2013年8月5日月曜日

模擬問題 31 (MCP 70-640 Windows Server 2008 Active Directory, Configuring)

問題:

あなたは、名前Server1とServer2の2つのサーバーを持っている。
両方のサーバーは、Windows Server 2008 R2を実行します。
Server1にはエンタープライズのルート証明機関(CA)として構成されています。

あなたは、Server2の上でオンラインレスポンダの役割サービスをインストールします。
あなたは、エンタープライズルートCAの証明書失効リスト(CRL)を発行するServer2を設定する必要があります。

あなたはどの2つのタスクを実行する必要がありますか?
(それぞれの正しい答えは、ソリューションの一部を紹介します。2を選択してください。)

A.は、エンタープライズルートCA証明書をインポートします。
B.は、OCSP応答の署名証明書をインポートします。
C.はCertPublishersグループにServer1にコンピュータアカウントを追加します。
D.自動に証明書伝搬サービスのスタートアップの種類を設定します。
解答:
 A B


参考:
オンラインレスポンダインストール、構成、およびトラブルシューティング·ガイド
公開鍵インフラストラクチャ(PKI)は、証明書、証明書の失効を含む、複数のコンポーネントで構成されています
リスト(CRL)と認証局(CA)。ほとんどのケースでは、X.509に依存するアプリケーション
このようなセキュアな/マルチパーパスインターネットメールエクステンション(S / MIME)、セキュア·ソケット·レイヤー(SSL)などの証明書、
そしてスマートカードは、認証を行う際に使用される証明書の状態を検証するために必要とされる
署名、または暗号化操作。証明書の状態と失効チェックは、プロセスであることで
時間と失効状態:証明書の有効性は、2つの主要カテゴリに基づいて検証されます。
..
検証していますが、証明書の失効ステータスを複数の方法で実行、共通することができます
メカニズムはCRLは、デルタCRLを、およびオンライン証明書状態プロトコル(OCSP)応答である。
Online Responder Installation, Configuration, and Troubleshooting Guide
Public key infrastructure (PKI) consists of multiple components, including certificates, certificate revocation
lists (CRLs) and certification authorities (CAs). In most cases, applications that depend on X.509
certificates, such as Secure/Multipurpose Internet Mail Extensions (S/MIME), Secure Sockets Layer (SSL)
and smart cards, are required to validate the status of the certificates used when performing authentication,
signing, or encryption operations. The certificate status and revocation checking is the process by which
the validity of certificates is verified based on two main categories: time and revocation status.
..
Although validating the revocation status of certificates can be performed in multiple ways, the common
mechanisms are CRLs, delta CRLs, and Online Certificate Status Protocol (OCSP) responses.

模擬問題 30 (MCP 70-640 Windows Server 2008 Active Directory, Configuring)

問題:

すべてのコンサルタントがTempWorkersという名前のグローバルグループに属しています。
あなたがSecureServersという新しい組織単位に3つのファイル·サーバを配置します。
3つのファイルサーバは、共有フォルダにある機密データが含まれています。

あなたは、機密データにアクセスするためにコンサルタントによって行われたすべての失敗した試行を記録する必要があります。
あなたはどちらつのアクションを実行する必要があります?
(それぞれの正しい答えは、ソリューションの一部を紹介します。2つを選択してください。)

A. Create and link a new GPO to the SecureServers organizational unit. Configure the Deny access to this
computer from the network user rights setting for the TempWorkers global group.
B. Create and link a new GPO to the SecureServers organizational unit. Configure the Audit privilege use
Failure audit policy setting.
C. Create and link a new GPO to the SecureServers organizational unit. Configure the Audit object access
Failure audit policy setting.
D. On each shared folder on the three file servers, add the three servers to the Auditing tab. Configure the
Failed Full control setting in the Auditing Entry dialog box.
E. On each shared folder on the three file servers, add the TempWorkers global group to the Auditing tab.
Configure the Failed Full control setting in the Auditing Entry dialog box.

