SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
MSITP
Start Test
Study First
Subjects
:
certifications
,
msitp
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. To decrease the amount of time it takes for the certain users to generate reports. You should recommend
Run auditpol and then configure the Security settings of the Domain Controllers OU.
Windows System Resource Manager (WSRM)
Active Directory Users and Computers
Install a Server Core installation of Windows Server 2008 R2 Enterprise. Note: Remember clusters must be either 2008 Enterprise or Datacenter - you cannot build a Microsoft Cluster using Web or Standard Editions
2. Internet access is provided through the main office to the satellite offices. You need to design a patch management for the satellite offices that meet the following requirements: WSUS updates are approved from a central location; internet traffic is
Modify properties of RODC server computer account.
Use Netsh tool from administrator's computer.
Install and share a printer on a server and then enable printer pooling.
In each office - install a WSUS server and configure the WSUS servers as a replica of the main office.
3. If you need to encrypt all data on all disks
Configure RADIUS accounting by using local file loggin on each server. Store the log files in an Internet Authentication Service (IAS) format on a shared folder on one of the servers (Srv1).
Then use Windows BitLocker Drive Encryption
Implement Windows System Resource Manager (WSRM) and configure a resource-allocation policy for process-based management.
Changed manually
4. Company users IPV4 and IPV6. A PC uses IPV6 and can no longer authenticate off the DC. What can be done to ensure IPV6 computers authenticate to DCs in same site...
Enable Windows Remote Management (WinRM) on the servers.
Deploy two writable domain controllers in ad.company.com and recommend to configure both domain controllers as GC's.
Subnet object needs to be created
Create an Active Directory-Integrated zone.
5. You need to create a DNS infrastructure that must allow client computers in each office to register DNA names within their respective offices and client computuers must be able to resolve names for hosts in all offices
Create an Active Directory-Integrated zone.
Backup operator's domain local group
Implement one LUN for the quorum and another LUN for the data
Configure separate application pools for each application
6. What GPO setting should be configured to prevent all users from running an application?
The applications within the VM by using RemoteApp. Create a RemoteApp and Desktop Connection for each VM.
Network Load Balancing (NLB) Cluser for the front end WSUS servers. This will allow users to have the continued access in the event that WSUS servers become unavailable.
Upgrading DFS to Windows Server 2008 R2
Software Restriction Polices
7. To backup Virtual Machines
New ACCOUNT STORE should be added and configured
Dfsrdiag
Deploy Microsoft System Center Data Protection Manager 2010 and create a new protection group.
Improve the performance of File Servers
8. You need to access some resources in another domain that is part of another forest. What type of trust should you create?
Install File Server Resource Manager (FSRM) role service - and then configure Quota Managment and Storage Reports Management
PowerShell 2.0
The WSUS client to retrieve updates from Microsoft Update (Do not Store updates locally)
Incoming external trust
9. A DNS structure should be deployed acording to the following requirements: ensure resources in the root and child domains are accessible by FQDN; provide name resolution services in the event that a single server fails for a prolonged period of time;
Then use Key Management Service (KMS) - DHCP server - and Windows Deployment Services.
Deploy Microsoft System Center Data Protection Manager 2010 and create a new protection group.
net stop ntds
You should: on one domain controller create an Active Directory-Integrated zone for remote domain and create and Active Directory-Integrated stub zone for main domain.
10. 4 steps to perform authoritative restore of a deleted OU...
Network Load Balancing (NLB) Cluser for the front end WSUS servers. This will allow users to have the continued access in the event that WSUS servers become unavailable.
1) Restart dc in DirectoryServiceRestoreMode - 2) Restory system state data to date before organizational unit was deleted - 3) Use ntdsutil utility to mark organizational unit as authoritative 4) Restart Domain Controller
Role Separation
Run auditpol and then configure the Security settings of the Domain Controllers OU.
11. You need a solution for your Web servers that meet these requirements: ensures that the Web site is accessible even if a single server fails; supports the addition of more Web servers without interrupting client connections.
Windows XP Mode
Implement Distributed File System Replication (DFSR) on both servers
Site
Create a Network Load Balancing cluster.
