Managing and Maintaining a Microsoft Windows Server 2003 Environment for a W2K MCSA

42 390 0
Managing and Maintaining a Microsoft Windows Server 2003 Environment for a W2K MCSA

Đang tải... (xem toàn văn)

Tài liệu hạn chế xem trước, để xem đầy đủ mời bạn chọn Tải xuống

Thông tin tài liệu

Managing and Maintaining a Microsoft Windows Server 2003 Environment for a W2K MCSA 070-292 Version 9.0 21certify.com 070-292 Study Tips This product will provide you questions and answers along with detailed explanations carefully compiled and written by our experts Try to understand the concepts behind the questions instead of cramming the questions Go through the entire document at least twice so that you make sure that you are not missing anything Latest Version We are constantly reviewing our products New material is added and old material is revised Free updates are available for 365 days after the purchase You should check the products page on the www.21certify.com web site for an update 3-4 days before the scheduled exam date Important Note: Please Read Carefully This 21certify Exam has been carefully written and compiled by 21certify Exams experts It is designed to help you learn the concepts behind the questions rather than be a strict memorization tool Repeated readings will increase your comprehension We continually add to and update our 21certify Exams with new questions, so check that you have the latest version of this 21certify Exam right before you take your exam For security purposes, each PDF file is encrypted with a unique serial number associated with your 21certify Exams account information In accordance with International Copyright Law, 21certify Exams reserves the right to take legal action against you should we find copies of this PDF file has been distributed to other parties Please tell us what you think of this 21certify Exam We appreciate both positive and critical comments as your feedback helps us improve future versions We thank you for buying our 21certify Exams and look forward to supplying you with all your Certification training needs Good studying! 21certify Exams Technical and Support Team 21certify.com 070-292 Q You are the network administrator for 21certify The network consists of a single Active Directory domain named contoso.com The network contains 100 Windows 2000 Professional computers and three Windows Server 2003 computers Information about the three servers is shown in the following table You add a network interface print device named 21certifyPrinter1 to the network You manually configure the IP address for 21certifyPrinter1 21certifyPrinter1 is not currently registered on the DNS server The relevant portion of the network is shown in the exhibit You need to ensure that client computers can connect to 21certifyPrinter1 by using its name What should you do? A On 21certifySrvA, add an alias (CNAME) record that references 21certifyPrinter1 B In the Hosts file on 21certifySrvC, add a line that references 21certifyPrinter1 C On 21certifySrvA, add a service locator (SRV) record that reference 21certifyPrinter1 D On 21certifySrvA, add a host (A) record that references 21certifyPrinter1 E In the Hosts file on 21certifySrvB, add a line that references 21certifyPrinter1 Answer: D Q 21certify.com 070-292 You are a network administrator for Fabrikam, Inc A company named 21certify GmBh., recently acquired Fabrikam, Inc., and another company named Proseware, Inc Your team is responsible for establishing connectivity between the companies Each of the three companies has its own Active Directory forest The relevant portion of the network is shown in the exhibit ***MISSING*** 21certify1, 21certify3, and 21certify5 runs Windows Server 2003 Each of these servers is the DNS server for its respective domain All three servers can currently resolve Internet host names 21certify3 is configured as a secondary zone server for fabrikam.com and proseware.com You need to configure 21certify5 to resolve host names for 21certify.com and proseware.com as quickly as possible, without adding new zones to 21certify5 Which two actions should you perform? (Each correct answer presents part of the solution Choose two) A Forward requests for 21certify.com to 131.107.1.2 B Forward requests for 21certify.com to 131.107.3.2 C Forward requests for 21certify.com to 131.107.10.2 D Forward requests for proseware.com to 131.107.1.2 E Forward requests for proseware.com to 131.107.3.2 F Forward requests for proseware.com to 131.107.10.2 Answer: ? Note: Exhibit needed Will be provided in later versions Q You are the network administrator for 21certify The network consists of a single DNS domain named 21certify.com You replace a UNIX server with a Windows Server 2003 computer named 21certify1 21certify1 is the DNS server and start authority (SOA) for 21certify.com A UNIX server named 21certify2 is the mail server for 21certify.com You receive reports that Internet users cannot send e-mail to the 21certify.com domain The host addresses are shown in the following window 21certify.com 070-292 You need to ensure that Internet users can send e-mail to the 21certify.com domain What should you do? A Add an _smtp service locator (SRV) DNS record for 21certify2 B Add a mail exchange (MX) DNS record