You are the network administrator for your company. The network consists of two Active Directory domains in a
single forest. The functional level of each domain is Windows 2000 mixed.
Your engineering department has 3,000 users. The engineering users are members of various global groups.
The company plans to open a new office where engineering users will test products. Engineering users will
need to dial in to the company network when they work at the new office.
You need to ensure that all new user accounts in the engineering department wilI have the appropriate group
memberships. These accounts must be allowed to connect to the network by using remote access permissions.
You must achieve your goal by using the minimum amount of administrative effort.
First, you create a template account for engineering users.
Which two additional actions should you perform? (Each correct answer presents part of the solution. Choose
two.)
You are the network administrator for your company. The network consists of a single Active Directory domain.
All domain controllers run Windows Server 2003.
You enabled the Audit account logon events policy and the Audit logon events policy on all domain controllers. You enabled both policies to audit for both success and failure attempts. In addition, you enabled
Audit logon events for all other computers in the domain for both success and failure attempts.
You suspect that an unauthorized user attempted to discover the password for the domain administrator account by using a computer located in a public area in the company's main office.
You need to find out if your network has been compromised.
What should you do?
You are the network administrator for your company. The network consists of a single Active Directory domain.
All domain controllers run Windows Server 2003.
The sales department recently hired 10 new employees. User accounts for these employees were created in
Active Directory. The manager of the sales department sent you a list of the new users and asked you to add
the user accounts to an existing global group named SalesDept.
You need to add the users to the SalesDept global group.
What are two possible ways to achieve this goal? (Each correct answer presents a complete solution. Choose
two.)
You are the network administrator for Fabrikam, Inc. The network contains a DNS server named Server1.
Server1 is configured to resolve queries for external internet resources. Server1 also hosts the fabrikam.com internal zone for Active Directory.
Users report that they are directed to the wrong Web site when browsing for well-known Internet Web sites.
You need to minimize the occurrence of unexpected results when users browse the Internet in the future. You also need to minimize disruption to users.
What should you do?
You are the network administrator for Contoso, Ltd. The network consists of a single Active Directory domain named contoso.com. The domain contains 125 Windows 2000 Professional computers and two Windows
Server 2003 computers. The network has no direct connection to the Internet.
A server named Server1 is a domain controller and the primary DNS server for the contoso.com domain. The network uses Server1 as the authoritative root server for the contoso.com domain. A server named Server2 is a
domain controller and DHCP server. Server2 is also used as a Web server, and it runs an intranet application.
Users report that when they try to connect to URLs outside of the contoso.com domain, their Web browsers are very slow to report that the URLs cannot be reached.
You need to ensure that DNS name resolution is as fast as possible.
What should you do?
You are the network administrator for your company. The network consists of a single Active Directory domain.
The Active Directory domain contains two domain controllers named DC1 and DC2.
During routine monitoring of the domain controllers, you observe numerous errors in the system log.
The errors are similar to the one shown in the following dialog box.
You need to resolve these errors on your domain controllers as quickly as possible.
What are two possible ways to achieve this goal? (Each correct answer presents a complete solution. Choose
two.)
You are the network administrator for your company. The network consists of a single Active Directory domain.
You install Windows Server 2003 on a computer named Server6. Server6 is a member of a workgroup. You configure Server6 as the Web server for the company's intranet Web site.
The company's written security policy states the following requirements:
- Smart cards are required to log on to all servers.
- Membership to the Remote Desktop Users group should remain empty.
- Users should not be able to log on through Terminal Server by using a blank password.
- Third-party applications should not be installed on network servers.
When you attempt to log on to Server6 by using your smart card, you receive an error message. You verify that
your user account is a member of the Domain Admins global group in your domain.
You need to be able to log on to Server6 by using your smart card.
What should you do?
You are the network administrator for your company. All client computers run Windows XP Professional. All servers run Windows Server 2003.
The company has offices in Los Angeles, San Francisco, and Seattle. Each office is configured as a separate
IP subnet. DNS is the only method of name resolution used on the network.
You need to implement a software update infrastructure on the network. You install Software Update Services
(SUS) on a computer named Server5 in the Los Angeles office. You install SUS on Server5 with all default settings. You have no plans to install additional SUS servers. You configure all client computers appropriately.
You must ensure that client computers can successfully connect to the SUS server.
What should you do?
You are the network administrator for your company. The network consists of a single Active Directory domain that contains two domain controllers. The domain controllers run Windows Server 2003 and Certificate
Services. Each domain controller has a single mirrored hard disk that contains a single NTFS volume.
You are responsible for backing up all servers. Company requirements state that backups must be performed only between the hours of 1:00 A.M. and 6:00 A.M. All servers share a single backup device. Because a large
amount of data must be backed up, you need to complete the required backups as quickly as possible in order to complete the backups within the allotted time.
You need to back up Active Directory and Certificate Services on the two domain controllers. The backup must include only the minimum amount of data necessary.
Which action or actions should you perform? (Choose all that apply.)
You are the network administrator for your company. The network consists of a single Active Directory domain.
All network servers run Windows Server 2003, and all client computers run Windows XP Professional.
You create a shared folder named Client Docs on a member server named Server1. Client Docs will store project documents. You configure shadow copies for the volume containing Client Docs.
You need to enable client computers to access previous versions of the documents in Client Docs.
What should you do?