PrepAway - Latest Free Exam Questions & Answers

Category: 70-646 (v.2)

Exam 70-646: Pro: Windows Server 2008, Server Administrator (March 28, 2013)

Which deployment strategy should you recommend?

Testlet: Graphic Design Institute, Case B
You are designing a Windows Server 2008 R2 deployment strategy for the Minneapolis campus servers.
Which deployment strategy should you recommend?\r\n
General Background
You are the systems administrator for the Graphic Design Institute (GDI). GDI is a private liberal arts and
technical college with campuses in multiple cities.
Technical Background
The campus locations, users, client computers, and servers are described in the following table.

The campuses are connected by a fully meshed WAN.
The corporate network includes Active Directory Domain Services (AD DS). Domain controllers are located
on each campus.
GDI uses Microsoft Windows Deployment Server (WDS) to distribute images by using Preboot Execution
Environment (PXE). GDI builds images by using the Windows Automated Installation Kit (WAIK).
GDI uses Microsoft Windows Server Update Services (WSUS) to distribute and manage Windows security
updates and software updates.
All private client computers and portable computersused by faculty and staff are members of the WSUS
computer group named Staff. All shared client computers are members of the WSUS computer group
named LabComputers. All faculty and staff users aremembers of the global security group named
GDI_Staff. All students are members of the global security group named GDI_Students.
Specific servers are configured as shown in the following table.

The main data center is located on the Boston campus. ADMX and ADML files are centrally stored on
BODC01.
All Charlotte servers reside in the CH_Servers organizational unit (OU). CHDATA01, CHDATA02,
CHDATA03, and CHDATA04 reside in the CH_FileServersOU. CH_FileServers is a child OU of
CH_Servers.
A Group Policy object (GPO) named ServerSettings applies Windows Internet Explorer settings to all
servers.
Business Requirements
After successful migrations to Windows Server 2008 R2 in Boston, New Haven, and Tacoma, GDI plans to
migrate its other campuses to Windows Server 2008 R2 in advance of a full Windows 7 client computer
deployment.
Server deployment on the Austin campus must be performed on weekends by using scheduled
deployments.
The post-migration environment must meet the following business requirements:
Maximize security.
Maximize data protection.
Maximize existing resources.
Minimize downtime.
Technical Requirements
The post-migration environment must meet the following security requirements:
All updates must be distributed by using WSUS.
All critical updates must be installed as soon as possible.
All drives on the Minneapolis campus servers must have Windows BitLocker Drive Encryption enabled.
The post-migration environment must meet the following data protection requirements:
All servers must have automated backup routines.
All backups must be replicated to the Boston data center at the end of each business week.
The post-migration environment must meet the following resource requirements:
Installations and recovery must be performed remotely.
All department volumes on file servers must have NTFS quotas.
Minimize download time for users who open MicrosoftOffice documents over the WAN.
Ensure that users’ files are always opened from theclosest file server when available.
Users’ files must be accessible by the same path from all campuses.

What should you recommend?

Testlet: Graphic Design Institute, Case B
You are planning the migration of client computers on the Northridge campus to Windows 7. Due to
compatibility concerns, the Northridge campus servers will not be migrated to Windows Server 2008 R2.
The Northridge campus uses customized options in the inters.adm and system.adm administrative templates to
handle key security restrictions.
You need to ensure that the security restrictions will be applied to the migrated client computers.
What should you recommend?\r\n
General Background
You are the systems administrator for the Graphic Design Institute (GDI). GDI is a private liberal arts and
technical college with campuses in multiple cities.
Technical Background
The campus locations, users, client computers, and servers are described in the following table.

