Configure Active Directory in a Complex Enterprise Environment Flashcards Preview

MCSA 70-742 > Configure Active Directory in a Complex Enterprise Environment > Flashcards

Flashcards in Configure Active Directory in a Complex Enterprise Environment Deck (30)
Loading flashcards...
1
Q

Where do you go to add domains or forests?

A

Within the ADDSC wizard on the Domain Options screen

2
Q

What tool do you use to configure domain and forest functional levels?

A

Active Directory Domains and Trusts

3
Q

Within AD DT, how do you configure domain and forest functional levels?

A

To raise the forest level, right click on AD DT (top node) and select Raise Forest Functional Level

To raise the domain level, right click on domain and select Raise Domain Functional Level

4
Q

Domain functional levels can go lower than Forest functional levels. True or False?

A

False. Domain functional levels can go higher than forest functional levels but never lower.

5
Q

What tool do you use to configure User Principal Name (UPN) suffixes?

A

Active Directory Domains and Trusts.

Right click on AD DT (top node), and select properties.
Enter name of alternative UPN suffixes to be added.

6
Q

What is a forest trust?

A

A forest trust is the trust relationship between two different forests.

7
Q

How do you configure a forest trust?

A

Within AD DT > Right click on domain and select properties > Trusts tab > Launch “New Trust” wizard specifically selecting Forest Trust on the Trust Type screen.

8
Q

What is an external trust?

A

The trust relationship between an AD forest and a NT 4.0 domain structure.

9
Q

What is a realm trust?

A

The trust relationship between an AD forest and a Kerberos, non-AD domain structure.

10
Q

What is a shortcut trust?

A

The trust relationship between AD trees within a forest to speed up authentication

11
Q

What is SID filtering and how is it configured?

A

Aka Selective authentication, is when, by default, access to domain resources is not allowed unless permissions are given.

Is configured when going through the new trust wizard and selecting authentication type.

12
Q

What is name suffix routing?

A

The routing of child domains to parent domain’s DC for authentication.

13
Q

How do you configure name suffix routing?

A

Within AD DT > Domain properties > Trust properties > Name Suffix Routing tab

14
Q

What are 3 main reasons for using AD Sites?

A
  1. Replication control
  2. Enhance GPO deployment
  3. Enhance use of SRV records
15
Q

What PowerShell cmdlet is used to create a new AD site?

A

New-ADReplicationSite

16
Q

How do you create a new site within AD SS?

A

Right click on Sites container and select New Site

17
Q

How do you create a new subnet within AD SS?

A

Right click on Subnets container and select New Subnet

18
Q

How do you create a new site link within AD SS?

A

Right click on Inter-Site Transports container (IP/SMTP) and select New Site Link

19
Q

What are 3 ways to implement site coverage?

A
  1. utilizing SRV records pointing sites to DCs.
  2. RODCs deployed within the site.
  3. Subnet added to a site already containing a DC.
20
Q

How do you manage registration of SRV records?

A

Within DNS Manager > Forward Lookup Zones > > _tcp

21
Q

How do you move domain controllers between sites within AD SS?

A

Right click on DC and select Move then select available site

22
Q

What protocol can be used with a slow, unreliable WAN link between your sites?

A

SMTP

23
Q

What is the default time for replication over an IP site link?

A

180 minutes

24
Q

When configuring a trust between to domains, what is result of selecting domain-wide authentication?

A

Domain-wide authentication provides users from a trusted domain the same level of access to local resources as for users from the local forest.

25
Q

When configuring a trust between two domains, what is the result of selecting selective authentication?

A

Selective authentication allows users from a trusted domain to authenticate only to those resources to which they are explicitly allowed to authenticate.

26
Q

How do you prioritize certain site links over others?

A

By configuring the cost of the site links.

Within AD SS > Sites > Inter-Site Transports > IP, open the properties of the site and within the General tab, the Cost value can be changed. The lower the value, the higher the priority.

27
Q

Site link bridging is enabled by default. True or False?

A

True.

28
Q

How do you disable site link bridging?

A

Right click IP under Inter-Site Transports within AD SS.

On the General tab, uncheck the “Bridge all site links” option.

29
Q

What service, on DCs, is responsible for registering and periodically refreshing SRV locator records?

A

netlogon service

30
Q

If users are experiencing slow logon times, what may need to be done to resolve this issue?

A

Restart the netlogon service on the corresponding domain controller.