for 21certify2 C Add an alias (CNAME) record for mail.21certify.com D Enable the SMTP service on 21certify1 Answer: B Q You are the network administrator for 21certify The network contains Windows Server 2003 computers and Windows XP Professional computers You are configuring Automatic Update on the servers The written company network security policy states that all updates must be reviewed and approved before they are installed All updates are received from the Microsoft Windows Update servers You want to automate the updates as much as possible What should you do? To answer, configure the appropriate option or options in the dialog box 21certify.com 070-292 Answer: Check "Keep my computer ", and click "Download " Q You are the network administrator for 21certify The network consists of a single Active Directory domain 21certify.com The domain contains 35 Windows Server 2003 computers; 3,000 Windows XP Professional computers; 2,200 Windows 2000 Professional computers The written company security policy states that all computers in the domain must be examined, with the following goals: • To find out whether all available security updates are present • To find out whether shared folders are present • To record the file system type on each hard disk You need to provide this security assessment of every computer and verify that the requirements of the written security policy are met What should you do? A Open the Default Domain Policy and enable the Configure Automatic Updates policy B Open the Default Domain Policy and enable the Audit object access policy, the Audit account management policy, and the Audit system events policy C On a server, install and run mbsacli.exe with the appropriate configuration switches D On a server, install and run HFNetChk.exe with the appropriate configuration switches Answer: C Q You are the network administrator for 21certify The network contains Windows Server 2003 computers and Windows XP Professional computers You install Software Update Services on a server named 21certify A You create a new Group Policy object (GPO) at the domain level 21certify.com 070-292 You need to properly configure the GPO so that all computers receive their updates from 21certify A How should you configure the GPO? To answer, configure the appropriate option or options in the dialog box Answer: Check "Enabled", Choose "http:// 21certifyA" in the "Set the intranet " and choose the same in "Set the intranet stat " Q You are the regional network administrator for the Boston branch office of 21certify's network The company network consists of a single Active Directory domain 21certify.com All computers in the Boston office run Windows XP Professional The domain contains an organizational unit (OU) named BostonClientsOU, which contains all the computer objects for the Boston office A Group Policy object (GPO) named BClientsGPO is linked to BostonClientsOU You have been granted the right to modify the GPO BClientsGPO contains a software restriction policy that prevents the execution of any file that has a vbs file extension All other applications are allowed to run You want to use a script file named maintenance.vbs, which you will schedule to run every night on the computers in the Boston office The maintenance.vbs file is located in the Scripts shared folder on a server named 21certifySrvC The contents of maintenance.vbs will frequently change based on the maintenance tasks you want to perform You need to modify the software restriction policy to prevent unauthorized vbs scripts from running on the computers in the Boston office, while allowing maintenance.vbs to run You want to ensure that no other applications are affected by your solution You want to implement a solution that you can configure once, without requiring additional administration in the future, when maintenance.vbs changes What should you do? 21certify.com 070-292 A Obtain a digital certificate Create a new certificate rule Set the security level of the rule to Unrestricted Digitally sign maintenance.vbs B Create a new path rule Set the security level on the rule to Unrestricted Set the path to \\21certifySrvC\Scripts\*.vbs C Create a new path rule Set the security level on the rule to Unrestricted Set the path to \\21certifySrvC\Scripts\maintenance.vbs D Create a new hash rule Set the security level on the rule to Unrestricted Create a file hash of maintenance.vbs Answer: C Q You are the network administrator for 21certify 21certify has offices in three countries The network contains Windows Server 2003 computers and Windows XP Professional computers The network is configured as shown in the exhibit Software Update Services (SUS) is installed on one server in each office Each SUS server is configured to synchronize by using the default settings 21certify.com 070-292 Because bandwidth at each office is limited, you want to ensure that updates require the minimum amount of time What should you do? A Synchronize the updates with an SUS server at another office B Select only the locales that are needed C Configure Background Intelligent Transfer Service (BITS) to limit file transfer size to MB D Configure Background Intelligent Transfer Service (BITS) to delete incomplete jobs after 20 minutes Answer: C