SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
MCTS: Monitoring Computers
Start Test
Study First
Subjects
:
certifications
,
mcts
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Event forwarding uses HTTP or HTTPS to send events from a forwarding computer to a collecting computer. Instead of using the standard TCP ports 80 and 443 - HTTP and HTTPS use ports ______ - respectively.
5985 and 5986
gr
Network Monitor
Collector initiated - Source computer initiated
2. With event forwarding - only these Windows versions can act as forwarding computers:
Win XP SP2 - Win Srvr 2003 SP1 or 2 - Win Srvr 2003 R2 - Vista - Win 7 - Win Srvr 2008 - and Win Srvr 2008 R2
Forwarded Events
Start A Program - Send An E-mail - Display A Message
NMCap /InputCapture "Capture1.cap" /capture "HTTP" /file "HttpOnlyCapture.cap"
3. Computers that have no errors and no new software installations are considered stable and can achieve the maximum system stability index of ______.
Application - Security - Setup - System - Forwarded Events
10
Performance Monitor
Forwarded Events
4. To run a file named Respond.exe whenever event 177 is published in the System event log - run the following command:
winrm quickconfig
When A Specific Event Is Logged
SCHTASKS /Create /TN EventLog /TR respond.exe /SC ONEVENT /EC System /MO *[System/EventID=177]
Win XP SP2 - Win Srvr 2003 SP1 or 2 - Win Srvr 2003 R2 - Vista - Win 7 - Win Srvr 2008 - and Win Srvr 2008 R2
5. The wecutil ______ parameter displays the status of subscriptions.
System
gr
winrm quickconfig
Start A Program - Send An E-mail - Display A Message
6. ______ gather system information - including configuration settings and performance data - and store it in a data file.
Collector initiated - Source computer initiated
Data Collector Sets
Collector initiated
gr
7. One of the most useful ways to use Task Scheduler is to launch a task in response to a specific event type that appears in Event Viewer. You can respond to events in three ways:
10
Start A Program - Send An E-mail - Display A Message
Find an example of the event in Event Viewer. - In Task Scheduler - click Create Basic Task in the actions pane. - Use the Schtasks command-line tool from a command prompt or a script.
Windows Logs and Applications And Services Logs.
8. ______ tracks a computer's stability.
gr
Data Collector Sets
Start A Program - Send An E-mail - Display A Message
Reliability Monitor
9. Custom views are filters that can display events from ______.
ds
multiple logs
winrm quickconfig
Forwarded Events
10. Check the Applications And Services LogsMicrosoftWindowsEventlog-ForwardingPluginOperational event log and verify that the subscription was created successfully. Event ID 100 indicates a new subscription whereas Event ID ______ indicates a subscripti
Latest Report
NMCap /network * /capture "DNS" /file filename.cap
multiple logs
103
11. Find an example of the event in Event Viewer. Then - right-click the event and click ______. A wizard will guide you through the process.
Windows Logs and Applications And Services Logs.
Attach Task To This Event
Performance Monitor
Win XP SP2 - Win Srvr 2003 SP1 or 2 - Win Srvr 2003 R2 - Vista - Win 7 - Win Srvr 2008 - and Win Srvr 2008 R2
12. To capture network traffic from a command prompt - switch to the Network Monitor installation folder (C:Program FilesMicrosoft Network Monitor 3 by default) and run the following command:
network adapter
NMCap /network * /capture /file filename.cap
103
SCHTASKS /Create /TN EventLog /TR respond.exe /SC ONEVENT /EC System /MO *[System/EventID=177]
13. This Windows log contains auditing events that Windows adds when a user accesses or attempts to access a resource that has been configured for auditing.
Security
Reliability Monitor
Source computer initiated
Vista - Win 7 - Win Server 2003 R2 - Win Server 2008 - and Win Server 2008 R2
14. This Windows log contains events generated while installing and updating Windows.
Setup
Vista - Win 7 - Win Server 2003 R2 - Win Server 2008 - and Win Server 2008 R2
winrm quickconfig
Right-click Data Collector SetsUser Defined - choose New - and then choose Data Collector Set. The Create New Data Collector Set Wizard appears.
15. Windows Server 2008 R2 includes several built-in Data Collector Sets located at Data Collector SetsSystem:
Active Directory Diagnostics - System Performance - System Diagnostics - Wireless Diagnostics
Start A Program - Send An E-mail - Display A Message
http://computername:5985 (or https://computername:5986 if you are using HTTPS)
5985 and 5986
16. The wecutil ______ parameter defines subscription configuration. To specify a custom interval for a subscription - run the following commands: ______.
ss - wecutil ss <subscription_name> /cm:custom wecutil ss <subscription_name> /hi:<milliseconds_delay>
Security
gr
Win XP SP2 - Win Srvr 2003 SP1 or 2 - Win Srvr 2003 R2 - Vista - Win 7 - Win Srvr 2008 - and Win Srvr 2008 R2
17. To use a Data Collector Set - right-click it - and then choose ______.
Data Collector Sets
winrm enumerate winrm/config/Listener
Vista - Win 7 - Win Server 2003 R2 - Win Server 2008 - and Win Server 2008 R2
Start
18. After using a Data Collector Set to gather information and then stopping the Data Collector Set - you can view a summary by right-clicking the Data Collector Set and then choosing ______.
