Documente Academic
Documente Profesional
Documente Cultură
o
o
o
o
o
o
o
o
o
What is DNS?
The Domain Name System (DNS) is a hierarchical, distributed database that maps
logical host names to IP addresses
What does a DNS server hold?
A DNS server holds a database of hostnames and their corresponding IP addresses.
Clients query the DNS server to get the IP address of a given host.
What was used before DNS?
a hosts file saved on each host computer
o
o
What is a FQDN?
Fully Qualified Domain Name - includes the host name and the name of all domains
back to root.
o
o
o
o
o
What is a zone?
Zones typically contain one or more domains, although additional servers might hold
information for child domains.
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
What is an A record?
The A record maps a host name to an IP address and is used for forward lookups.
What is the process followed when a client computer needs to find an IP address?
- The client examines its HOSTS file for the IP address.
- If the IP address is not in the HOSTS file, it examines its local DNS cache for the IP address.
- If the IP address is not in the cache, the client sends the request to a DNS server.
What is the process when a DNS server received a name resolution request?
1) The DNS server examines its local DNS cache for the IP address
2) If the IP address is not in the server cache, it checks its HOSTS file.
3) If the information is not in the HOSTS file, the server checks any zones for which it is authoritative.
4) Forwarding or Recursion
5) After the information is found or received from another server, the DNS server returns the result to
the client, and places the information in its server cache.
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
How would you add the DNS role from a command prompt (or on a server core)?
start /w ocsetup DNS-Server-Core-Role
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
The GlobalNames zone is a special zone in the DNS database that is used for singlelabel name resolution.
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
How can you restrict the servers to which zone transfers are allowed?
- Allow zone transfers only to servers that are listed as name servers.
- Allow zone transfers only to servers you specifically identify.
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
What is an OU?
An Organizational Unit (OU) is similar to a folder that subdivides and organizes
network resources within a domain.
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
When you create an organizational unit, leave the Protect container from accidental
deletion check box selected. This is the default. Other types of objects do not have this default setting
and must be manually configured.
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
The Builtin container holds default service administrator accounts and domain local
security groups. These groups are pre-assigned permissions needed to perform domain management
tasks.
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
What is special about AD containers and how do they differ from OU's?
They are automatically created and cannot have GPO's applied to them.
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
How would you add a User Principal Name (UPN) suffix to a forest?
1) Open Active Directory Domains and Trusts.
2) Right-click Active Directory Domains and Trusts in the Tree window pane, then select Properties.
3) Type the new UPN suffix that you would like to add to the forest on the UPN Suffixes tab.
4) Click Add.
5) Click OK.
o
o
o
Where is the computer account created when you join a workstation to the domain?
In the Computers built-in container
How would you control where computer accounts are placed when a computer joins
the domain?
o
o
o
o
o
o
o
o
o
o
o
o
o
o
How many computers are the Authenticated Users group members allowed to join to
the domain (from a workstation)?
10 - this wil also create the computer account automatically if it doesn't already exist.
This ability comes from the Add workstations to a domain user right.
How would you allow a specific user to join a specific computer to the domain?
You can also allow specific users to join specific computers to a domain by selecting
The following user or group can join this computer to a domain when creating the computer account.
How would you give other users permissions to create computer accounts in AD?
By giving them the Create Computer Objects right over the Active Directory OU. This
permission does not have a limit on the number of accounts that can be created. Note: You must grant
this right to the domain or specific OUs.
Will a computer receive group policy settings once the computer account is created?
No, the computer must be joined to the domain before it receives any GPO settings or
AD receives any workstation-specific information
What commands can be used to create computer accounts from a command prompt
or script?
o
o
o
o
What establishes a secure channel between a computer and the domain controller?
The computer password (authomatically generated when the computer joins the
domain).
o
o
o
o
o
This problem will also occur if you have rebuilt the computer, or if you are replacing the computer with
another one using the same computer account name.
o
o
o
How would you reset the computer account after a logon failure?
- Run the netdom reset command followed by the computer account name and the
domain.
- In Active Directory Users and Computers, right-click the computer account and select Reset
Account.
- Create a script in Visual Basic.
After resetting the computer account, you must rejoin the computer to the domain.
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
Security
o
o
o
o
o
Can you convert a global group nested in another global group into a universal
group?
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
What is an RODC?
A Read Only Domain Controller
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
What is NTDS.dit?