Q You are the file server administrator for 21certify The company network consists of a single Active Directory domain named 21certify.com The domain contains 12 Windows Server 2003 computers and 1,500 Windows XP Professional computers You manage three servers named 21certify1, 21certify2, and 21certify3 You need to update the driver for the network adapater that is installed in Serve1 You log on to 21certify1 by using a nonadministrative domain user account named King You open the Computer Management console When you select Device Manager, you receive the following error message: “You not have sufficient security privileges to uninstall devices or to change device properties or device drivers” You need to be able to run the Computer Management console by using the local administrator account The local administrator account on 21certify1, 21certify2, and 21certify3 has been renamed Tess Tess’s password is kY74X In Control Panel, you open Administrative Tools You right-click the Computer Management shortcut and click Run ass on the shortcut menu What should you next? 21certify.com 070-292 10 Answer: Explanation: Choose "The following User", Enter "21certify1\Tess" in the User Name field, enter kY74X" in the password field Q 10 You are the network administrator for 21certify The network consists of a single Active Directory domain named 21certify.com The domain contains Windows Server 2003 computers and Windows XP Professional computers All confidential company files are stored on a file server named 21certify1 The written company security states that all confidential data must be stored and transmitted in a secure manner To comply with the security policy, you enable Encrypting File System (EFS) on the confidential files You also add EFS certificates to the data decryption field (DDF) of the confidential files for the users who need to access them While performing network monitoring, you notice that the confidential files that are stored on 21certify1 are being transmitted over the network without encryption You must ensure that encryption is always used when the confidential files on 21certify1 are stored and transmitted over the network What are two possible ways to accomplish this goal? (Each correct answer presents a complete solution 21certify.com 070-292 28 A Answer: Default User Q 34 You are the network administrator for 21certify The network consists of a single Active Directory domain named 21certify.com All network servers run Windows Server 2003, and all client computers run Windows 2000 Professional Your company is organized in three departments Each department corresponds to a separate organizational unit (OU) Computer accounts for each department reside in the corresponding OU Domain users report that their accounts are locked out after three unsuccessful attempts to log on You need to increase your account lockout setting to five unsuccessful attempts to log on You also need to ensure that you can review all unsuccessful attempts to log on to the domain or to log on locally to client computers The new settings must be applied to a limited number of objects What should you do? To answer, drag the appropriate security policy settings to the correct locations in the work are A Answer: 21certify.com 070-292 29 Q 35 You are the network administrator for 21certify Your network consists of two Active Directory domains Each department has its own organizational unit (OU) for departmental user accounts Each OU has a separate Group Policy object (GPO) A single terminal server named 21certifyTerm1 is reserved for remote users In addition, several departments have their own terminal servers for departmental use Your help desk reports that user sessions on 21certifyTerm1 remain connected even if the sessions are inactive for days Users in the accounting department report slow response times on their terminal server You need to ensure that users of 21certifyTerm1 are automatically logged off when their sessions are inactive for more than two hours Your solution must not affect users of any other terminal servers What should you do? A For all accounting users, change the session limit settings B On 21certifyTerm1, use the Terminal Services configuration tool to change the session limit settings C Modify the GPO linked to the Accounting OU by changing the session limit settings in user-level group polices D Modify the GPO linked to the Accounting OU by changing the session limit settings in computer-level group polices Answer: C Q 36 You are the network administrator for 21certify The network consists of a single Active Directory forest The forest contains one domain named 21certify.com The network contains two subnets named subnet A and subnet B The two subnets are connected by a router The network also contains four Windows Server 2003 computers, 300 Windows 2000 Professional computers, and 25 Windows NT Server 4.0 computers Three of the servers are configured as shown in the following table 21certify.com 070-292 30 The DNS zone currently records for only Windows 2000 Professional computers Each client computer is configured to transmit name resolution requests to 21certifySrvA and 21certifySrvC Users are able to access all resources on the network You plan to change the