SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
MSITP
Start Test
Study First
Subjects
:
certifications
,
msitp
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Your data recovery strategy for your Server 2008 R2 file server must meet the followign requirements: All data volumes on the server must be backed up daily; backups must have a minimal impact on performance; if a disk fails - the recovery strategy m
Enable Windows Remote Management (WinRM) on the servers.
Role Separation
Creating a data collector set that kick off a scritp that either move or delete files.
Use Windows Server Backup to perform a daily backup to an external disk. Enable shadow copies for the volumes that contain shared user data. Store the shadow copies on a separate physical disk.
2. Several employees say they can't get on domain with "password incorrect" message. What utility tool can be used to identify issue and also ensure users can log into domain?
Windows Deployment Services (WDS)
Store all sensitive files in EFS encrypted folders and require home users to access the files by using SSTP
Add \file2templates as a folder target for \domain.comdfstemplates - Create a DFS replication group that contains \file1templates and \File2templates
Repadmin
3. To deploy templates across the organization
Deploying a WSUS server in replica mode at the Branch office. You can also configure the WSUS in replica mode/split - this will allos the WSUS server to download list of updates from the parent but download the actual updates directly from Windows up
Incoming external trust
Add \file2templates as a folder target for \domain.comdfstemplates - Create a DFS replication group that contains \file1templates and \File2templates
Dynamically expanding VHD's
4. You are about to deploy a distributed database appliation that will run on multiple 2008 R2 servers. This deployment needs to follow these requirements: uses the existing network infrastructure; uses standard Windows management tools; allocates stora
Include an iSCSI disk storage subsystem that supports Virtual Disk Service (VDS). Configure the storage subsystem as a RAID 5 array.
Add \file2templates as a folder target for \domain.comdfstemplates - Create a DFS replication group that contains \file1templates and \File2templates
FILES option within Ntdsutil
Network Load Balancing (NLB)
5. To enforce corporate policy on ALL computers in the domain to show a legal notice when a user logs on to the domain
ntdsutil
Create a GPO and link the GPO to the domain then configure the GPO to be enforced
Deploy a failover cluster that contains one node in each office.
Then use Key Management Service (KMS) - DHCP server - and Windows Deployment Services.
6. Your office has no Internet connection. Your data provisioning solution must meet these requirements: users that are not connected to the network must be able to access files and folders on the network; unauthorized users must not have access to the
Configure caching on the shared folder and configure offline files to use encryption
Microsoft Desktop Optimization Pack (MDOP) to your company
Attach VHD file created by Windows server backup
Install WSUS 3.0 on a 2008 R2 server and configure Windows Update by using a GPO
7. To ensure that the branch office with its own high speed internet connection receives the exact same updates as the corporate office you should recommend this.
Dynamically expanding VHD's
Congifure the new Local User and Groups by using Group Policy Preferences option and link the policy to the Branch office site.
Configure each SharePoint site to use a separate application pool - and then implement Windows System Resource Manager (WSRM)
WSUS server running in replica mode that is configured to download updates from Microsoft Update (a.k.a. replica split)
8. 2 ways to relocate user and computer accounts to different OUs
Then Migrate DHCP server role from the domain controllers to the files servers. On file servers - add admin for office to DHCP admin local group.
Create an e-mail account in AD DS for your RMS users.
Migrate the namespace to Windows SErver 2008 mode and enable access based enumeration (ABE). NOTE: ABE is a new feature in SERVER 2008; this requires that all DFS Server be 2008 or later.
DSMOD - ADUC
9. To monitor replication of group policy template files when DFL set at Windows 2008 R2...
Windows XP Mode
Dfsrdiag
Utilize IFM (Install From Media)
Active Directory Users and Computers utility
10. If subnets are connected by CISCO router that is RFC-1542 compliant
Software Restriction Polices
FFL Windows Server 2008 R2
Install From Media IFM
Use CISCO IP Helper command to configure.
11. RDSrv1 is a Server 2008 R2 server with Remote Desktop Services installed. You are planning to establish a Terminal Server Farm that must meet these requirements: New users automatically connect to the terminal server that has the fewest active sessio
Raise the DFL to Windows Server 2008 R2.
Implement a Remote Desktop Connection Broker (RD Connection Broker)
Distributed File System (DFS) Replication
In AD Sites and Services - assign a new IP subnet to SiteB - and then move the new DC object to SiteB.
12. You have 5 windows Server 2008 R2 servers that are configured with the File Server role. you need to monitor the file servers with the following requirements in mind: administrators must be able to create reports that display folder usage by differen
Deploy an additional WSUS server for the remote teachers. Configure the remote teacher's laptops to use the additional WSUS server. Configure the addtional WSUS server to leave the updates on the Microsoft Update Web Site.
