SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
MCTS: Monitoring Computers
Start Test
Study First
Subjects
:
certifications
,
mcts
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. You can create two types of subscriptions:
System Performance
Collector initiated - Source computer initiated
When A Specific Event Is Logged
SCHTASKS /Create /TN EventLog /TR respond.exe /SC ONEVENT /EC System /MO *[System/EventID=177]
2. This Windows log contains auditing events that Windows adds when a user accesses or attempts to access a resource that has been configured for auditing.
Custom Views
gr
network adapter
Security
3. ______ graphically shows real-time performance data - including processor utilization - network bandwidth usage - and thousands of other statistics.
System Performance
winrm quickconfig
event forwarding
Performance Monitor
4. The wecutil ______ parameter defines subscription configuration. To specify a custom interval for a subscription - run the following commands: ______.
Attach Task To This Event
ss - wecutil ss <subscription_name> /cm:custom wecutil ss <subscription_name> /hi:<milliseconds_delay>
Windows Logs and Applications And Services Logs.
System
5. To create a custom Data Collector Set - follow these steps:
winrm quickconfig
Setup
Vista - Win 7 - Win Server 2003 R2 - Win Server 2008 - and Win Server 2008 R2
Right-click Data Collector SetsUser Defined - choose New - and then choose Data Collector Set. The Create New Data Collector Set Wizard appears.
6. To use a filter capture - type the filter capture in quotation marks after the /capture parameter. For example - the following command captures only DNS traffic:
Source computer initiated
Vista - Win 7 - Win Server 2003 R2 - Win Server 2008 - and Win Server 2008 R2
Custom Views
NMCap /network * /capture "DNS" /file filename.cap
7. Windows Server 2008 R2 includes several built-in Data Collector Sets located at Data Collector SetsSystem:
Active Directory Diagnostics - System Performance - System Diagnostics - Wireless Diagnostics
NMCap /network * /capture /file filename.cap
Subscriptions
Server Manager
8. You can also use the /inputcapture parameter of NMCap to process an existing capture file.E.g. To read a file named Capture1.cap and write a new capture file containing only HTTP packets - use this command:
System Performance
Reliability Monitor
NMCap /InputCapture "Capture1.cap" /capture "HTTP" /file "HttpOnlyCapture.cap"
event forwarding
9. With event forwarding - only these Windows versions can act as forwarding computers:
Win XP SP2 - Win Srvr 2003 SP1 or 2 - Win Srvr 2003 R2 - Vista - Win 7 - Win Srvr 2008 - and Win Srvr 2008 R2
Windows Remote Management - Windows Event Collector
RACAgent.exe
Source computer initiated
10. The log files are contained in two subnodes:
5985 and 5986
Hypertext Transfer Protocol (HTTP) or HTTPS (Hypertext Transfer Protocol Secure)
When A Specific Event Is Logged
Windows Logs and Applications And Services Logs.
11. Event forwarding uses HTTP or HTTPS to send events from a forwarding computer to a collecting computer. Instead of using the standard TCP ports 80 and 443 - HTTP and HTTPS use ports ______ - respectively.
Setup
wecutil qc
5985 and 5986
Application - Security - Setup - System - Forwarded Events
12. Custom views are filters that can display events from ______.
winrm quickconfig
DiagnosticsPerformanceMonitoring Tools
multiple logs
RACAgent.exe
13. The Reliability Monitor displays data gathered by the Reliability Analysis Component (RAC) - which is implemented using ______ command.
Network Monitor
RACAgent.exe
Win XP SP2 - Win Srvr 2003 SP1 or 2 - Win Srvr 2003 R2 - Vista - Win 7 - Win Srvr 2008 - and Win Srvr 2008 R2
wecutil qc
14. Check the Applications And Services LogsMicrosoftWindowsEventlog-ForwardingPluginOperational event log and verify that the subscription was created successfully. Event ID 100 indicates a new subscription whereas Event ID ______ indicates a subscripti
wecutil qc
103
System Performance
gr
15. Network Monitor can capture only traffic that the ______ receives.
When A Specific Event Is Logged
network adapter
RACAgent.exe
Right-click Data Collector SetsUser Defined - choose New - and then choose Data Collector Set. The Create New Data Collector Set Wizard appears.
16. To capture network traffic from a command prompt - switch to the Network Monitor installation folder (C:Program FilesMicrosoft Network Monitor 3 by default) and run the following command:
Collector initiated - Source computer initiated
NMCap /network * /capture /file filename.cap
Server Manager
ds
17. Present only on DCs - the ______ Data Collector Set logs kernel trace data - AD trace data - performance counters - and AD registry configuration.
Active Directory Diagnostics
Attach Task To This Event
http://computername:5985 (or https://computername:5986 if you are using HTTPS)
winrm quickconfig -transport:https
18. Microsoft provides ______ - a powerful protocol analyzer - as a free download.
Windows Logs and Applications And Services Logs.
Right-click Data Collector SetsUser Defined - choose New - and then choose Data Collector Set. The Create New Data Collector Set Wizard appears.
Active Directory Diagnostics - System Performance - System Diagnostics - Wireless Diagnostics
Network Monitor
19. The wecutil ______ parameter displays the status of subscriptions.
event forwarding
103
gr
Latest Report
20. To use a Data Collector Set - right-click it - and then choose ______.
SCHTASKS /Create /TN EventLog /TR respond.exe /SC ONEVENT /EC System /MO *[System/EventID=177]
System
Reliability Monitor
Start
21. To open Reliability Monitor - right-click the ______ node in Server Manager and then click View System Reliability.
103
DiagnosticsPerformanceMonitoring Tools
ds
NMCap /network * /capture /file filename.cap
22. After using a Data Collector Set to gather information and then stopping the Data Collector Set - you can view a summary by right-clicking the Data Collector Set and then choosing ______.
Custom Views
ss - wecutil ss <subscription_name> /cm:custom wecutil ss <subscription_name> /hi:<milliseconds_delay>
Latest Report
Ctrl+C
23. What command should you run to configure a forwarding computer?
winrm quickconfig -transport:https
Windows Logs and Applications And Services Logs.
winrm quickconfig
Start
24. One of the most useful ways to use Task Scheduler is to launch a task in response to a specific event type that appears in Event Viewer. You can respond to events in three ways:
RACAgent.exe
Start A Program - Send An E-mail - Display A Message
Reliability Monitor
wecutil qc
25. In Task Scheduler - click Create Basic Task in the actions pane. On the Trigger page of the wizard - select ______. Then - specify the Log - Source - and Event ID.
Ctrl+C
winrm quickconfig
When A Specific Event Is Logged
event forwarding
26. This captures all traffic on all network interfaces and saves it to a file named Filename.cap. When you are finished capturing - press ______.
Attach Task To This Event
Vista - Win 7 - Win Server 2003 R2 - Win Server 2008 - and Win Server 2008 R2
Data Collector Sets
Ctrl+C
27. When you create a custom view - Event Viewer saves it within the ______ node so that you can quickly view the same set of events.
event forwarding
DiagnosticsPerformanceMonitoring Tools
Custom Views
Find an example of the event in Event Viewer. - In Task Scheduler - click Create Basic Task in the actions pane. - Use the Schtasks command-line tool from a command prompt or a script.
28. Windows Logs contains five subnodes:
Active Directory Diagnostics - System Performance - System Diagnostics - Wireless Diagnostics
event forwarding
Application - Security - Setup - System - Forwarded Events
NMCap /network * /capture "DNS" /file filename.cap
29. You can open Event Viewer from within ______ by selecting the DiagnosticsEvent Viewer node.
Data Collector Sets
System Diagnostics
Server Manager
NMCap /network * /capture "DNS" /file filename.cap
30. The wecutil ______ parameter performs the initial configuration required to collect events. If a subscription already exists - the necessary configuration must have already been performed.
qc
Subscriptions
Latest Report
wecutil qc
31. To configure Event Forwarding to use HTTPS - create a Windows Firewall exception for TCP port 5986 and run the following command:
Vista - Win 7 - Win Server 2003 R2 - Win Server 2008 - and Win Server 2008 R2
winrm quickconfig -transport:https
Attach Task To This Event
Windows Logs and Applications And Services Logs.
32. To configure a computer running Vista - Win 7 - Win Srvr 2008 - or Win Srvr 2008 R2 to collect events - open a command prompt with administrative privileges. Then - run the following command to configure the Windows Event Collector service:
Find an example of the event in Event Viewer. - In Task Scheduler - click Create Basic Task in the actions pane. - Use the Schtasks command-line tool from a command prompt or a script.
Start A Program - Send An E-mail - Display A Message
winrm get winrm/config
wecutil qc
33. Although you can create data collector sets using the Logman tool - creating them using the Data Collector Sets console is easier. You can then run the data collector set by using the following command:
Ctrl+C
winrm quickconfig
logman start "<Data Collector Set>"
System Performance
34. To trigger a task when an event occurs - follow one of these three procedures:
Attach Task To This Event
wecutil qc
Application
Find an example of the event in Event Viewer. - In Task Scheduler - click Create Basic Task in the actions pane. - Use the Schtasks command-line tool from a command prompt or a script.