TCP/IP settings for each client computer to remove the pointer to 21certifySrvC You need to ensure that the client computers can continue to access e-mail What should you do? A In the advanced TCP/IP settings, enable NetBIOS over TCP/IP B In the advanced TCP/IP settings, enable Lmhosts lookup C In the properties of 21certify.com, add a name server (NS) resource record for 21certifySrvC D In the properties of 21certify.com, enable WINS forward lookup Answer: D Q 37 You are the network administrator for 21certify Your network consists of a single Active Directory domain 21certify.com All network servers run Windows Server 2003 A single server running Terminal Server is available to remote users Your help desk staff is responsible for monitoring user activity on the terminal server The staff is also responsible for sending message to users about new programs and about modifications to the terminal server A company developer writes a script that will log the relevant user information in a file and provide pop-up messages as needed You need to ensure that the script runs every time a user logs on to the terminal server What should you do? A Deploy a client connection object for remote users Configure the client connection object to run the script B On the terminal server, configure the RDP-Tcp properties with the name of the script Override other settings C In the Default Domain Group Policy object (GPO), select the Start a program on startup option and specify the name of the script D On the terminal server, configure the RDP client properties with the name of the script Answer: B Q 38 You are the network administrator for 21certify The network consists of a single Active Directory domain named 21certify.com All network servers run Windows Server 2003, and all client computers run Windows XP Professional You install Terminal Server on three member servers named 21certify1, 21certify2, and 21certify3 You add a domain group named HR to the Remote Desktop Users group on all three terminal servers 21certify.com 070-292 31 One week later, you discover that files on 21certify1 and 21certify2 were deleted by a user named Tess, who is a member of the HR group You need to prevent Tess from connecting to any of the terminal servers What should you do? A On all three terminal servers, modify the RDP-Tcp connection permissions to assign the Deny – Users Access and the Deny – Guest Access permissions to the HR group B On all three terminal servers, modify the RDP-Tcp connection permissions to assign the Allow – Guest Access permission to Tess’s user account C In the properties of Tess’s user account, disable the Allow logon to a terminal server option D On all three terminal servers, modify the RDP-Tcp connection permissions to assign the Deny – User Access and the Deny –Guest Access permissions to the Remote Desktop Users group E In the properties of Tess’s user account, enable the End session option Answer: C Q 39 You are the network administrator for 21certify The network consists of a single Active Directory domain named 21certify.com The functional level of the domain is Windows Server 2003 You install Terminal Services on all domain controllers However, your technical support specialists report that they cannot use Terminal Services to access any domain controllers Which action or actions should you perform to solve this problem? (Choose all that apply) A Install Remote Desktop for Administration B Require the support specialists to use a console session to connect to the terminal servers C Add the Remote Administrators group to the Account Operators group D Add the support specialists to the Remote Desktop group E Modify the Default Domain Controller Group Policy object (GPO) to grant the Log on locally user right to the support specialists Answer: A, D Q 40 You are the network administrator for 21certify The network consists of a single Active Directory domain named 21certify.com The network contains 15 Windows Server 2003 computers that function as intranet Web servers You install a Windows Server 2003 computer named 21certify7 with Routing and Remote Access 21certify7 has the NAT/Basic Firewall routing protocol enabled to route traffic between the LAN and the Internet 21certify7 uses an internal LAN IP address of 10.10.1.1 The 15 intranet Web servers use a DNS server named Server3 for local host name resolution Each of the 15 intranet Web servers uses static IP configuration as shown in the TCP/IP properties exhibit ****MISSING**** The Web servers also require Internet access to display certain public Web content within intranet Web pages All the Web servers are configured with the Internet Explorer LAN settings shown in the LAN Settings exhibit ****MISSING**** Local network users report that only the local Web content on the intranet Web servers appears You attempt to access public Web pages from one of the intranet Web servers and confirm that it cannot access public Internet Web content 21certify.com 070-292 32 You want the 15 intranet Web servers to access public Internet Web content What should you do? A On the DHCP server, create DHCP client reservation for each of the Web servers B In the Internet Explorer LAN settings, use a proxy server address of 10.10.1.1 and a port number