Your machine and remote desktops
Install File Server Resource Manager (FSRM) role service - and then configure Quota Managment and Storage Reports Management
Data Recovery Agent
13. To restore previous version of script without taking up too much of time...
Attach VHD file created by Windows server backup
Enable - ADoptionalFeature cmdlet
Implement Windows System Resource Manager (WSRM)
The computer must be connected to the network when the end user clicks the icon and launches the install of the application.
14. All DCs run Windows Server 2008 R2 and have the DNS Server role installed. The domain controllers for each location are stored locally. Each has its own standard primary zone to support its local domain.You need a plan that meets the following: WAN l
Then configure auto enrollment of certificates and Credential Roaming.
Configure RODC for Administrator Role Separation
Create a standard secondary of domain and create standard secondary of other domain.
AD RMS
15. All servers run 2008 R2 and all client computers run Windows 7. Server users have laptops and work from home. You need to plan an infrastructure to secure sensitive files according to these requirements: files must be - stored in an encrypted format;
Store all sensitive files in EFS encrypted folders and require home users to access the files by using SSTP
Implement Network Access Protection (NAP)
Administrators is the minimum group membership required to complete this procedure.
Add all the particular accounts into a new global security group. - Create new (PSO) and apply to group.
16. AD structure includes a forest with one root domain and one child domain. Child domain lists entries that start with "S-1-5-21" but no account name listed. What should be done so account names are listed?
Disable Site Link Bridging from IP Properties
Move "Infrasture Master" role in child domain to a DC that does not hold the Global Catalog.
Software Restriction Polices
Upgrading DFS to Windows Server 2008 R2
17. To make sure that all current certificate holders automatically enroll for the new template - use what utility?
Configure each SharePoint site to use a separate application pool - and then implement Windows System Resource Manager (WSRM)
Use a GPO to configure device installation restrictions
Network Load Balancing (NLB) Cluser for the front end WSUS servers. This will allow users to have the continued access in the event that WSUS servers become unavailable.
Certificate Templates
18. You need a solution that allows a global group to perform the following: stop and start services; change registry settings; change network settings
Execute the Set-ADServiceAccount cmdlet
Add the Remote1-Admins group to the Administrators local group on each server in Remote1.
Install a Server Core installation of Windows Server 2008 R2 Enterprise. Note: Remember clusters must be either 2008 Enterprise or Datacenter - you cannot build a Microsoft Cluster using Web or Standard Editions
Execute the Active Directory Diagnostics Data Collector Set and then review the report.
19. To ensure that when certain users log on to any client computers in the branch office - they automatically receive the local administrator rights to the computer - and when they log off - they must lose the administrator rights
IPSec based enforcement. IPSec enforcement should be used when you want a stronger solution than 802.1x - DHCP or VPN based NAP. IPSec based NAP cannot be bypassed by modifying the NAP agent/client.
IIS Manager user account
Certificate Templates
Congifure the new Local User and Groups by using Group Policy Preferences option and link the policy to the Branch office site.
20. Two different solutions are available to help assign IP addresses to remote clients that need to VPN or Dial-in to the branch office.
21. Client computers run Windows 7 and all applications on the computers are configured to save documetns to the local Documents folder. You need a backup strategy that meets these: Back up the Documents folder for all users; minimize admin effort. To ac
1) Restart dc in DirectoryServiceRestoreMode - 2) Restory system state data to date before organizational unit was deleted - 3) Use ntdsutil utility to mark organizational unit as authoritative 4) Restart Domain Controller
Install a Server Core installation of Windows Server 2008 R2 Enterprise. Note: Remember clusters must be either 2008 Enterprise or Datacenter - you cannot build a Microsoft Cluster using Web or Standard Editions
DFL needs to be Windows Server 2008
Implement folder redirection by using GPO. Then backup the folder redirection target.
22. Currently you already have in place AD - DNS and DHCP. You need an automated deployment solution for the new servers that will boot using native VHD's. You should recommend
Subnet object needs to be created
Run the Delegation of Control Wizard on the Staff OU
Windows Deployment Services (WDS)
Remote Desktop Virtualization host - you wouldn't want all the users on the same Remote Desktop Session host to be local administrators.
23. AD CS is configured on Server1 as a standalone CA. What two actions should you do to audit changes to the CA configuration settings and the CA security settings?
1) Enable the Audit object access setting in the Local Security Policy for Srv1. 2) Configure auditing in the Certification Authority snap-in.
Network Load Balancing (NLB)
CAPublishGP group should have the Manage CA permission.
Then Install IIS on perimeter network and redirect request to Online Responder on internal network.
24. Recently you have installed a special application on your web sites that requires using a managed service account on the Web Servers. This application runs on a web server in each of 10 separate Active Directory domains.