The campuses are connected by a fully meshed WAN.
The corporate network includes Active Directory Domain Services (AD DS). Domain controllers are located
on each campus.
GDI uses Microsoft Windows Deployment Server (WDS) to distribute images by using Preboot Execution
Environment (PXE). GDI builds images by using the Windows Automated Installation Kit (WAIK).
GDI uses Microsoft Windows Server Update Services (WSUS) to distribute and manage Windows security
updates and software updates.
All private client computers and portable computersused by faculty and staff are members of the WSUS
computer group named Staff. All shared client computers are members of the WSUS computer group
named LabComputers. All faculty and staff users aremembers of the global security group named
GDI_Staff. All students are members of the global security group named GDI_Students.
Specific servers are configured as shown in the following table.

The main data center is located on the Boston campus. ADMX and ADML files are centrally stored on
BODC01.
All Charlotte servers reside in the CH_Servers organizational unit (OU). CHDATA01, CHDATA02,
CHDATA03, and CHDATA04 reside in the CH_FileServersOU. CH_FileServers is a child OU of
CH_Servers.
A Group Policy object (GPO) named ServerSettings applies Windows Internet Explorer settings to all
servers.
Business Requirements
After successful migrations to Windows Server 2008 R2 in Boston, New Haven, and Tacoma, GDI plans to
migrate its other campuses to Windows Server 2008 R2 in advance of a full Windows 7 client computer
deployment.
Server deployment on the Austin campus must be performed on weekends by using scheduled
deployments.
The post-migration environment must meet the following business requirements:
Maximize security.
Maximize data protection.
Maximize existing resources.
Minimize downtime.
Technical Requirements
The post-migration environment must meet the following security requirements:
All updates must be distributed by using WSUS.
All critical updates must be installed as soon as possible.
All drives on the Minneapolis campus servers must have Windows BitLocker Drive Encryption enabled.
The post-migration environment must meet the following data protection requirements:
All servers must have automated backup routines.
All backups must be replicated to the Boston data center at the end of each business week.
The post-migration environment must meet the following resource requirements:
Installations and recovery must be performed remotely.
All department volumes on file servers must have NTFS quotas.
Minimize download time for users who open MicrosoftOffice documents over the WAN.
Ensure that users’ files are always opened from theclosest file server when available.
Users’ files must be accessible by the same path from all campuses.

What should you recommend?

Testlet: Tailspin Toys
You need to recommend a solution to migrate shared printers from the print server at Wingtip Toys to the print
server at Tailspin Toys.
What should you recommend?\r\n
General Background
You are the Windows Server Administrator for Tailspin Toys. Tailspin Toys has a main office and a
manufacturing office.
Tailspin Toys recently acquired Wingtip Toys and isin the beginning stages of Merging the IT environments.
Wingtip Toys has a main office and a sales office.
Technical Background
The companies use the network subnets indicated in the following table:

The Tailspin Toys network and the Wingtip Toys are connected by a point-to-point dedicated 45 Mbps
circuit that terminates in the main offices.
The current Tailspin Toys server topology is shown in the following table:

The Tailspin Toys environment has the following characteristics:
All servers are joined to the tailspintoys.com domain
In the Default Domain Policy, the Retain old eventsGroup Policy setting is enabled.
An Active Directory security group named “Windows System Administrators” is used to control all files
and folders on TT-PRINT01
A Tailspin Toys administrator named Marx has been delegated rights to multiple Organizational Units
(OUs) and object in the tailspintoys.com domain.
Tailspin Toys developers use Hyper-V Virtual Machines (VM’s) for development. There are 10
development VM’s named TT-DEV01 to TT-DEV20
The current Wingtip Toys server topology is shown in the following table:

All servers in the Wingtip Toys environment are joined to the wingtiptoys.com domain.
Infrastructure Services
You must ensure that the following infrastructure services requirements are met:
All domain zones must be stored as Active Directory-integrated zones.
Only DNS servers located in the Tailspin Toys main offices may communicate with the DNS servers at
Wingtip Toys.
Only DNS servers located in the Wingtip Toys main offices may communicate with the DNS servers at
Tailspin Toys
All tailspintoys.com resources must be resolved from the Wingtip Toys offices.
All wingtiptoys.com resources must be resolved fromthe Tailspin toys offices.
Certificates must be distributed automatically to all Tailspin Toys and Wingtip Toys computers.
Delegated Administration
You must ensure that the following delegated administration requirements are met:
Tailspin Toys IT security administrators must be able to create, modify and delete user objects in the
wingtip.com domain.
Members of the Domain Admins Group in the tailspintoys.com domain must have full access to the
wingtiptoys.com Active Directory environment.
A delegation policy must grant minimum access rights and simplify the process of delegating rights.
Minimum permissions must always be delegated to ensure that the least privilege is granted for a job
task.
Members of the TAILSPINTOYS\Helpdesk group must be able to update drivers and add printer ports
on TT-PRINT01.
Members of the TAILSPINTOYS\Helpdesk group must notbe able to cancel a print job on TT-PRINT01.
Tailspin Toys developers must be able to start,stopand apply snapshots to their development VM’s.
IT Security
Server security must be automated to ensure that newly deployed servers automatically have the same
security configurations as existing servers.
Auditing must be configured to ensure that the deletion of users objects and OUs is logged.
Microsoft Word and Microsoft Excel files must be automatically encrypted when uploaded to the
Confidential documents library on the Tailspin ToysMicrosoft SharePoint site.
Multi factor authentication must control access to Tailspin Toys domain controllers.
All file and folder auditing must capture the reason for access.
All folder auditing must capture all delete actionsfor all existing folders and newly created folders.
New events must be written to the Security event log in the tailspintoys.com domain and retained
indefinitely.
Drive X:\ on the TT-FILE01 must be encrypted by using Windows BitLocker Drive Encryption and must
be automatically unlock.

What should you recommend?

Testlet: Tailspin Toys
You are planning for the IT integration of TailspinToys and Wingtip Toys.
The company has decided on the following name resolution requirements:
Name resolution for Internet-based resources must continue to operate by using the same DNS servers as
prior to the merger.
The existing connectivity between Tailspin Toys andWingtip Toys must be used for all network
communication.
The documented name resolution goals must be met.
You need to provide a name resolution solution thatmeets the requirements.
What should you recommend? (Choose all that apply.)\r\n
General Background
You are the Windows Server Administrator for Tailspin Toys. Tailspin Toys has a main office and a
manufacturing office.
Tailspin Toys recently acquired Wingtip Toys and isin the beginning stages of Merging the IT environments.
Wingtip Toys has a main office and a sales office.
Technical Background
The companies use the network subnets indicated in the following table:

The Tailspin Toys network and the Wingtip Toys are connected by a point-to-point dedicated 45 Mbps
circuit that terminates in the main offices.
The current Tailspin Toys server topology is shown in the following table:

The Tailspin Toys environment has the following characteristics:
All servers are joined to the tailspintoys.com domain
In the Default Domain Policy, the Retain old eventsGroup Policy setting is enabled.
An Active Directory security group named “Windows System Administrators” is used to control all files
and folders on TT-PRINT01
A Tailspin Toys administrator named Marx has been delegated rights to multiple Organizational Units
(OUs) and object in the tailspintoys.com domain.
Tailspin Toys developers use Hyper-V Virtual Machines (VM’s) for development. There are 10
development VM’s named TT-DEV01 to TT-DEV20
The current Wingtip Toys server topology is shown in the following table:

All servers in the Wingtip Toys environment are joined to the wingtiptoys.com domain.
Infrastructure Services
You must ensure that the following infrastructure services requirements are met:
All domain zones must be stored as Active Directory-integrated zones.
Only DNS servers located in the Tailspin Toys main offices may communicate with the DNS servers at
Wingtip Toys.
Only DNS servers located in the Wingtip Toys main offices may communicate with the DNS servers at
Tailspin Toys
All tailspintoys.com resources must be resolved from the Wingtip Toys offices.
All wingtiptoys.com resources must be resolved fromthe Tailspin toys offices.
Certificates must be distributed automatically to all Tailspin Toys and Wingtip Toys computers.
Delegated Administration
You must ensure that the following delegated administration requirements are met:
Tailspin Toys IT security administrators must be able to create, modify and delete user objects in the
wingtip.com domain.
Members of the Domain Admins Group in the tailspintoys.com domain must have full access to the
wingtiptoys.com Active Directory environment.
A delegation policy must grant minimum access rights and simplify the process of delegating rights.
Minimum permissions must always be delegated to ensure that the least privilege is granted for a job
task.
Members of the TAILSPINTOYS\Helpdesk group must be able to update drivers and add printer ports
on TT-PRINT01.
Members of the TAILSPINTOYS\Helpdesk group must notbe able to cancel a print job on TT-PRINT01.
Tailspin Toys developers must be able to start,stopand apply snapshots to their development VM’s.
IT Security
Server security must be automated to ensure that newly deployed servers automatically have the same
security configurations as existing servers.
Auditing must be configured to ensure that the deletion of users objects and OUs is logged.
Microsoft Word and Microsoft Excel files must be automatically encrypted when uploaded to the
Confidential documents library on the Tailspin ToysMicrosoft SharePoint site.
Multi factor authentication must control access to Tailspin Toys domain controllers.
All file and folder auditing must capture the reason for access.
All folder auditing must capture all delete actionsfor all existing folders and newly created folders.
New events must be written to the Security event log in the tailspintoys.com domain and retained
indefinitely.
Drive X:\ on the TT-FILE01 must be encrypted by using Windows BitLocker Drive Encryption and must
be automatically unlock.

What should you recommend?

Testlet: Tailspin Toys
You need to recommend a solution to meet the IT security requirements and data encryption requirementsfor
TT-FILE01 with the minimum administrative effort.
What should you recommend? (Choose all that apply.)\r\n
General Background
You are the Windows Server Administrator for Tailspin Toys. Tailspin Toys has a main office and a
manufacturing office.
Tailspin Toys recently acquired Wingtip Toys and isin the beginning stages of Merging the IT environments.
Wingtip Toys has a main office and a sales office.
Technical Background
The companies use the network subnets indicated in the following table:

The Tailspin Toys network and the Wingtip Toys are connected by a point-to-point dedicated 45 Mbps
circuit that terminates in the main offices.
The current Tailspin Toys server topology is shown in the following table:

The Tailspin Toys environment has the following characteristics:
All servers are joined to the tailspintoys.com domain
In the Default Domain Policy, the Retain old eventsGroup Policy setting is enabled.
An Active Directory security group named “Windows System Administrators” is used to control all files
and folders on TT-PRINT01
A Tailspin Toys administrator named Marx has been delegated rights to multiple Organizational Units
(OUs) and object in the tailspintoys.com domain.
Tailspin Toys developers use Hyper-V Virtual Machines (VM’s) for development. There are 10
development VM’s named TT-DEV01 to TT-DEV20
The current Wingtip Toys server topology is shown in the following table:

All servers in the Wingtip Toys environment are joined to the wingtiptoys.com domain.
Infrastructure Services
You must ensure that the following infrastructure services requirements are met:
All domain zones must be stored as Active Directory-integrated zones.
Only DNS servers located in the Tailspin Toys main offices may communicate with the DNS servers at
Wingtip Toys.
Only DNS servers located in the Wingtip Toys main offices may communicate with the DNS servers at
Tailspin Toys
All tailspintoys.com resources must be resolved from the Wingtip Toys offices.
All wingtiptoys.com resources must be resolved fromthe Tailspin toys offices.
Certificates must be distributed automatically to all Tailspin Toys and Wingtip Toys computers.
Delegated Administration
You must ensure that the following delegated administration requirements are met:
Tailspin Toys IT security administrators must be able to create, modify and delete user objects in the
wingtip.com domain.
Members of the Domain Admins Group in the tailspintoys.com domain must have full access to the
wingtiptoys.com Active Directory environment.
A delegation policy must grant minimum access rights and simplify the process of delegating rights.
Minimum permissions must always be delegated to ensure that the least privilege is granted for a job
task.
Members of the TAILSPINTOYS\Helpdesk group must be able to update drivers and add printer ports
on TT-PRINT01.
Members of the TAILSPINTOYS\Helpdesk group must notbe able to cancel a print job on TT-PRINT01.
Tailspin Toys developers must be able to start,stopand apply snapshots to their development VM’s.
IT Security
Server security must be automated to ensure that newly deployed servers automatically have the same
security configurations as existing servers.
Auditing must be configured to ensure that the deletion of users objects and OUs is logged.
Microsoft Word and Microsoft Excel files must be automatically encrypted when uploaded to the
Confidential documents library on the Tailspin ToysMicrosoft SharePoint site.
Multi factor authentication must control access to Tailspin Toys domain controllers.
All file and folder auditing must capture the reason for access.
All folder auditing must capture all delete actionsfor all existing folders and newly created folders.
New events must be written to the Security event log in the tailspintoys.com domain and retained
indefinitely.
Drive X:\ on the TT-FILE01 must be encrypted by using Windows BitLocker Drive Encryption and must
be automatically unlock.

What should you recommend?

Testlet: Tailspin Toys
You need to recommend a solution that meets the following requirements:
Log access to all shared folders on TT-FILE02.
Minimize administrative effort.
Ensure that further administrative action is not required when new shared folders are added to TT-FILE02.
What should you recommend?\r\n
General Background
You are the Windows Server Administrator for Tailspin Toys. Tailspin Toys has a main office and a
manufacturing office.
Tailspin Toys recently acquired Wingtip Toys and isin the beginning stages of Merging the IT environments.
Wingtip Toys has a main office and a sales office.
Technical Background
The companies use the network subnets indicated in the following table:

The Tailspin Toys network and the Wingtip Toys are connected by a point-to-point dedicated 45 Mbps
circuit that terminates in the main offices.
The current Tailspin Toys server topology is shown in the following table:

The Tailspin Toys environment has the following characteristics:
All servers are joined to the tailspintoys.com domain
In the Default Domain Policy, the Retain old eventsGroup Policy setting is enabled.
An Active Directory security group named “Windows System Administrators” is used to control all files
and folders on TT-PRINT01
A Tailspin Toys administrator named Marx has been delegated rights to multiple Organizational Units
(OUs) and object in the tailspintoys.com domain.
Tailspin Toys developers use Hyper-V Virtual Machines (VM’s) for development. There are 10
development VM’s named TT-DEV01 to TT-DEV20
The current Wingtip Toys server topology is shown in the following table:

All servers in the Wingtip Toys environment are joined to the wingtiptoys.com domain.
Infrastructure Services
You must ensure that the following infrastructure services requirements are met:
All domain zones must be stored as Active Directory-integrated zones.
Only DNS servers located in the Tailspin Toys main offices may communicate with the DNS servers at
Wingtip Toys.
Only DNS servers located in the Wingtip Toys main offices may communicate with the DNS servers at
Tailspin Toys
All tailspintoys.com resources must be resolved from the Wingtip Toys offices.
All wingtiptoys.com resources must be resolved fromthe Tailspin toys offices.
Certificates must be distributed automatically to all Tailspin Toys and Wingtip Toys computers.
Delegated Administration
You must ensure that the following delegated administration requirements are met:
Tailspin Toys IT security administrators must be able to create, modify and delete user objects in the
wingtip.com domain.
Members of the Domain Admins Group in the tailspintoys.com domain must have full access to the
wingtiptoys.com Active Directory environment.
A delegation policy must grant minimum access rights and simplify the process of delegating rights.
Minimum permissions must always be delegated to ensure that the least privilege is granted for a job
task.
Members of the TAILSPINTOYS\Helpdesk group must be able to update drivers and add printer ports
on TT-PRINT01.
Members of the TAILSPINTOYS\Helpdesk group must notbe able to cancel a print job on TT-PRINT01.
Tailspin Toys developers must be able to start,stopand apply snapshots to their development VM’s.
IT Security
Server security must be automated to ensure that newly deployed servers automatically have the same
security configurations as existing servers.
Auditing must be configured to ensure that the deletion of users objects and OUs is logged.
Microsoft Word and Microsoft Excel files must be automatically encrypted when uploaded to the
Confidential documents library on the Tailspin ToysMicrosoft SharePoint site.
Multi factor authentication must control access to Tailspin Toys domain controllers.
All file and folder auditing must capture the reason for access.
All folder auditing must capture all delete actionsfor all existing folders and newly created folders.
New events must be written to the Security event log in the tailspintoys.com domain and retained
indefinitely.
Drive X:\ on the TT-FILE01 must be encrypted by using Windows BitLocker Drive Encryption and must
be automatically unlock.

