SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
MCTS: Monitoring Computers
Start Test
Study First
Subjects
:
certifications
,
mcts
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. To capture network traffic from a command prompt - switch to the Network Monitor installation folder (C:Program FilesMicrosoft Network Monitor 3 by default) and run the following command:
NMCap /network * /capture /file filename.cap
RACAgent.exe
Server Manager
Collector initiated
2. With ______ subscriptions - the collecting computer contacts the source computers to retrieve events.
Hypertext Transfer Protocol (HTTP) or HTTPS (Hypertext Transfer Protocol Secure)
Collector initiated - Source computer initiated
Collector initiated
winrm enumerate winrm/config/Listener
3. This Windows log contains events forwarded to this computer from other computers.
Active Directory Diagnostics
Windows Logs and Applications And Services Logs.
Forwarded Events
103
4. This Windows log contains events generated by applications.
network adapter
Start
winrm get winrm/config
Application
5. The wecutil ______ parameter displays the status of subscriptions.
Active Directory Diagnostics - System Performance - System Diagnostics - Wireless Diagnostics
Data Collector Sets
qc
gr
6. Microsoft provides ______ - a powerful protocol analyzer - as a free download.
RACAgent.exe
When A Specific Event Is Logged
Security
Network Monitor
7. Present only on DCs - the ______ Data Collector Set logs kernel trace data - AD trace data - performance counters - and AD registry configuration.
Find an example of the event in Event Viewer. - In Task Scheduler - click Create Basic Task in the actions pane. - Use the Schtasks command-line tool from a command prompt or a script.
wecutil qc
Active Directory Diagnostics
10
8. What command should you run to configure a collecting computer?
wecutil qc
logman start "<Data Collector Set>"
10
winrm quickconfig
9. The Reliability Monitor displays data gathered by the Reliability Analysis Component (RAC) - which is implemented using ______ command.
wecutil qc
logman start "<Data Collector Set>"
RACAgent.exe
System Diagnostics
10. Event forwarding uses HTTP or HTTPS to send events from a forwarding computer to a collecting computer. Instead of using the standard TCP ports 80 and 443 - HTTP and HTTPS use ports ______ - respectively.
NMCap /network * /capture /file filename.cap
winrm enumerate winrm/config/Listener
System Performance
5985 and 5986
11. The wecutil ______ parameter performs the initial configuration required to collect events. If a subscription already exists - the necessary configuration must have already been performed.
Wireless Diagnostics
qc
Subscriptions
winrm quickconfig
12. You can create two types of subscriptions:
Collector initiated - Source computer initiated
multiple logs
Custom Views
Reliability Monitor
13. Windows Logs contains five subnodes:
winrm quickconfig
Server Manager
Attach Task To This Event
Application - Security - Setup - System - Forwarded Events
14. In Task Scheduler - click Create Basic Task in the actions pane. On the Trigger page of the wizard - select ______. Then - specify the Log - Source - and Event ID.
When A Specific Event Is Logged
Data Collector Sets
Win XP SP2 - Win Srvr 2003 SP1 or 2 - Win Srvr 2003 R2 - Vista - Win 7 - Win Srvr 2008 - and Win Srvr 2008 R2
wecutil qc
15. With ______ subscriptions - the forwarding computers contact the collecting computer.
Source computer initiated
Reliability Monitor
Server Manager
qc
16. To configure a computer running Vista - Win 7 - Win Srvr 2008 - or Win Srvr 2008 R2 to collect events - open a command prompt with administrative privileges. Then - run the following command to configure the Windows Event Collector service:
RACAgent.exe
5985 and 5986
Collector initiated
wecutil qc
17. This Windows log contains auditing events that Windows adds when a user accesses or attempts to access a resource that has been configured for auditing.
ss - wecutil ss <subscription_name> /cm:custom wecutil ss <subscription_name> /hi:<milliseconds_delay>
When A Specific Event Is Logged
Hypertext Transfer Protocol (HTTP) or HTTPS (Hypertext Transfer Protocol Secure)
Security
18. After using a Data Collector Set to gather information and then stopping the Data Collector Set - you can view a summary by right-clicking the Data Collector Set and then choosing ______.
Latest Report
Server Manager
Security
multiple logs
19. At a command prompt with administrative privileges - run the following command to configure the Windows Remote Management service on the forwarding computer:
Subscriptions
5985 and 5986
Hypertext Transfer Protocol (HTTP) or HTTPS (Hypertext Transfer Protocol Secure)
winrm quickconfig
20. What command should you run to configure a forwarding computer?
Application
Collector initiated - Source computer initiated
winrm quickconfig
DiagnosticsPerformanceMonitoring Tools
21. The log files are contained in two subnodes:
5985 and 5986
Windows Logs and Applications And Services Logs.
event forwarding
Active Directory Diagnostics - System Performance - System Diagnostics - Wireless Diagnostics
22. Present only on computers with wireless capabilities - the ______ Data Collector Set logs the same info as the LAN Diagnostics Data Collector Set - plus info relevant to troubleshooting wireless network connections.