12. In AD Sites and Service - which level is Universal Group Membership caching activated / deactivated?
Configure caching on the shared folder and configure offline files to use encryption
Configure a server with the Remote Desktop Services role and install Outlook 2003 on the Remote Desktop Services server. Then publish Outlook 2003 as a Remote Desktop Services RemoteApp (RD RemoteApp).
Site
Modify the schema of LDSInst1
13. You have 9 2008 R2 servers that host Web apps. You need a remote mgmt strategy to manage the Web servers according to these requirements: Web developers need to be able to configure features on the Web sites; Web developers should not have full admin
Configure authorization rules for Web developers on each web server
Configure Microsoft SQL Server 2008 failover cluster. Configure two WSUS servers in a Network Load Balancing cluster. Configure WSUS to use the remote SQL Server 2008 database instance.
Congifure the new Local User and Groups by using Group Policy Preferences option and link the policy to the Branch office site.
Copy the ADMX files from your company's PDC emulator to the PolicyDefinitions folder on other company's PDC emulator.
14. AD structure includes a forest with one root domain and one child domain. Child domain lists entries that start with "S-1-5-21" but no account name listed. What should be done so account names are listed?
Apply a WMI Filter to the policy. Note: You can use a WMI filter to filter out VM from being affected by a GPO the same way you can a physcial machine.
Certificate Templates
Additional DFS Targets
Move "Infrasture Master" role in child domain to a DC that does not hold the Global Catalog.
15. When service account passwords need to be changed for SQL they should be...
Event Subscriptions
Add George to the Domain Admins group.
Enable Windows Remote Management (WinRM) on each server.
Changed manually
16. If a user needs to access a new cert template when logging on to any client computer in domain and you need to automatically install on each client computer a cert
Create a Network Load Balancing cluster.
Implement Shadow Copies
Then configure auto enrollment of certificates and Credential Roaming.
Publish the application as a Remote App. Enable Remote Desktop Web Access (RD Web Access).
17. To ensure that a file on a file server do not leave the organization you must implement this.
AD RMS
Establish a Federated Trust between your company and the external partner. Deploy a 2008 R2 server that runs MIcrosoft SharePoint 2010 and that has the Active Directory Rights Management Services (AD MS) role installed.
Implement Shadow Copies
Create an e-mail account in AD DS for your RMS users.
18. ServerA collects all events that occur on domain controllers with minimum effort from Event Viewer - what should be done to ensure notified when specific event occurs on any domain controllers...
Win2000
From Server A - run Create Basic Task Wizard
Microsoft Application Virtualization (AppV)
Migrate the namespace to Windows SErver 2008 mode and enable access based enumeration (ABE). NOTE: ABE is a new feature in SERVER 2008; this requires that all DFS Server be 2008 or later.
19. File that contains the last logon time and custom attributes values for each user in your forest.
Modify Object Access Settings AND Global Object Access Auditing settings FROM Advanced Audit Policy configurations
Get-ADUser cmdlet
Assign the application to computers in the PC OU
Windows XP Mode
20. To recover objects deleted from Active Directory you should recommend
Raise the DFL to Windows Server 2008 R2.
Active Directory snapshots and Tombstone reanimation
Implement Shadow Copies
Deploying a WSUS server in replica mode at the Branch office. You can also configure the WSUS in replica mode/split - this will allos the WSUS server to download list of updates from the parent but download the actual updates directly from Windows up
21. You have few Server 2003 servers that have Terminal services installed. You also have a firewall that runs ISA Server 2006. Your remote access strategy for the terminal servers needs to meeet the following: restricts accsss to specific Remote Desktop
Refresh the zone on DNS2
Upgrade one of the Server 2003 servers to Server 2008 R2. On this server - implement the Remote Desktop Services Gateway (RD Gateway) role and configure a Remote Desktop Services Resource authorization policy (RD RAP).
Add all the particular accounts into a new global security group. - Create new (PSO) and apply to group.
Disable Site Link Bridging from the IP properties
22. 2 ways to relocate user and computer accounts to different OUs
Then use Windows Deployment Services (WDS) on DHCP1.
Utilize IFM (Install From Media)
DSMOD - ADUC
Dsmgmt
23. You have three domain controllers that perform a full back up every day. You need a recovery strategy for AD objects that meets these requirements: allows objects in a backup to be compared to objects in the live AD database; minimizes admin effort.
You could restore the backup to an alternate location. Then mount the database using the AD Database Mounting Tool (Dsamain.exe)
Run a full back up by using Windows Server Backup - and then run a full back up of the Hyper-V hosts by using Windows Server Backup.
Install Windows Server 2008 R2 Web Edition - it will use the least amount of disk space.
Disable Site Link Bridging from IP Properties
24. Client computers run Windows 7 and all applications on the computers are configured to save documetns to the local Documents folder. You need a backup strategy that meets these: Back up the Documents folder for all users; minimize admin effort. To ac
Implement folder redirection by using GPO. Then backup the folder redirection target.
Run the Delegation of Control Wizard on the Staff OU
Active Directory snapshots and Tombstone reanimation
Raise the DFL to Windows Server 2008 R2.
25. What should be used to montior the replication of group policy template files when your DFL is set at Windows Server 2008 R2?
Deploy WSUS server on secure network. From an online WSUS server - copy the update metadata and the WSUS content to the WSUS server on the secure network.
Logged changes must include old and new values of any attributes. - Run auditpol and then configure Security settings of Domain Controllers OU
Dfsrdiag
Branch Cache server that operates in Hosted Cache mode in your recommendation. This is an ideal solution if the branch office already maintains a Server 2008 R2 server solution (no additional licenses would be needed)
26. When implementing a Hyper-V environment the benefits are enormous - however there are certain aspects of virtualization that can create some additional administrative overhead that you can not have in a pure physical environment for example
Converting physical servers to VMs - implementing SANn and SAN management components such as backup and site resiliency will create additional administrative overhead.
net stop ntds
Use Netsh tool from administrator's computer.
Create ADMX and ADML files. Configure the GPO and link it to the domain.
27. When using Remote Desktop and Remote Desktop Session hosts - to be able to control both who can gain access - and to what - on the network configure;
WDS
Disable the user half of the policy. For flow reasons we can stop policies from affecting certain computers and users by placing blocks at the OU level. This will prevent the policy from parent OUs from flowing into the child OU as long as the parent
Click Start - click Run - type cmd - and then press ENTER. - At the command prompt - type dsmgmt.exe - and then press ENTER. - For a list of valid parameters - type ? - and then press ENTER. - By default - no local administrator role is defined on th
One Remote Desktop connection authorization policy (RD CAP) and two Remote Desktop resource authorization polices (RD RAPs)
28. In order to manage websites without having to logon you can use
PowerShell 2.0
Upgrade all the client computers to Windows 7 and implement a Secure Socket Tunneling Protocol (SSTP) VPN solution.
Add \file2templates as a folder target for \domain.comdfstemplates - Create a DFS replication group that contains \file1templates and \File2templates
In each satellite office - install a WSUS server and configure the WSUS servers to use the main office WSUS server as an upstream server.
29. USB storage deviced on the client computers can be very convenient; however they create a huge security risk. To help reduce the risk of USB deviced you can implement...
Enhanced Storage Access settings in Group Policy on the local machine to require a unique vendor ID to identify the device or even require a certificate for the device to connect to your machine. This policy can even lock the device when the computer
Store all sensitive files in EFS encrypted folders and require home users to access the files by using SSTP
The Group Policy Management Console
Then Upgrade clients to Win7 - implement Enterprise CA on Win 2008 R2 and implement IPSec VPN with cert-based authentication.
30. To add a new UPN for all user accounts...
Install the full installation of Windows Server 2008 R2 Web Edition on two servers - and configure them in a Network Load Balancing cluster
Registry on users computer needs to be modified
AD Domains and Trusts
Deploy a failover cluster that contains one node in each office.
31. If you need to minimize the bandwidth for installation
Utilize IFM (Install From Media)
AD Domains and Trusts
DSMOD - ADUC
IIS Chared Configuration
32. To create and additional AD LDS applicaiton directory partition in existing instance...
Ldp
Assign the application to all client computers by using a GPO.
Modify Object Access Settings AND Global Object Access Auditing settings FROM Advanced Audit Policy configurations
You can apply IE Group Policies only to the OU's that contain clients that must be restricted based on your corporate policies.