What should you recommend?

Testlet: Tailspin Toys
You need to recommend a solution to meet the certificate distribution requirements.
What should you recommend?\r\n
General Background
You are the Windows Server Administrator for Tailspin Toys. Tailspin Toys has a main office and a
manufacturing office.
Tailspin Toys recently acquired Wingtip Toys and isin the beginning stages of Merging the IT environments.
Wingtip Toys has a main office and a sales office.
Technical Background
The companies use the network subnets indicated in the following table:

The Tailspin Toys network and the Wingtip Toys are connected by a point-to-point dedicated 45 Mbps
circuit that terminates in the main offices.
The current Tailspin Toys server topology is shown in the following table:

The Tailspin Toys environment has the following characteristics:
All servers are joined to the tailspintoys.com domain
In the Default Domain Policy, the Retain old eventsGroup Policy setting is enabled.
An Active Directory security group named “Windows System Administrators” is used to control all files
and folders on TT-PRINT01
A Tailspin Toys administrator named Marx has been delegated rights to multiple Organizational Units
(OUs) and object in the tailspintoys.com domain.
Tailspin Toys developers use Hyper-V Virtual Machines (VM’s) for development. There are 10
development VM’s named TT-DEV01 to TT-DEV20
The current Wingtip Toys server topology is shown in the following table:

All servers in the Wingtip Toys environment are joined to the wingtiptoys.com domain.
Infrastructure Services
You must ensure that the following infrastructure services requirements are met:
All domain zones must be stored as Active Directory-integrated zones.
Only DNS servers located in the Tailspin Toys main offices may communicate with the DNS servers at
Wingtip Toys.
Only DNS servers located in the Wingtip Toys main offices may communicate with the DNS servers at
Tailspin Toys
All tailspintoys.com resources must be resolved from the Wingtip Toys offices.
All wingtiptoys.com resources must be resolved fromthe Tailspin toys offices.
Certificates must be distributed automatically to all Tailspin Toys and Wingtip Toys computers.
Delegated Administration
You must ensure that the following delegated administration requirements are met:
Tailspin Toys IT security administrators must be able to create, modify and delete user objects in the
wingtip.com domain.
Members of the Domain Admins Group in the tailspintoys.com domain must have full access to the
wingtiptoys.com Active Directory environment.
A delegation policy must grant minimum access rights and simplify the process of delegating rights.
Minimum permissions must always be delegated to ensure that the least privilege is granted for a job
task.
Members of the TAILSPINTOYS\Helpdesk group must be able to update drivers and add printer ports
on TT-PRINT01.
Members of the TAILSPINTOYS\Helpdesk group must notbe able to cancel a print job on TT-PRINT01.
Tailspin Toys developers must be able to start,stopand apply snapshots to their development VM’s.
IT Security
Server security must be automated to ensure that newly deployed servers automatically have the same
security configurations as existing servers.
Auditing must be configured to ensure that the deletion of users objects and OUs is logged.
Microsoft Word and Microsoft Excel files must be automatically encrypted when uploaded to the
Confidential documents library on the Tailspin ToysMicrosoft SharePoint site.
Multi factor authentication must control access to Tailspin Toys domain controllers.
All file and folder auditing must capture the reason for access.
All folder auditing must capture all delete actionsfor all existing folders and newly created folders.
New events must be written to the Security event log in the tailspintoys.com domain and retained
indefinitely.
Drive X:\ on the TT-FILE01 must be encrypted by using Windows BitLocker Drive Encryption and must
be automatically unlock.

