You need to create an organizational unit (OU) structure to support the GPO requirements
You are the network administrator for Consolidated Messenger. The network consists of a single Active Directory forest that contains three domains named consolidatedmessenger.com, child1.consolidatedmessenger.com, and child2.consolidatedmessenger.com. The functional level of the forest is Windows Server 2003.Both child1.consolidatedmessenger.com and child2.consolidatedmessenger.com contain employee user accounts, client computer accounts, and resource server computer accounts. The domain named consolidatedmessenger.com contains only administrative user accounts and computer accounts for two domain controllers. Each resource server computer provides a single service of file server, print server, Web server, or database server.Your company plans to use Group Policy objects (GPOs) to centrally apply security settings to resource server computers. Some security settings need to apply to all resource servers and must not be overridden. Other security settings need to apply to specific server roles only. You need to create an organizational unit (OU) structure to support the GPO requirements. You want to create as few GPOs and links as possible.What should you do?
You need to recover from the corrupted quorum log
Your company has an Active Directory directory service domain. You have a four-node failover cluster that is a member of the domain. The quorum log is corrupted.
You do not have a backup of the quorum log file. You need to recover from the corrupted quorum log.
What should you do first?
You need to ensure that all Group Policy processing continues in the event of a local domain controller outage
You have a single Active Directory directory service domain. All domain controllers run Windows Server 2003. You have two physical locations, which correspond to two Active Directory sites. A domain controller is deployed to each location. A high-speed WAN link connects the two sites. Network utilization is low. Administrators create and edit Group Policy objects (GPOs) to configure security settings, login scripts, roaming profiles, and software installation. You need to ensure that all Group Policy processing continues in the event of a local domain controller outage. What should you do?
You need to ensure that as soon as possible, client computers do not trust the revoked certificates
Your company has an Active Directory directory service domain. All servers run Windows Server 2003. You have an Enterprise root certification authority (CA). Several critical certificates are compromised.
You revoke the compromised certificates. You need to ensure that as soon as possible, client computers do not trust the revoked certificates.
What should you do?
What are two possible ways to achieve this goal? (Each correct answer presents a complete solution
You are a network administrator for your company. The network consists of a single Active Directory
domain. All servers run Windows Server 2003. You use a Group Policy object (GPO) to change the default
storage location of the My Documents folder for all user accounts. The GPO redirects the My Documents
folder to \\SERVER1\USERFILES\%USERNAME%. The Redirect the folder back to the local user profile
location when policy is removed option is selected. The network does not use roaming user profiles. The My
Documents folders of several users are very large and consume too much disk space on Server1. As a
result, users report slow response times for shared files. You need to ensure that the My Documents folder
for each user is stored and maintained on the user’s client computer. You must not affect any other policies.
What are two possible ways to achieve this goal? (Each correct answer presents a complete solution.
Choose two.)
Which two settings should you configure? (Each correct answer presents part of the solution
Your company has an Active Directory directory service domain. All servers run Windows Server 2003. You are designing a security plan to reduce the risk in the event of a brute force password attack.
You need to modify Group Policy settings to record unauthorized access attempts.
Which two settings should you configure? (Each correct answer presents part of the solution. Choose two.)
You need to be able to create the new child domain
You are the network administrator for Contoso, Ltd. The network consists of a single Active Directory forest
that contains a single domain named contoso.com. You have a user account named CONTOSO\admin that
is a member of the Domain Admins global group. You need to create a new child domain named NA.
contoso.com in the forest. You install a stand-alone Windows Server 2003 computer named DC3. You use
the Active Directory Installation Wizard to promote DC3 to a domain controller in the new domain. You
choose to create a domain controller for a new child domain in an existing domain tree. You enter the user
name and password for CONTOSO\admin. You choose contoso.com as the parent domain, and you type
NA as the name of the child domain. You receive the error message shown in the exhibit.
You need to be able to create the new child domain. What should you do?
You need to apply the FilePrint
Your company has an Active Directory directory service domain. All file servers run Windows Server 2003 and are located in the FilePrint organizational unit (OU). You create a security template named FilePrint.inf that modifies existing audit settings and disables unwanted services.
You need to apply the FilePrint.inf security template to all file servers, and you must ensure that the security settings applied by the template cannot be overwritten.
What should you do?
You need to configure the settings to hide the Screen Saver tab and set the desktop wallpaper to Autumn
You are the network administrator for your company. The network consists of a single Active Directory domain. The domain contains an organizational unit (OU) named Sales. You create three Group Policy objects (GPOs) that have four configuration settings, as shown in the following table. The ScreenSaver GPO has the No Override setting enabled. The Sales OU has the Block Policy inheritance setting enabled. The priority for GPOs linked to the Sales OU specifies first priority for the Display and Wallpaper GPO and second priority for the Wallpaper GPO. For user accounts in the Sales OU, you want the Screen Saver tab to be hidden and the desktop wallpaper to be Autumn.jpg. You log on to a test computer by using a user account from the Sales OU, but you do not receive the settings you wanted. You need to configure the settings to hide the Screen Saver tab and set the desktop wallpaper to Autumn.jpg for the user accounts in the Sales OU. You want to avoid affecting user accounts in other OUs. What should you do?
You need to ensure that all users can auto-enroll by using the template
Your company has a single Active Directory directory service domain. All servers in your environment run Windows Server 2003. You install a Windows Server 2003 Enterprise root certification authority (CA). Users are unable to auto-enroll by using an existing version 2 User certificate template that has two registration authorities assigned. Users have the Enroll and Read permissions for the template.
You need to ensure that all users can auto-enroll by using the template. What should you do?


