Grant the new employees the Allow Full control permission.
Grant the new employees the Allow Access Dial-in permission.
Add the new employees to the Remote Desktop Users security group.
Add the new employees to the Windows Authorization Access security group.
第1题:
You are a Windows Server 2008 systems administrator responsible for configuring the Streaming MediaServices server role. Your organization would like to make numerous human resources training videosavailable for access by its employees. Employees should be able to pause and fast-forward content asneeded. You also want to ensure that users can access the content only while they are connected to your company's LAN. Which actions should you take?()
第2题:
Your network consists of a single Active Directory domain. The network is located on the 172.16.0.0/23 subnet. The company hires temporary employees. You provide user accounts and computers to the temporaryem ployees. The temporary employees receive computers that are outside the Active Directory domain. The temporary employees use their computers to connect to the network by using wired connections andwireless connections. The company’s security policy specifies that the computers connected to the network must have the latest updates for the operating system. You need to plan the network’s security so that it complies with the company 's security policy. What should you include in your plan?()
第3题:
You are the administrator of Company.com’s Windows 2000 Network. Your routed TCP/IP network consists of 10 Windows 2000 Server computers and 75 Windows 2000 Professional computers. All computers are in the Company.com domain. Your network uses TCP/IP as the only network protocol. You are installing 10 new Windows 2000 Professional computers. You want to enable the new computers to use host names to connect to shared resources on the network. You configure a TCP/IP address, a gateway address and a subnet mask on each new computer. You want to complete the configuration to allow the computers to communicate on the network. What should you do?()
第4题:
Your company hires 10 new employees. You want the new employees to connect to the main office through a VPN connection. You create new user accounts and grant the new employees the Allow Read and Allow Execute permissions to shared resources in the main office. The new employees are unable to access shared resources in the main office. You need to ensure that users are able to establish a VPN connection to the main office. What should you do()
第5题:
The human resources department has informed you that two new temporary part-time employees will join your company next week. You are required to set up a workstation that will be used bythese employees. They do not need access to the network but they will need to access an HP LaserJet printer attached to the local computer. You install Windows 2000 Professional and format the hard disk using NTFS. What type of user account should you create for them?()
第6题:
You and Stephen are the desktop administrators for your company. You install a printer on your Windows XP Professional computer. You share this printer on the company network. You want to ensure that only members of the DTAdmins local group can use this printer, and that only you and Stephen can manage the printer and all print jobs. You also want to ensure that members of the DTAdmins local group can manage only their own print jobs. How should you configure security on this printer?()
第7题:
You have stored confidential financial data in a shared folder named AccSecured on your Windows 2000 Professional computer. Your company hires an intern named Richard. You create a subfolder named intern, which Richard needs to access. You want to allow Richard access to the intern subfolder only. You create a user account named intern. You want to allow the intern user account the ability to update, create, and delete files within the intern folder. You need to prevent Richard from accessing any other files or folders within the AccSecured folder. What should you do?()
第8题:
Rename Drew’s user account to Adam, and change the account password.
Create a new account and link it to the previous users account.
Delete the account and create a new one.
Add a new user account to all the groups that the previous employee was added.
第9题:
The Add-Member cmdlet
ADSI Edit
The csvde.exe command
Active Directory Users and Computers
第10题:
Map a network drive to the AccSecuredintern folder from Richard’s computer.
Map a network drive to the AccSecured shared folder from Richard’s computer.
Allow the intern user account modify permissions on the intern subfolder.
Allow the intern user account traverse folder/execute file permission on the AccSecured folder.
Allow the intern user account list folder content permission on the AccSecured folder. Remove read extended attributes and read permissions.
第11题:
Create a script that uses Active Directory Services Interfaces (ADSI) to import all user account into the new environment.
Create new accounts for all users. Create a trust relationship between the existing environment and the new environment to enable access to resources in the existing environment.
Import all user accounts into the new environment by using the Active Directory Migration Tool (ADMT).
Import all user accounts into the new environment. Instruct users to no change their passwords during the migration phase so that they can access resources in the existing environment.
