多选题Your company has a single Active Directory domain. All servers run Windows Server 2008. The company network has servers that perform as Web Servers. All confidential files are located on a server named FSS1. The company security policy states that all 

题目
多选题
Your company has a single Active Directory domain. All servers run Windows Server 2008. The company network has servers that perform as Web Servers. All confidential files are located on a server named FSS1. The company security policy states that all confidential data must be transmitted in the most secure manner. When you monitor the network you notice that the confidential files stored on FSS1 server are being transmitted over the network without encryption. You need to ensure that encryption is always usedwhen the confidential files on the FSS1 server are transmitted over the network. What are two possible ways to achieve this goal? ()
A

Deactivate all LM and NTLM authentication methods on FSS1 server

B

Use IIS to publish the confidential files, activate SSL on the IIS server, and then open the files as a web folder

C

Use IPsec encryption between the FSS1 server and the computers of the users who need to access the confidential files.

D

Use the Server Message Block (SMB) signing between the FSS1 server and the computers of the users who want to access the confidential files.

E

Activate offline files for the confidential files that are stored on the FSS1 server. In the Folder avanced Properties box, select the Encrypt contents to secure data optiion


相似考题

3. Your network consists of a single Active Directory domain. All domain controllers run Windows Server2008 R2. Your company and an external partner plan to collaborate on a project. The external partner has an Active Directory domain that contains Windows Server 2008 R2 domain controllers. You need to design a collaboration solution that meets the following requirements:   èAllows users to prevent sensitive documents from being forwarded to untrusted recipients or from being  printed.   èAllows users in the external partner organization to access the protected content to which they have been granted rights.   èSends all inter-organizational traffic over port 443.   èMinimizes the administrative effort required to manage the external users. What should you include in your design?()A、Establish a federated trust between your company and the external partner. Deploy a Windows Server 2008 R2 server that has Microsoft SharePoint Foundation 2010 installed.B、Establish a federated trust between your company and the external partner. Deploy a Windows Server 2008 R2 server that runs Microsoft SharePoint 2010 and that has the Active Directory Rights  Management Services (AD?RMS) role installed.C、Establish an external forest trust between your company and the external partner. Deploy a Windows Server 2008 R2 server that has the Active Directory Certificate Services server role installed. Implement Encrypting File System (EFS).D、Establish an external forest trust between your company and the external partner. Deploy a Windows Server 2008 R2 server that has the Active Directory Rights Management Service (AD?RMS)role installed  and Microsoft SharePoint Foundation 2010 installed.

更多“Your company has a single Active Directory domain. All serve”相关问题
  • 第1题:

    our company has a single active directory forest that has six domains. All DNS servers in the forest run windows serve 2008. You need to ensure that all public DNS queries are channeled though a single-caching-only DNS server.Which two actions should you perform? ()

    • A、Disable the root hints.
    • B、Enable BIND secondaries.
    • C、Configure a forwarder to the caching DNS server.
    • D、Configure a GlobalNames host (A) record for the hostname of the caching DNS server.

    正确答案:A,C

  • 第2题:

    Contoso Ltd. has a single Active Directory forest that has five domains. Each domain has two DNS servers. Each DNS server hosts Active Directory-integrated zones for all five domains. All domain controllers run windows server 2008. Contoso acquires a company names Tailspin Toys. Tailspin Toys has a single Active Directory forest that contains a single domain. You need to configure the DNS system in the Contoso forest to provide name resolution for resources in both forests. What should you do?()

    • A、Configure client computers in the Contoso forest to use the Tailspin Toys DNS server as the alternate DNS server
    • B、Create a new conditional forwarder and store it in Active Directory. Replicate the new conditional forwarded to all DNS server in the Contoso forest.
    • C、Create a new application directory partition in the Contoso forest. Enlist the directory partition for all DNS servers
    • D、Create a new host (A) record in the GlobalNames folder on one of the DNS servers in the contoso forest. Configure the host (A) record by using the Tailspin Toys domain name and the ip address of the DNS server in the Tailspin Toys forest.

