MCSE 70-294 Practice Exam -1 Quiz

39 Questions | Total Attempts: 961

SettingsSettingsSettings
MCSE Quizzes & Trivia

MCSE 70-294 Practice Exam - 1: "Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure". This MCSE 70-294 practice exam tests you on tests you about Active Directory. You are required to be comfortable with Windows Server 2003 forests, domains, sites, Group Policies, and trusts. Also, try free MCSE practice questions and other resources from our free online MCSE school.


Related Topics
Questions and Answers
  • 1. 
    View Exhibit. The newly acquired domain shown in the exhibit needs to be allowed to access a file server in ‘Insure.MetroTech.com’ child domain. For this purpose, you are required to build the relevant trust relationship between the domains. Which of the following choices would be an appropriate direction of trust here?View Exhibit
    • A. 

      A bi-directional trust between the root and the newly acquired domain

    • B. 

      The root should be establishing external trust with the new domain

    • C. 

      ‘Insure.MetroTech.com’ should be establishing external trust with the new domain

    • D. 

      ‘Insure.MetroTech.com’ should be establishing external trust with the new domain

  • 2. 
    View Exhibit. Shown in the exhibit are three sites Site A, Site B and Site C. Each site has 2 DCs each. There are persistent links configured between each two sites BA, BC and AC. For the purpose of replication, it is required that only A_DC2 replicates with C_DC2 and B_DC2, whereas the only C_DC2 replicates with B_DC2. How would you achieve this?
    • A. 

      Ensure all DCs other than the mentioned get down graded to member servers.

    • B. 

      Configure A_DC2, B_DC2 and C_DC2 as preferred bridgehead servers.

    • C. 

      Configure A_DC1, B_DC1 and C_DC1 as preferred bridgehead servers.

    • D. 

      D. Remove all DCs other than the ones that need to replicate.

  • 3. 
    Your software development team has a proposed design for an application that will be configured to send Company related news to all users who are logged on to the network. This application will be using the ADS to store its data. You are required to allow the team the relevant permissions to create the application directory partition as required by the application to function accurately. Which of the following choices would help you achieve the same in this situation?
    • A. 

      Allow them permissions to modify the Schema.

    • B. 

      Add the team to the Enterprise Admins group.

    • C. 

      Add the team to the domain Admins group

    • D. 

      Delegate permissions to the team for the created cross-reference object

  • 4. 
    Type the command used to de-promote a domain controller from the ADS.
    • A. 

      Configure your server wizard

    • B. 

      Active Directory Schema

    • C. 

      Active Directory Installation Wizard

    • D. 

      DCPROMO

  • 5. 
    View the exhibit.Which of the following statements are true?
    • A. 

      A.MetroTech.com has a bi-directional trust with A.MetroTech.com and B.MetroTech.com. MetroTech.com trusts Infinity.com

    • B. 

      A.MetroTech.com has a bi-directional trust with A.MetroTech.com and B.MetroTech.com. B.MetroTech.com trusts Infinity.com

    • C. 

      A.MetroTech.com has a bi-directional trust with A.MetroTech.com and B.MetroTech.com. Infinity.com trusts Infinity.com

    • D. 

      A.MetroTech.com has a bi-directional trust with A.MetroTech.com and B.MetroTech.com. Infinity.com trusts B.MetroTech.com

  • 6. 
    Which of the following statements that relate to preferred Bridgehead servers are true?
    • A. 

      They are servers that have the best hardware configuration in the entire forest/domain.

    • B. 

      They are the DCs preferred for replication between partners across a site.

    • C. 

      They are capable of replicating with DCs internal to the site as well.

    • D. 

      They can only replicate across a WAN link and not within a site using Ethernet links.

  • 7. 
    You have just enabled your DC that was running as GC (Global Catalog) server to also function as Infrastructure master to ensure all domain related changes get replicated as quickly as possible. You have at least 10 DCs in the domain. But you hear complaints form administrators that this has not affected the functioning for the better at all. Many changes that were made were not replicated and hence not reflected. What could the problem be?
    • A. 

