单项选择题
Your company has a main office and a branch office. The company has a single-domain Active Directory forest. The main office has two domain controllers named DC1 and DC2 that run Windows Server 2008. The branch office has a Windows Server 2008 read-only domain controller (RODC) named DC3. All domain controllers hold the DNS Server role and are configured as Active Directory-integrated zones. The DNS zones only allow secure updates. You need to enable dynamic DNS updates on DC3. What should you do()
A.Run the Ntdsutil.exe > DS Behavior commands on DC3.
B.Run the Dnscmd.exe /ZoneResetType command on DC3.
C.Reinstall Active Directory Domain Services on DC3 as a writable domain controller.
D.Create a custom application directory partition on DC1. Configure the partition to store Active Directory- integrated zones.
相关考题
-
多项选择题
AllconsultantsbelongtoaglobalgroupnamedTempWorkers.YouplacethreefileserversinaneworganizationalunitnamedSecureServers.Thethreefileserverscontainconfidentialdatalocatedinsharedfolders.Youneedtorecordanyfailedattemptsmadebytheconsultantstoaccesstheconfidentialdata.Whichtwoactionsshouldyouperform()
A.Create and link a new GPO to the SecureServers organizational unit Configure the Audit privilege use Failure audit policy setting.
B.Create and link a new GPO to the SecureServers organizational unit Configure the Audit object access Failure audit policy setting.
C.Create and link a new GPO to the SecureServers organizational unit Configure the Deny access to this computer from the network user rights setting for the TempWorkers global group.
D.On each shared folder on the three file servers, add the three servers to the Auditing tab Configure the Failed Full control setting in the Auditing Entry dialog.
E.On each shared folder on the three file servers, add the TempWorkers global group to the Auditing tab Configure the Failed Full control setting in the Auditing Entry dialog box. -
单项选择题
YourcompanyhasasingleActiveDirectorydomainnamedintranet.adatum.com.ThedomaincontrollersrunWindowsServer2008andtheDNSserverrole.Allcomputers,includingnon-domainmembers,dynamicallyregistertheirDNSrecords.Youneedtoconfiguretheintranet.adatum.comzonetoallowonlydomainmemberstodynamicallyregisterDNSrecords.Whatshouldyoudo()
A.Set dynamic updates to Secure Only.
B.Enable zone transfers to Name Servers.
C.Remove the Authenticated Users group.
D.Deny the Everyone group the Create All Child Objects permission. -
多项选择题
YourcompanyhasanorganizationalunitnamedProduction.TheProductionorganizationalunithasachildorganizationalunitnamedR&DYoucreateaGPOnamedSoftwareDeploymentandlinkittotheProductionorganizationalunit.YoucreateashadowgroupfortheR&Dorganizationalunit.YouneedtodeployanapplicationtousersintheProductionorganizationalunit.YoualsoneedtoensurethattheapplicationisnotdeployedtousersintheR&Dorganizationalunit.Whataretwopossiblewaystoachievethisgoal()
A.Configure the Enforce setting on the software deployment GPO.
B.Configure the Block Inheritance setting on the R&D organizational unit.
C.Configure the Block Inheritance setting on the Production organizational unit.
D.Configure security filtering on the Software Deployment GPO to Deny Apply group policy for the R&D security group.