第12题:
Csvde.exe
Dsmod.exe
ldifde.exe
Ntdsutil.exe
第13题:
Your network contains an Active Directory forest. You set the Windows PowerShell execution policy to allow unsigned scripts on a domain controller in the network. You create a Windows PowerShell script named new-users.ps1 that contains the following lines: new-aduser user1 new-aduser user2 new-aduser user3 new-aduser user4 new-aduser user5 On the domain controller, you double-click the script and the script runs. You discover that the script fails to create the user accounts. You need to ensure that the script creates the user accounts. Which cmdlet should you add to the script()
第14题:
You are the network administrator for Testking.com. The network consists of a single Active Directory domain named testking.com. The sales department is hiring employees. An OU named TestKingSales is created to hold objects for the new sales department users. Each sales department user has a portable computer. Each portable computer runs Windows XP Professional. The sales department users are responsible for joining their portable computers to the domain. You need to ensure that the computer accounts for the Sales department user's portable computers are created in the TestKingSales OU. You need to achieve this goal without granting any unnecessary permissions. What should you do?()
第15题:
You are designing a migration strategy to create user IDs for all company users in the new environment. What should you do?()
第16题:
You have stored confidential financial data in a shared folder named AccSecured on your Windows 2000 Prfessional computer. Your company hires an intern named Richard. You create a subfolder named intern, which Richard needs to access. You want to allow Richard access to the intern subfolder only. You create a user account named intern. You want to allow the intern user account the ability to update, create, and delete files within the intern folder. You need to prevent Richard from accessing any other files or folders within the AccSecured folder. What should you do?()
第17题:
Your network contains an Active Directory domain named contoso.com. Your company hires 500 temporary employees for the summer. The human resources department gives you a Microsoft Excel document that contains a list of the temporary employees. You need to automate the creation of user accounts for the 500 temporary employees. Which tool should you use?()
第18题:
You install Windows 2000 Professional on your portable computer. You create a new dial up connection to connect to your company’s remote access server. You connect to the remote access server by using the dial up connection. You can connect to the servers on the same segment as the remote access server. You cannot access the shared resources that are on the remote segments from the remote access server. What should you do? ()
第19题:
Grant the new employees the Allow Full control permission.
Grant the new employees the Allow Access Dial-in permission.
Add the new employees to the Remote Desktop Users security group.
Add the new employees to the Windows Authorization Access security group.
第20题:
Assign the sales department users the Allow - Read permissions for the Computer container.
Configure the sales department users' user accounts to be trusted for delegation
Prestage the computer accounts in the TestKingSales OU for the sales department users' portable computers.
Assign the sales depertment users the Allow - Create all Child Objects permission for the TestKingSales OU.
第21题:
Modify the discretionary access control list (DACL) settings of the GPO to assign the Accountants and Management security groups the Deny - Read and the Deny - Apply Group Policy permissions. Modify the DACL of the GPO to assign the users who are in both the Accountants and Management security groups the Allow - Read and the Allow - Apply Group Policy permissions.
Modify the discretionary access control list (DACL) settings of the GPO to assign the Accountants and Management security groups the Deny - Read and the Deny - Apply Group Policy permissions. Create a new security group named Mixed that contains all the user accounts from the Processors group and the specific user accounts from the Management group to which you want the GPO to apply. Modify the DACL of the GPO to assign the Mixed security group the Allow - Read and the Allow - Apply Group Policy permissions.
Modify the discretionary access control list (DACL) settings of the GPO to assign the Accountants security group the Deny - Read and the Deny - Apply Group Policy permissions. Modify the DACL settings of the GPO to remove the Authenticated Users special group. Modify the DACL settings of the GPO to add the Processors group and assign the Allow - Read and the Allow - Apply Group Policy permissions.
Modify the discretionary access control list (DACL) settings of the GPO to assign the Accountants security group the Deny - Read and the Allow - Apply Group Policy permissions. Modify the DACL settings of the GPO to assign the Management security group the Deny - Read and the Deny - Apply Group Policy permissions.
第22题:
Map a network drive to the AccSecured/intern folder from Richard’s computer.
Map a network drive to the AccSecured shared folder from Richard’s computer.
Allow the intern user account modify permissions on the intern subfolder.
Allow the intern user account traverse folder/execute file permission on the AccSecured folder.
Allow the intern user account list folder content permission on the AccSecured folder. Removeread extended attributes and read permissions.
第23题:
Import-Module
Register-ObjectEvent
Set-ADDomain
Set-ADUser
第24题:
Implement a Network Access Protection (NAP) strategy for the 172.16.0.0/23 subnet.
Create an extranet domain within the same forest. Migrate the temporary employees user accounts to the extranet domain. Install the necessary domain resources on the 172.16.0.0/23 subnet.
Move the temporary employees user accounts to a new organizational unit (OU). Create a new Group Policy object (GPO) that uses an intranet Microsoft Update server. Link the new GPO tothe new OU.
Create a new subnet in a perimeter network. Relocate the wireless access point to the perimeter network. Require authentication through a VPN server before allowing access to the internal resources.