of 8080 C In the Internet Explorer LAN settings, select Automatically detect settings D Configure the Internet Explorer LAN settings to use an automatic configuration script pointing to http://21certify7:8080/arrat.dll?Get.Routing.Script E Configure TCP/IP properties of each Web server to use 10.10.1.1 as the default gateway Answer: E Q 41 You are the network administrator for 21certify The network configuration is shown in the Network exhibit ***MISSING*** A DHCP server on the local subnet is configured to assign IP addresses to client computers in the 10.10.22.20 – 10.10.22.254 range All client computers connect to the Internet by using the server named NAT1 NAT1 is a Windows 2003 Server that has Routing and Remote Access installed NAT1 has the NAT/Basic Firewall routing protocol enabled The network interfaces on NAT1 are configured as shown in the following table Interface name IP address Connect to Ethernet1 10.10.22.10 LAN Ethernet2 131.107.100.202 Internet The configuration of the NAT/Basic Firewall routing on NAT1 is shown in the NAT Configuration exhibit: ***MISSING*** Client computers are unable to connect to the Internet You run the ping command from a command prompt on Windows XP Professional computer on the local network, and you receive the following result C:\>ping 10.10.22.10 Pinging 10.10.22.10 with 32 bytes of data: Request timed out: Request timed out: Request timed out: Request timed out: Ping statistics for 10.10.22.10: Packets: Sent = 4, Received = 0, Lost = 4(100% loss), You need to ensure that client computers are able to connect to the Internet Which two actions should you perform? (Each correct answer presents part of the solution Choose two) 21certify.com 070-292 33 A Configure the DHCP server to assign a default gateway of 131.107.100.202 to client computers B Configure the DHCP server to assign a default gateway of 131.107.100.201 to client computers C Configure the NAT/Basic Firewall interface type for Ethernet1 to be a private interface D Configure the NAT/Basic Firewall interface type for Ethernet2 to be a public interface E Configure the outbound port filters on Ethernet1 to allow all network protocols F Configure the outbound port filters on Ethernet2 to allow all network protocols Answer: ? Note: Exhibits needed Will be provided in later versions Q 42 You are the network administrator for 21certify All network servers run either Windows 2000 Server or Windows Server 2003, and all client computers run Windows XP Professional A computer named 21certifySrvA runs Windows Server 2003 with IIS 6.0 installed On 21certifySrvA, you create a virtual directory named WebFolder You use IIS Manager to enable the following permissions on WebFolder: Read, Write, and Directory Browsing When users try to access WebFolder as a Web folder from Internet Explorer, they receive the error message shown in the exhibit ***MISSING*** You need to ensure that all users can access WebFolder as a Web folder What should you do? A Restart the World Wide Web Publishing Service on 21certifySrv A B Enable anonymous access to WebFolder C Modify the Execute permissions to allow scripts and executable files D Enable the WebDAV Web service extension on 21certifySrv A Answer: B (?) Note: Exhibit needed to confirm answer Will be provided in later versions Q 43 You are the network administrator for 21certify The network originally consists of a single Windows NT 4.0 domain You upgrade the domain to a single Active Directory domain All network servers now run Windows Server 2003, and all client computers run Windows XP Professional 21certify.com 070-292 34 Your staff provides technical support to the network They frequently establish Remote Desktop connections with a domain controller named DC1 You hire 25 new support specialists for your staff You use Csvde.exe to create Active Directory user accounts for all 25 A new support specialist named King reports that he cannot establish a Remote Desktop connection with DC1 He receives the message shown in the Logon Message exhibit: ***MISSING*** You open Gpedit.msc on DC1 You see the display shown in the Security Policy exhibit: ***MISSING*** You need to ensure that King can establish Remote Desktop connections with DC1 What should you do? A Direct King to establish a VPN connection with DC1 before he starts Remote Desktop Connection B Direct King to set a password for his user account before he starts Remote Desktop Connection C In the local security policy of DC1, disable the Require strong (Windows 2000 or later) session key setting D In the local security policy of DC1, enable the Disable machine account password changes setting Answer: ? Note: Exhibits needed to provide answer Will be provided in later versions Q 44 You are the network administrator for 21certify The network consists of a single Active Directory domain named 21certify.com All network servers run Windows Server 2003, and all client computers run Windows XP Professional A member server named 21certifySrv1 runs Software Update Services (SUS) 21certifySrv1 is configured to synchronize directly from the Microsoft Windows Update servers every day All client computers are configured to use the Automatic Updates client software to receive updates from 21certifySrv1 All client