SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
MSITP
Start Test
Study First
Subjects
:
certifications
,
msitp
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. If you need to implement a Cert Services solution that automates distribution of certificates - ensures security and gives external users acess to resources that use cert-based authentication
Microsoft System Center Data Protection Manager
Implement Windows System Resource Manager (WSRM)
Deploy an off-line standalone Root CA - deploy an on-line Enterprise Subordinate CA - and deploy an on-line standalone Subordinate CA.
Then use Key Management Service (KMS) - DHCP server - and Windows Deployment Services.
2. AD CS is configured on Server1 as a standalone CA. What two actions should you do to audit changes to the CA configuration settings and the CA security settings?
Modify the DNS zone replication properties of the root domain - and change it to the ForestDNSZones application directory partition
Share and Storage Management
Raise the DFL to Windows Server 2008 R2.
1) Enable the Audit object access setting in the Local Security Policy for Srv1. 2) Configure auditing in the Certification Authority snap-in.
3. If you need to be able to create shared folders on Server 2008 R2
Ensure your account - or the group is a member of the local Administrators group for that specific server.
The WSUS client to retrieve updates from Microsoft Update (Do not Store updates locally)
Incoming external trust
Run a full back up by using Windows Server Backup - and then run a full back up of the Hyper-V hosts by using Windows Server Backup.
4. to prevent VMs from receiving updats from a group policy
Store the WSUS updates on a Distributed File System (DFS) link that uses multiple replicating targets.
Configure RADIUS accounting by using SQL loggin on each server and use Srv1 as database for RADIUS aaccounting.
Apply a WMI Filter to the policy. Note: You can use a WMI filter to filter out VM from being affected by a GPO the same way you can a physcial machine.
Copy the ADMX files from your company's PDC emulator to the PolicyDefinitions folder on other company's PDC emulator.
5. To make a 64-bit application available to several 32-bit XP SP3 computers in the branch office you could use either a remote desktop session host or a remote desktop virtualization host. However - if the application requires you to be a local adminis
6. Your AD domain has an OU named Sales OU that contains the user accounts of the Sales department. A new password polity needs to be created for the Sales department that is different from the domain password policy. How is this accomplished?
IIS Manager user account
Implement Network Access Protection (NAP) that uses 802.1x enforcement
Add all the sales user accounts into a new global security group. Create a new Password Policy Object (PSO) and apply it to the group.
Enable - ADoptionalFeature cmdlet
7. To help restrict access to Windows 7 computer in the event that it gets stolen implement
Deploy a failover cluster that contains one node in each office.
Properties of PSO need modified
Windows BitLocker Drive Encryption (Bit Locker)
From Server A - run Create Basic Task Wizard
8. You just dconfigured so that Server1 zone is stored in AD and accept secure dynamic updates. What command should be executed so that Server2 can accept secure dynamic updates?
dnscmd dcsrv2.company.com /zoneresettype company.com /dsprimary
Disable Site Link Bridging from IP Properties
Implement Network Access Protection (NAP) that uses 802.1x enforcement
Install Windows Server 2008 R2 Datacenter Edition on each server. Deploy the servers in a failover cluster. Deploy an iSCSI storage area network (SAN) - You have a main office and branch office.
9. What shold be done to configure AD RMS so users can protect their data?
Authorization Manager
Run the Delegation of Control Wizard on Sales OU. In Group Policy Management Console - modify the permissions of the Group Policy Objects container in the hr.domain.com domain.
Implement folder redirection by using GPO. Then backup the folder redirection target.
Create an e-mail account in AD DS for your RMS users
10. To decrease the amount of time it takes for the certain users to generate reports. You should recommend
Event Subscriptions
Install Hyper-V role and convert physical machines into virtual machines
Run the Delegation of Control Wizard on Sales OU. In Group Policy Management Console - modify the permissions of the Group Policy Objects container in the hr.domain.com domain.
Windows System Resource Manager (WSRM)
11. A specific application requires registry modifications to be in place before installing; you should use
Get-ADUser cmdlet
Service user account for AD LDS
Group Policy Preferences
In each satellite office - install a WSUS server and configure the WSUS servers to use the main office WSUS server as an upstream server.
