1.You are the network administrator for your company. Your network consists of a single Active Directory domain. You are responsible for configuring Active Directory security for the domain. All groups for the domain are in an organizational unit (OU) named Groups. Resource groups will be used to provide permissions to users in accounts groups. The human resources department needs to be able to manage the membership of only the accounts groups. The server support department needs to be able to manage the membership of only the resource groups. The Domain Admins group needs to be able to manage all groups. You need to configure the OU structure to allow the appropriate permissions to be granted. You want to achieve this goal by using the minimum amount of administrative effort. What should you do? To answer, drag the appropriate OU or OUs to the correct location or locations in the work area.

Drag and drop question. Drag the items to the proper locations.
Correct Answers:

2.You are the network administrator for your company. The network consists of a single Active Directory forest that contains two domains with three sites. Domain1 is used as an empty root domain for security purposes. Domain1 has a domain controller only in Site1. Domain2 has domain controllers in all three sites. The domain controllers in Site1 and Site2 are global catalog servers. Each client computer on the network runs Windows NT Workstation 4.0, Windows 2000 Professional, or Windows XP Professional. You and your administration staff are located at Site1, where you perform administrative tasks. You want to minimize network traffic as much as possible. The number of user accounts per site for each domain is shown in the following table. Site1 Site2 Site3 Users - Domain1 5 0 0 Users - Domain2 5 100 25,000 You are planning the placement of the operations master role holders. You need to place your operations master roles in the appropriate sites. How many operations master roles should you place in each site? To answer, drag the appropriate number of roles to the correct locations in the work area.

Drag and drop question. Drag the items to the proper locations.
Correct Answers:

3.You are the network administrator for your company. The network consists of a single Active Directory domain. The domain contains an organizational unit (OU) named Sales. You create three Group Policy objects (GPOs) that have four configuration settings, as shown in the following table.

3.The Sales OU has the Block Policy inheritance setting enabled. The priority for GPOs linked to the Sales OU specifies first priority for the Display and Wallpaper GPO and second priority for the Wallpaper GPO. For user accounts in the Sales OU, you want the Screen Saver tab to be hidden and the desktop wallpaper to be Autumn.jpg. You log on to a test computer by using a user account from the Sales OU, but you do not receive the settings you wanted. You need to configure the settings to hide the Screen Saver tab and set the desktop wallpaper to Autumn.jpg for the user accounts in the Sales OU. You want to avoid affecting user accounts in other OUs. What should you do? A: Enable the No Override setting for the Display and Wallpaper GPO.B: Disable the No Override setting on the ScreenSaver GPO. Reorder the Wallpaper GPO to be first in the list.C: Create a GPO and link it to the Default-First-Site-Name. Configure the GPO to set the Active Desktop Wallpaper to c:\WINNT\web\wallpaper\autumn.jpgD: Disable the Block Policy inheritance setting on the Sales OU. Change the Display and Wallpaper GPO to set the Active Desktop Wallpaper to c:\WINNT\web\wallpaper\autumn.jpg
Correct Answers: B 4.You are the network administrator for your company. The network consists of a single Active Directory domain with six sites. The Active Directory site configuration is shown in the exhibit. (Click the Exhibit button.) The network connection connecting Site3 and Site4 has more than 80 percent utilization during the company's business hours. The network bandwidth is required for a critical business application, and so you must ensure that Active Directory replication does not interfere with the application. The other network connections have adequate bandwidth to support Active Directory replication. You must ensure that the Active Directory replication traffic does not cross the network connection connecting Site3 and Site4 during the company's business hours. Replication connecting all other Active Directory sites must occur at least every three hours throughout the day. What should you do?

A: Configure the replication schedule for the site link connecting Site3 and Site4 to replicate only during nonbusiness hours.B: Disable automatic site link bridging. Create one site link bridge that bridges the site links connecting Site1, Site2, and Site3. Create another site link bridge that bridges the site links connecting Site4, Site5, and Site6.C: Configure one domain controller in Site3 and one domain controller in Site4 as preferred bridgehead servers.D: Configure the site link cost between Site3 and Site4 to be 1,000. Configure the other site link costs to be 100.
Correct Answers: A 5.You are the network administrator for Consolidated Messenger. The network consists of a single Active Directory forest that contains three domains named consolidatedmessenger.com, child1.consolidatedmessenger.com, and child2.consolidatedmessenger.com. The functional level of the forest is Windows Server 2003.Both child1.consolidatedmessenger.com and child2.consolidatedmessenger.com contain employee user accounts, client computer accounts, and resource server computer accounts. The domain named consolidatedmessenger.com contains only administrative user accounts and computer accounts for two domain controllers. Each resource server computer provides a single service of file server, print server, Web server, or database server.Your company plans to use Group Policy objects (GPOs) to centrally apply security settings to resource server computers. Some security settings need to apply to all resource servers and must not be overridden. Other security settings need to apply to specific server roles only. You need to create an organizational unit (OU) structure to support the GPO requirements. You want to create as few GPOs and links as possible.What should you do?