computers are located in an organizational unit (OU) named Clients Microsoft releases a critical security update for Windows XP Professional computers 21certifySrv1 receives the update Client computers on the network not receive this update However, they receive other updates from 21certifySrv1 You need to ensure that all client computers receive the critical security update What should you do? 21certify.com 070-292 35 A In the System Properties dialog box on each client computer, enable the Keep my computer up to date option B Edit the Group Policy object (GPO) for the Clients OU by enabling the Reschedule Automatic Updates scheduled installations setting C On 21certifySrv1, open the SUS content folder Select the file that contains the security update, and assign the Allow – Read permissions on the file to all client computers D Use Internet Explorer to connect to the SUS administration page Approve the security update Answer: D Q 45 You are the network administrator for 21certify The network consists of a single Active Directory domain named 21certify.com The domain contains three servers Information about the servers is shown in the following table 21certifyA is the start of authority (SOA) for 21certify.com Test King adds a new branch office The network in the new office is assigned to a child DNS domain named south.21certify.com The two domains connect to each other through a VPN connection 21certifyB is configured as the SOA for south.21certify.com A Windows XP Professional computer named 21certify1 is located in the 21certify.com domain The relevant portion of the network is shown in the exhibit ***MISSING*** A user reports that he cannot connect to 21certifyC from 21certify1 You need to ensure that client computers in the 21certify.com domain can resolve host named in south.21certify.com What are two possible ways to achieve this goal? (Each correct answer presents a complete solution Choose two) A On 21certifyB, add a host (A) record for 21certify A B On 21certifyA, add a delegation for south.21certify.com C On 21certifyB, add a pointer (PTR) record for 21certify A 21certify.com D On 21certifyA, add a host (A) record for 21certifyB 21certify.com 070-292 36 E On 21certifyA, add a stub zone for south.21certify.com Answer: D, E (?) Note: Exhibits needed to verify answer Will be provided in later versions Q 46 You are the network administrator for 21certify Your network consists of a single Active Directory domain named 21certify.com All network servers run Windows Server 2003, and all client computers run Windows 2000 Professional You install Windows Server 2003 with default settings on a new computer named 21certifySrv1 You install and share several printers on 21certifySrv1 You instruct all users to connect to these printers by using the address http://21certifySrv1/Printers However, users report that they cannot connect to this address You need to ensure that all users can connect to the printers by using HTTP Which two actions should you perform? (Each correct answer presents part of the solution Choose two) A Publish all shared printers that are installed on 21certifySrv1 B Create a virtual directory named Printers on 21certifySrv1 C Install IIS with default settings on 21certifySrv1 D Reshare all printers on 21certifySrv1 E Install the Internet Printing component of IIS F Type Net Stat W3SVC at a command prompt Answer: C, E Q 47 You are the network administrator for 21certify The company operates a main office and two branch offices The network consists of a single Active Directory domain named 21certify.com All network servers run Windows Server 2003, and all client computers run Windows XP Professional A server named 21certifySrvA is located in one of the branch offices, where it is a member of a workgroup 21certifySrvA is configured with default operating system settings Remote Desktop and Remote Assistance are enabled, and Windows Messenger is installed The company intranet site is hosted on this server Mr King is the local administrator who manages the intranet site He requests your assistance in installing an application on 21certifySrv A You need the ability to view Mr King’s desktop during the installation process What should you do? A From your computer, open a Remote Desktop connection with 21certifySrv A B Direct Mr King to create and send an invitation for Remote Assistance from 21certifySrv A C From your computer, offer Remote Assistance to 21certifySrv A D Direct Mr King to start Application Sharing from Windows Messenger Answer: B 21certify.com 070-292 37 Q 48 You are the network administrator for 21certify The network consists of a single Active Directory domain named 21certify.com All network servers run Windows Server 2003 All company Web sites are hosted on a server named 21certify5, which runs IIS You create two new Web sites, Marketing and Sales You create the appropriate host records on the DNS server You test both Web sites offline and successfully access all content However, when you test the Web site online, you cannot access either site You are directed to pages on the default Web site You open IIS Manager and see the display shown in the exhibit: ****MISSING**** You need to ensure that you can start all Web sites on 21certify5 What