The AD database
What is a domain?
A domain is an administratively-defined collection of network resources that share a
common directory database and security policies
o
o
What is an AD tree?
A tree is a group of related domains that share the same contiguous DNS name
space.
o
o
o
o
o
What is an AD forest?
A forest is a collection of related domain trees. The forest establishes the relationship
between trees that have different DNS name spaces.
o
o
o
o
o
o
o
o
o
o
o
What is replication?
Replication is the process of copying changes to Active Directory between the domain
controllers.
o
o
o
o
o
o
o
o
o
o
What two objects does AD use to represent the physical structure of the network?
- A subnet represents a physical network segment. Each subnet possesses its own
unique network address space.
- A site represents a group of well-connected networks (networks that are connected with high-speed
links).
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
Which level do the Schema and Domain Naming Master roles operate at?
The Forest Level
What level do the RID, PDC and Infrastructure Master roles operate at?
The domain level
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
What is an AD role?
A role is a set of software features that provides a specific server function. Examples
of roles include DNS server, DHCP server, File Server, and Print Server.
What is an AD feature?
A feature is a software program not directly related to a server role but which adds
functionality to the entire server. Features include management tools, communication protocols or
clients, and clustering support.
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
What methods can you use to manage a Server 2008 core system?
Log on and use the command prompt.
Log on using Remote Desktop to gain access to the command prompt.
Use Windows Remote Shell (winrm).
Run Server Manager or another tool on another computer and connect to the server core system. This
method allows you to use a GUI interface for managing the server core system.
How would you add server roles to a Server 2008 core system?
Run start /w ocsetup to add server roles to the server core system. Switches for the
role or service must be typed exactly as they are listed, and role names are case-sensitive.
o
o
How would you see a list of roles, role services and features that can be installed on
Server 2008 core?
run the oclist command
Cards
Term
Definition
Definition
Definition
What is a domain
Term
what is a tree in AD
Term
Term
what is a forest in AD
Term
Term
What are an OU (organizational unit) logical subgroup within a domain, used to locate
single workgroup, section, or department
Term
Definition
What is a site in AD
Term
Term
Definition
Term
Definition
Term
Term
Term
Term
Term
What is FSMO
Term
Term
1. schema master
2. Domain naming master
3. PDC emulator (Primary domain
controller)
4. Infrastructure master
5. RID masster (Relative Identifier
Definition
Term
Term
What is a feature
Term
Term
1. Initial config
2. Server Manager
3. command line
Definition
Term
Definition
What is the server core and its functionA stripped down version of server 2008 without a
GUI, taskbar, or start menu
Term
Definition
Term
What is AD CS
Term
Term
Definition
Term
Term
Start
Run
CMD
ServerManagerCmd.exe
Definition
Schema
Definition
Objects
Term
Global Catalog
Term
Definition
Definition
Schema master
Term
Definition
Term
One of five
Forest-wide operations master roles.
The domain controller holding the ______ ______
______role controls the addition or removal of
domains in the forest. There can be only one in
the entire forest.
Definition
One of five
Forest-wide operations master roles.
The _____ master allocates sequences of relative
IDs to each of the various domain controllers in
its domain. At any time, there can be only one
domain controller acting as the _____ master in
each domain in the forest.
Definition
One of five
Forest-wide operations master roles.
The PDC _____ ______ master processes
password changes from client computers and
replicates these updates to all domain controllers
throughout the domain. At any time, there can be
Definition
Infrastructure master
Term
One of five
Forest-wide operations master roles.
At any time, there can be only one domain
controller acting as the ______ ______ in each
domain. The ______ ______ is responsible for
updating references from objects in its domain to
objects in other domains. The ______ ______
compares its data with that of a global catalog.
Global catalogs receive regular updates for
objects in all domains through replication, so the
global catalog data will always be up to date. If
the ______ ______ finds data that is out of date, it
requests the updated data from a global catalog.
The infrastructure master then replicates that
updated data to the other domain controllers in
the domain.
The ______ ______ is also responsible for
updating the group-to-user references whenever
the members of groups are renamed or changed.
Definition
Definition
Term
Distribution group
Definition
Security group
Term
Definition
Term
Global group
Term
Universal group
Term
an ______ _____.
Term
Definition
Term
Definition
Term
Realm trust (Non-transitive) _____ _____ allow trust relationships with Unix
systems that use Kerberos for authentication.
