网友您好, 请在下方输入框内输入要搜索的题目:

题目内容 (请给出正确答案)
多选题
Your company has an Active Directory domain. You plan to install the Active Directory Certificate Services (AD CS) server role on a member  server that runs Windows Server 2008 R2.     You need to ensure that members of the Account Operators group are able to issue smartcard  credentials. They should not be able to revoke certificates.     Which three actions should you perform()
A

Install the AD CS server role and configure it as an Enterprise Root CA .

B

Install the AD CS server role and configure it as a Standalone CA .

C

Restrict enrollment agents for the Smartcard logon certificate to the Account Operator group.

D

Restrict certificate managers for the Smartcard logon certificate to the Account Operator group.

E

Create a Smartcard logon certificate.

F

Create an Enrollment Agent certificate.


参考答案

参考解析
解析: 暂无解析
更多 “多选题Your company has an Active Directory domain. You plan to install the Active Directory Certificate Services (AD CS) server role on a member  server that runs Windows Server 2008 R2.     You need to ensure that members of the Account Operators group are able to issue smartcard  credentials. They should not be able to revoke certificates.     Which three actions should you perform()AInstall the AD CS server role and configure it as an Enterprise Root CA .BInstall the AD CS server role and configure it as a Standalone CA .CRestrict enrollment agents for the Smartcard logon certificate to the Account Operator group.DRestrict certificate managers for the Smartcard logon certificate to the Account Operator group.ECreate a Smartcard logon certificate.FCreate an Enrollment Agent certificate.” 相关考题
考题 Your company has a single Active Directory directory service domain. All servers in your environment run Windows Server 2003. Client computers run Windows XP or Windows Vista. You plan to create a security update scan procedure for client computers. You need to choose a security tool that supports all the client computers.  Which tool should you choose? ()A、 UrlScan Security ToolB、 Enterprise Scan Tool (EST)C、 Malicious Removal Tool (MRT)D、 Microsoft Baseline Security Analyzer (MBSA)

考题 Your company has a branch office that is configured as a separate Active Directory site and has  an Active Directory domain controller.     The Active Directory site requires a local Global Catalog server to support a new application.     You need to configure the domain controller as a Global Catalog server.     Which tool should you use()A、The Dcpromo.exe utilityB、The Server Manager consoleC、The Computer Management consoleD、The Active Directory Sites and Services consoleE、The Active Directory Domains and Trusts console

考题 Your network consists of a single Active Directory domain. All domain controllers run Windows Server2008 R2. Your company and an external partner plan to collaborate on a project. The external partner has an Active Directory domain that contains Windows Server 2008 R2 domain controllers. You need to design a collaboration solution that meets the following requirements:   èAllows users to prevent sensitive documents from being forwarded to untrusted recipients or from being  printed.   èAllows users in the external partner organization to access the protected content to which they have been granted rights.   èSends all inter-organizational traffic over port 443.   èMinimizes the administrative effort required to manage the external users. What should you include in your design?()A、Establish a federated trust between your company and the external partner. Deploy a Windows Server 2008 R2 server that has Microsoft SharePoint Foundation 2010 installed.B、Establish a federated trust between your company and the external partner. Deploy a Windows Server 2008 R2 server that runs Microsoft SharePoint 2010 and that has the Active Directory Rights  Management Services (AD?RMS) role installed.C、Establish an external forest trust between your company and the external partner. Deploy a Windows Server 2008 R2 server that has the Active Directory Certificate Services server role installed. Implement Encrypting File System (EFS).D、Establish an external forest trust between your company and the external partner. Deploy a Windows Server 2008 R2 server that has the Active Directory Rights Management Service (AD?RMS)role installed  and Microsoft SharePoint Foundation 2010 installed.

考题 Your company has a single Active Directory directory service forest with three domains. You plan to modify the Active Directory schema. You need to identify the schema master for the forest.  What should you do?()A、 Run the regsvr32 schmmgmt.dll command. Use the Active Directory Domains and Trusts snap-in. B、 Run the regsvr32 schmmgmt.dll command. Use the Active Directory Users and Computers snap-in. C、 Use the Dsget command-line tool.D、 Use the Dsquery command-line tool.

考题 You are a network administrator for Alpine Ski House. The network consists of a single Active Directory domain. The domain name is alpineskihouse.com. The network contains three Windows Server 2003 domain controllers. You are creating the recovery plan for the company. According to the existing backup plan, domain controllers are backed up by using normal backups each night. The normal backups of the domain controllers include the system state of each domain controller. Your recovery plan must incorporate the following organizational requirements. Active Directory objects that are accidentally or maliciously deleted must be recoverable. Active Directory must be restored to its most recent state as quickly as possible. Active Directory database replication must be minimized.You need to create a plan to restore a deleted organizational unit (OU).  Which two actions should you include in your plan?()A、 Restart a domain controller in Directory Services Restore Mode.B、 Restart a domain controller in Safe Mode.C、 Use the Ntdsutil utility to perform an authoritative restore operation of the Active Directory database.D、 Restore the system state by using the Always replace the file on my computer option.E、 Use the Ntdsutil utility to perform an authoritative restore operation of the appropriate subtree.

