Which toolshould you use?
Your network contains an Active Directory forestnamed contoso.com.
The forest contains six domains.
You need to ensure that the administrators of any of the domains can specify a user principal name
(UPN) suffix of litwareinc.com when they create user accounts by using Active Directory Users and
Computers.
Which toolshould you use?
Which toolshould you use?
Your network contains an Active Directory domainnamed litwareinc.com.
The domain contains two sitesnamed Site1and Site2.
Site2contains a read-only domain controller(RODC).
You need to identify which user accounts attempted to authenticate to the RODC.
Which toolshould you use?
You need to generate a file that contains the last logon time and the custom attribute values for each user in
Your network contains an Active Directory forest.
The forest schemacontains a custom attribute for user objects.
You need to generate a file that contains the last logon time and the custom attribute values for each
user in the forest.
What should you use?
Which toolshould you use?
You have an Active Directory domainnamed contoso.com.
You need to view the account lockout threshold and duration for the domain.
Which toolshould you use?
You need to ensure that DNS1 receives zone updates fromDC4
A domain controllernamed DC4runs Windows Server 2008 R2.
DC4is configured as a DNS server for fabrikam.com.
You install the DNS Server server roleon a member servernamed DNS1and then you create a standard
secondary zone for fabrikam.com.
You configure DC4as the master server for the zone.
You need to ensure that DNS1 receives zone updates fromDC4.
What should you do?
What should you do first?
A company has an Active Directory forest.
You plan to installan offline Enterprise root certification authority (CA)on a servernamed CA1.
CA1is a memberof the PerimeterNetwork workgroupand is attached to a hardware security module for
private key storage.
You attempt to add the Active Directory Certificate Services (AD CS) server role to CA1.
The Enterprise CA option is not available.
You needto install the AD CS server role as an Enterprise CA on CA1.
What should you do first?
You need to install a Microsoft Office 2007 applicationonly on the computers in the Marketing OUs
Your company has an Active Directory forest.
Each regional officehas an organizational unit(OU) named Marketing.
The Marketing OU contains all users and computers in the region’s Marketing department.
You need to install a Microsoft Office 2007 applicationonly on the computers in the Marketing OUs.
You create a GPO named MarketingApps.
What should you do next?
You need to ensure that DC1 and DC4 are the only servers that replicate Active Directory changes between the s
how many dayswill the record be deleted?
Your network contains an Active Directory domainnamed contoso.com.
The domain contains a domain controllernamed DC1.
DC1has the DNS Server roleinstalled and hosts an Active Directory-integrated zone for contoso.com.
The no-refresh intervaland the refresh intervalare both set to three days.
The Advanced DNS settingsof DC1are shown in the Advanced DNS Settings exhibit:
You open the propertiesof a static recordnamed Server1as shown in the Server1 Record exhibit:
You discover that the scavenging process ran today, but the record for Server1 was not deleted.
You run dnscmd.exeand specify the ageallrecords parameter.
You need to identify when the record for Server1 will be deleted from the zone.
In how many dayswill the record be deleted?
What should you do?
Your network contains an Active Directory domain.
The domain is configured as shown in the exhibit:
Each organizational unit(OU) contains over 500 user accounts.
The Finance OUand the Human Resources OUcontain several user accountsthat are members of a
universal groupnamed Group1.
You have a Group Policy object (GPO) linked to the domain.
You needto prevent the GPO from being applied to the members of Group1 only.
What should you do?
Exhibit: