You need to minimize the amount of SYSVOL replication traffic on the network
Your network contains an Active Directory domain.
All domain controllersrun Windows Server 2003.
You replace all domain controllerswith domain controllers that run Windows Server 2008 R2.
You raise the functional levelof the domainto Windows Server 2008 R2.
You need to minimize the amount of SYSVOL replication traffic on the network.
What should you do?
You need to ensure that all client computers in the domain keep the same time as an external time server
Your network contains an Active Directory forest.
The forest contains two domain controllers.
The domain controllers are configured as shown in the following table:
All clientcomputers run Windows 7.
You need to ensure that all client computers in the domain keep the same time as an external time
server.
What should you do?
You need to minimize the number of client authentication requests sent to DC2
Your network contains an Active Directory domainnamed contoso.com.
Contoso.com contains two domain controllers.
The domain controllers are configured as shown in the following table:
All client computershave IP addressesin the 10.1.2.1 to 10.1.2.240 range.
You need to minimize the number of client authentication requests sent to DC2.
What should you do?
Which two actionsshould you perform?
Active Directory Rights Management Services(AD RMS) is deployedon your network.
You need to configure AD RMS to use Kerberos authentication.
Which two actionsshould you perform?
(Each correct answer presents part of the solution. Choose two.)
You need to configure the RODC to store only the passwords of users in the remote site
Your network contains an Active Directory forest.
The forest contains an Active Directory sitefor a remote office.
The remote sitecontains a read-only domain controller (RODC).
You need to configure the RODC to store only the passwords of users in the remote site.
What should you do?
You need to ensure that the support technicians can reset the passwords for the user accounts in their respect
Your company has four offices.
The network contains a single Active Directory domain.
Each officehas a domain controller.
Each officehas an organizational unit(OU) that contains the user accountsfor the users in that office.
In each office, support techniciansperform basic troubleshootingfor the users in their respective office.
You need to ensure that the support technicians can reset the passwords for the user accounts in their
respective office only.
The solution must prevent the technicians from creatinguser accounts.
What should you do?
You need to ensure that GPO10 is applied only to clientcomputers that run Windows 7
Your network contains a single Active Directory domain.
Client computersrun either Windows XP Service Pack 3 (SP3) orWindows 7.
All of the computer accountsfor the client computersare located in an organizational unit(OU) named
OU1.
You link a new Group Policy object (GPO)named GPO10to OU1.
You need to ensure that GPO10 is applied only to clientcomputers that run Windows 7.
What should you do?
Which security policy setting should you configure?
Your network contains an Active Directory domainnamed contoso.com.
You need to audit changes to a service account.
The solution must ensure that the audit logs contain the before and after values of all the changes.
Which security policy setting should you configure?
You need to ensure that users from the nwtraders.com forest can access AD RMS protected content in the contoso
Your network contains two Active Directory forestsnamed contoso.comand nwtraders.com.
Active Directory Rights Management Services(AD RMS) is deployed in each forest.
You need to ensure that users from the nwtraders.com forest can access AD RMS protected content in
the contoso.com forest.
What should you do?
You need to ensure that you can use the new certificatefor AD FS
Your network contains a servernamed Server1that runs Windows Server 2008 R2.
Server1is configured as an Active Directory Federation Services (AD FS) 2.0 standalone server.
You plan to add a new token-signing certificate to Server1.
You import the certificate to the serveras shown in the exhibit:
When you run the Add Token-Signing Certificate wizard, you discover that the new certificate is
unavailable.
You need to ensure that you can use the new certificatefor AD FS.
What should you do?