secondary server - without any contact with its master server - continues to answer queries from DNS clients. After this time elapses - the data is considered unrelia
parent zone to a child zone
Expires After
NRPT
Win Srvr 2008 and Win Srvr 2008 R2
44. DNSSEC enables a DNS server to ______ the resource records in its zones.
Trust anchors
digitally sign
the cache life of a resource record
asymmetric encryption
45. The _____ option stores the zone in the domain partition. Every DC in the local domain will receive a copy of the zone - regardless of whether the DNS Server role is installed on that DC.
Netlogon
To All Domain Controllers In This Domain
use more than one name to point to
trigger zone transfers on secondary zones
46. Increasing the refresh interval ______ zone transfer traffic.
Secondary
decreases
14
asymmetric encryption
47. In this way - digital signatures use ______ cryptography to prove that information is unspoofed and unchanged.
NS record and an associated A record
public key
enable zone transfers
Service location (SRV)
48. Together - aging and scavenging provide a mechanism to ______ resource records - which can accumulate in zone data over time. Both aging and scavenging are disabled by default.
aging
Remove stale
1. Start of Authority (SOA) record that defines basic properties for the zone. 2. NS record signifying the name of the server or servers authoritative for the zone.
notification
49. To enable aging for a particular zone - you have to enable this feature both at the ______ level.
To All Domain Controllers In This Domain
Enterprise Admins
server level and at the zone level
enable zone transfers
50. To enable GlobalNames zone support - At an elevated command prompt - type the following: ______.
notification
NS record and an associated A record
dnscmd . /config /enableglobalnamessupport 1
DNS zone
//
//