Documente Academic
Documente Profesional
Documente Cultură
Ans. New sites are configured through Active Directory Sites and Services. After creating a new site, the following tasks must be
completed:
Ans. To configure a server as a GC server, use Active Directory Sites and Services. Select the desired domain controller, then right-
click on NTDS settings and choose properties. Check the box for Global Catalog.
Ans. The AD system state data backup can be taken by using windows 2000 backup utility.
Ans. Non-Authoritative restore is use when you are restoring out-of-date information and want the restored data to be overwritten by
newer data stored in Active Directory on other domain controllers. For example, you would do this if you were recovering a DC from
a failed hard drive and restored the server.
Ans. All domains in a tree automatically establish two way trust relationships called Kerberos trusts. Trust relationships between
Windows 2000 domains and NT 4 domains must be configured manually, just as you would configure a trust relationship between two
NT 4 domains.
Ans. Caching servers do not store an editable copy of the zone database. Active directory integrated zones can reside only on domain
controllers, not member servers or non-Windows 2000 servers of any kind (NT 4, Unix, and so on).
17. What should be checked if a user gets an error message Domain controller cannot be found while logging in?
Ans. If a user who is trying to log on gets an error that a Domain controller cannot be found, check for the presence of SRV records in
the DNS database for domain controllers.
Ans. Secure dynamic updates allow only computers and users who have been given permission to update their records into the DNS
database. Secure dynamic update is supported only for Active Directory integrated zones.
Ans. DNS replication is accomplished through Active Directory replication for AD integrated zones and zone transfer for standard
zones.
Ans. A reverse lookup zone must be configured in order to perform reverse lookup queries. Installing AD through Configure Your
Server does not create a reverse lookup zone in DNS.
How to Verify an Active Directory Installation in Windows Server 2003
SUMMARY
After you have performed an upgrade, you can verify the promotion
of a server to a domain controller by verifying the following items.
•
Default Containers
You must have a DNS server installed and configured for Active
Directory and the associated client software to function correctly.
Microsoft recommends that you use Microsoft version of DNS
Server as your DNS server (this is bundled with Windows Server
2003). However, this version of DNS is not required. The DNS server
that you use must support the Service Resource Record (SRV RR)
Requests for Comments (RFC) 2052, and the dynamic update
protocol (RFC 2136). Use the DNS Manager MMC snap-in to verify
that the correct zones and resource records are created for each
DNS zone. Active Directory creates its SRV RRs in the following
folders:
• _Msdcs/Dc/_Sites/Default-first-site-name/_Tcp
• _Msdcs/Dc/_Tcp