25. To ensure that user's documents are stored on the file server and thus subject to the corporate backup solution - you should implement this.
Then Upgrade clients to Win7 - implement Enterprise CA on Win 2008 R2 and implement IPSec VPN with cert-based authentication.
Folder redirection. Folder redirection is also useful when using roamin profiles.
Include an iSCSI disk storage subsystem that supports Virtual Disk Service (VDS). Configure the storage subsystem as a RAID 5 array.
Create a Central Store
26. 3 Servers are Network Policy Servers (NPS) that function as RADIUS servers. The network has 20 wireless access points that are configured as RADIUS clients. You need to plan an audit strategy with the following requirements: stores audit data in a ce
Zone transfer settings
Congifure the new Local User and Groups by using Group Policy Preferences option and link the policy to the Branch office site.
Configure RADIUS accounting by using local file loggin on each server. Store the log files in an Internet Authentication Service (IAS) format on a shared folder on one of the servers (Srv1).
You can apply IE Group Policies only to the OU's that contain clients that must be restricted based on your corporate policies.
27. The two role services must be deployed to prevent machines from connecting to the network if their security center settings (Firewall - Windows Updates - Defender) are NOT up to date are
Dfsrdiag
Create a Central Store
Network Policy Server (NPS) and Routing and Remote Access Service (RRAS)
Active Directory Rights Management Services (AD RMS) and Microsoft SharePoint Foundation 2010
28. What shold be done to configure AD RMS so users can protect their data?
Domain based Distributed File System (DFS) will reduce network traffic
Create an e-mail account in AD DS for your RMS users
Install Microsoft Secure Socket Tunneling Protocol (SSTP)
Additional DFS Targets
29. Domain.com's network consists of a Single AD domain. All servers and domain controllers run Windows Server 2008 R2. You need to ensure that you can: track all changes made to AD objects by the recently hired IT consulting firm; Ensure that the audits
Install a new server that runs a 64-bit version of Windows Server 2008 R2 Enterprise Edition. Install the Hyper-V role. Install the App1 and App2 in separate child virtual machines.
Configure an audit policy by editing the default domain policy and configure Event Forwarding
Add the user to the Domain Admins global group
Network Load Balancing (NLB) cluster
30. You need to manage GPO to meet the following: allow administrators to view and edit the GPO in their own language; minimize number of GPOs deployed
Changed manually
Create ADMX and ADML files. Configure the GPO and link it to the domain.
dsa.msc - dsamain.exe - ntdsutil.exe
Add the new UPN Suffix to the forest
31. UPN Suffix xxxx.com needs to be available for user accounts...
Implement Network Access Protection (NAP)
Folder redirection. Folder redirection is also useful when using roamin profiles.
Add the new UPN Suffix to the forest
Raise the DFL to Windows Server 2008 R2.
32. To allow all users in the forest to be able to resolve the names in the Forest Root Partition
Move "Infrasture Master" role in child domain to a DC that does not hold the Global Catalog.
Assign permissions for the Groups OU and Branch OU to the help desk technicians.
Event Viewer
Modify the DNS zone replication properties of the root domain - and change it to the ForestDNSZones application directory partition
33. If you want to allow the administrator in each office to manage DHCP scope for their own office - and prevent the administror of one office from managing DHCP scopes on the DHCP server in another office with mimimal admin effort
Event Viewer
Then Migrate DHCP server role from the domain controllers to the files servers. On file servers - add admin for office to DHCP admin local group.
Perform an authoritative restore
Implement Distributed File System Replication (DFSR) on both servers
34. DCA is DC and DNS server that holds ADI zone for company.com DNSB is member server that has DNS server role installed. What should be done so DNSB can get zone updates from DCA?
Modify zone transfer settings for company.com zone on DCA
The Group Policy Management Console
Deploy it by using Group Policy Software Installation method
Changed manually
35. DCDNS1 is a DC and DNS server that host and ADI zone for company.com and is located in the main office. DNS2 is a DNS server that hosts a secondary zone for company.com and is located in the branch office. FSrv1 is a new file server that is located i
Refresh the zone on DNS2
Microsoft Desktop Optimization Pack (MDOP)
Deploy a failover cluster that contains one node in each office.
Provide remote access to a Windows Server 2008 R2 server that has the Remote Server Administration Tools (RSAT) installed.
36. What should be used to montior the replication of group policy template files when your DFL is set at Windows Server 2008 R2?
AD RMS
Dfsrdiag
NOT be able to store that data on an iSCSI SAN
View properties of %systemroot%ntdsntds.dit
37. To build a highly secure server cluster with a reduced attack surface area
Then configure auto enrollment of certificates and Credential Roaming.