gr
event forwarding
Wireless Diagnostics
Application - Security - Setup - System - Forwarded Events
23. This captures all traffic on all network interfaces and saves it to a file named Filename.cap. When you are finished capturing - press ______.
gr
103
Active Directory Diagnostics - System Performance - System Diagnostics - Wireless Diagnostics
Ctrl+C
24. The Minimize Bandwidth and Minimize Latency options of Event Subscriptions - both batch a default number of items at a time. You can determine the value of this default by typing the following command at a command prompt:
winrm get winrm/config
System Diagnostics
Application
Start
25. One of the most useful ways to use Task Scheduler is to launch a task in response to a specific event type that appears in Event Viewer. You can respond to events in three ways:
Reliability Monitor
Start A Program - Send An E-mail - Display A Message
NMCap /network * /capture /file filename.cap
network adapter
26. ______ graphically shows real-time performance data - including processor utilization - network bandwidth usage - and thousands of other statistics.
System
Collector initiated - Source computer initiated
Latest Report
Performance Monitor
27. Logs all the info included in the System Performance Data Collector Set - plus detailed system information. Use the ______ Data Collector Set when troubleshooting reliability problems such as problematic hardware - driver failures - or Stop errors (a
Forwarded Events
System Diagnostics
winrm quickconfig
network adapter
28. To use a filter capture - type the filter capture in quotation marks after the /capture parameter. For example - the following command captures only DNS traffic:
NMCap /network * /capture "DNS" /file filename.cap
Ctrl+C
winrm get winrm/config
Source computer initiated
29. Custom views are filters that can display events from ______.
multiple logs
wecutil qc
103
Latest Report
30. Find an example of the event in Event Viewer. Then - right-click the event and click ______. A wizard will guide you through the process.
Application
When A Specific Event Is Logged
SCHTASKS /Create /TN EventLog /TR respond.exe /SC ONEVENT /EC System /MO *[System/EventID=177]
Attach Task To This Event
31. Windows Server 2008 R2 includes several built-in Data Collector Sets located at Data Collector SetsSystem:
Win XP SP2 - Win Srvr 2003 SP1 or 2 - Win Srvr 2003 R2 - Vista - Win 7 - Win Srvr 2008 - and Win Srvr 2008 R2
ss - wecutil ss <subscription_name> /cm:custom wecutil ss <subscription_name> /hi:<milliseconds_delay>
Wireless Diagnostics
Active Directory Diagnostics - System Performance - System Diagnostics - Wireless Diagnostics
32. This Windows log contains core system events. Other system events are contained with Applications And Services Logs.
RACAgent.exe
NMCap /network * /capture "DNS" /file filename.cap
System
Collector initiated - Source computer initiated
33. With event forwarding - only these Windows versions can act as collecting computers:
Vista - Win 7 - Win Server 2003 R2 - Win Server 2008 - and Win Server 2008 R2
Ctrl+C
event forwarding
Start A Program - Send An E-mail - Display A Message
34. ______ gather system information - including configuration settings and performance data - and store it in a data file.
Windows Logs and Applications And Services Logs.
Data Collector Sets
Wireless Diagnostics
5985 and 5986
35. Because the forwarding computer must have HTTP and possibly HTTPS available - you can attempt to connect to it from the collecting computer by using Windows Internet Explorer
winrm quickconfig
http://computername:5985 (or https://computername:5986 if you are using HTTPS)
multiple logs
Latest Report
36. When you create a custom view - Event Viewer saves it within the ______ node so that you can quickly view the same set of events.
winrm get winrm/config
Windows Remote Management - Windows Event Collector
Data Collector Sets
Custom Views
37. With event forwarding - only these Windows versions can act as forwarding computers:
Reliability Monitor
Win XP SP2 - Win Srvr 2003 SP1 or 2 - Win Srvr 2003 R2 - Vista - Win 7 - Win Srvr 2008 - and Win Srvr 2008 R2
Find an example of the event in Event Viewer. - In Task Scheduler - click Create Basic Task in the actions pane. - Use the Schtasks command-line tool from a command prompt or a script.
wecutil qc
38. With ______ - you can send events that match specific criteria to an administrative computer - allowing you to centralize event management.
Collector initiated - Source computer initiated
Right-click Data Collector SetsUser Defined - choose New - and then choose Data Collector Set. The Create New Data Collector Set Wizard appears.
event forwarding
5985 and 5986
39. You can open Event Viewer from within ______ by selecting the DiagnosticsEvent Viewer node.
Server Manager
Find an example of the event in Event Viewer. - In Task Scheduler - click Create Basic Task in the actions pane. - Use the Schtasks command-line tool from a command prompt or a script.