What would you recommend?

Testlet: Tailspin Toys
You need to remove Marc’s delegated rights.
What would you recommend?\r\n
General Background
You are the Windows Server Administrator for Tailspin Toys. Tailspin Toys has a main office and a
manufacturing office.
Tailspin Toys recently acquired Wingtip Toys and isin the beginning stages of Merging the IT environments.
Wingtip Toys has a main office and a sales office.
Technical Background
The companies use the network subnets indicated in the following table:

The Tailspin Toys network and the Wingtip Toys are connected by a point-to-point dedicated 45 Mbps
circuit that terminates in the main offices.
The current Tailspin Toys server topology is shown in the following table:

The Tailspin Toys environment has the following characteristics:
All servers are joined to the tailspintoys.com domain
In the Default Domain Policy, the Retain old eventsGroup Policy setting is enabled.
An Active Directory security group named “Windows System Administrators” is used to control all files
and folders on TT-PRINT01
A Tailspin Toys administrator named Marx has been delegated rights to multiple Organizational Units
(OUs) and object in the tailspintoys.com domain.
Tailspin Toys developers use Hyper-V Virtual Machines (VM’s) for development. There are 10
development VM’s named TT-DEV01 to TT-DEV20
The current Wingtip Toys server topology is shown in the following table:

All servers in the Wingtip Toys environment are joined to the wingtiptoys.com domain.
Infrastructure Services
You must ensure that the following infrastructure services requirements are met:
All domain zones must be stored as Active Directory-integrated zones.
Only DNS servers located in the Tailspin Toys main offices may communicate with the DNS servers at
Wingtip Toys.
Only DNS servers located in the Wingtip Toys main offices may communicate with the DNS servers at
Tailspin Toys
All tailspintoys.com resources must be resolved from the Wingtip Toys offices.
All wingtiptoys.com resources must be resolved fromthe Tailspin toys offices.
Certificates must be distributed automatically to all Tailspin Toys and Wingtip Toys computers.
Delegated Administration
You must ensure that the following delegated administration requirements are met:
Tailspin Toys IT security administrators must be able to create, modify and delete user objects in the
wingtip.com domain.
Members of the Domain Admins Group in the tailspintoys.com domain must have full access to the
wingtiptoys.com Active Directory environment.
A delegation policy must grant minimum access rights and simplify the process of delegating rights.
Minimum permissions must always be delegated to ensure that the least privilege is granted for a job
task.
Members of the TAILSPINTOYS\Helpdesk group must be able to update drivers and add printer ports
on TT-PRINT01.
Members of the TAILSPINTOYS\Helpdesk group must notbe able to cancel a print job on TT-PRINT01.
Tailspin Toys developers must be able to start,stopand apply snapshots to their development VM’s.
IT Security
Server security must be automated to ensure that newly deployed servers automatically have the same
security configurations as existing servers.
Auditing must be configured to ensure that the deletion of users objects and OUs is logged.
Microsoft Word and Microsoft Excel files must be automatically encrypted when uploaded to the
Confidential documents library on the Tailspin ToysMicrosoft SharePoint site.
Multi factor authentication must control access to Tailspin Toys domain controllers.
All file and folder auditing must capture the reason for access.
All folder auditing must capture all delete actionsfor all existing folders and newly created folders.
New events must be written to the Security event log in the tailspintoys.com domain and retained
indefinitely.
Drive X:\ on the TT-FILE01 must be encrypted by using Windows BitLocker Drive Encryption and must
be automatically unlock.

