Designate a data recovery agent and issue an EFS certificate to the data recovery agent. Export the private key and restrict access to the exported key
Make the data recovery agent a local administrator on all client computers
Remove the default data recovery agent from the Default Domain Policy GPO. Then, include the new data recovery agent instead
Delete the Default Domain Policy GPO. Configure a new GPO linked to the domain that does not specify a data recovery agent
第1题:
You are the network administrator for your company. Your network consists of a single Active Directory domain. Three security groups named Accountants, Processors, and Management are located in an organizational unit (OU) named Accounting. All of the user accounts that belong to these three groups are also in the Accounting OU. You create a Group Policy object (GPO) and link it to the Accounting OU. You configure the GPO to disable the display options under the User Configuration section of the GPO. You need to achieve the following goals: You need to ensure that the GPO applies to all user accounts that are members of the Processors group. You need to prevent the GPO fromapplying to any user account that is a member of the Accountants group. You need to prevent the GPO from applying to any user account that is a member of the Management group, unless the user account is also a member of the Processors group. What should you do?()
第2题:
You have a single Active Directory directory service domain. You back up your domain controllers on a nightly basis. You perform Group Policy backups on a nightly basis. A Group Policy object (GPO) is accidentally deleted. You need to restore the GPO. What should you do?()
第3题:
You need to configure the security settings for the new app servers. Which two actions should you perform?()
第4题:
You have a single Active Directory directory service domain. All servers run Windows Server 2003. You need to specify the list of applications that users are permitted to run. You create a new Group Policy object (GPO) and link it to the domain. What should you do next?()
第5题:
You create a Password Settings object (PSO). You need to apply the PSO to a domain user named User1. What should you do()
第6题:
In a Group Policy object (GPO), configure the autoenrollment settings.
In a Group Policy object (GPO), configure the Automatic Certificate Request Settings.
On the certificate template, assign the Read and Autoenroll permission to the Authenticated Users group.
On the certificate template, assign the Read, Enroll, and Autoenroll permission to the Domain Users group.
第7题:
Create a Group Policy object (GPO) that configures the Allow .rdp files from unknown publishers policy setting in the Remote Desktop Client Connection template to Disabled. Apply the GPO to the TSUsers OU.
Create a Group Policy object (GPO) that configures the Allow .rdp files from valid publishers and users default .rdp settings policy setting in the Remote Desktop Client Connection template to Disabled. Apply the GPO to the TSUsers OU.
Create a Group Policy object (GPO) that configures the Allow .rdp files from valid publishers and users default .rdp settings policy setting in the Remote Desktop Client Connection template to Enabled. Apply the GPO to the TSAdmins OU.
Create a Group Policy object (GPO) that configures the Specify SHA1 thumbprints of certificates representing trusted .rdp publishers policy setting in the Remote Desktop Client Connection template to Enabled. Apply the GPO to the TSAdmins OU.
第8题:
On each client computer in the call center, configure a local policy that lists only authorized programs in the Allowed Windows Programs list
Using NTFS permissions, assign the Deny – Read permission for all unauthorized executable files to the client computer domain accounts
Design a Group Policy object (GPO) that enforces a software restriction policy on all client computers in the call center
Design a Group Policy object (GPO) that implements an IPSec policy on all client computers in the call center. Ensure that the IPSec policy rejects connections to any Web servers that the company does not operate
第9题:
Configure an Event Viewer subscription.
Increase the maximum log size.
Modify the event log policy settings in the Default Domain Policy Group Policy object (GPO).
Modify the event log policy settings in the Default Domain Controllers Policy Group Policy object(GPO).
第10题:
Get-AppLockerFileInformation
Get-GPOReport
Get-GPPermissions
Test-AppLockerPolicy
第11题:
Configure the kiosk computers as computers that are not members of any domain.Use Local Computer Policy to configure the computers with the collection of settings in the Kiosk Desktop Specification
Install one kiosk computer as a model.Configure this computer with the collection of settings in the Kiosk Desktop Specification.Copy the content of the C:///Documents and Settings/Default Users folder from this model computer to all other kiosk computers
Create a system policy file named Ntconfig.pol and configure it with the collection of settings in the Kiosk Desktop Specification.Make the kiosk computers members of the Active Directory domain.Use a Group Policy object (GPO) to run a startup script that copies the Ntconfig.pol file to the System32 folder on each kiosk computer
Create a Group Policy object (GPO) and configure it with the collection of settings in the Kiosk Desktop Specification: Also include an appropriate software restriction policy.Make the kiosk computers members of the Active Directory domain, and place the computer account objects in a dedicated OU. Link the GPO to this OU
第12题:
You have a single Active Directory directory service domain. You use a Group Policy object (GPO) to apply security settings to your client computers. You configure the startup type for system services settings in a new GPO, and you link the GPO to an organizational unit (OU). You discover that the startup type for system services on one of the client computers has not been updated. You need to ensure that the Group Policy settings are applied to the client computer. What should you do?()
第13题:
You have Active Directory Certificate Services (AD CS) deployed. You create a custom certificate template. You need to ensure that all of the users in the domain automatically enroll for a certificate based on the custom certificate template. Which two actions should you perform()
第14题:
Your company has deployed network access protection (NAP) enforcement for VPNs. You need to ensure that the health of all clients can be monitored and reported. What should you do?()
第15题:
You need to create a Password Settings object (PSO). Which tool should you use()
第16题:
You have Active Directory Certificate Services (AD CS) deployed. You create a custom certificate template. You need to ensure that all of the users in the domain automatically enroll for a certificate based on the custom certificate template. Which two actions should you perform()
第17题:
Configure the software restriction policy in the Default Domain Policy Group Policy object (GPO)
Create a new connection object by using the Connection Manager Administration Kit (CMAK), and install the new connection object on all client computers
Create and configure a local security policy on both of the ISA server computers
Configure the Internet Explorer settings in the Default Domain Policy Group Policy object (GPO)
第18题:
Run the New-GPStarterGPO cmdlet and the Copy-GPO cmdlet
Create a new starter GPO and manually configure the policy settings of the starter GPO.
Right-click GPO1, and then click Back Up.Create a new starter GPO,Right-click the new GPO, and then click Restore from Backup
Right-click GPO1, and then click Copy. Right-click Starter GPOs, and then click Paste
第19题:
In a Group Policy object (GPO), configure the autoenrollment settings
In a Group Policy object (GPO), configure the Automatic Certificate Request Settings.
On the certificate template, assign the Read and Autoenroll permission to the Authenticated Users group.
On the certificate template, assign the Read, Enroll, and Autoenroll permission to the Domain Users group.
第20题:
Create a Group Policy object (GPO) to publish the application. Link the GPO to the ContosoComputers OU.
Create a Group Policy object (GPO) to assign the application. Link the GPO to the ContosoComputers OU.
Create a Group Policy object (GPO) to publish the application. Link the GPO to the ContosoUsers OU.
Create a Group Policy object (GPO) to assign the application. Link the GPO to the ContosoUsers OU.
第21题:
Designate a data recovery agent and issue an EFS certificate to the data recovery agent. Export the private key and restrict access to the exported key
Make the data recovery agent a local administrator on all client computers
Remove the default data recovery agent from the Default Domain Policy GPO. Then, include the new data recovery agent instead
Delete the Default Domain Policy GPO. Configure a new GPO linked to the domain that does not specify a data recovery agent