(What Microsoft calls domains Unix call realms.)
Term
Definition
Forest
Definition
Term
Definition
Term
Definition
Term
Features:
Enabled by default
Supports most older versions of Windows
Support LMHOSTS local resolution
Can use a WINS server
Drawbacks:
Only supports IPv4
Uses broadcasts
15 Character Maximum
Local Subnet only without WINS
Definition
Definition
Term
Definition
Definition
Recursion
Term
__________:
Client sends a ________ request to a DNS server
DNS server completes query on behalf of the
DNS client and sends result back to client.
Definition
Iteration
__________:
Used by DNS server when contacting other DNS
servers
Receives referral from one server and directly
queries the server listed in the referral.
One DNS server does most of the work
Term
Definition
Root Hints
Term
____ _____
Used during recursion
Gives DNS a starting point
Can be modified for private namespaces
Stored in Windows \System32 \DNS\Cache.dns
Loaded when DNS service starts
Definition
Definition
Definition
Term
Definition
DNS Forwarders
Definition
Conditional Forwarders
Term
______ Forwarders:
Forwards queries for a specific domain name to
specific DNS servers
Often used to improve performance for DNS
resolution of partner domain names and
resources
Definition
Definition
Resource Records
Term
NAT
o
o
You decide to create a trust relationship between Domain A and Domain B. Before
you take any other actions, can users in Domain A use resources from Domain B yet?
No.
A trust relationship only allows for the possibility of sharing resources between domains; it does not
explicitly provide any permissions. In order to allow users to access resources in another domain, you
must configure the appropriate permissions.
Plans are to deploy four Active Directory domains with the following requirements:
minimize the number of servers
o
o
o
o
o
o
o
o
o
o
o
o
enough fault tolerance to survive the complete failure of one domain controller.
What is the minimum number of domain controllers to deploy initially?
8
Two per domain for fault tolerance
What are several Active Directory domains that share a contiguous namespace
called?
o
o
o
o
A tree
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
Which pieces of information should you have before you use the Active Directory
Installation Wizard to install a new subdomain?
name of the child domain
name of the parent domain
DNS configuration information
NetBIOS name for the server
Which type of trust is automatically created between the domains in a domain tree?
Transitive two-way
New remote location with very slow WAN link. Needs following specs:
Fast logon times
Reduced network bandwidth
Ability to use existing hardware
What can you implement to achieve the above requirements?
Universal group membership caching stores information locally once a user attempts
to log on for the first time.
Of the five main single master functions, two apply to an entire Active Directory forest.
What are the three that apply to just the domain?
RID Master
PDC Emulator Master
Infrastructure Master
When deploying Active Directory, you decide to create a new domain tree. What do
you need to do to create this?
Promote a Windows Server 2008 computer to a domain controller and select the
option that makes this domain controller the first machine in a new domain that is a child of an existing
one.
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
If you want to join a W2k8 server to an existing W2k3 Forest what do you need to do
first?
o
o
What naming information do you need prior to joining a domain to a new tree?
name of the parent domain
name of the child domain
NetBIOS name for the new server
o
o
o
o
o
What other information (other than the 3 names) do you need prior to joining a
domain to a new tree?
DNS configuration
domain administrator username and password
o
o
o
o
Type of trust between the Forest Root Domain and all the rest of the domains in the
forest
2-way Transitive
o
o
o
o
o
o
o
o
o
True of False? A Trust grants all users in one domain access to the other domains.
False.
Trust only provides the foundation.
Rights must be granted to resources once Trust is established.
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
What do you need to ensure is done before you remove the last DC from a Domain?
Computers no longer log on to this domain
No user accounts are needed
All encrypted data is decrypted
All cryptographic keys are backed up
In a Forest running at 2k Native or later what role does the PDC play?
Acts as default DC if another is not available
o
o
o
o
o
o
o
o
o
How do you assign all of the RID, PDC and Infrastructure Roles?
Open AD U&C
right-click Domain
Select Operation Masters
Click Change
o
o
o
o
o
On External Trusts, what is enabled by default to prevent hackers from using SID info
to gain access?
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
o
What happens when Selective authentication is used with Cross Forest Trusts?
users can't authenticate to DC or resource server unless explicitly enabled
You need to add another Global Catalog server to an existing domain. Where would
you go to do this?
AD S&S
- DC
- NTDS Settings Properties
- GC Checkbox
o
o
o
o