Start
Setup
40. The wecutil ______ parameter deletes a subscription.
ds
Server Manager
RACAgent.exe
Security
41. In Win Srvr 2008 and Win Srvr 2008 R2 - you can also simply select the ______ node in the console tree of Event Viewer to confiture the collecting computer.
ds
When A Specific Event Is Logged
winrm quickconfig -transport:https
Subscriptions
42. To open Reliability Monitor - right-click the ______ node in Server Manager and then click View System Reliability.
http://computername:5985 (or https://computername:5986 if you are using HTTPS)
winrm quickconfig
When A Specific Event Is Logged
DiagnosticsPerformanceMonitoring Tools
43. To configure Event Forwarding to use HTTPS - create a Windows Firewall exception for TCP port 5986 and run the following command:
ss - wecutil ss <subscription_name> /cm:custom wecutil ss <subscription_name> /hi:<milliseconds_delay>
DiagnosticsPerformanceMonitoring Tools
winrm quickconfig -transport:https
Start
44. Logs processor - disk - memory - and network performance counters and kernel tracing. Use the ______ Data Collector Set when troubleshooting a slow computer or intermittent performance problems.
Latest Report
multiple logs
System Performance
103
45. Event forwarding uses ______ or ______ to send events from a forwarding computer to a collecting computer.
Subscriptions
Source computer initiated
Start A Program - Send An E-mail - Display A Message
Hypertext Transfer Protocol (HTTP) or HTTPS (Hypertext Transfer Protocol Secure)
46. Using event forwarding requires you to configure both the forwarding and collecting computers. First - you must start the following services on both the forwarding and collecting computer:
Windows Remote Management - Windows Event Collector
network adapter
103
winrm quickconfig
47. To create a custom Data Collector Set - follow these steps:
Start A Program - Send An E-mail - Display A Message
Right-click Data Collector SetsUser Defined - choose New - and then choose Data Collector Set. The Create New Data Collector Set Wizard appears.
NMCap /network * /capture "DNS" /file filename.cap
Custom Views
48. To trigger a task when an event occurs - follow one of these three procedures:
Hypertext Transfer Protocol (HTTP) or HTTPS (Hypertext Transfer Protocol Secure)
Forwarded Events
Setup
Find an example of the event in Event Viewer. - In Task Scheduler - click Create Basic Task in the actions pane. - Use the Schtasks command-line tool from a command prompt or a script.
49. You can also use the /inputcapture parameter of NMCap to process an existing capture file.E.g. To read a file named Capture1.cap and write a new capture file containing only HTTP packets - use this command:
Collector initiated - Source computer initiated
Data Collector Sets
qc
NMCap /InputCapture "Capture1.cap" /capture "HTTP" /file "HttpOnlyCapture.cap"
50. The wecutil ______ parameter defines subscription configuration. To specify a custom interval for a subscription - run the following commands: ______.
ss - wecutil ss <subscription_name> /cm:custom wecutil ss <subscription_name> /hi:<milliseconds_delay>
Right-click Data Collector SetsUser Defined - choose New - and then choose Data Collector Set. The Create New Data Collector Set Wizard appears.
Windows Remote Management - Windows Event Collector
Server Manager
Sorry!:) No result found.
Can you answer 50 questions in 15 minutes?
Let me suggest you:
Browse all subjects
Browse all tests
Most popular tests
Major Subjects
Tests & Exams
AP
CLEP
DSST
GRE
SAT
GMAT
Certifications
CISSP go to https://www.isc2.org/
PMP
ITIL
RHCE
MCTS
More...
IT Skills
Android Programming
Data Modeling
Objective C Programming
Basic Python Programming
Adobe Illustrator
More...
Business Skills
Advertising Techniques
Business Accounting Basics
Business Strategy
Human Resource Management
Marketing Basics
More...
Soft Skills
Body Language
People Skills
Public Speaking
Persuasion
Job Hunting And Resumes
More...
Vocabulary
GRE Vocab
SAT Vocab
TOEFL Essential Vocab
Basic English Words For All
Global Words You Should Know
Business English
More...
Languages
AP German Vocab
AP Latin Vocab
SAT Subject Test: French
Italian Survival
Norwegian Survival
More...
Engineering
Audio Engineering
Computer Science Engineering
Aerospace Engineering
Chemical Engineering
Structural Engineering
More...
Health Sciences
Basic Nursing Skills
Health Science Language Fundamentals
Veterinary Technology Medical Language
Cardiology
Clinical Surgery
More...
English
Grammar Fundamentals
Literary And Rhetorical Vocab
Elements Of Style Vocab
Introduction To English Major
Complete Advanced Sentences
Literature
Homonyms
More...
Math
Algebra Formulas
Basic Arithmetic: Measurements
Metric Conversions
Geometric Properties
Important Math Facts
Number Sense Vocab
Business Math
More...
Other Major Subjects
Science
Economics
History
Law
Performing-arts
Cooking
Logic & Reasoning
Trivia
Browse all subjects
Browse all tests
Most popular tests