考题 Your company has an Active Directory domain. The company has two domain controllers named  DC1 and DC2. DC1 holds the schema master role.   DC1 fails. You log on to Active Directory by using the administrator account. You are not able to  transfer the schema master role.     You need to ensure that DC2 holds the schema master role.     What should you do()A、Register the Schmmgmt.dll. Start the Active Directory Schema snap-in.B、Configure DC2 as a bridgehead server.C、On DC2, seize the schema master role.D、Log off and log on again to Active Directory by using an account that is a member of the Schema Admins group. St

考题 Your company has a main office and three branch offices. The company has an Active Directory forest that has a single domain. Each office has one domain controller. Each office is configured as an Active Directory site. All sites are connected with the DEFAULTIPSITELINK object. You need to decrease the replication latency between the domain controllers. What should you do()A、Decrease the cost between the connection objects.B、Decrease the replication interval for all connection objects.C、Decrease the replication interval for the DEFAUL TIPSITELINK object.D、Decrease the replication schedule for the DEFAUL TIPSITELINK object.

考题 单选题Your company has an Active Directory domain. The company has two domain controllers named DC1   and DC2. DC1 holds the schema master role.    DC1 fails. You log on to Active Directory by using the administrator account. You are not able to transfer  the schema master role.    You need to ensure that DC2 holds the schema master role.  What should you do()A Register the Schmmgmt.dll. Start the Active Directory Schema snap-in.B Configure DC2 as a bridgehead server.C On DC2, seize the schema master role.D Log off and log on again to Active Directory by using an account that is a member of the Schema  Admins group. Start the Active Directory Schema snap-in.

考题 单选题Your company has an Active Directory domain. A user attempts to log on to a computer that was turned off for twelve weeks. The administrator receives an error message that authentication has failed. You need to ensure that the user is able to log on to the computer. What should you do()A Run the netdom TRUST /reset command.B Run the netsh command with the set and machine options.C Run the Active Directory Users and Computers console to disable, and then enable the computer account.D Reset the computer account. Disjoin the computer from the domain, and then rejoin the computer to the domain.

考题 单选题Your company has an Active Directory domain. The company has two domain controllers named DC1 and DC2. DC1 holds the Schema Master role DC1 fails You log on to Actrve Directory by using the administrator account. You are not able to transfer the Schema Master operations role. You need to ensure that DC2 holds the Schema Master role. What should you do()A Register the Schmmgmt.dll. Start the Active Directory Schema snap-in.B Configure DC2 as a bridgehead serverC On DC2, seize the Schema Master roleD Log off and log on again to Active Directory by using an account that is a member of the Schema Administrators group. Start the Actrve Directory Schema snap-in.

考题 单选题Your company has a single Active Directory directory service forest with three domains. You plan to modify the Active Directory schema. You need to identify the schema master for the forest.  What should you do?()A  Run the regsvr32 schmmgmt.dll command. Use the Active Directory Domains and Trusts snap-in. B  Run the regsvr32 schmmgmt.dll command. Use the Active Directory Users and Computers snap-in. C  Use the Dsget command-line tool.D  Use the Dsquery command-line tool.

考题 单选题Your company has an Active Directory domain. You log on to the domain controller. The Active Directory Schema snap-in is not available in the Microsoft Management Console (MMC). You need to access the Actrve Directory Schema snap-in. What should you do()A Register Schmmgml.dll.B Log off and log on again by using an account that is a member of the Schema Administrators group.C Use the Ntdsutil.exe command to connect to the Schema Master operations master and open the schema for writing.D Add the Active Directory Lightweight Directory Services (AD LDS) role to the domain controller by using Server Manager.

考题 单选题Your company has an Active Directory forest. You plan to install an Enterprise certification authority (CA) on a dedicated stand-alone server. When you attempt to add the Active Directory Certificate Services (AD CS) role, you find that the Enterprise CA option is not available. You need to install the AD CS role as an Enterprise CA. What should you do first()A Add the DNS Server role.B Join the server to the domain.C Add the Web server (IIS) role and the AD CS role.D Add the Active Directory Lightweight Directory Service (AD LDS) role.