33. You have a 2008 R2 serever that has SQL Server 2008 installed. The server has one RAID 5 array and two RAID 1 arrays. You need to allocate hard disck space on the server according to the followign requirements: prevent data los if a single hard disk
Software Restriction Polices
Recommend Group Policy preferences
Place the operating system files on one of the RAID 1 array - place the SQL transaction logs on the other RAID 1 array - and place the SQL database files on the RAID 5 array
Windows BitLocker Drive Encryption (Bit Locker)
34. All client computers run Windows 7. You have 8 Window Server 2003 servers that run Terminal Services. There is also an ISA server that runs the firewall. You need to plan on giving remote users access to the Terminal Servers according to these requir
Software Restriction Polices
Upgrade one of the TS to Windows Server 2008 R2 and configure it as the Remote Desktop Services Gateway (RD Gateway). Then implement Network Access Protection (NAP).
Dfsrdiag
Install WSUS 3.0 on a 2008 R2 server and configure Windows Update by using a GPO
35. You need to allow remote access to the servers on your network while meeting the following requirements: all remote connections to the servers must be encrypted; all remote authentication attempts to the servers must be encrypted; only inbound connec
Apply a WMI Filter to the policy. Note: You can use a WMI filter to filter out VM from being affected by a GPO the same way you can a physcial machine.
Implement GPO for all client computers
Install Microsoft Secure Socket Tunneling Protocol (SSTP)
1) Enable the Audit object access setting in the Local Security Policy for Srv1. 2) Configure auditing in the Certification Authority snap-in.
36. To enforce corporate policy on ALL computers in the domain to show a legal notice when a user logs on to the domain
Storage manager for SANs
Create a GPO and link the GPO to the domain then configure the GPO to be enforced
Establish a Federated Trust between your company and the external partner. Deploy a 2008 R2 server that runs MIcrosoft SharePoint 2010 and that has the Active Directory Rights Management Services (AD MS) role installed.
IPSec based enforcement. IPSec enforcement should be used when you want a stronger solution than 802.1x - DHCP or VPN based NAP. IPSec based NAP cannot be bypassed by modifying the NAP agent/client.
37. To back up your Hyper-VMs and the Hyper-V host; for each VM -
net stop ntds
Run a full back up by using Windows Server Backup - and then run a full back up of the Hyper-V hosts by using Windows Server Backup.
Create TWO new starter GPO's one with user administrative templates configure - and one with computer admin template configured - and export them to .cab files - and make the .cab files available in both forests...Then when creating new group policie
Loopback Processing - The purpose of the Loopback Processing policy is to prevent usesr policies that currently affect the user from following them to a publicly used or (shared remote desktop) computer. We may indeed in many cases want these policie
38. you have fewer Server 2003 servers that have Terminal Services installed. you also have a firewall that runs ISA Server 2006. Your remote access strategy for the terminal servers needs to meet the following: encrypts all remote connections to the ter
Upgrade all the client computers to Windows 7 and implement a Secure Socket Tunneling Protocol (SSTP) VPN solution.
Install and share a printer on a server and then enable printer pooling.
Upgrade one of the Server 2003 servers to Server 2008 R2. On this server implement the Remote Desktop Services Gateway (RD Gateway) role and configure a Remote Desktop Services connection authorization policy (RD CAP).
Encrypting File System (EFS). This can be enabled locally or through a GPO.
39. You plan to deploy 12 file servers. All computers and servers connect to Ethernet switches. Your data storage solution must meet these: maximizes performance and fault tolerance; allocates storage to the servers as needed; utilizes the existing netwo
Administrative Role Separation
Install Windows Server 2008 R2 Datacenter Edition on each server. Deploy the servers in a failover cluster. Deploy an iSCSI storage area network (SAN) - You have a main office and branch office.
Install the RSAT tool on their workstation to provide for more efficient network management
Create a standard secondary of domain and create standard secondary of other domain.
40. Ensure password length for a group set to 12 characters long while others keep password policy
dsa.msc - dsamain.exe - ntdsutil.exe
Add-ADFineGrainedPasswordPolicySubject cmdlet
Creating a data collector set that kick off a scritp that either move or delete files.
Install Hyper-V role and convert physical machines into virtual machines
41. Certain apps may require that the end user have the ability to make changes to the application - however some applications may allow these changes to be made in the registry. To give you as the administrator the ability to make changes as necessary -
Assign permissions for the Groups OU and Branch OU to the help desk technicians.
Group Policy Preferences
Store all sensitive files in EFS encrypted folders and require home users to access the files by using SSTP
Deploy a GPO to the WebSrvOU
42. You have two identical print devices. You must plan a print services infrastructure where: the print services must be available - even if one print device fails and have the ability to manage the print queue from a central location
Winrm quickconfig
dnscmd dcsrv2.company.com /zoneresettype company.com /dsprimary
Install Windows Server 2008 R2 Datacenter Edition on each server. Deploy the servers in a failover cluster. Deploy an iSCSI storage area network (SAN) - You have a main office and branch office.
Install and share a printer on a server and then enable printer pooling.
43. You need to design patch management for satellite offices that meet the following requirements: WSUS updates are approved independently for each satellite office; Internet traffic is minimized. To accomplish
Add the Windows Server Backup feature and Windows System Image recovery.
In each satellite office - install a WSUS server and configure the WSUS servers to use the main office WSUS server as an upstream server.
Implement Network Access Protection (NAP)
WSUS servers running in replica mode - and configure them to download updates from the WSUS server in the main office
44. Policy states that domain controllers cannot contain optical drives. You need a backup and recovery plan that restores the domain controllers in the event of a catastrophic server failure. To accomplish this
Configure a server with the Remote Desktop Services role and install Outlook 2003 on the Remote Desktop Services server. Then publish Outlook 2003 as a Remote Desktop Services RemoteApp (RD RemoteApp).
Use Windows Server Backup to back up each domain controller to a remote network share. Use Windows Deployment Services (WDS) to deploy the Windows Recovery Environment (Windows RE)
dsa.msc - dsamain.exe - ntdsutil.exe
Network Load Balancing (NLB)
45. Files servers need to stay connected to the SAN if a NIC fails. You should recommend
Multipath I/O feature
Then Upgrade clients to Win7 - implement Enterprise CA on Win 2008 R2 and implement IPSec VPN with cert-based authentication.
Configure offline files and enable manual caching
Run a full back up by using Windows Server Backup - and then run a full back up of the Hyper-V hosts by using Windows Server Backup.
46. 3 servers are configured as DNS servers and are ADI for the company.com zone. DNS only allows for secure updates - but you need to enable dynamic DNS updates on DCC.company.com...What do you do?
Reinstall AD DS on DCC.company.com as a WRITABLE DC.
Assign the application to computers in the PC OU
Winrm quickconfig
Configure RODC for Administrator Role Separation
47. To backup to tape/robotic tape and to backup VMs you must use...
Copy the ADMX files from your company's PDC emulator to the PolicyDefinitions folder on other company's PDC emulator.
IPSec based enforcement. IPSec enforcement should be used when you want a stronger solution than 802.1x - DHCP or VPN based NAP. IPSec based NAP cannot be bypassed by modifying the NAP agent/client.
Microsoft System Center Data Protection Manager 2010
Use Netsh tool from administrator's computer.
48. There is a file server in each office that contains a shared folder named Data. You need to plan the data availability for the Data folder according to these requirements: if WAN link fails - the files in the Data folder must be available in all of t
Then use Windows BitLocker Drive Encryption
Utilize IFM (Install From Media)
In each office - install a WSUS server and configure the WSUS servers as a replica of the main office.
Implement a domain-based DFS namespace that uses DFS Replication in a hub and spoke topology
49. DFL is Windows Server 2003 and client computers run Vista. DCRMS is a server that holds AD RMS. What should be done to configure AD RMS so users - including Waldo - can protect their data?
Use CISCO IP Helper command to configure.
The computer must be connected to the network when the end user clicks the icon and launches the install of the application.
Create an e-mail account in AD DS for your RMS users.
1) Stop AD services service 2) Compact ntds.dit 3) Move to %windir% ntds 4) Start AD domain services service
50. The servers in each office run Server 2008 R2 Enterprise Edition. You need to plan a failover cluster solution to service users in both offices that meet these: maintain the availability of services if a single server fails; minimize the number of se
1) Remove the Auth Users account from the Secutiy tab of the company.com DNS zone properties. 2) Assign the server computer accounts to the Allow on Create All Child Objects permission on the Security tab of the company.com DNS zone properties.
Deploy a failover cluster that contains one node in each office.
Purchase one additional Enterprise License
dnscmd tool