You need to create new organizational units in the AD LDS application directory partition
Your company has a server that runs an instance of Active Directory Lightweight Directory
Service (AD LDS).
You need to create new organizational units in the AD LDS application directory partition.
What should you do?
You need to ensure that DC2 holds the Schema Master role
Your company has an Active Directory domain. The company has two domain controllers
named DC1 and DC2. DC1 holds the Schema Master role.
DC1 fails. You log on to Active Directory by using the administrator account. You are not
able to transfer the Schema Master operations role.
You need to ensure that DC2 holds the Schema Master role.
What should you do?
Which two actions should you perform?
Your company has an Active Directory forest that runs at the functional level of Windows
Server 2008.
You implement Active Directory Rights Management Services (AD RMS).
You install Microsoft SQL Server 2005. When you attempt to open the AD RMS
administration Web site, you receive the following error message: “SQL Server does not
exist or access denied.”
You need to open the AD RMS administration Web site.
Which two actions should you perform? (Each correct answer presents part of the solution.
Choose two.)
You need to ensure a user is able to modify records in the contoso.com zone
Your network consists of an Active Directory forest that contains one domain named
contoso.com. All domain controllers run Windows Server 2008 R2 and are configured as
DNS servers. You have two Active Directory-integrated zones: contoso.com and
nwtraders.com.
You need to ensure a user is able to modify records in the contoso.com zone. You must
prevent the user from modifying the SOA record in the nwtraders.com zone.
What should you do?
You need to ensure that revoked certificate information is highly available
Your company has an Active Directory domain. All servers run Windows Server 2008 R2.
Your company uses an Enterprise Root certificate authority (CA).
You need to ensure that revoked certificate information is highly available.
What should you do?
You need to configure Server1 to support the Online Responder
You have two servers named Server1 and Server2. Both servers run Windows Server 2008
R2. Server1 is configured as an enterprise root certification authority (CA).
You install the Online Responder role service on Server2.
You need to configure Server1 to support the Online Responder.
What should you do?
You need to ensure that the user is able to log on to the computer
Your company has an Active Directory domain. A user attempts to log on to a computer that
was turned off for twelve weeks. The administrator receives an error message that
authentication has failed.
You need to ensure that the user is able to log on to the computer.
What should you do?
You need to configure AD FS to ensure that AD FS tokens contain information from the Active Directory domain
Your company has an Active Directory forest that contains a single domain. The domain
member server has an Active Directory Federation Services (AD FS) role installed.
You need to configure AD FS to ensure that AD FS tokens contain information from the
Active Directory domain.
What should you do?
What tool should you use?
You network consists of a single Active Directory domain. All domain controllers run
Windows Server 2008 R2.
You need to reset the Directory Services Restore Mode (DSRM) password on a domain
controller.
What tool should you use?
You need to ensure that users at the branch office are able to log on to the domain by using the RODC
Your company has a main office and a branch office. You deploy a read-only domain
controller (RODC) that runs Microsoft Windows Server 2008 to the branch office.
You need to ensure that users at the branch office are able to log on to the domain by using
the RODC.
What should you do?