12. You need to recommend a Windows update strategy for the new branch office. The branch office has a 512 Kbps connection the corporate office and a 2 MB connection to the Internet. You should recommend this.
Dsmgmt
Deploying a WSUS server in replica mode at the Branch office. You can also configure the WSUS in replica mode/split - this will allos the WSUS server to download list of updates from the parent but download the actual updates directly from Windows up
File Server Resource Manager (FSRM) quotas and file screens
Then make sure all DCs are runing Windows Server 2008 R2 - and then use a GPO to enable Trusted Platform Module backups to AD.
13. DFL is Windows Server 2003 and client computers run Vista. DCRMS is a server that holds AD RMS. What should be done to configure AD RMS so users - including Waldo - can protect their data?
A relying party trust should be created.
Encrypting File System (EFS). This can be enabled locally or through a GPO.
Create an e-mail account in AD DS for your RMS users.
Deploy the Root CA certificate to the external computers.
14. When recommending a monitoring solution for an application so that it's events can be stored in a central
Event Subscriptions
Assign permissions for the Groups OU and Branch OU to the help desk technicians.
Windows System Resource Manager (WSRM)
Upgrade all the client computers to Windows 7 and implement a Secure Socket Tunneling Protocol (SSTP) VPN solution.
15. You need to devise a security solution so that after 15 days the documents distributed to the members of the School Board can only be opened by the creator owners in the high school year book department. You should recommend...
Active Directory Right Management Services (AD RMS)
Perform an authoritative restore
Configure each SharePoint site to use a separate application pool - and then implement Windows System Resource Manager (WSRM)
newly implemented technologies must have a minimal effect on LAN traffic - is met by using express installation files
16. If you need to minimize amount of time and impact of 50 simultaneous Win7 installations
Then deploy Windows Deployment Services (WDS) and Transport Server feature and configure transport server to use static multicast address range.
One virtual network...Install two network adapaters on each node. Configure the network adapters to communicate on separate subnets.
You could restore the backup to an alternate location. Then mount the database using the AD Database Mounting Tool (Dsamain.exe)
Use a GPO to configure device installation restrictions
17. You need to relocate an AD LDS instance from C: Drive to D: Drive
1) Run net stop ADLDS command 2) Use ntdsutil tool to move db files 3) Run net start ADLDS cmd
Publish the application as a Remote App. Enable Remote Desktop Web Access (RD Web Access).
net stop ntds
Zone transfer settings
18. You are about to deploy 1 -000 Windows 7 desktops and your company has a web based application that only runs correctly when using IE 6. You should use
Logged changes must include old and new values of any attributes. - Run auditpol and then configure Security settings of Domain Controllers OU
Discover the run Microsoft Baseline Security Analyzer (MBSA)
MEDV to deploy virtual desktops
Use the Local Roles options with dsmgmt.
19. When one needs to audit files - folders - printers and the registry enable
Add the Remote1-Admins group to the Administrators local group on each server in Remote1.
Object access auditing on the server that supports the resource. Note: Enabling audit access also helps when auditing your Cert Servers
Incoming external trust
1) Run net stop ADLDS command 2) Use ntdsutil tool to move db files 3) Run net start ADLDS cmd
20. You have 9 2008 R2 servers that host Web apps. You need a remote mgmt strategy to manage the Web servers according to these requirements: Web developers need to be able to configure features on the Web sites; Web developers should not have full admin
Improve the performance of File Servers
Active Directory Rights Management Services (AD RMS) and Microsoft SharePoint Foundation 2010
Configure authorization rules for Web developers on each web server
Domain based DFS namespace and configure a DFS replication group
21. To monitor replication of group policy template files when DFL set at Windows 2008 R2...
Authorization Manager
Store the WSUS updates on a Distributed File System (DFS) link that uses multiple replicating targets.
Deploy a failover cluster that contains one node in each office.
Dfsrdiag
22. To allow connection to a 256 Kbps ISDN...
Dfsrdiag
Recommend Group Policy preferences
Enable - ADoptionalFeature cmdlet
DISABLE slow link detection in the GPO
23. 2 ways to relocate user and computer accounts to different OUs
DSMOD - ADUC
Group Policy Preferences
Then Migrate DHCP server role from the domain controllers to the files servers. On file servers - add admin for office to DHCP admin local group.
