PrepAway - Latest Free Exam Questions & Answers

Author: seenagape

You need to allow the sales and research departments to administer their own Active Directory user…

You have a single Active Directory directory service domain. You have several domain security policies in place. The relevant part of the network consists of the servers shown in the following table. You create two global security groups named Sales Admins and Research Admins. You add the users in the sales and research departments into their respective groups. You need to allow the sales and research departments to administer their own Active Directory user, computer, and group objects, while maintaining the existing security policies of the company. What should you do?

Which two settings in the Default Domain Policy should you plan to configure? (Each correct answer presents pa

Your company has an Active Directory directory service domain. All servers run Windows Server 2003. You are creating a security monitoring plan. You need to audit all domain authentication attempts and write these events to an event log on the local computer and also to an event log on the domain controller.

Which two settings in the Default Domain Policy should you plan to configure? (Each correct answer presents part of the solution. Choose two.)

You need to improve logon performance for users in the New York office without

You are the network administrator for Blue Yonder Airlines. The company has offices in Toronto, New York, and Chicago. The network connections are shown in the exhibit.

The network consists of two Active Directory domains. User objects for users in the Toronto office and the New York office are stored in the blueyonderairlines.com domain. User objects for users in the Chicago office are stored in the production.blueyonderairlines.com domain. Active Directory is configured as shown in the following table. Users in the New York office frequently report that they cannot log on to the network, or that logging on takes a very long time. You notice increased global catalog queries to servers in the Toronto office during peak logon times. You need to improve logon performance for users in the New York office without
increasing WAN traffic that is due to replication. What should you do?

You need to ensure that the server does not continue to send the unsolicited commercial e-mail messages

All servers in your company run Windows Server 2003. You discover that your public IP address is listed on an SMTP blacklist, and that one of your servers is sending unsolicited commercial e-mail that originates from outside your network. You need to ensure that the server does not continue to send the unsolicited commercial e-mail messages.

What should you do?

You need to be able to promote DC1 to a domain controller as the first domain controller of the child domain i

You are the network administrator for the Baldwin Museum of Science. The network consists of a single Active Directory forest that contains one domain named baldwinmuseumofscience.com. You need to deploy a new domain named NA.baldwinmuseumofscience.com as a child domain of baldwinmuseumofscience.com. You install a new stand-alone Windows Server 2003 computer named DC1. You plan to make DC1 the first domain controller in the NA.baldwinmuseumofscience.com domain. You configure DC1 with a static IP configuration. You run the Active Directory Installation Wizard on DC1. The wizard prompts you for the network credentials to use to join the NA.baldwinmuseumofscience.com domain to the forest. You enter the appropriate credentials for an account in the baldwinmuseumofscience.com domain. You receive an error message stating that a domain controller in the baldwinmuseumofscience.com domain cannot be located. You need to be able to promote DC1 to a domain controller as the first domain controller of the child domain in the existing forest. What should you do?

You need to enforce a maximum session time for all remote connections

Your company has an Active Directory directory service domain. All servers run Windows Server 2003. You control remote access to the internal network by using several custom remote access policies. You need to enforce a maximum session time for all remote connections. In the Routing and Remote Access console, you create a new remote session policy.

What should you do next?

You need to ensure that the user can immediately run the client component

Your company has a main office in Chicago and a branch office in New York. The company has a single Active Directory directory service forest with four domains. Two of the domain controllers are described in the following table. An application has a server component and a client component. When the server component is installed, several schema classes and attributes are added. A user in the ne.sales.contoso.com domain installs the client component on his client computer. You then install the server component. Thirty minutes after you install the server component, the user attempts to run the client component, but receives an error message stating that the schema objects cannot be found. You verify that the objects are present on DC1. The users logon server is DC4. You need to ensure that the user can immediately run the client component. What should you do?

You need to configure the domain controllers so that the loss of data in Active Directory is minimized during

You are the network administrator for your company. The network consists of a single Active Directory domain with two sites named Site1 and Site2. Site1 contains two domain controllers. Site2 contains one domain controller. Each site contains two member servers. All domain controllers are backed up every night. Each of the domain controllers is installed with a similar hardware configuration, which includes a single processor and a single hard disk. You create several user accounts on the domain controller in Site2. The hard disk on that domain controller fails. You install a new hard disk on the domain controller and restore the domain controller from the most recent backup tape. You notice that the new user accounts you created on the domain controller do not appear. The only way that you can restore the user accounts is to re-create them. You need to configure the domain controllers so that the loss of data in Active Directory is minimized during a similar hard disk failure. What should you do?