解答:
Correct Answer:
 C E
参考:
http://technet.microsoft.com/ja-jp/library/cc776774%28v=ws.10%29.aspx

模擬問題 29 (MCP 70-640Windows Server 2008 Active Directory, Configuring)


問題:

あなたの会社では、contoso.comとfabrikam.comという名前の2つのActive Directoryフォレストがあります。両方のフォレストは、Windows Server 2008を実行するドメインコントローラのみを実行します。 contoso.comのドメイン機能レベルは、Windows Server 2008である。 fabrikam.comのドメイン機能レベルがWindows Server 2003のネイティブモードです。
あなたは、contoso.comとfabrikam.com間に外部の信頼を設定します。
あなたは、KerberosのAES暗号化オプションを有効にする必要があります。
あなたはどうすればいいの?
A. Windows Server 2008にfabrikam.comのフォレストの機能レベルを上げます。
B.は、Windows Server 2008にfabrikam.comのドメインの機能レベルを上げる。
C.は、Windows Server 2008にcontoso.comのフォレストの機能レベルを上げます。
D.は、新しいフォレストの信頼を作成し、フォレスト全体の認証を有効にします。
正解:
B
回答:
Windows Server 2008にfabrikam.comのドメインの機能レベルを上げる。
Raise the domain functional level of fabrikam.com to Windows Server 2008.

ドメインの機能レベルで利用可能な機能レベルは、利用可能なActive Directoryドメインサービス(AD DS)ドメインまたはフォレストの機能を決定する。彼らはまた、ドメインまたはフォレスト内のドメインコントローラ上で実行できるWindows Serverオペレーティングシステムを決定します。しかし、機能レベルは、ドメインまたはフォレストに参加しているワークステーションとメンバーサーバー上で実行できるオペレーティングシステムに影響を与える可能性はありません。 ..

Windows Server 2008では、デフォルトのAD DSの機能はすべて、Windows Server 2003ドメインの機能レベルのすべての機能と、次の機能が用意されています。..
Kerberosプロトコルのための*高度な暗号化標準(AES128およびAES 256)をサポート。ためにAESを使用して発行するTGTのために、ドメインの機能レベルは、Windows Server 2008以上でなければなりませんし、ドメインのパスワードは変更する必要があります。

Functional levels determine the available Active Directory Domain Services (AD DS) domain or forest capabilities. They also determine which Windows Server operating systems you can run on domain controllers in the domain or forest. However, functional levels do not affect which operating systems you can run on workstations and member servers that are joined to the domain or forest. ..
Features that are available at domain functional levels
..
Windows Server 2008 All of the default AD DS features, all of the features from the Windows Server 2003 domain functional level, and the following features are available: ..
* Advanced Encryption Standard (AES 128 and AES 256) support for the Kerberos protocol. In order for TGTs to be issued using AES, the domain functional level must be Windows Server 2008 or higher and the domain password needs to be changed.

模擬問題 28 (MCP 70-640Windows Server 2008 Active Directory, Configuring)


問題:

あなたの会社は別のActive Directoryサイトとして構成され、Active Directoryドメインコントローラを持っている支店があります。
Active Directoryサイトは、新しいアプリケーションをサポートするために、地元のグローバルカタログサーバが必要です。

あなたは、グローバルカタログサーバーとしてドメインコントローラを構成する必要があります。
あなたは、どのツールを使うべきでしょうか?
A. サーバーマネージャコンソール
B. Active Directoryサイトとサービスコンソール
C. Dcpromo.exeのユーティリティ
D. コンピュータの管理コンソール
E. Active Directoryドメインと信頼関係コンソール
解答:
Correct Answer: B
 The Active Directory Sites and Services console

