which groupshould you add the users?
Your network contains two Active Directory forestsnamed contoso.comand fabrikam.com.
Each forestcontains one domain.
A two-way forest trustexists between the forests.
You plan to add users from fabrikam.com to groups in contoso.com.
You need to identify which group you must use to assignusers in fabrikam.com access to the shared
folders in contoso.com.
To which groupshould you add the users?
Which toolsshould you use?
Your network contains an Active Directory domain.
The domain contains 5,000 user accounts.
You need to disable all of the user accounts that have a description of Temp.
You must achieve this goal by using the minimum amount of administrative effort.
Which toolsshould you use?
(Each correct answer presents part of the solution. Choose two.)
You need to ensure that access to the file shares on Server1 is audited
Your network contains an Active Directory domain.
The domain contains two file servers.
The file serversare configuredas shown in the following table:
You create a Group Policy object(GPO) named GPO1and you link GPO1 to OU1.
You configurethe advanced audit policy.
You discover that the settings are not applied to Server1.
The settings are applied to Server2.
You need to ensure that access to the file shares on Server1 is audited.
What should you do?
You need to prevent the GPO from being applied to the members of Group1 only
Your network contains an Active Directory domainnamed contoso.com.
You have an organizational unit(OU) named Salesand an OUnamed Engineering.
Each OUcontains over 200 user accounts.
The Sales OUand the Engineering OUcontain several user accountsthat are members of a universal
groupnamed Group1.
You have a Group Policy object(GPO) linked to the domain.
You need to prevent the GPO from being applied to the members of Group1 only.
What should you do?
You need to ensure that the settings in GPO1 supersede the settings in GPO2
Your network contains an Active Directory domain.
You have two Group Policy objects(GPOs) named GPO1and GPO2.
GPO1 and GPO2 are linked to the Finance organizational unit(OU) and contain multiple settings.
You discover that GPO2 has a setting that conflicts witha setting in GPO1.
When the policies are applied, the setting in GPO2 takes effect.
You need to ensure that the settings in GPO1 supersede the settings in GPO2.
The solution must ensure that all non-conflicting settings in both GPOs are applied.
What should you do?
What should you do?
You have a domain controllernamed DC1that runs Windows Server 2008 R2.
DC1is configured as a DNS serverfor contoso.com.
You installthe DNS server roleon a member servernamed Server1and then you create a standard
secondary zone for contoso.com.
You configure DC1as the master server for the zone.
You needto ensure that Server1 receives zone updates from DC1.
What should you do?
Which toolshould you use?
A corporate network includes an Active Directory-integrated zone.
AIl DNS serversthat host the zoneare domain controllers.
You add multiple DNS records to the zone.
You needto ensure that the new records are available on all DNS servers as soon as possible.
Which toolshould you use?
You need to ensure that the stale DNS records are deleted from contoso.com
Your network contains an Active Directory domainnamed contoso.com.
Contoso.com contains two domain controllersnamed DC1and DC2.
DC1 and DC2are configured as DNS serversand host the Active Directory-integrated zone for contoso.
com.
From DNS Manageron DC1, you enable scavenging for the contoso.com zone.
You discover stale DNS records in the zone.
You need to ensure that the stale DNS records are deleted from contoso.com.
What should you do?
You need to ensure that the domain controllers can acquire new account-identifier pools successfully
Your network contains an Active Directory forest.
The forest contains one domainnamed contoso.com.
You discoverthe following event in the Event logof domain controllers:
” The request for a new account-identifier pool failed. The operation will be retried until the request
succeeds. The error is ” %1 ” “
You need to ensure that the domain controllers can acquire new account-identifier pools successfully.
What should you do?
Which snap-inshould you use?
Your network contains an Active Directory domainnamed adatum.com.
All serversrun Windows Server 2008 R2 Enterprise.
All client computersrun Windows 7 Professional.
The network contains an enterprise certification authority(CA).
You enable key archivalon the CA.
The CA is configured to use custom certificate templatesfor Encrypted File System (EFS) certificates.
All users plan to encrypt files by using EFS.
You need to ensure that the private keys for all new EFS certificates are archived.
Which snap-inshould you use?