Which tool should you use to create these accounts?
HOTSPOT
Your network contains an Active Directory forest named contoso.com.
The password policy of the forest requires that the passwords for all of the user accounts be
changed every 30 days.
You need to create user accounts that will be used by services. The passwords for these
accounts must be changed automatically every 30 days.
Which tool should you use to create these accounts?
To answer, select the appropriate tool in the answer area.
Which service should you restart on the domain controllers?
HOTSPOT
Your network contains an Active Directory forest.
The DNS infrastructure fails.
You rebuild the DNS infrastructure.
You need to force the registration of the Active Directory Service Locator (SRV) records in
DNS.
Which service should you restart on the domain controllers?
To answer, select the appropriate service in the answer area.
You need to create four new groups in the forest root domain
DRAG DROP
Your network contains an Active Directory forest named adatum.com.
The forest contains four child domains named europe.adatum.com,
northamerica.adatum.com, asia.adatum.com, and africa.adatum.com.
You need to create four new groups in the forest root domain. The groups must be
configured as shown in the following table.
What should you do?
To answer, drag the appropriate group type to the correct group name in the answer area.
You need to use Group Policies to deploy the line-of-business applications shown in the following table
You need to prevent the GPO from being applied to the members of Group1 only
Your network contains an Active Directory domain. The domain is configured as shown in
the exhibit. (Click the Exhibit button.)
Each organizational unit (OU) contains over 500 user accounts.
The Finance OU and the Human Resources OU contain several user accounts that are
members of a universal group named Group1.
You have a Group Policy object (GPO) linked to the domain.
You need to prevent the GPO from being applied to the members of Group1 only.
What should you do?
how many days will the record be deleted?
Your network contains an Active Directory domain named contoso.com. The domain
contains a domain controller named DC1. DC1 has the DNS Server server role installed and
hosts an Active Directory-integrated zone for contoso.com. The no-refresh interval and the
refresh interval are both set to three days. The Advanced DNS settings of DC1 are shown in
the Advanced DNS Settings exhibit. (Click the Exhibit button.)
You open the properties of a static record named Server1 as shown in the Server1 Record
exhibit.(Click the Exhibit button.)
You discover that the scavenging process ran today, but the record for Server1 was not
deleted.
You run dnscmd.exe and specify the age all records parameter.
You need to identify when the record for Server1 will be deleted from the zone.
In how many days will the record be deleted?
You need to ensure that DC1 and DC4 are the only servers that replicate Active Directory changes between the s
Your network contains an Active Directory domain named contoso.com.
The Active Directory sites are configured as shown in the Sites exhibit. (Click the Exhibit
button.)
You need to ensure that DC1 and DC4 are the only servers that replicate Active Directory
changes between the sites.
What should you do?
You need to install a Microsoft Office 2007 application only on the computers in the Marketing OUs
Your company has an Active Directory forest. Each regional office has an organizational unit
(OU) named Marketing. The Marketing OU contains all users and computers in the region’s
Marketing department.
You need to install a Microsoft Office 2007 application only on the computers in the
Marketing OUs.
You create a GPO named MarketingApps.
What should you do next?
You need to install the AD CS server role as an Enterprise CA on CA1
A company has an Active Directory forest. You plan to install an offline Enterprise root
certification authority (CA) on a server named CA1. CA1 is a member of the
PerimeterNetwork workgroup and is attached to a hardware security module for private key
storage.
You attempt to add the Active Directory Certificate Services (AD CS) server role to CA1. The
Enterprise CA option is not available.
You need to install the AD CS server role as an Enterprise CA on CA1.
What should you do first?
You need to ensure that DNS1 receives zone updates from DC4
A domain controller named DC4 runs Windows Server 2008 R2. DC4 is configured as a
DNS server for fabrikam.com.
You install the DNS Server server role on a member server named DNS1 and then you
create a standard secondary zone for fabrikam.com. You configure DC4 as the master
server for the zone.
You need to ensure that DNS1 receives zone updates from DC4.
What should you do?