Deploy a GPO for the Sales OU
24. Backup solutions for the files servers that support a robotic-based tape library must support the enterprise; you should recommend
Restore-ADObject cmdlet
Microsoft System Center Data Protection Manager
Certificate Templates
Store all sensitive files in EFS encrypted folders and require home users to access the files by using SSTP
25. If the branch office has its own high speed WAN link and you need to minimize traffice between the corporate office and the Branch office - configure this.
Administrators is the minimum group membership required to complete this procedure.
Use local roles options within "dsmgmt"
Modify properties of RODC server computer account.
The WSUS client to retrieve updates from Microsoft Update (Do not Store updates locally)
26. To ensure that admins in the corporate office can manage and control all Windows Updates and manage WSUS computer groups - deploy this.
WSUS server in the branch office in replica mode.
Install WSUS 3.0 on a 2008 R2 server and configure Windows Update by using a GPO
Deploy WSUS server on secure network. From an online WSUS server - copy the update metadata and the WSUS content to the WSUS server on the secure network.
Configure each SharePoint site to use a separate application pool - and then implement Windows System Resource Manager (WSRM)
27. To build a highly secure server cluster with a reduced attack surface area
Ldp
Deploy a GPO to the WebSrvOU
Upgrade all the client computers to Windows 7 and implement a Secure Socket Tunneling Protocol (SSTP) VPN solution.
Install a Server Core installation of Windows Server 2008 R2 Enterprise. Note: Remember clusters must be either 2008 Enterprise or Datacenter - you cannot build a Microsoft Cluster using Web or Standard Editions
28. You need to design patch management for satellite offices that meet the following requirements: WSUS updates are approved independently for each satellite office; Internet traffic is minimized. To accomplish
fsconfig on FSSrv2
Deploy a failover cluster that contains one node in each office.
Run adprep /forestprep and adprep /domainprep
In each satellite office - install a WSUS server and configure the WSUS servers to use the main office WSUS server as an upstream server.
29. What Function Level (FL) needs to be in place to enable AD Recycle Bin?
Administrators is the minimum group membership required to complete this procedure.
Modify zone transfer settings for company.com zone on DCA
FFL Windows Server 2008 R2
Modify Object Access Settings AND Global Object Access Auditing settings FROM Advanced Audit Policy configurations
30. to protect file servers and hard disks that may be at risk of being accessed or stolen
Then use on install image file that contains a single install image.
Implement Windows BitLocker Drive Encryption (BitLocker)
1) Remove the Auth Users account from the Secutiy tab of the company.com DNS zone properties. 2) Assign the server computer accounts to the Allow on Create All Child Objects permission on the Security tab of the company.com DNS zone properties.
Add the new UPN Suffix to the forest
31. You have 2 Server Core servers that are part of a Network Load Balance that host a web site. To be able to allow administrators - on their Windows 7 computers - remotely manage the NLB with automation
Use Windows Server Backup to back up each domain controller to a remote network share. Use Windows Deployment Services (WDS) to deploy the Windows Recovery Environment (Windows RE)
Enable Windows Remote Management (WinRM) on the servers.
Add the IT Help Desk Users to the Group Policy Creator Owners group and then create a new Starter GPO.
WSUS server running in replica mode that is configured to download updates from Microsoft Update (a.k.a. replica split)
32. To create AD Domain Services snapshot
Folder redirection. Folder redirection is also useful when using roamin profiles.
dnscmd dcsrv2.company.com /zoneresettype company.com /dsprimary
Ntdsutil
Properties of PSO need modified
33. To protect all computers on the network from unwanted access and to ensure a consistent configuration
Configure Firewall Group Policies and link them at the Domain level
dnscmd dcsrv2.company.com /zoneresettype company.com /dsprimary
Then use Windows Deployment Services (WDS) on DHCP1.
Creating a data collector set that kick off a scritp that either move or delete files.
