What should you specify in your design?
Your company has an Active Directory directory service domain. All servers run Windows Server 2003. All servers are located in an organizational unit (OU) named Servers. You need to design an IPSec policy strategy that provides security for the duration of the server startup process. What should you specify in your design?
Which command should you run?
Your company has a single Active Directory directory service forest with three domains and multiple sites.You need to manually create intersite connections for a site named Site1. You need to ensure that the KCC continues to generate the intrasite replication topology within each Active Directory site. Which command should you run?
You need to find out why Group Policy is not applying the new IPSec policy
Your company has a single Active Directory directory service domain. All servers in your environment run Windows Server 2003. You assign an IPSec policy to a member server. Group Policy does not apply the IPSec policy when the member server communicates with a domain controller. You need to find out why Group Policy is not applying the new IPSec policy. What should you do?
You need to log on to DC1 to complete the restore operation
You are a network administrator for Litware, Inc. The network consists of a single Active Directory domain named sales.litwareinc.com. The Active Directory database is contained on a Windows Server 2003 domain controller named DC1. The hard disk that contains the Active Directory database fails. You restart DC1 in Directory Services Restore Mode. When prompted to log on, you type administrator@sales.litwareinc.com as your user name and enter your domain password. Your logon attempt fails. You need to log on to DC1 to complete the restore operation. What should you do?
You need to ensure that support technicians have the appropriate remote administration access to all servers
Your company has an Active Directory directory service domain. All servers run Windows Server 2003. You are planning security policies for remote network administration. You plan to deploy the policies by using Group Policy. You must support the following requirements. Tier 1 support technicians must be able to request support from Tier 2 support technicians. Tier 1 support technicians must not be able to remotely connect to server consoles. Tier 2 support technicians must be able to remotely connect to server consoles.
You need to ensure that support technicians have the appropriate remote administration access to all servers.
What should you do?
You need to ensure that DC1 can immediately replicate with other domain controllers
You have a single Active Directory directory service domain. A domain controller named DC1 cannot replicate with other domain controllers. DC1 holds no FSMO roles. You notice that the time on DC1 is 11:30 AM while the time on all the other domain controllers is 11:00 AM. You need to ensure that DC1 can immediately replicate with other domain controllers. What should you do?
Which two Security Options policy settings should you enable? (Each correct answer presents part of the soluti
Your company has an Active Directory directory service domain. All client computers run Windows XP Professional. You are upgrading your servers from Windows 2000 Server to Windows Server 2003. You need to ensure that all network traffic between all computers uses server message block (SMB) signing, while maintaining client computer connectivity.
Which two Security Options policy settings should you enable? (Each correct answer presents part of the solution. Choose two.)
You need to ensure that Marie immediately has
You are the network administrator for your company. The network consists of a single Active Directory
domain. The domain contains an organizational unit (OU) named Research. All users who have user
accounts in the Research OU use portable computers that run Windows XP Professional. You create a
Group Policy object (GPO) named PowerManagement and link it to the Research OU. You configure the
PowerManagement GPO to enable the Prompt for password on resume from hibernate/suspend policy. A
user named Marie has a user account in the Research OU. Marie reports that she is not prompted for a
password when her computer resumes from hibernation. You need to ensure that Marie immediately has
password protection for her portable computer when resuming from hibernation mode. What should you do?
You need to prevent interference to your storage logical unit numbers (LUNs) from other clusters that use the
Your company has an Active Directory directory service domain. You are setting up a six-node Windows Server 2003 file services cluster. You plan to configure a Fibre Channel SAN to store six 2-TB volumes that will be used as cluster resources. You need to prevent interference to your storage logical unit numbers (LUNs) from other clusters that use the SAN.
What should you do?
structure should you use?
You are a network administrator for your company. The network consists of a single Active Directory forest
that contains one domain. The company has its main office and one branch office in San Francisco. The
company has additional branch offices in Chicago, New York, and Toronto. Administrators at the main office
are responsible for managing all objects in the domain. Administrators at each branch office are responsible
for managing user and computer objects for employees who work in the same branch office as the
administrator. Administrators for the San Francisco branch office are also responsible for managing user
and computer objects for employees who work in the main office. These users are managed as a single
unit. You want administrators to be authorized to make changes only to the objects for which they are
responsible. You need to plan an organizational unit (OU) structure that allows the delegation of required
permissions. You want to achieve this goal by using the minimum amount of administrative effort. Which OU
structure should you use?
Figure A
Figure B
Figure C
Figure D




