PrepAway - Latest Free Exam Questions & Answers

Author: seenagape

You need to grant a user the following permissions:To create Group Policy objects (GPOs) in the domain…

You have a single Active Directory directory service domain. You need to grant a user the following permissions:To create Group Policy objects (GPOs) in the domainTo modify all existing and new GPOs in the domainYou add the users user account to the Group Policy Creator Owners group. What should you do next?

You need to configure Server1 to log the details of access attempts by VPN users

You are the network administrator for your company. The network consists of a single Active Directory domain. The network contains Windows Server 2003 file servers. The network also contains a Windows Server 2003 computer named Server1 that runs Routing and Remote Access and Internet Authentication Service (IAS).

Server1 provides VPN access to the network for users’ home computers. You suspect that an external unauthorized user is attempting to access the network through Server1. You want to log the details of access attempts by VPN users when they attempt to access the network.

You want to compare the IP addresses of users’ home computers with the IP addresses used in the access attempts to verify that the users are authorized. You need to configure Server1 to log the details of access attempts by VPN users.

What should you do?

You need to ensure that the Secure Client Computer GPO is automatically applied to current and future Windows

You have a single Active Directory directory service domain. All client computers run either Windows Vista or Windows XP. You create and configure a Group Policy object (GPO) named Secure Client Computer. You need to ensure that the Secure Client Computer GPO is automatically applied to current and future Windows XP client computers. What should you do?

You need to minimize bandwidth utilization

You are a network administrator for your company. The company has a main office and two branch offices. The branch offices are connected to the main office by T1 lines. The network consists of three Active Directory sites, one for each office. All client computers run either Windows 2000 Professional or Windows XP Professional.

Each office has a small data center that contains domain controllers, WINS, DNS, and DHCP servers, all running Windows Server 2003. Users in all offices connect to a file server in the main office to retrieve critical files. The network team reports that the WAN connections are severely congested during peak business hours. Users report poor file server performance during peak business hours. The design team is concerned that the file server is a single point of failure.

The design team requests a plan to alleviate the WAN congestion during business hours and to provide high availability for the file server. You need to provide a solution that improves file server performance during peak hours and that provides high availability for file services. You need to minimize bandwidth utilization.

What should you do?

You need to ensure that all client computers have the antivirus application installed

You are the network administrator for your company. The network consists of a single Active Directory domain. All servers run Windows Server 2003. All client computers run Windows XP Professional and are members of the domain. Only designated IT support staff have administrative rights on client computers. The company requires all client computers to run antivirus software. The company licenses an antivirus application that is installed on a file server named Server1. An unattended installation can be performed on each client computer by running the setup command from a shared folder on Server1. Several users report that when they attempt to install the antivirus application, they receive the following error message: “You do not have sufficient privileges on this computer to perform this action.” You verify that the antivirus application is not installed on any client computers. You need to ensure that all client computers have the antivirus application installed. You want to accomplish this task by using the minimum amount of administrative effort. What should you do?

What should you do?

You are a network administrator for your company. The network consists of a single Active Directory domain. All domain controllers run Windows Server 2003. The domain contains 20 member servers that run Windows Server 2003. Client computers run either Windows 2000 Professional or Windows XP Professional. The network does not use IPSec policies.

You receive a report that a member server named Server1 cannot communicate with any domain controllers in the domain. The other member servers are operating properly. Client computers continue to connect to Server1 normally. You examine the security settings in the local computer policy of Server1. The relevant settings are shown in the exhibit.

You want Server1 to be able to connect to the domain controllers in the domain.

What should you do?

Exhibit:

You need to ensure that the new GPO settings take precedence over settings from other GPOs

Your network consists of Windows XP computers joined to an Active Directory directory service domain. All users are located in a single organizational unit (OU). Several Group Policy objects (GPOs) are linked to this OU. A new GPO is created and must be linked to the OU. You need to ensure that the new GPO settings take precedence over settings from other GPOs. What should you do?

You need to decide where to place the test computer accounts in the domain

You are the network administrator for Contoso, Ltd. The network consists of a single Active Directory domain named contoso.com. The functional level of the domain is Windows Server 2003. The domain contains Windows Server 2003 computers and Windows XP Professional computers.

The domain consists of the containers shown in the exhibit.

All production server computer accounts are located in an organizational unit (OU) named Servers. All production client computer accounts are located in an OU named Desktops. There are Group Policy objects (GPOs) linked to the domain, to the Servers OU, and to the Desktops OU.

The company recently added new requirements to its written security policy. Some of the new requirements apply to all of the computers in the domain, some requirements apply to only servers, and some requirements apply to only client computers. You intend to implement the new requirements by making modifications to the existing GPOs.

You configure 10 new Windows XP Professional computers and 5 new Windows Server 2003 computers in order to test the deployment of settings that comply with the new security requirements by using GPOs. You use the Group Policy Management Console (GPMC) to duplicate the existing GPOs for use in testing. You need to decide where to place the test computer accounts in the domain.

You want to minimize the amount of administrative effort required to conduct the test while minimizing the impact of the test on production computers. You also want to avoid linking GPOs to multiple containers.

What should you do?

Exhibit:

You need to ensure that the settings in the Software GPO are applied to all users except one specific user

You have a Windows Server 2003 Active Directory directory service environment that contains an organizational unit (OU) named Corp. All computers and users are located in the Corp OU. An existing Group Policy object (GPO) named HR is linked to the Corp OU. You deploy a new GPO named Software to the Corp OU. A global group named Corp Users contains all users and has the Read and the Apply Group Policy permissions for the Software GPO and to the Corp OU. You need to ensure that the settings in the Software GPO are applied to all users except one specific user. The settings in the HR GPO must continue to be applied to all users. What should you do?

You need to identify the resource bottleneck that is causing the poor performance

You are a network administrator for your company. The network contains a Windows Server 2003 computer named Server1. Server1 has a single CPU, 512 MB of RAM, and a single 100-Mb network adapter.

All network users’ home folders are stored on Server1. Users access their home folders by using a mapped network drive that connects to a shared folder on Server1. After several weeks, users report that accessing home folders on Server1 is extremely slow at certain times during the day. You need to identify the resource bottleneck that is causing the poor performance.

What should you do?