34. To add a server with AD FS 2.0 role to an existing AD FS farm...
Create TWO new starter GPO's one with user administrative templates configure - and one with computer admin template configured - and export them to .cab files - and make the .cab files available in both forests...Then when creating new group policie
Recommend one AD based service account for each web site in each domain - that would mean 10 total. NOTE: Because you're using AD accounts that there is one web site in each domain the number of service accounts will match the number of domains.
fsconfig on FSSrv2
Disable Site Link Bridging from the IP properties
35. You need to ensure that users that access your web site can use any browser; however - they must be authenticated on a membership page. In order for this authentication to be done securely in IIS implement
Configure RADIUS accounting by using SQL loggin on each server and use Srv1 as database for RADIUS aaccounting.
Changed manually
Basic Authentication and SSL
Use Windows Server Backup to back up each domain controller to a remote network share. Use Windows Deployment Services (WDS) to deploy the Windows Recovery Environment (Windows RE)
36. File that contains the last logon time and custom attributes values for each user in your forest.
Object access auditing on the server that supports the resource. Note: Enabling audit access also helps when auditing your Cert Servers
Get-ADUser cmdlet
Logged changes must include old and new values of any attributes. - Run auditpol and then configure Security settings of Domain Controllers OU
Use CISCO IP Helper command to configure.
37. With AppLocker settings - which Windows PowerShell cmdlet would be used to identify whether a specific application file is allowed to run on a computer?
Winrm quickconfig
Then make sure all DCs are runing Windows Server 2008 R2 - and then use a GPO to enable Trusted Platform Module backups to AD.
Test-AppLockerPolicy
Microsoft Desktop Optimization Pack (MDOP) to your company
38. You need to recommend a solution for users in the branch office to access files in the main office. To minimize the amount of time it takes for users in the Branch office to access files stored on servers in the main office - and minimize the number
In AD Sites and Services - assign a new IP subnet to SiteB - and then move the new DC object to SiteB.
Branch Cache server that operates in Hosted Cache mode in your recommendation. This is an ideal solution if the branch office already maintains a Server 2008 R2 server solution (no additional licenses would be needed)
Either implement a DHCP server at the branch office - or configure a "Static Pool" on the RRAS server itself. If deploying a DHCP server at the branch office isn't an option - then once the Remote Access Server role has been deployed you can configur
Store all sensitive files in EFS encrypted folders and require home users to access the files by using SSTP
39. All servers use internal storage only. Srv1 is a Server 2008 R2 file server. you need to deploy a client/server application so that it is available if a single server fails. To achieve this while minimizing cost
DSMOD
Deploy a failover cluster that uses Node and File Share Disk Majority
Implement a Remote Desktop Connection Broker (RD Connection Broker)
Group Policy Preferences
40. You have a main office and 2 branch offices. Your OU structure mimics this. The branch office admins need to be able to apply GPOs only to their respective OUs. What 2 steps should you take to accomplish this?
Implement a Remote Desktop Connection Broker (RD Connection Broker)
Loopback Processing - The purpose of the Loopback Processing policy is to prevent usesr policies that currently affect the user from following them to a publicly used or (shared remote desktop) computer. We may indeed in many cases want these policie
1) Add the branch office admin accounts to teh Group Policy Creator Owners Group. 2) Run the Delegation of Control Wizard and delegate the right to link GPOs for their branch OUs to the branch office admins.
Copy the ADMX files from your company's PDC emulator to the PolicyDefinitions folder on other company's PDC emulator.
41. There are now 4 primary types of VPN solutions - PPTP - L2TP - SSTP and Direct Access. If you need to implement a VPN on Vista SP1 or higher machines you can implement SSTP.
Active Directory Users and Computers utility
Disable the user half of the policy. For flow reasons we can stop policies from affecting certain computers and users by placing blocks at the OU level. This will prevent the policy from parent OUs from flowing into the child OU as long as the parent
Create a new Password Settings Object (PSO) for the IT users.
SSTP is a good solution if you have Vista SP1 or higher and your security team has already opened port 443 on the firewall and the coporate security policy states that they would prefer not to open any more ports on the firewall than necessary. SSTP
42. PowerShell script to create user accounts with passwords from a file called password.csv
Create a GPO and link the GPO to the domain then configure the GPO to be enforced
Folder redirection. Folder redirection is also useful when using roamin profiles.