35. Event forwarding uses ______ or ______ to send events from a forwarding computer to a collecting computer.
Hypertext Transfer Protocol (HTTP) or HTTPS (Hypertext Transfer Protocol Secure)
Network Monitor
ss - wecutil ss <subscription_name> /cm:custom wecutil ss <subscription_name> /hi:<milliseconds_delay>
network adapter
36. What command should you run to configure a collecting computer?
Setup
ds
Right-click Data Collector SetsUser Defined - choose New - and then choose Data Collector Set. The Create New Data Collector Set Wizard appears.
wecutil qc
37. The Minimize Bandwidth and Minimize Latency options of Event Subscriptions - both batch a default number of items at a time. You can determine the value of this default by typing the following command at a command prompt:
Wireless Diagnostics
winrm get winrm/config
5985 and 5986
System
38. ______ gather system information - including configuration settings and performance data - and store it in a data file.
Data Collector Sets
winrm quickconfig -transport:https
Attach Task To This Event
network adapter
39. Because the forwarding computer must have HTTP and possibly HTTPS available - you can attempt to connect to it from the collecting computer by using Windows Internet Explorer
SCHTASKS /Create /TN EventLog /TR respond.exe /SC ONEVENT /EC System /MO *[System/EventID=177]
http://computername:5985 (or https://computername:5986 if you are using HTTPS)
network adapter
System Performance
40. To verify that the forwarding computer has the Windows Remote Management listener properly configured - from an elevated command prompt - run the following command:
gr
Performance Monitor
Windows Remote Management - Windows Event Collector
winrm enumerate winrm/config/Listener
41. This Windows log contains events forwarded to this computer from other computers.
103
Forwarded Events
logman start "<Data Collector Set>"
http://computername:5985 (or https://computername:5986 if you are using HTTPS)
42. This Windows log contains events generated by applications.
Application
NMCap /network * /capture "DNS" /file filename.cap
winrm get winrm/config
ss - wecutil ss <subscription_name> /cm:custom wecutil ss <subscription_name> /hi:<milliseconds_delay>
43. This Windows log contains events generated while installing and updating Windows.
Right-click Data Collector SetsUser Defined - choose New - and then choose Data Collector Set. The Create New Data Collector Set Wizard appears.
winrm quickconfig
Setup
RACAgent.exe
44. At a command prompt with administrative privileges - run the following command to configure the Windows Remote Management service on the forwarding computer:
Active Directory Diagnostics - System Performance - System Diagnostics - Wireless Diagnostics
event forwarding
Collector initiated
winrm quickconfig
45. Using event forwarding requires you to configure both the forwarding and collecting computers. First - you must start the following services on both the forwarding and collecting computer:
http://computername:5985 (or https://computername:5986 if you are using HTTPS)
Network Monitor
103
Windows Remote Management - Windows Event Collector
46. This Windows log contains core system events. Other system events are contained with Applications And Services Logs.
Subscriptions
Collector initiated - Source computer initiated
System
Attach Task To This Event
47. Present only on computers with wireless capabilities - the ______ Data Collector Set logs the same info as the LAN Diagnostics Data Collector Set - plus info relevant to troubleshooting wireless network connections.
Vista - Win 7 - Win Server 2003 R2 - Win Server 2008 - and Win Server 2008 R2
ss - wecutil ss <subscription_name> /cm:custom wecutil ss <subscription_name> /hi:<milliseconds_delay>
Active Directory Diagnostics - System Performance - System Diagnostics - Wireless Diagnostics
Wireless Diagnostics
48. Computers that have no errors and no new software installations are considered stable and can achieve the maximum system stability index of ______.
multiple logs
Vista - Win 7 - Win Server 2003 R2 - Win Server 2008 - and Win Server 2008 R2
NMCap /InputCapture "Capture1.cap" /capture "HTTP" /file "HttpOnlyCapture.cap"
10
49. With ______ - you can send events that match specific criteria to an administrative computer - allowing you to centralize event management.
event forwarding
winrm quickconfig
Start
Network Monitor
50. In Win Srvr 2008 and Win Srvr 2008 R2 - you can also simply select the ______ node in the console tree of Event Viewer to confiture the collecting computer.
Application
Subscriptions
Vista - Win 7 - Win Server 2003 R2 - Win Server 2008 - and Win Server 2008 R2
Win XP SP2 - Win Srvr 2003 SP1 or 2 - Win Srvr 2003 R2 - Vista - Win 7 - Win Srvr 2008 - and Win Srvr 2008 R2