NMCap /InputCapture "Capture1.cap" /capture "HTTP" /file "HttpOnlyCapture.cap"
Latest Report
SCHTASKS /Create /TN EventLog /TR respond.exe /SC ONEVENT /EC System /MO *[System/EventID=177]
qc
19. Using event forwarding requires you to configure both the forwarding and collecting computers. First - you must start the following services on both the forwarding and collecting computer:
Collector initiated - Source computer initiated
ds
Windows Remote Management - Windows Event Collector
Ctrl+C
20. Present only on DCs - the ______ Data Collector Set logs kernel trace data - AD trace data - performance counters - and AD registry configuration.
logman start "<Data Collector Set>"
http://computername:5985 (or https://computername:5986 if you are using HTTPS)
Start A Program - Send An E-mail - Display A Message
Active Directory Diagnostics
21. Although you can create data collector sets using the Logman tool - creating them using the Data Collector Sets console is easier. You can then run the data collector set by using the following command:
Security
logman start "<Data Collector Set>"
Vista - Win 7 - Win Server 2003 R2 - Win Server 2008 - and Win Server 2008 R2
System
22. With event forwarding - only these Windows versions can act as collecting computers:
Wireless Diagnostics
Vista - Win 7 - Win Server 2003 R2 - Win Server 2008 - and Win Server 2008 R2
5985 and 5986
Active Directory Diagnostics
23. This Windows log contains events generated by applications.
winrm get winrm/config
Application
Reliability Monitor
qc
24. With ______ subscriptions - the collecting computer contacts the source computers to retrieve events.
wecutil qc
Wireless Diagnostics
Collector initiated
Application
25. To create a custom Data Collector Set - follow these steps:
Right-click Data Collector SetsUser Defined - choose New - and then choose Data Collector Set. The Create New Data Collector Set Wizard appears.
event forwarding
ss - wecutil ss <subscription_name> /cm:custom wecutil ss <subscription_name> /hi:<milliseconds_delay>
Win XP SP2 - Win Srvr 2003 SP1 or 2 - Win Srvr 2003 R2 - Vista - Win 7 - Win Srvr 2008 - and Win Srvr 2008 R2
26. Because the forwarding computer must have HTTP and possibly HTTPS available - you can attempt to connect to it from the collecting computer by using Windows Internet Explorer
SCHTASKS /Create /TN EventLog /TR respond.exe /SC ONEVENT /EC System /MO *[System/EventID=177]
Data Collector Sets
ss - wecutil ss <subscription_name> /cm:custom wecutil ss <subscription_name> /hi:<milliseconds_delay>
http://computername:5985 (or https://computername:5986 if you are using HTTPS)
27. Logs all the info included in the System Performance Data Collector Set - plus detailed system information. Use the ______ Data Collector Set when troubleshooting reliability problems such as problematic hardware - driver failures - or Stop errors (a
Performance Monitor
SCHTASKS /Create /TN EventLog /TR respond.exe /SC ONEVENT /EC System /MO *[System/EventID=177]
Reliability Monitor
System Diagnostics
28. The Minimize Bandwidth and Minimize Latency options of Event Subscriptions - both batch a default number of items at a time. You can determine the value of this default by typing the following command at a command prompt:
Data Collector Sets
Right-click Data Collector SetsUser Defined - choose New - and then choose Data Collector Set. The Create New Data Collector Set Wizard appears.
SCHTASKS /Create /TN EventLog /TR respond.exe /SC ONEVENT /EC System /MO *[System/EventID=177]
winrm get winrm/config
29. You can also use the /inputcapture parameter of NMCap to process an existing capture file.E.g. To read a file named Capture1.cap and write a new capture file containing only HTTP packets - use this command:
gr
NMCap /InputCapture "Capture1.cap" /capture "HTTP" /file "HttpOnlyCapture.cap"
Application - Security - Setup - System - Forwarded Events
winrm quickconfig -transport:https
30. This captures all traffic on all network interfaces and saves it to a file named Filename.cap. When you are finished capturing - press ______.
Collector initiated - Source computer initiated
Security
Ctrl+C
Active Directory Diagnostics
31. To open Reliability Monitor - right-click the ______ node in Server Manager and then click View System Reliability.
winrm quickconfig -transport:https
DiagnosticsPerformanceMonitoring Tools
103
Wireless Diagnostics
32. To configure a computer running Vista - Win 7 - Win Srvr 2008 - or Win Srvr 2008 R2 to collect events - open a command prompt with administrative privileges. Then - run the following command to configure the Windows Event Collector service:
ds
wecutil qc
event forwarding
Network Monitor
33. The log files are contained in two subnodes:
Windows Logs and Applications And Services Logs.
network adapter
Vista - Win 7 - Win Server 2003 R2 - Win Server 2008 - and Win Server 2008 R2
Security
34. In Task Scheduler - click Create Basic Task in the actions pane. On the Trigger page of the wizard - select ______. Then - specify the Log - Source - and Event ID.