Microsoft System Center Data Protection Manager
Import-csv password.csv | Foreach {New-ADUser -Name $_.Name -Enabled $true_AccountPassword (ConvertTo_SecureString $_.Password -AsPlainText -force)}
43. You plan to deploy 12 file servers. All computers and servers connect to Ethernet switches. Your data storage solution must meet these: maximizes performance and fault tolerance; allocates storage to the servers as needed; utilizes the existing netwo
Add the Windows Server Backup feature and Windows System Image recovery.
Enhanced Storage Access settings in Group Policy on the local machine to require a unique vendor ID to identify the device or even require a certificate for the device to connect to your machine. This policy can even lock the device when the computer
Install Windows Server 2008 R2 Datacenter Edition on each server. Deploy the servers in a failover cluster. Deploy an iSCSI storage area network (SAN) - You have a main office and branch office.
Use Windows Server Backup to perform a daily backup to an external disk. Enable shadow copies for the volumes that contain shared user data. Store the shadow copies on a separate physical disk.
44. To allow administrators tha trun Windows 7 ability to manage the DNS server that runs on the Server Core installation of Server 2008 R2
A Distributed File System (DFS) namespace
Basic Authentication and SSL
Install the Remote Server Administration Tools (RSAT) on the Windows 7 computers.
Converting physical servers to VMs - implementing SANn and SAN management components such as backup and site resiliency will create additional administrative overhead.
45. When configuring delegation of administration for Domain Controllers at a remote location you must Add the users or groups as members of the Domain Admins Group. However - be careful to allow just a certain user or group of users to manage the Domain
Request and obtain a server authentication certificate from a trusted certification authority (CA) in your organization or from a trusted third-party CA - Authorization Manager provides a flexible framework for integratin role-based access control in
Ensure your account - or the group is a member of the local Administrators group for that specific server.
Create an e-mail account in AD DS for your RMS users.
Branch Cache server that operates in Hosted Cache mode in your recommendation. This is an ideal solution if the branch office already maintains a Server 2008 R2 server solution (no additional licenses would be needed)
46. You need to deploy 15 Server Core installations that are only accessible by HTTP and HTTPS. Administration of these must be able to enable administrators to install and administer server roles remotely and fully manage servers remotely
Changed manually
Deploy an additional WSUS server for the remote teachers. Configure the remote teacher's laptops to use the additional WSUS server. Configure the addtional WSUS server to leave the updates on the Microsoft Update Web Site.
dnscmd tool
Enable Windows Remote Management (WinRM) on each server.
47. To know if a new applicaiton is going to run on your network computers via AppLocker in GPO
Configure each SharePoint site to use a separate application pool - and then implement Windows System Resource Manager (WSRM)
Test-AppLockerPolicy
Click Start - click Run - type cmd - and then press ENTER. - At the command prompt - type dsmgmt.exe - and then press ENTER. - For a list of valid parameters - type ? - and then press ENTER. - By default - no local administrator role is defined on th
Copy the ADMX files from your company's PDC emulator to the PolicyDefinitions folder on other company's PDC emulator.
48. To ensure IT Help Desk Users can create GPOs in the domain and give them a GPO that contains preconfigured settings that will be used to create new GPOs -
Add the IT Help Desk Users to the Group Policy Creator Owners group and then create a new Starter GPO.
Then use Windows Deployment Services (WDS) on DHCP1.
Data Recovery Agent
Application to the computer if you need to ensure that the application is installed on the computer before the user logs in.
49. Help desk staff must be able to update drivers on the domain controllers at the branch office and assign them the proper
Zone transfer settings
Deploy Microsoft System Center Data Protection Manager 2010 and create a new protection group.
Administrative Role Separation
Add the new UPN suffix to the forest.
50. An AD LDS instance needs to be replicated from one server to another...
Service user account for AD LDS
Domain based Distributed File System (DFS) will reduce network traffic
Modify zone transfer settings for company.com zone on DCA
Configure each SharePoint site to use a separate application pool - and then implement Windows System Resource Manager (WSRM)