    正确答案:B

  • 第3题:

    Your company has a single Active Directory domain. All domain controllers run Windows Server  2003.     You install Windows Server 2008 R2 on a server.     You need to add the new server as a domain controller in your domain.     What should you do first()

    • A、On the new server, run dcpromo /adv.
    • B、On the new server, run dcpromo /createdcaccount.
    • C、On a domain controller run adprep /rodcprep.
    • D、On a domain controller, run adprep /forestprep.

    正确答案:D

  • 第4题:

    Your company has a main office and three branch offices. The company has an Active Directory forest that has a single domain. Each office has one domain controller. Each office is configured as an Active Directory site. All sites are connected with the DEFAULTIPSITELINK object. You need to decrease the replication latency between the domain controllers. What should you do()

    • A、Decrease the cost between the connection objects.
    • B、Decrease the replication interval for all connection objects.
    • C、Decrease the replication interval for the DEFAUL TIPSITELINK object.
    • D、Decrease the replication schedule for the DEFAUL TIPSITELINK object.

    正确答案:C

  • 第5题:

    单选题
    Your company has a single domain named contoso.com. The contoso.com DNS zone is Active Directoryintegrated. Your partner company has a single domain named partner.com. The partner.com DNS zone is Active Directory-integrated. The IP Addresses of the DNS servers in the partner domain will change. You need to ensure name resolution for users in contoso.com to resources in partner.com on each DNS server in contoso.com. What should you do?()
    A

    Create a stub zone for partner.com on each DNS server in contoso.com

    B

    Configure the zone replication scope for partner.com to replicate to all DNS servers in the forest

    C

    Configure an application directory partition in the contoso.com forest. Enlist all DNS servers in the contoso.com forest in the partition

    D

    Configure an application directory partition in the partner forest. Enlist all DNS servers in the partner forest in the partition.


    正确答案: A
    解析: 暂无解析

  • 第6题:

    单选题
    Your company has an Active Directory forest. All domain controllers run the DNS Server server role.The company plans to decommission the WINS service.You need to enable forest-wide single name resolution.What should you do?()
    A

    Enable WINS-R lookup in DNS.

    B

    Create Service Location (SRV) records for the single name resources.

    C

    Create an Active Directory-integrated zone named LegacyWINS. Create host (A) records for the single name resources.

    D

    Create an Active Directory-integrated zone named GlobalNames. Create host (A) records for the single name resources.


    正确答案: D
    解析: 暂无解析

  • 第7题:

    单选题
    Your company has a single Active Directory directory service domain. All servers in your environment run Windows Server 2003. All domain controllers run Active DirectoryCintegrated DNS. You create several static host (A) resource records. You need to verify that the DNS server is sending the correct host records to all client computers.  Which command-line tool should you use?()
    A

     netsh

    B

     tracert

    C

     ntdsutil

    D

     nslookup


    正确答案: D
    解析: 暂无解析

  • 第8题:

    单选题
    Your company has an Active Directory forest that contains a single domain. The domain member   server has an Active Directory Federation Services (AD FS) server role installed.   You need to configure AD FS to ensure that AD FS tokens contain information from the Active Directory  domain.   What should you do()
    A

    Add and configure a new account store.

    B

    Add and configure a new account partner.

    C

    Add and configure a new resource partner.

    D

    Add and configure a Claims-aware application.


    正确答案: B
    解析: 暂无解析

  • 第9题:

    单选题
    Your company has a single Active Directory domain. The domain runs at the functional level of Windows Server 2003. You install the DHCP service on a server named DHCP1. You attempt to startthe DHCP service, but it does not start. You need to ensure that the DHCP service starts. What should you do?()
    A

    Restart DHCP1.

    B

    Configure a scope on DHCP1.

    C

    Activate the scope on DHCP1.

    D

    Authorize DHCP1 in the Active Directory domain.


    正确答案: D
    解析: 暂无解析

  • 第10题:

    多选题
    Your company has a single Active Directory directory service forest. All user accounts are located in  the Users container. You need to create a number of organizational units (OUs) that will be used to store  user accounts.  What are two possible ways to achieve this goal?()
    A

    Use the Active Directory Sites and Services snap-in.

