You need to configure the RODC to store only the passwords of users in the remote site
Your network contains an Active Directory forest. The forest contains an Active Directory site
for a remote office. The remote site contains a read-only domain controller (RODC).
You need to configure the RODC to store only the passwords of users in the remote site.
What should you do?
You need to ensure that the support technicians can reset the passwords for the user accounts in their respect
Your company has four offices. The network contains a single Active Directory domain. Each
office has a domain controller. Each office has an organizational unit (OU) that contains the
user accounts for the users in that office. In each office, support technicians perform basic
troubleshooting for the users in their respective office.
You need to ensure that the support technicians can reset the passwords for the user
accounts in their respective office only. The solution must prevent the technicians from
creating user accounts.
What should you do?
You need to ensure that GPO10 is applied only to client computers that run Windows 7
Your network contains a single Active Directory domain. Client computers run either
Windows XP Service Pack 3 (SP3) or Windows 7. All of the computer accounts for the client
computers are located in an organizational unit (OU) named OU1.
You link a new Group Policy object (GPO) named GPO10 to OU1.
You need to ensure that GPO10 is applied only to client computers that run Windows 7.
What should you do?
Which security policy setting should you configure?
Your network contains an Active Directory domain named contoso.com.
You need to audit changes to a service account. The solution must ensure that the audit logs
contain the before and after values of all the changes.
Which security policy setting should you configure?
You need to ensure that users from the nwtraders.com forest can access AD RMS protected content in the contoso
Your network contains two Active Directory forests named contoso.com and nwtraders.com.
Active Directory Rights Management Services (AD RMS) is deployed in each forest.
You need to ensure that users from the nwtraders.com forest can access AD RMS protected
content in the contoso.com forest.
What should you do?
You need to ensure that you can use the new certificate for AD FS
Your network contains a server named Server1 that runs Windows Server 2008 R2. Server1
is configured as an Active Directory Federation Services (AD FS) 2.0 standalone server.
You plan to add a new token-signing certificate to Server1.
You import the certificate to the server as shown in the exhibit. (Click the Exhibit button.)
When you run the Add Token-Signing Certificate wizard, you discover that the new
certificate is unavailable.
You need to ensure that you can use the new certificate for AD FS.
What should you do?
You need to purge the list of user accounts that were authenticated on a read-only domain controller (RODC)
You need to purge the list of user accounts that were authenticated on a read-only domain
controller (RODC).
What should you do?
You need to ensure that the domain controllers in the branch offices only replicate to the domain controller i
Your company has a main office and four branch offices. An Active Directory site exists for
each office. Each site contains one domain controller. Each branch office site has a site link
to the main office site.
You discover that the domain controllers in the branch offices sometimes replicate directly to
each other.
You need to ensure that the domain controllers in the branch offices only replicate to the
domain controller in the main office.
What should you do?
You need to ensure that you can add 1,000 new user accounts to the domain
Your network contains an Active Directory forest. The forest contains one domain. The
domain contains two domain controllers named DC1 and DC2 that run Windows Server
2008 R2.
DC1 was installed before DC2.
DC1 fails.
You need to ensure that you can add 1,000 new user accounts to the domain.
What should you do?
You need to identify whether the Active Directory Recycle Bin is enabled
Your network contains an Active Directory domain named contoso.com.
You need to identify whether the Active Directory Recycle Bin is enabled.
What should you do?