are three possible ways for you to achieve this goal? (Each correct answer presents a complete solution Choose three) A Specify Marketing.21certify.com and Sales.21certify.com as the host header names for the two new Web sites B For each new Web site, create a file named Default.html in the directory path C For each new Web site, specify a unique TCP port Ensure that all client computers use the appropriate port to connect to each site, D For all Web sites, create custom HTTP headers E For all Web sites, specify unique IP addresses Modify the appropriate host records on the DNS server F For all Web sites, enable anonymous access Answer: D, E, F Q 49 You are the network administrator for 21certify The company consists of a main office and five branch offices Network servers are installed in each office All servers run Windows Server 2003 The technical support staff is located in the main office Users in the branch offices not have the Log on locally right on local servers Servers in the branch offices collect auditing information You need to ability to review the auditing information located on each branch office server while you are working at the main office You also need to save the auditing information on each branch office server in the local hard disk Which two actions should you perform? (Each correct answer presents part of the solution Choose two) A From the Security Configuration and Analysis snap-in, save the appropriate inf file on the local hard disk B Solicit Remote Assistance from each branch office server C From Computer Management, open Event Viewer Save the appropriate evt file on the local hard disk D Run Secedit.exe, specifying the appropriate parameters E Establish a Remote Desktop client session with each branch office server 21certify.com 070-292 38 Answer: C, D Q 50 You are the network administrator for 21certify All network servers run Windows Server 2003 You install Software Update Services (SUS) on one server You configure the following settings: • Do not use a proxy server for Internet access • Synchronize directly from the Microsoft Windows Update servers • Automatically approve new versions of previously approved updates • Save updates in a local folder You perform a manual synchronization Now you need to back up the critical information that is related to your installation of SUS What should you do? A First, use the Backup utility to back up the System State dat A Then, use the IIS administration tool to back up the default Web site B First, use the IIS administration tool to back up the default Web site Then, use the Backup utility to back up the System State dat A C First, use the IIS administration tool to back up the IIS metabase Then, use the Backup utility to back up the IIS metabase file, the default Web site, and the content storage location D First, use the Backup utility to back up the IIS metabase file, the default Web site, and the content storage location Then, use the IIS administration tool to back up the IIS metabase Answer: C Q 51 You are the network administrator for 21certify The network consists of a single Active Directory domain named 21certify.com All network servers run Windows Server 2003 The domain contains a member server named 21certify1, which is located in an organizational unit (OU) named Servers 21certify1 is managed by an application administrator named King His domain user account is a member of the local Administrators group on the server Members of this group are the only users who have the Log on locally user right on 21certify1 The written company security policy states that only authorized individuals can access 21certify1 However, you discover that help desk technicians use the Remote Assistance feature to share their server logon session with unauthorized individuals You need to reconfigure 21certify1 so the Remote Assistance feature cannot be enabled or used by the help desk technicians However, King should have the ability to enable and use this feature What should you do? A In the System Properties dialog box on 21certify1, disable the Turn on Remote Assistance and allow invitations to be sent from this computer option B In the System Properties dialog box on 21certify1, disable the Allow users to connect remotely to this computer option C Edit the Group Policy object (GPO) for the Servers OU by disabling the Offer Remote 21certify.com 070-292 Assistance setting D Edit the Group Policy object (GPO) for Assistance setting 39 the Servers OU by disabling the Solicited Remote Answer: A Q 52 You are the network administrator for 21certify The network consists of a single Active Directory domain named 21certify.com All network servers run Windows Server 2003, and all client computers run Windows XP Professional XML Web services for the internal network run on a member server named 21certifySrv1, which is configured with default settings You are a member of the local Administrators group on 21certifySrv1 You need the ability to remotely manage 21certifySrv1 You have no budget to purchase any additional licensing for your network until the next fiscal year How should you reconfigure 21certifySrv1? A In the System Properties dialog box, enable Remote Desktop B Add your user account to the Remote Desktop Users