参考:
グローバルカタログは、マルチドメインのActive Directoryドメインサービス(AD DS)、フォレスト内のすべてのドメイン内のすべてのオブジェクトの検索、部分的な表現を含む分散データリポジトリです。グローバルカタログは、グローバルカタログサーバーとして指定されており、マルチマスター·レプリケーションを介して配布されているドメインコントローラに保存されます。彼らは別のドメインコントローラへの紹介を伴わないので、グローバルカタログに向けられている検索が高速になります。
構成およびスキーマディレクトリパーティションのレプリカに加えて、フォレスト内のすべてのドメインコントローラは、単一のドメインディレクトリパーティションの完全な、書き込み可能なレプリカを格納します。そのため、ドメインコントローラは、そのドメイン内のオブジェクトだけを見つけることができます。異なるドメイン内のオブジェクトを配置すると、ユーザーまたはアプリケーションが要求されたオブジェクトのドメインを提供することが必要になります。
グローバルカタログは、ドメイン名を知らなくても、任意のドメインからのオブジェクトを検索する機能を提供します。グローバルカタログサーバーはまた、フォレスト内の他のすべてのドメインディレクトリパーティションの部分、読み取り専用のレプリカが格納され、その完全な、書き込み可能なドメインディレクトリパーティションのレプリカに加えて、ドメインコントローラである。属性の限られたセットは、オブジェクトごとに含まれているため、追加のドメインディレクトリパーティションは部分です。ほとんどの検索に使用されている属性のみを含めることで、あっても最大のフォレスト内のすべてのドメイン内のすべてのオブジェクトは、単一のグローバルカタログサーバーのデータベースで表すことができます。
注:グローバルカタログサーバは、アプリケーションディレクトリパーティションの完全な、書き込み可能なレプリカを格納できますが、アプリケーションディレクトリパーティション内のオブジェクトは、部分、読み取り専用のディレクトリパーティションとしてグローバルカタログに複製されません。
グローバルカタログが構築され、AD DSのレプリケーションシステムによって自動的に更新されます。グローバルカタログにレプリケートされる属性は、部分的な属性セット(PAS)としてスキーマで識別され、Microsoftがデフォルトで定義されています。しかし、検索を最適化するためには、グローバル·カタログに格納されている属性を追加または削除することによって、スキーマを編集することができます。
Windows 2000 Serverの環境では、グローバルカタログの完全同期でPAS結果(すべての属性の更新)に変更。以降のWindows Serverの
バージョンでは、属性だけその変更を複製することによって、グローバルカタログの更新の影響を低減。
単一ドメインフォレストでは、グローバルカタログサーバーは、ドメインの完全な、書き込み可能なレプリカを保存し、任意の部分レプリカを格納しません。フォレスト全体の検索の処理を除き、非グローバルカタログサーバーと同じ方法で、単一ドメインのフォレスト機能のグローバルカタログサーバ。
The global catalog is a distributed data repository that contains a searchable, partial representation of every object in every domain in a multidomain Active Directory Domain Services (AD DS) forest. The global catalog is stored on domain controllers that have been designated as global catalog servers and is distributed through multimaster replication. Searches that are directed to the global catalog are faster because they do not involve referrals to different domain controllers.
In addition to configuration and schema directory partition replicas, every domain controller in a forest stores a full, writable replica of a single domain directory partition. Therefore, a domain controller can locate only the objects in its domain. Locating an object in a different domain would require the user or application to provide the domain of the requested object.
The global catalog provides the ability to locate objects from any domain without having to know the domain name. A global catalog server is a domain controller that, in addition to its full, writable domain directory partition replica, also stores a partial, read-only replica of all other domain directory partitions in the forest. The additional domain directory partitions are partial because only a limited set of attributes is included for each object. By including only the attributes that are most used for searching, every object in every domain in even the largest forest can be represented in the database of a single global catalog server.
Note: A global catalog server can also store a full, writable replica of an application directory partition, but objects in application directory partitions are not replicated to the global catalog as partial, read-only directory partitions.
The global catalog is built and updated automatically by the AD DS replication system. The attributes that are replicated to the global catalog are identified in the schema as the partial attribute set (PAS) and are defined by default by Microsoft. However, to optimize searching, you can edit the schema by adding or removing attributes that are stored in the global catalog.
In Windows 2000 Server environments, any change to the PAS results in full synchronization (update of all attributes) of the global catalog. Later versions of Windows Server reduce the impact of updating the global catalog by replicating only the attributes that change.
In a single-domain forest, a global catalog server stores a full, writable replica of the domain and does not store any partial replica. A global catalog server in a single-domain forest functions in the same manner as a non-global-catalog server except for the processing of forest-wide searches.

模擬問題 27 (MCP 70-640Windows Server 2008 Active Directory, Configuring)

問題:

あなたの会社は別のActive Directoryサイトとして構成され、Active Directoryドメインコントローラを持っている支店があります。
Active Directoryサイトは、新しいアプリケーションをサポートするために、地元のグローバルカタログサーバが必要です。

あなたは、グローバルカタログサーバーとしてドメインコントローラを構成する必要があります。
あなたは、どのツールを使うべきでしょうか?
A. サーバーマネージャコンソール
B. Active Directoryサイトとサービスコンソール
C. Dcpromo.exeのユーティリティ
D. コンピュータの管理コンソール
E. Active Directoryドメインと信頼関係コンソール
解答:
Correct Answer: B
 The Active Directory Sites and Services console