What should you recommend?

Testlet: Tailspin Toys
You need to recommend a solution to meet the following requirements:
Meet the company auditing requirements.
Ensure that further administrative action is not required when new folders are added to the file server.
What should you recommend? (Choose all that apply.)\r\n
General Background
You are the Windows Server Administrator for Tailspin Toys. Tailspin Toys has a main office and a
manufacturing office.
Tailspin Toys recently acquired Wingtip Toys and isin the beginning stages of Merging the IT environments.
Wingtip Toys has a main office and a sales office.
Technical Background
The companies use the network subnets indicated in the following table:

The Tailspin Toys network and the Wingtip Toys are connected by a point-to-point dedicated 45 Mbps
circuit that terminates in the main offices.
The current Tailspin Toys server topology is shown in the following table:

The Tailspin Toys environment has the following characteristics:
All servers are joined to the tailspintoys.com domain
In the Default Domain Policy, the Retain old eventsGroup Policy setting is enabled.
An Active Directory security group named “Windows System Administrators” is used to control all files
and folders on TT-PRINT01
A Tailspin Toys administrator named Marx has been delegated rights to multiple Organizational Units
(OUs) and object in the tailspintoys.com domain.
Tailspin Toys developers use Hyper-V Virtual Machines (VM’s) for development. There are 10
development VM’s named TT-DEV01 to TT-DEV20
The current Wingtip Toys server topology is shown in the following table:

All servers in the Wingtip Toys environment are joined to the wingtiptoys.com domain.
Infrastructure Services
You must ensure that the following infrastructure services requirements are met:
All domain zones must be stored as Active Directory-integrated zones.
Only DNS servers located in the Tailspin Toys main offices may communicate with the DNS servers at
Wingtip Toys.
Only DNS servers located in the Wingtip Toys main offices may communicate with the DNS servers at
Tailspin Toys
All tailspintoys.com resources must be resolved from the Wingtip Toys offices.
All wingtiptoys.com resources must be resolved fromthe Tailspin toys offices.
Certificates must be distributed automatically to all Tailspin Toys and Wingtip Toys computers.
Delegated Administration
You must ensure that the following delegated administration requirements are met:
Tailspin Toys IT security administrators must be able to create, modify and delete user objects in the
wingtip.com domain.
Members of the Domain Admins Group in the tailspintoys.com domain must have full access to the
wingtiptoys.com Active Directory environment.
A delegation policy must grant minimum access rights and simplify the process of delegating rights.
Minimum permissions must always be delegated to ensure that the least privilege is granted for a job
task.
Members of the TAILSPINTOYS\Helpdesk group must be able to update drivers and add printer ports
on TT-PRINT01.
Members of the TAILSPINTOYS\Helpdesk group must notbe able to cancel a print job on TT-PRINT01.
Tailspin Toys developers must be able to start,stopand apply snapshots to their development VM’s.
IT Security
Server security must be automated to ensure that newly deployed servers automatically have the same
security configurations as existing servers.
Auditing must be configured to ensure that the deletion of users objects and OUs is logged.
Microsoft Word and Microsoft Excel files must be automatically encrypted when uploaded to the
Confidential documents library on the Tailspin ToysMicrosoft SharePoint site.
Multi factor authentication must control access to Tailspin Toys domain controllers.
All file and folder auditing must capture the reason for access.
All folder auditing must capture all delete actionsfor all existing folders and newly created folders.
New events must be written to the Security event log in the tailspintoys.com domain and retained
indefinitely.
Drive X:\ on the TT-FILE01 must be encrypted by using Windows BitLocker Drive Encryption and must
be automatically unlock.


Page 24 of 24« First...10...2021222324