DiagnosticsPerformanceMonitoring Tools
When A Specific Event Is Logged
winrm quickconfig
Source computer initiated
35. With ______ - you can send events that match specific criteria to an administrative computer - allowing you to centralize event management.
Attach Task To This Event
event forwarding
logman start "<Data Collector Set>"
Active Directory Diagnostics - System Performance - System Diagnostics - Wireless Diagnostics
36. Windows Logs contains five subnodes:
SCHTASKS /Create /TN EventLog /TR respond.exe /SC ONEVENT /EC System /MO *[System/EventID=177]
qc
Network Monitor
Application - Security - Setup - System - Forwarded Events
37. Network Monitor can capture only traffic that the ______ receives.
Active Directory Diagnostics - System Performance - System Diagnostics - Wireless Diagnostics
ds
network adapter
winrm enumerate winrm/config/Listener
38. This Windows log contains events forwarded to this computer from other computers.
Forwarded Events
http://computername:5985 (or https://computername:5986 if you are using HTTPS)
Hypertext Transfer Protocol (HTTP) or HTTPS (Hypertext Transfer Protocol Secure)
103
39. In Win Srvr 2008 and Win Srvr 2008 R2 - you can also simply select the ______ node in the console tree of Event Viewer to confiture the collecting computer.
event forwarding
Subscriptions
NMCap /InputCapture "Capture1.cap" /capture "HTTP" /file "HttpOnlyCapture.cap"
Start A Program - Send An E-mail - Display A Message
40. The wecutil ______ parameter performs the initial configuration required to collect events. If a subscription already exists - the necessary configuration must have already been performed.
Vista - Win 7 - Win Server 2003 R2 - Win Server 2008 - and Win Server 2008 R2
winrm quickconfig
qc
Latest Report
41. At a command prompt with administrative privileges - run the following command to configure the Windows Remote Management service on the forwarding computer:
winrm get winrm/config
winrm quickconfig
Active Directory Diagnostics - System Performance - System Diagnostics - Wireless Diagnostics
NMCap /network * /capture /file filename.cap
42. To configure Event Forwarding to use HTTPS - create a Windows Firewall exception for TCP port 5986 and run the following command:
Find an example of the event in Event Viewer. - In Task Scheduler - click Create Basic Task in the actions pane. - Use the Schtasks command-line tool from a command prompt or a script.
winrm quickconfig -transport:https
qc
Source computer initiated
43. You can open Event Viewer from within ______ by selecting the DiagnosticsEvent Viewer node.
Forwarded Events
Server Manager
NMCap /InputCapture "Capture1.cap" /capture "HTTP" /file "HttpOnlyCapture.cap"
winrm get winrm/config
44. This Windows log contains core system events. Other system events are contained with Applications And Services Logs.
Application - Security - Setup - System - Forwarded Events
http://computername:5985 (or https://computername:5986 if you are using HTTPS)
Start
System
45. The Reliability Monitor displays data gathered by the Reliability Analysis Component (RAC) - which is implemented using ______ command.
wecutil qc
Security
RACAgent.exe
SCHTASKS /Create /TN EventLog /TR respond.exe /SC ONEVENT /EC System /MO *[System/EventID=177]
46. What command should you run to configure a forwarding computer?
Setup
winrm quickconfig
Hypertext Transfer Protocol (HTTP) or HTTPS (Hypertext Transfer Protocol Secure)
Latest Report
47. Present only on computers with wireless capabilities - the ______ Data Collector Set logs the same info as the LAN Diagnostics Data Collector Set - plus info relevant to troubleshooting wireless network connections.
Wireless Diagnostics
System Performance
When A Specific Event Is Logged
NMCap /network * /capture "DNS" /file filename.cap
48. You can create two types of subscriptions:
NMCap /network * /capture "DNS" /file filename.cap
System
Collector initiated - Source computer initiated
Windows Logs and Applications And Services Logs.
49. What command should you run to configure a collecting computer?
wecutil qc
Windows Logs and Applications And Services Logs.
Custom Views
Reliability Monitor
50. To verify that the forwarding computer has the Windows Remote Management listener properly configured - from an elevated command prompt - run the following command:
winrm enumerate winrm/config/Listener
Win XP SP2 - Win Srvr 2003 SP1 or 2 - Win Srvr 2003 R2 - Vista - Win 7 - Win Srvr 2008 - and Win Srvr 2008 R2
Right-click Data Collector SetsUser Defined - choose New - and then choose Data Collector Set. The Create New Data Collector Set Wizard appears.
Collector initiated - Source computer initiated