Home
16.
Isabel, a system administrator, created a new Active Directory domain in an environment that already contains two trees. During the promotion of the domain controller, she chose to create a new Active Directory forest. Isabel is a member of the Enterprise Administrators group and has full permissions over all domains. During the organization’s migration to Active Directory, many updates were made to the information stored within the domains. Recently, users and other system administrators have complained about not being able to find specific Active Directory objects in one or more domains (although the objects exist in others). To investigate the problem, Isabel wants to check for any objects that have not been properly replicated among domain controllers. If possible, she would like to restore these objects to their proper place within the relevant Active Directory domains.
Which two of the following actions should she perform to be able to view the relevant information? (Choose two.)
  • A.
    Change Active Directory permissions to allow object information to be viewed in all domains.
  • B.
    Select the Advanced Features item in the View menu.
  • C.
    Promote a member server in each domain to a domain controller.
  • D.
    Rebuild all domain controllers from the latest backups.
  • E.
    Examine the contents of the LostAndFound folder using the Active Directory Users and Computers tool.
  • Answer & Explanation
  • Report
Answer : [B, E]
Explanation :
Enabling the Advanced Features item in the View menu will allow Isabel to see the LostAndFound and System folders. The LostAndFound folder contains information about objects that could not be replicated among domain controllers.
Report
Name Email  
17.
You are a consultant hired to evaluate an organization’s Active Directory domain. The domain contains more than 200,000 objects and hundreds of OUs. You begin examining the objects within the domain, but you find that the loading of the contents of specific OUs takes a long time. Furthermore, the list of objects can be large. You want to do the following:
--> Use the built-in Active Directory administrative tools and avoid the use of third-party tools or utilities.
--> Limit the list of objects within an OU to only the type of objects that you’re examining (for example, only Computer objects).
--> Prevent any changes to the Active Directory domain or any of the objects within it.
Which one of the following actions meets these requirements?
  • A.
    Use the Filter option in the Active Directory Users and Computers tool to restrict the display of objects.
  • B.
    Use the Delegation of Control Wizard to give yourself permissions over only a certain type of object.
  • C.
    Implement a new naming convention for objects within an OU and then sort the results using this new naming convention.
  • D.
    Use the Active Directory Domains and Trusts tool to view information from only selected domain controllers.
  • E.
    Edit the domain Group Policy settings to allow yourself to view only the objects of interest.
  • Answer & Explanation
  • Report
Answer : [A]
Explanation :
Through the use of filtering, you can choose which types of objects you want to see using the Active Directory Users and Computers tool. Several of the other choices may work, but they require changes to Active Directory settings or objects.
Report
Name Email  
18.
You are the administrator for a small organization with four servers. You have one file server named StormSrvA that runs Windows Server 2016. You have a junior administrator who needs to do backups on this server. You need to ensure that the junior admin can use Windows Server Backup to create a complete backup of StormSrvA. What should you configure to allow the junior admin to do the backups?
  • A.
    The local groups by using Computer Management
  • B.
    A task by using Authorization Manager
  • C.
    The User Rights Assignment by using the Local Group Policy Editor
  • D.
    The Role Assignment by using Authorization Manager
  • Answer & Explanation
  • Report
Answer : [A]
Explanation :
To allow the junior admin to do backups, their account needs to be part of the Backup Operators local group. To add their account to the local group, you need to use Computer Management.
Report
Name Email  
19.
Miguel is a junior-level system administrator, and he has basic knowledge about working with Active Directory. As his supervisor, you have asked Miguel to make several securityrelated changes to OUs within the company’s Active Directory domain. You instruct Miguel to use the basic functionality provided in the Delegation of Control Wizard. Which of the following operations are represented as common tasks within the Delegation of Control Wizard? (Choose all that apply.)
  • A.
    Reset passwords on user accounts.
  • B.
    Manage Group Policy links./li>
  • C.
    Modify the membership of a group.
  • D.
    Create, delete, and manage groups.
  • Answer & Explanation
  • Report
Answer : [A, B, C, D]
Explanation :
All of the options listed are common tasks presented in the Delegation of Control Wizard.
Report
Name Email  
20.
You are the primary system administrator for a large Active Directory domain. Recently, you have hired another system administrator upon whom you intend to offload some of your responsibilities. This system administrator will be responsible for handling help desk calls and for basic user account management. You want to allow the new employee to have permissions to reset passwords for all users within a specific OU. However, for security reasons, it’s important that the user not be able to make permissions changes for objects within other OUs in the domain. Which of the following is the best way to do this?
  • A.
    Create a special administration account within the OU and grant it full permissions for all objects within Active Directory.
  • B.
    Move the user’s login account into the OU that the new employee is to administer.
  • C.
    Move the user’s login account to an OU that contains the OU (that is, the parent OU of the one that the new employee is to administer).
  • D.
    Use the Delegation of Control Wizard to assign the necessary permissions on the OU that the new employee is to administer.
  • Answer & Explanation
  • Report
Answer : [D]
Explanation :
The Delegation of Control Wizard is designed to allow administrators to set up permissions on specific Active Directory objects.
Report
Name Email