Dfsrdiag
Create a GPO and link the GPO to the domain then configure the GPO to be enforced
Install a Server Core installation of Windows Server 2008 R2 Enterprise. Note: Remember clusters must be either 2008 Enterprise or Datacenter - you cannot build a Microsoft Cluster using Web or Standard Editions
38. For the users that work remotely that need access to files from the corporate office you should...
Upgrade all the client computers to Windows 7 and implement a Secure Socket Tunneling Protocol (SSTP) VPN solution.
Recommend Offline Files
Include a server that runs Microsoft Office SharePoint Server 2010
Configure caching on the shared folder (offline files)
39. New Password Policy needs to be created for OU different from domain password policy
Store the WSUS updates on a Distributed File System (DFS) link that uses multiple replicating targets.
Prestage the computer account in AD
1) Restart dc in DirectoryServiceRestoreMode - 2) Restory system state data to date before organizational unit was deleted - 3) Use ntdsutil utility to mark organizational unit as authoritative 4) Restart Domain Controller
Add all the particular accounts into a new global security group. - Create new (PSO) and apply to group.
40. CAPublishGP needs to be able to publish new certificate revocation lists - but not be able to revoke certificates. How is this accomplished?
Run a full back up by using Windows Server Backup - and then run a full back up of the Hyper-V hosts by using Windows Server Backup.
Software Restriction Polices
Use local roles options within "dsmgmt"
CAPublishGP group should have the Manage CA permission.
41. Tools to view contents of an OU in an AD snapshot...
Install From Media IFM
dsa.msc - dsamain.exe - ntdsutil.exe
Add \file2templates as a folder target for \domain.comdfstemplates - Create a DFS replication group that contains \file1templates and \File2templates
Use a GPO to configure device installation restrictions
42. If you need to ensure that data is protected by BitLocker then you will...
The applications within the VM by using RemoteApp. Create a RemoteApp and Desktop Connection for each VM.
Configure caching on the shared folder (offline files)
Add the IT Help Desk Users to the Group Policy Creator Owners group and then create a new Starter GPO.
NOT be able to store that data on an iSCSI SAN
43. Your data provisioning solution must meet the following requirements: users must have access to their Documents folder regardless of the client computer that they use; user documents should not be stored on the local client computer; minimize the tim
Subnet object needs to be created
1) Stop AD services service 2) Compact ntds.dit 3) Move to %windir% ntds 4) Start AD domain services service
Configure folder redirection
On one server - create event subscriptions for each server...on the server - attach tasks to the application error events
44. If the branch office has its own high speed WAN link and you need to minimize traffice between the corporate office and the Branch office - configure this.
The WSUS client to retrieve updates from Microsoft Update (Do not Store updates locally)
Deploy one new server that runs Windows Server 2008 R2 Enterprise Edition and install the Hyper-V feature on the new server. Then create three child virtual machines.
Assign permissions for the Groups OU and Branch OU to the help desk technicians.
Loopback Processing - The purpose of the Loopback Processing policy is to prevent usesr policies that currently affect the user from following them to a publicly used or (shared remote desktop) computer. We may indeed in many cases want these policie
45. SiteA is an existing AD site. You just created a new site in AD named SiteB. AD replication needs to be configured betwen the two sites so you install a new DC and you careatd a site link between the two sites. What should be done next?
In AD Sites and Services - assign a new IP subnet to SiteB - and then move the new DC object to SiteB.
Use the Local Roles options with dsmgmt.
Repadmin
ntdsutil
46. If you need to change the TCP/IP addresses on 30 servers using the minimum amount of administrative effort
47. To delegate authority to users to manage only certain areas in Hyper-V use the
Network Policy Server (NPS) and Routing and Remote Access Service (RRAS)
Authorization Manager role assignment
DISABLE slow link detection in the GPO
Login to one DC and create and configure a conditional forwarder to replicate to all DNS servers in the forest.
48. To allow a specifc user or group to manage the address information for the user accounts...
Recommend Active Directory delegation
Implement a domain-based DFS namespace that uses DFS Replication in a hub and spoke topology
Modify the GPO to include folder redirection
Basic Authentication and SSL
49. George needs to administer a read-only domain controller named Server1 - but to do this with minimal permissions assigned to him. What tool should be used for this daunting task?
New ACCOUNT STORE should be added and configured
Windows Deployment Services (WDS)
Dsmgmt
Run a full back up by using Windows Server Backup - and then run a full back up of the Hyper-V hosts by using Windows Server Backup.
50. to ensure that server backups can be performed remotely from your backup server on your company file server you should perform these two actions
Execute the Set-ADServiceAccount cmdlet
Utilize IFM (Install From Media)
Install Windows Server Backup and modify the Windows firewall settings
Disable Site Link Bridging from IP Properties