      The Infrastructure Master configuration was incorrect.

    • B. 

      The GC configuration was incorrect.

    • C. 

      The service pack version is incorrect.

    • D. 

      The GC and IM should not be hosted on the same DC.

  • 8. 
    You have an AD forest that has 3 levels of hierarchy under the root with a implicit bi-directional trust between all the levels. You have now configured a single direction external trust with the last level of domains and a domain of a company that you have recently acquired. Once the merger is complete, you are required to re-name this domain. Which of the following is true about the after effects of re-naming the new domain?
    • A. 

      This domain will be accessible as usual to all the domains in your AD forest.

    • B. 

      You will have to rebuild the trust after the renaming is done

    • C. 

      Unless the re-building of trust is done the new domain will be inaccessible to the domains in your forest.

    • D. 

      You will have to rename the last level domains in your AD forest as well.

  • 9. 
    You are the administrator for MetroTech.com that has an Active Directory infrastructure that consists of a single domain that resides on three domain controllers. During the latest replication, one of the OUs residing on one of the domain controller was not replicated to the other domain controllers. As a work around you instruct a junior administrator to perform a manual replication and he receives “access is denied” when the replication is attempted. What could the problem be?
    • A. 

      FRS is not configured properly

    • B. 

      Assign the relevant permission to the administrator.

    • C. 

      Links are not functioning properly

    • D. 

      None of the above

  • 10. 
    Which of the following are ideal situations to perform a non-authoritative restore on a DC?
    • A. 

      When all the Active Directory related information needs to be updated manually

    • B. 

      When only the data needs to be restored

    • C. 

      When only Active Directory related information needs to be restored

    • D. 

      When all updated data needs to be discarded

  • 11. 
    You have for some time now been receiving Hard disk space related error messages on your DC that is running a Windows Server 2003 domain. Active Directory is generating numerous errors due to the lack of hard drive space. You decide to install and configure a new HDD to rectify the problem. Which of the following should you first perform before you move the Active Directory to the new HDD?
    • A. 

      Run the ntdsutil command.

    • B. 

      Restart the domain controller in safe mode

    • C. 

      Restart the domain controller normally.

    • D. 

      Restart the domain controller in Directory Services Restore Mode.

  • 12. 
    Which of the following should be done to restore Active Directory to a DC from a tape backup?
    • A. 

      Perform a non-authoritative restore.

    • B. 

      Perform an authoritative restore.

    • C. 

      Use DCPROMO to upgrade the DC status.

    • D. 

      Re-install Active Directory.

  • 13. 
    Which of the following admin groups will be able to run "adprep /forestprep" successfully?
    • A. 

      Schema Admins group

    • B. 

      Domain Admins group

    • C. 

      Enterprise Admins group

    • D. 

      Administrators local group

  • 14. 
    You have just physically removed one of the DCs from the AD as it has suffered hardware failure and cannot be recovered. You now need to remove all reference of this object from the AD. You decide to use NTDSUTIL for this purpose. Which of the following are the most suitable NTDSUTIL command options to be chosen in this situation?
    • A. 

      Metadata cleanup

    • B. 

      Authoritative restore

    • C. 

      Semantic database analysis

    • D. 

      None of the above

  • 15. 
    Your DC that is also a GC currently is suffering performance wise. You have decided to introduce a new DC into the AD network, move the GC to this new DC and clean the disk space on the original GC so it can be used as a file server. You will be using the Active Directory Sites and Services tool for this purpose.What should you do? (Choose all that apply)
    • A. 

      Using NTDS settings on new DC check the GC setting.

    • B. 

      Using NTDS settings on old DC check the GC setting.

    • C. 

      Using NTDS settings on new DC uncheck the GC setting.

    • D. 

      Using NTDS settings on old DC uncheck the GC setting.

  • 16. 
    Your Windows Server 2003 AD network has one root and 5 child domains spread across as many locations. The network has a special set of users who will require unconditional access on all resource servers across domains and the network. These servers and users are spread across all locations in the network. Which of the following groups will be ideal to grant security access to the said users?
    • A. 