    B

    Use the Active Directory Users and Computers snap-in.

    C

    Use the Dsadd command-line tool with the OU parameter.

    D

    Use the Dsmod command-line tool with the OU parameter.


    正确答案: B,D
    解析: 暂无解析

  • 第11题:

    单选题
    Your company has a single domain named contoso.com. The contoso.com DNS zone is Active Directory-integrated. Your partner company has a single domain named partner.com. The partner.com DNS zone is Active Directory-integrated. The IP addresses of the DNS servers in the partner domain will change. You need to ensure name resolution for users in contoso.com to resources in partner.com. What should you do?()
    A

    Create a stub zone for partner.com on each DNS server in contoso.com.

    B

    Configure the Zone Replication Scope for partner.com to replicate to all DNS servers in the forest.

    C

    Configure an application directory partition in the contoso.com forest. Enlist all DNS servers in the contoso.com forest in the partition.

    D

    Configure an application directory partition in the partner forest. Enlist all DNS servers in the partner forest in the partition.


    正确答案: B
    解析: 暂无解析

  • 第12题:

    Contoso Ltd. has a single active directory forest that has five domains. Each domain has two DNS servers. Each DNS server hosts active directory-integrated zones for all five domains. All domain controllers run windows server 2008. Contoso acquires a company names tailspin toys. Tailspin toys has a single active directory forest that contains a single domain. You need to configure the DNS system in the contoso forest to provide name resolution for resources in both forests. What should you do?()

    • A、Configure client computers in the contoso forest to use the tailspin toys DNS server as the alternate DNS server.
    • B、Create a new conditional forwader and store it in active directory. Replicate the new conditional forwarded to all DNS server in the contoso forest.
    • C、Create a new application directory partition in the contoso forest. Enlist the directory partition for all DNS servers.
    • D、Create a new host (A) record in the globalnames folder on one of the DNS servers in the contoso forest. Configure the host (A) record by using by using the tailspin toys domain name and the ip address of the DNS server in the tailspin toys forest.

    正确答案:B

  • 第13题:

    You are a security administrator for your company. The network consists of three Active Directory domains. All Active Directory domains are running at a Windows Server 2003 mode functionality level.    Employees in the editorial department of your company need access to resources on file servers that are in each of the Active Directory domains. Each Active Directory domain in the company contains at least one editorial department employee user account.    You need to create a single group named Company Editors that contains all editorial department employee user accounts and that has access to the resources on file server computers.  What should you do?()

    • A、 Create a global distribution group in the forest root domain and name it Company Editors.
    • B、 Create a global security group in the forest root domain and name it Company Editors.
    • C、 Create a universal distribution group in the forest root domain and name it Company Editors. 
    • D、 Create a universal security group in the forest root domain and name it Company Editors.

    正确答案:D

  • 第14题:

    Your company has a single Active Directory directory service domain. Servers in your environment run Windows Server 2003. Client computers run Windows XP or Windows Vista. You plan to create an internal centrally managed security update infrastructure for client computers. You need to choose a security update management tool that supports all the client computers.  Which tool should you choose? ()

    • A、 Microsoft Assessment and Planning (MAP) Toolkit
    • B、 Microsoft Baseline Security Analyzer
    • C、 Microsoft System Center Operations Manager
    • D、 Windows Server Update Services (WSUS)

    正确答案:D

  • 第15题:

    Your company has an Active Directory forest. All domain controllers run the DNS server role. The company plans to decommission the WINS service. You need to enable forest-wide single name resolution. What should you do?()

    • A、Enable WINS-R lookup in DNS
    • B、Create Service Locator (SRV) records for the single name resources
    • C、Create an Active Directory-Integrated zone named LegacyWINS. Create host (A) records for the single name resources
    • D、Create an Active Directory-integrated zone named GlobalNames. Create host (A) records for the single name resources

    正确答案:D

  • 第16题:

    单选题
    You are a security administrator for your company. The network consists of three Active Directory domains. All Active Directory domains are running at a Windows Server 2003 mode functionality level.    Employees in the editorial department of your company need access to resources on file servers that are in each of the Active Directory domains. Each Active Directory domain in the company contains at least one editorial department employee user account.    You need to create a single group named Company Editors that contains all editorial department employee user accounts and that has access to the resources on file server computers.  What should you do?()
    A

     Create a global distribution group in the forest root domain and name it Company Editors.