考题 单选题Your company has an Active Directory domain.     You log on to the domain controller. The Active Directory Schema snap-in is not available in the  Microsoft Management Console (MMC).   You need to access the Active Directory Schema snap-in.     What should you do()A Register Schmmgmt.dll.B Log off and log on again by using an account that is a member of the Schema Admins group.C Use the Ntdsutil.exe command to connect to the schema master operations master and open the schema for writingD Add the Active Directory Lightweight Directory Services (AD/LDS) role to the domain controller by using Server Man

考题 单选题Your company has a single Active Directory directory service domain. All servers in your environment run Windows Server 2003. All domain controllers run Active DirectoryCintegrated DNS. You create several static host (A) resource records. You need to verify that the DNS server is sending the correct host records to all client computers.  Which command-line tool should you use?()A  netshB  tracertC  ntdsutilD  nslookup

考题 单选题Your company has a main office and a branch office. You plan to deploy a Read-only Domain  Controller (RODC) in the branch office.   You need to plan a strategy to manage the RODC. Your plan must meet the following requirements:   èAllow branch office support technicians to maintain drivers and disks on the RODC èPrevent branch office support technicians from managing domain user accounts  What should you include in your plan?()A Configure the RODC for Administrator Role Separation.B Configure the RODC to replicate the password for the branch office support technicians.C Set NTFS permissions on the Active Directory database to Read  Execute for the branch officesupport technicians.D Set NTFS permissions on the Active Directory database to Deny Full Control for the branch office support technicians.

考题 单选题Your company has a branch office that is configured as a separate Active Directory site and has an  Active Directory domain controller.   The Active Directory site requires a local Global Catalog server to support a new application.  You need to configure the domain controller as a Global Catalog server.  Which tool should you use()A The Dcpromo.exe utilityB The Server Manager consoleC The Computer Management consoleD The Active Directory Sites and Services consoleE The Active Directory Domains and Trusts console

考题 单选题Your company has a single Active Directory directory service domain. All servers in your environment run Windows Server 2003. Client computers run Windows XP or Windows Vista. You plan to create a security update scan procedure for client computers. You need to choose a security tool that supports all the client computers.  Which tool should you choose? ()A  UrlScan Security ToolB  Enterprise Scan Tool (EST)C  Malicious Removal Tool (MRT)D  Microsoft Baseline Security Analyzer (MBSA)

考题 单选题Your company has an Active Directory forest that contains a single domain. The domain member   server has an Active Directory Federation Services (AD FS) server role installed.   You need to configure AD FS to ensure that AD FS tokens contain information from the Active Directory  domain.   What should you do()A Add and configure a new account store.B Add and configure a new account partner.C Add and configure a new resource partner.D Add and configure a Claims-aware application.

考题 单选题Your company has an Active Directory domain. You log on to the domain controller. The Active Directory Schema snap-in is not available in the Microsoft Management Console (MMC). You need to access the Active Directory Schema snap-in. What should you do()A Register Schmmgmt.dll.B Log off and log on again by using an account that is a member of the Schema Administrators group.C Use the Ntdsutil.exe command to connect to the Schema Master operations master and open the schema for writing.D Add the Active Directory Lightweight Directory Services (AD LDS) role to the domain controller by using Server Manager.

考题 单选题Your company has an Active Directory domain. The company has purchased 100 new computers. You want to deploy the computers as members of the domain. You need to create the computer accounts in an organizational unit. What should you do()A Run the csvde f computers.csv command.B Run the ldifde f computers.ldf command.C Run the dsadd computer  command.D Run the dsmod computer  command.

考题 单选题Your company has a single Active Directory directory service forest with multiple domains. The  company has a main office with 1,000 users and a single branch office with 500 users. Each office is aseparate Active Directory site. The main office Active Directory site has two domain controllers with Global  Catalog services. Company employees must be able to work in both offices. You need to plan the  placement and configuration of domain controllers.  What should you do?()A  Deploy two additional domain controllers in the main office Active Directory site.B  Deploy global catalog servers in the branch office Active Directory site.C  Enable change notification on the site link between the main office Active Directory site and the branch office Active Directory site.D  Disable change notification on the site link between the main office Active Directory site and the branch office Active Directory site.

考题 单选题Your company has a single Active Directory domain. The domain runs at the functional level of Windows Server 2003. You install the DHCP service on a server named DHCP1. You attempt to startthe DHCP service, but it does not start. You need to ensure that the DHCP service starts. What should you do?()A Restart DHCP1.B Configure a scope on DHCP1.C Activate the scope on DHCP1.D Authorize DHCP1 in the Active Directory domain.

考题 单选题Your company has a single Active Directory directory service domain. Servers in your environment run Windows Server 2003. Client computers run Windows XP or Windows Vista. You plan to create an internal centrally managed security update infrastructure for client computers. You need to choose a security update management tool that supports all the client computers.  Which tool should you choose? ()A  Microsoft Assessment and Planning (MAP) ToolkitB  Microsoft Baseline Security AnalyzerC  Microsoft System Center Operations ManagerD  Windows Server Update Services (WSUS)