      Universal

    • B. 

      Domain Local

    • C. 

      Global

    • D. 

      Local

  • 17. 
    As a part of the internal audit exercise, your organization has decided that a couple of employees from each department will be grouped under a department called audit to ensure the audit exercise will be carried out smoothly. In accordance you will be required to deploy policies that will affect this group and provide them necessary permissions and access rights across the network. As a senior administrator of MetroTech.com forest, you decide to deploy a few of the team members of the IT department on to the task of managing the network scenario.Which of the following would be an ideal way of managing this scenario?
    • A. 

      A. Create a new organizational unit (OU) under MetroTech.com named Audit and move the audit users into it. Delegate the appropriate level of permissions at the audit OU to the IT users who will manage the users and computers. Create and link a GPO to the Audit OU that will restrict the client computers and distribute the applications.

    • B. 

      B. Create a new organizational unit (OU) under MetroTech.com named Audit and move the audit users into it. Place all the audit users and computers into a universal group called audit. Delegate control of the audit OU to the IT users. Create and link a GPO to the audit universal group that will restrict the desktops and distribute the applications.

    • C. 

      C. Create a child domain named audit.MetroTech.com. Add the IT users who need control over the users and computers in to the Domain Admins group. Create and link a GPO to the new domain to restrict the client computers and distribute the applications.

    • D. 

      D. Create a universal group named Audit and place the new audit users and computers into it. Delegate control over the universal group to the IT staff responsible for management of the audit users and computers. Create and link a GPO to the audit universal group that will restrict the client computers and distribute the applications.

  • 18. 
    MetroTech Finance has an AD structure that contains Windows Server 2003 forest/domain. They have just acquired a small subsidiary that will be treated as a child domain under the root. This organization has so far been running on Windows NT 4.0 network. Although there are plans for upgrade in the near future, you will be required to manage the existing setup as is. Each of the organization has offices spread across different geographical location and each office has a finance department. A part of each of the finance team is dedicated for auditing and is entitled to resources access across the network. You will be needed to work out a security strategy that will need to meet with the needs and will also specifically satisfy these goals: • The finance department's employees in each office should be able to access resources in the other office. • Administrators in each office will be responsible for managing the users in the group or groups. Which of the following will help you achieve the said strategy with minimum efforts? Choose all that apply. Each answer is part of the solution.
    • A. 

      Add the Finance groups of each location as members to MetroTech Finance.

    • B. 

      Create a universal group named MetroTech Finance.

    • C. 

      Create two domain local groups named after locations.

    • D. 

      Create global groups named after the location.

    • E. 

      Add individual finance members to the global groups created based on locations.

  • 19. 
    Which of the following can the Universal group be a parent to?
    • A. 

      User accounts

    • B. 

      Global groups

    • C. 

      Universal groups

    • D. 

      Local groups

  • 20. 
    Ywhile calculating the combined effect of Local permissions and Share permissions to arrive at NTFS permissions, which of the following statements can be considered true?
    • A. 

      The cumulative effect is most restrictive

    • B. 

      The cumulative effect is least restrictive

    • C. 

      Local permissions override share permissions

    • D. 

      Share permissions override local permissions

  • 21. 
    You wish to audit resource access of certain folders create and accessed by users belonging to a specific OU. You are required to use Group Policy Editor for computers in that OU. How can you achieve the said goal?
    • A. 

      Enable Audit account management.

    • B. 

      Enable Audit system events.

    • C. 

      Enable Audit logon events.

    • D. 

      Enable Audit object access.

  • 22. 
    You are the administrator for a single Active Directory domain called MetroTech.com. Your network is a Windows Server 2003/Windows XP platform. Each department has been assigned one OU. You are currently administering the Sales OU. You have a team of junior administrators. One of your junior administrator has reported that she is unable to modify existing Group Policy Objects (GPOs) links for the OU. The other administrators are not experiencing this problem. You need to achieve the following goals: • Provide this administrator with the ability to manage GPOs linked to the Sales OU. • Retain the exclusive ability to create new GPOs to yourselves. Which of the following would help you achieve the said goals?
    • A. 