参考:
グローバルカタログは、マルチドメインのActive Directoryドメインサービス(AD DS)、フォレスト内のすべてのドメイン内のすべてのオブジェクトの検索、部分的な表現を含む分散データリポジトリです。グローバルカタログは、グローバルカタログサーバーとして指定されており、マルチマスター·レプリケーションを介して配布されているドメインコントローラに保存されます。彼らは別のドメインコントローラへの紹介を伴わないので、グローバルカタログに向けられている検索が高速になります。
構成およびスキーマディレクトリパーティションのレプリカに加えて、フォレスト内のすべてのドメインコントローラは、単一のドメインディレクトリパーティションの完全な、書き込み可能なレプリカを格納します。そのため、ドメインコントローラは、そのドメイン内のオブジェクトだけを見つけることができます。異なるドメイン内のオブジェクトを配置すると、ユーザーまたはアプリケーションが要求されたオブジェクトのドメインを提供することが必要になります。
グローバルカタログは、ドメイン名を知らなくても、任意のドメインからのオブジェクトを検索する機能を提供します。グローバルカタログサーバーはまた、フォレスト内の他のすべてのドメインディレクトリパーティションの部分、読み取り専用のレプリカが格納され、その完全な、書き込み可能なドメインディレクトリパーティションのレプリカに加えて、ドメインコントローラである。属性の限られたセットは、オブジェクトごとに含まれているため、追加のドメインディレクトリパーティションは部分です。ほとんどの検索に使用されている属性のみを含めることで、あっても最大のフォレスト内のすべてのドメイン内のすべてのオブジェクトは、単一のグローバルカタログサーバーのデータベースで表すことができます。
注:グローバルカタログサーバは、アプリケーションディレクトリパーティションの完全な、書き込み可能なレプリカを格納できますが、アプリケーションディレクトリパーティション内のオブジェクトは、部分、読み取り専用のディレクトリパーティションとしてグローバルカタログに複製されません。
グローバルカタログが構築され、AD DSのレプリケーションシステムによって自動的に更新されます。グローバルカタログにレプリケートされる属性は、部分的な属性セット(PAS)としてスキーマで識別され、Microsoftがデフォルトで定義されています。しかし、検索を最適化するためには、グローバル·カタログに格納されている属性を追加または削除することによって、スキーマを編集することができます。
Windows 2000 Serverの環境では、グローバルカタログの完全同期でPAS結果(すべての属性の更新)に変更。以降のWindows Serverの
バージョンでは、属性だけその変更を複製することによって、グローバルカタログの更新の影響を低減。
単一ドメインフォレストでは、グローバルカタログサーバーは、ドメインの完全な、書き込み可能なレプリカを保存し、任意の部分レプリカを格納しません。フォレスト全体の検索の処理を除き、非グローバルカタログサーバーと同じ方法で、単一ドメインのフォレスト機能のグローバルカタログサーバ。
The global catalog is a distributed data repository that contains a searchable, partial representation of every object in every domain in a multidomain Active Directory Domain Services (AD DS) forest. The global catalog is stored on domain controllers that have been designated as global catalog servers and is distributed through multimaster replication. Searches that are directed to the global catalog are faster because they do not involve referrals to different domain controllers.
In addition to configuration and schema directory partition replicas, every domain controller in a forest stores a full, writable replica of a single domain directory partition. Therefore, a domain controller can locate only the objects in its domain. Locating an object in a different domain would require the user or application to provide the domain of the requested object.
The global catalog provides the ability to locate objects from any domain without having to know the domain name. A global catalog server is a domain controller that, in addition to its full, writable domain directory partition replica, also stores a partial, read-only replica of all other domain directory partitions in the forest. The additional domain directory partitions are partial because only a limited set of attributes is included for each object. By including only the attributes that are most used for searching, every object in every domain in even the largest forest can be represented in the database of a single global catalog server.
Note: A global catalog server can also store a full, writable replica of an application directory partition, but objects in application directory partitions are not replicated to the global catalog as partial, read-only directory partitions.
The global catalog is built and updated automatically by the AD DS replication system. The attributes that are replicated to the global catalog are identified in the schema as the partial attribute set (PAS) and are defined by default by Microsoft. However, to optimize searching, you can edit the schema by adding or removing attributes that are stored in the global catalog.
In Windows 2000 Server environments, any change to the PAS results in full synchronization (update of all attributes) of the global catalog. Later versions of Windows Server reduce the impact of updating the global catalog by replicating only the attributes that change.
In a single-domain forest, a global catalog server stores a full, writable replica of the domain and does not store any partial replica. A global catalog server in a single-domain forest functions in the same manner as a non-global-catalog server except for the processing of forest-wide searches.