local group C In the System Properties dialog box, enable Remote Assistance D Install Terminal Services by using Add or Remove Programs Answer: B Q 53 You are the network administrator for 21certify The network consists of a single Active Directory domain named 21certify.com The network contains a Windows Server 2003 computer named 21certifySrv A 21certifySrvA is a domain controller and primary DNS server for 21certify.com The company opens a new branch office A Windows Server 2003 computer named Serve2 is located at the new office 21certifySrvB is a domain controller and a DNS server You set up a DNS zone for east.21certify.com on Serve2 You need to ensure that computers in 21certify.com can resolve host names in east.21certify.com on 21certifySrvB What are two possible ways to achieve this goal? (Each correct answer presents a complete solution Choose two) A Add a start-of-authority (SOA) record to 21certifySrvA that refers to 21certifySrvB.east.21certify.com B Add a new delegation on 21certifySrvA for east.21certify.com to 21certifySrvB C Add a new stub zone to 21certifySrvA named east.21certify.com D Add a service locator (SRV) record to 21certifySrvA that refers to 21certifySrvB.east.21certify.com Answer: B, C Q 54 You are the network administrator for Test King Inc The network consists of a single Active Directory forest The forest contains three domains named 21certify.com, corp.21certify.com, and regions.21certify.com The company has offices in many cities 21certify.com 070-292 40 All domain controllers are configured as DNS servers Zone replication for each DNS zone is configured to occur between the domain controllers in each domain The domain controllers are configured as shown in the following table You perform a recursive query against 21certify1 and discover that 21certify1 queries only 21certify3 for the zone information in regions.21certify.com You need to ensure that a recursive query against Serve1 will request information from 21certify4 and 21certify5, in addition to 21certify3 You also need to ensure that any domain controllers that are added to regions.21certify.com will be added automatically to the list of servers against which 21certify1 will query What should you do? A On 21certify1, create a stub zone for regions.21certify.com B On 21certify1, create a secondary zone for regions.21certify.com C On 21certify3, configure regions.21certify.com to replicate to all DNS servers in the forest D On 21certify3, configure regions.21certify.com to replicate to all DNS servers in the domain Answer: C Q 55 You are the network administrator for 21certify The network consists of a single Active Directory domain named 21certify.com A Windows Server 2003 computer named 21certifyA is currently the only domain controller for 21certify.com 21certifyA is also the DNS server for the Active Directoryintegrated zone named 21certify.com You configure a new Windows Server 2003 computer named 21certifyB to query Serve1 for DNS name resolution You run the Active Directory Installation Wizard on 21certifyB and restart 21certifyB Forty-five minutes later, you discover the service location (SRV) resource records, which are shown in the exhibit ***MISSING*** You need to ensure that the SRV records on 21certifyA are complete What should you do? A Restart the Net Logon service on 21certify A 21certify.com 070-292 41 B Restart the Net Logon service on 21certifyB C Run the ipconfig /registerdns command on 21certify A D Run the ipconfig /registerdns command on 21certifyB Answer: D Q 56 You are a network administrator for Fabrikam, Inc The Fabrikam, Inc., network consists of a forest that contains a single Active Directory domain named fabrikam.com Fabrikam, Inc., was recently acquired by 21certify The 21certify network consists of a forest that contains two Active Directory domains named 21certify.com and east.21certify.com 21certify1, 21certify2, and 21certify3 are Windows Server 2003 computers They function as domain controllers and DNS servers in their respective domains, as shown in the exhibit ***MISSING*** You need to configure name resolution for the 21certify.com domain on 21certify3 Computers in the fabrikam.com domain should resolve names in 21certify.com as quickly as possible Name resolution to 21certify.com should also be fault tolerant How should you configure the DNS forwarder IP addresses To answer, drag the appropriate IP addresses to the correct locations in the dialog box 21certify.com 070-292 Answer: ? Note: Exhibit needed Will be provided in later versions 21certify.com 42 ... You are a network administrator for Fabrikam, Inc A company named 21certify GmBh., recently acquired Fabrikam, Inc., and another company named Proseware, Inc Your team is responsible for establishing... utility and schedule a daily backup Answer: C Q 20 You are the network administrator for 21certify All network servers run Windows Server 2003 A file server named 21certifySrvA has shadow copies enabled... named NAT1 NAT1 is a Windows 2003 Server that has Routing and Remote Access installed NAT1 has the NAT/Basic Firewall routing protocol enabled The network interfaces on NAT1 are configured as shown

Ngày đăng: 26/10/2013, 22:15

Từ khóa liên quan

Tài liệu cùng người dùng

Tài liệu liên quan