      Use the Delegation of Control wizard to assign the Read all user information setting to this administrator for the domain.

    • B. 

      Use the Delegation of Control wizard to assign the Manage Group Policy links setting to this administrator for the Sales OU.

    • C. 

      Use the Active Directory Users and Computers console to add this administrator to the Owners/Creators group for the Sales OU.

    • D. 

      Use the Active Directory Users and Computers console to assign this administrator the Full Control permission for all relevant GPOs.

    • E. 

      Use the Active Directory Users and Computers console to assign this administrator the Read and Assign Group Policy Object permissions for all relevant GPOs.

  • 23. 
    You are the network administrator for MetroTech. The company's network consists of a single Active Directory forest that contains three domains: MetroTech.com, east. MetroTech.com, and west. MetroTech.com. The forest operates at the Windows Server 2003 forest functional level. The root domain contains administrative user accounts and computer accounts for three domain controllers and a member server hosting Routing and Remote Access Service (RRAS). Both child domains contain user accounts and computer accounts for client computers, file servers, application servers, and print servers. Each child domain contains user accounts for users in the sales, marketing, and accounting departments. You want to define MetroTech 's organizational unit (OU) structure to allow the creation of group policies that achieve the following goals: • Group policies can be applied to all users in each child domain and configured so that they are not overridden. • Group policies can be applied to users in each department in each domain. • All Group Policy Objects (GPOs) will be linked to OU objects. • A minimal number of OU objects will be created. • A minimal number of GPO links will be used. Which OU structure can be created to meet these goals
    • A. 

      You should create a parent OU container in each child domain. Then, you should create a child OU container below each parent container named for each of the three departments.

    • B. 

      You should create a parent OU container in each child domain.

    • C. 

      You should create a parent OU container in each level

    • D. 

      None of the above

  • 24. 
    You are the network administrator for MetroData. All servers run Windows Server 2003, and all client computers run Windows XP Professional. All domains operate at the Windows 2003 native domain functional level. Each domain has helpdesk personnel that are members of a global group named HDesk. An OU named Contract is located in MetroData.com, which contains the user accounts for all contract employees. You want to delegate the ability to reset passwords for users accounts located in the Contract OU to the helpdesk personnel in each domain. Which of the following should you perform? Choose two. Each correct answer represents part of the solution.
    • A. 

      Create a domain local group named ResetPass in MetroData.com and place U-HDesk in this group.

    • B. 

      Create a global group named U-HDesk in MetroData.com and add the three HDesk groups to this group.

    • C. 

      Create a universal group named U-HDesk in MetroData.com and add the three HDesk groups to this group.

    • D. 

      On the Contract OU, delegate the Reset passwords on user accounts permission to the U-HDesk universal group.

  • 25. 
    Your network consists of two domain controllers running Microsoft Windows Server 2003 and 5,000 workstation computers running Microsoft Windows 2000 Professional. There are 2 sites and organizational units (OUs) are set up for Accounting and Human Resources (HR). There is a domain controller at each site. You have three links configured between the Site A and Site B: 56 Kbps (slow link), 512 Kbps, and T1. Group Policy settings are applied at the site, domain, and organizational unit (OU) levels. You want to determine the effects of software deployment options settings on individual computers. You want to customize how group policy is applied to computers in the domain. You also want to allow the processing of software installation policy Group Policy object (GPO) settings over slow link connections. How can you accomplish this?
    • A. 

      From the Computer Configuration Administrative Templates, enable the background refresh of group policy.

    • B. 

      From the Computer Configuration Windows Settings, configure Software Restriction Policies.

    • C. 

      From the Computer Configuration Windows Settings, configure Security Settings.

    • D. 

      From the Computer Configuration Administrative Templates, click System, and then Group Policy. Under the Software Installation policy properties setting, select Enabled, and then select Allow processing across a slow network connection.