2013年8月2日金曜日

模擬問題 26 (MCP 70-640 Windows Server 2008 Active Directory, Configuring)

問題:

あなたの会社は生産という名前の組織単位を持っています。生産組織単位は、​​R&Dという名前の子の組織単位を持っているあなたは、GPOという名前のソフトウェアデプロイメントを作成し、生産組織単位にリンクします。

あなたは、R&Dの組織単位のシャドウグループを作成します。

あなたは、生産組織単位内のユーザーにアプリケーションをデプロイする必要があります。また、アプリケーションは、R&Dの組織単位のユーザーに展開されていないことを確認する必要があります。

この目標を達成するには、2つの可能な方法は何ですか? (それぞれの正しい答えは、完全なソリューションを提供します。2を選択してください。)

A.は、R&Dの組織単位でブロックの継承設定を行います。

B.は、強制ソフトウェア展開GPOで設定を構成します。

C.設定セキュリティは、R&Dのセキュリティグループのグループポリシーの適用を拒否するには、Software展開GPOのフィルタリング。

D.は、生産組織単位でブロックの継承設定を行います。



回答:
Correct Answer: AC


 Explanation:

http://technet.microsoft.com/en-us/library/cc757050%28v=ws.10%29.aspx

Managing inheritance of Group Policy ..

Blocking Group Policy inheritance

You can block policy inheritance for a domain or organizational unit. Using block inheritance prevents GPOs linked to higher sites, domains, or organizational units from being automatically inherited by the child-level. By default, children inherit all GPOs from the parent, but it is sometimes useful to block inheritance. For example, if you want to apply a single set of policies to an entire domain except for one organizational unit, you can link the required GPOs at the domain level (from which all organizational units inherit policies by default) and then block inheritance only on the organizational unit to which the policies should not be applied.

Enforcing a GPO link

You can specify that the settings in a GPO link should take precedence over the settings of any child object by setting that link to Enforced. GPO-links that are enforced cannot be blocked from the parent container. Without enforcement from above, the settings of the GPO links at the higher level (parent) are overwritten by settings in GPOs linked to child organizational units, if the GPOs contain conflicting settings. With enforcement, the parent GPO link always has precedence. By default, GPO links are not enforced. In tools prior to GPMC, "enforced" was known as "No override." ..

模擬問題 25 (MCP 70-640 Windows Server 2008 Active Directory, Configuring)

問題:

あなたの会社はad.contoso.comという名前のActive Directoryドメインがあります。ドメインはDC1とDC2という名前の2つのドメインコントローラを持っています。両方のドメインコントローラは、DNSサーバーの役割がインストールされています。

あなたは、境界ネットワーク上DNS1.contoso.comという新しいDNSサーバをインストールします。あなたがDNS1.contoso.comにすべての未解決の名前要求を転送するDC1設定。

あなたは、DNS転送オプションはDC2に使用できないことを発見。

あなたがDNS1.contoso.comサーバを指すようにDC2サーバーにDNS転送を設定する必要があります。

あなたはどちらつのアクションを実行する必要があります? (それぞれの正しい答えは、ソリューションの一部を紹介します。2を選択してください。)

A.はDC2でDNSキャッシュをクリアします。

B.は、DC2に条件付き転送を設定します。

C.はDC2上のアドレスでlistenを設定します。

D.は、DC2にルートゾーンを削除します。


回答: B,D
Explanation/Reference:
 Answer: Delete the Root zone on DC2.
 Configure conditional forwarding on DC2.


 Explanation:

http://technet.microsoft.com/en-us/library/cc754941.aspx

Configure a DNS Server to Use Forwarders

A forwarder is a Domain Name System (DNS) server on a network that is used to forward DNS queries for external DNS names to DNS servers outside that network. You can also configure your server to forward queries according to specific domain names using conditional forwarders.

http://social.technet.microsoft.com/Forums/en-US/winserverNIS/thread/0ca38ece-d76e-42f0-85d5a342f9e169f5/

Deleting .root dns zone in 2008 DNS