Which tool should you use to assign permissions to Admin1?
Your network contains an Active Directory domain. The domain contains an enterprise
certification authority (CA).
You need to ensure that only members of a group named Admin1 can create certificate
templates.
Which tool should you use to assign permissions to Admin1?
You need to configure Server2 as an enterprise subordinate C
Your network contains an Active Directory domain named contoso.com.
Contoso.com contains a server named Server2.
You open the System properties on Server2 as shown in the exhibit. (Click the Exhibit
button.)
When you attempt to configure Server2 as an enterprise subordinate certification authority
(CA), you discover that the enterprise subordinate CA option is unavailable.
You need to configure Server2 as an enterprise subordinate CA.
What should you do first?
You need to ensure that the users in Site2 always attempt to authenticate to DC2 first
Your network contains an Active Directory domain named contoso.com. Contoso.com
contains two sites named Site1 and Site2. Site1 contains a domain controller named DC1.
In Site1, you install a new domain controller named DC2. You ship DC2 to Site2.
You discover that certain users in Site2 authenticate to DC1.
You need to ensure that the users in Site2 always attempt to authenticate to DC2 first.
What should you do?
You need to deploy App1 to all client computers
Your network contains an Active Directory domain. The domain contains 3,000 client
computers. All of the client computers run Windows 7.
Users log on to their client computers by using standard user accounts.
You plan to deploy a new application named App1.
The vendor of App1 provides a Setup.exe file to install App1. Setup.exe requires
administrative rights to run.
You need to deploy App1 to all client computers. The solution must meet the following
requirements:
App1 must automatically detect and replace corrupt application files.
App1 must be available from the Start menu on each client computer.
What should you do first?
You need to view the most recent user accounts authenticated by RODC1
Your network contains an Active Directory domain named contoso.com.
Contoso.com contains a domain controller named DC1 and a read-only domain controller
(RODC) namedRODC1.
You need to view the most recent user accounts authenticated by RODC1.
What should you do first?
You need to monitor the following information on the domain controllers during the next five days: Memory usag
Your network contains an Active Directory domain. The domain contains 10 domain
controllers that run Windows Server 2008 R2.
You need to monitor the following information on the domain controllers during the next five
days:
Memory usage
Processor usage
The number of LDAP queries
What should you do?
How should you modify the command?
Your network contains a domain controller that runs Windows Server 2008 R2.
You run the following command on the domain controller:
dsamain.exe C dbpath c:\$SNAP_201006170326_VOLUMEC$\Windows\NTDS\ntds.dit C
ldapport 389 -allowNonAdminAccess
The command fails.
You need to ensure that the command completes successfully.
How should you modify the command?
You need to ensure that the DNS records are deleted automatically from the zone
Your network contains an Active Directory-integrated DNS zone named contoso.com.
You discover that the zone includes DNS records for computers that were removed from the
network.
You need to ensure that the DNS records are deleted automatically from the zone.
What should you do?
You need to ensure that the encryption keys for e-mail certificates can be recovered from the CA database
Your network contains a single Active Directory domain. The domain contains an enterprise
certification authority (CA).
You need to ensure that the encryption keys for e-mail certificates can be recovered from the
CA database.
You modify the e-mail certificate template to support key archival.
What should you do next?
You need to ensure that users in the human resources department can search for employees by using the employee
Your network contains an Active Directory forest. The forest contains multiple domains.
You need to ensure that users in the human resources department can search for
employees by using the employeeNumber attribute.
What should you do?