    B

     Create a global security group in the forest root domain and name it Company Editors.

    C

     Create a universal distribution group in the forest root domain and name it Company Editors. 

    D

     Create a universal security group in the forest root domain and name it Company Editors.


    正确答案: A
    解析: 暂无解析

  • 第17题:

    单选题
    Your company has an Active Directory forest. The company has servers that run Windows Server  2008 R2 and client computers that run Windows 7. The domain uses a set of GPO administrative  templates that have been approved to support regulatory compliance requirements.     Your partner company has an Active Directory forest that contains a single domain. The company  has servers that run Windows Server 2008 R2 and client computers that run Windows 7.     You need to configure your partner company’s domain to use the approved set of administrative  templates.   What should you do()
    A

    Use the Group Policy Management Console (GPMC) utility to back up the GPO to a file. In each site, import the GP

    B

    Copy the ADMX files from your company’s PDC emulator to the PolicyDefinitions folder on the partner company’s PDC

    C

    Copy the ADML files from your company’s PDC emulator to the PolicyDefinitions folder on the partner company’s PDC 

    D

    Download the conf.adm, system.adm, wuau.adm, and inetres.adm files from the Microsoft Updates Web site. 


    正确答案: C
    解析: 暂无解析

  • 第18题:

    单选题
    Your company has a single Active Directory directory service domain. All servers in your environment run Windows Server 2003. Client computers run Windows XP or Windows Vista. You plan to create a security update scan procedure for client computers. You need to choose a security tool that supports all the client computers.  Which tool should you choose? ()
    A

     UrlScan Security Tool

    B

     Enterprise Scan Tool (EST)

    C

     Malicious Removal Tool (MRT)

    D

     Microsoft Baseline Security Analyzer (MBSA)


    正确答案: B
    解析: 暂无解析

  • 第19题:

    单选题
    Your company has a single Active Directory directory service forest with multiple domains. The  company has a main office with 1,000 users and a single branch office with 500 users. Each office is aseparate Active Directory site. The main office Active Directory site has two domain controllers with Global  Catalog services. Company employees must be able to work in both offices. You need to plan the  placement and configuration of domain controllers.  What should you do?()
    A

     Deploy two additional domain controllers in the main office Active Directory site.

    B

     Deploy global catalog servers in the branch office Active Directory site.

    C

     Enable change notification on the site link between the main office Active Directory site and the branch office Active Directory site.

    D

     Disable change notification on the site link between the main office Active Directory site and the branch office Active Directory site.


    正确答案: B
    解析: 暂无解析

  • 第20题:

    单选题
    Your company has a single Active Directory domain. All domain controllers run Windows Server 2003.    You install Windows Server 2008 R2 on a server.    You need to add the new server as a domain controller in your domain.    What should you do first()
    A

    On the new server, run dcpromo /adv.

    B

    On the new server, run dcpromo /createdcaccount.

    C

    On a domain controller run adprep /rodcprep.

    D

    On a domain controller, run adprep /forestprep.


    正确答案: C
    解析: 暂无解析

  • 第21题:

    单选题
    Your company has a single Active Directory directory service domain. Servers in your environment run Windows Server 2003. Client computers run Windows XP or Windows Vista. You plan to create an internal centrally managed security update infrastructure for client computers. You need to choose a security update management tool that supports all the client computers.  Which tool should you choose? ()
    A

     Microsoft Assessment and Planning (MAP) Toolkit

    B

     Microsoft Baseline Security Analyzer

    C

     Microsoft System Center Operations Manager

    D

     Windows Server Update Services (WSUS)


    正确答案: D
    解析: 暂无解析