单选题Your network contains an Active Directory forest. The forest contains two domains.  You have a standalone root certification authority (CA).   On a server in the child domain, you run the Add Roles Wizard and discover that the option to select an  ente

题目
单选题
Your network contains an Active Directory forest. The forest contains two domains.  You have a standalone root certification authority (CA).   On a server in the child domain, you run the Add Roles Wizard and discover that the option to select an  enterprise CA is disabled.   You need to install an enterprise subordinate CA on the server.   What should you use to log on to the new server()
A

an account that is a member of the Certificate Publishers group in the child domain

B

an account that is a member of the Certificate Publishers group in the forest root domain

C

an account that is a member of the Schema Admins group in the forest root domain

D

an account that is a member of the Enterprise Admins group in the forest root domain


相似考题
更多“Your network contains an Active Directory forest. The forest”相关问题
  • 第1题:

    Your network contains an Active Directory forest. The forest contains one domain and three sites.   Each site contains two domain controllers. All domain controllers are DNS servers.  You create a new Active Directory-integrated zone.   You need to ensure that the new zone is replicated to the domain controllers in only one of the sites.   What should you do first()

    • A、Modify the NTDS Site Settings object for the site.
    • B、Modify the replication settings of the default site link.
    • C、Create an Active Directory connection object.
    • D、Create an Active Directory application directory partition.

    正确答案:D

  • 第2题:

    Your network contains an Active Directory forest. The forest contains an Acitve Directory site for a  remote office. The remote site contains a read-only domain controller (RODC).     You need to configure the RODC to store only the password of users in the remote site.     What should you do()

    • A、Create a Paasword Settings object (PSO).
    • B、Modify the Partial-Attribute-Set attribute of the forest.
    • C、Add the users accounts of the remote site users to the Allowed RODC Password Replication Group.
    • D、Add the users accounts of users who are not in the remote site to the Denied RODC Password Replication Group.

    正确答案:C

  • 第3题:

    Your network consists of a single Active Directory forest. The forest contains one Active Directory domain. The domain contains eight domain controllers. The domain controllers run Windows Server 2003 Service Pack 2.   You upgrade one of the domain controllers to Windows Server 2008 R2.   You need to recommend an Active Directory recovery strategy that supports the recovery of deletedobjects. The solution must allow deleted objects to be recovered for up to one year after the date of  deletion. What should you recommend?()

    • A、Increase the tombstone lifetime for the forest.
    • B、Increase the interval of the garbage collection process for the forest.
    • C、Configure daily backups of the Windows Server 2008 R2 domain controller.
    • D、Enable shadow copies of the drive that contains the Ntds.dit file on the Windows Server 2008 R2 domain controller.

    正确答案:A

  • 第4题:

    Your network contains an internal network and a perimeter network. The internal network contains an Active Directory forest. The forest contains a single domain.  You plan to deploy 10 Edge Transport servers on the perimeter network.  You need to recommend a solution for the Edge Transport server deployment. The solution must meet the following requirements: .Allow administrators to apply a single security policy to all Edge Transport servers .Reduce the administrative overhead that is required to manage servers .Minimize the attack surface of the internal network  What should you recommend?()

    • A、Implement Network Policy and Access Services (NPAS).
    • B、Implement Active Directory Federation Services (AD FS).
    • C、Create a new Active Directory domain in the internal forest, and then join all EdgeTransport servers to the new domain.
    • D、Create an Active Directory forest in the perimeter network, and then join all Edge Transport servers to the new domain.

    正确答案:D

  • 第5题:

    单选题
    Your network contains an Active Directory forest. The forest schema contains a custom attribute for  user objects.   You need to give the human resources department a file that contains the last logon time and the custom  attribute values for each user in the forest.   What should you use()
    A

    the Dsquery tool

    B

    the Export-CSV cmdlet

    C

    the Get-ADUser cmdlet

    D

    the Net.exe user command


    正确答案: C
    解析: 暂无解析

  • 第6题:

    单选题
    Your network contains an Active Directory forest. All domain controllers run Windows Server 2008. You need to ensure that you can install an Exchange Server 2010 server in the Active Directory forest.  What should you do()?
    A

    From the Exchange Server 2010 installation media, run setup /ps.

    B

    From the Exchange Server 2010 installation media, run setup /NewProvisionedServer.

    C

    From the Windows Server 2008 installation media, run adprep.exe /forestprep.

    D

    From the Windows Server 2008 installation media, run adprep.exe /domainprep.


    正确答案: D
    解析: 暂无解析

  • 第7题:

    Your network contains an Active Directory forest. The forest schema contains a custom attribute for  user objects.   You need to modify the custom attribute value of 500 user accounts.   Which tool should you use()

    • A、Csvde
    • B、Dsmod
    • C、Dsrm
    • D、Ldifde

    正确答案:D

  • 第8题:

    Your network contains an Active Directory forest. The forest contains multiple sites.     You need to enable universal group membership caching for a site.  What should you do()

    • A、From Active Directory Sites and Services, modify the NTDS Settings.
    • B、From Active Directory Sites and Services, modify the NTDS Site Settings.
    • C、From Active Directory Users and Computers, modify the properties of all universal groups used in the site.
    • D、From Active Directory Users and Computers, modify the computer objects for the domain controllers in the site.

    正确答案:B

  • 第9题:

    Your network contains an Active Directory forest.   You add an additional user principal name (UPN) suffix to the forest.   You need to modify the UPN suffix of all users. You want to achieve this goal by using the minimum  amount of administrative effort.   What should you use()

    • A、the Active Directory Domains and Trusts console
    • B、the Active Directory Users and Computers console
    • C、the Csvde tool
    • D、the Ldifde tool

    正确答案:B

  • 第10题:

    单选题
    Your network contains an Active Directory forest. The forest contains a single domain. You want  to access resources in a domain that is located in another forest.     You need to configure a trust between the domain in your forest and the domain in the other  forest.     What should you create()
    A

    an incoming external trust

    B

    an incoming realm trust

    C

    an outgoing external trust

    D

    an outgoing realm trust


    正确答案: D
    解析: 暂无解析

  • 第11题:

    单选题
    Your network contains an Active Directory forest named contoso.com. You plan to add a new  domain named nwtraders.com to the forest.  All DNS servers are domain controllers.     You need to ensure that the computers in nwtraders.com can update their Host (A) records on  any of the DNS servers in the forest.     What should you do()
    A

    Add the computer accounts of all the domain controllers to the DnsAdmins group.

    B

    Add the computer accounts of all the domain controllers to the DnsUpdateProxy group.

    C

    Create a standard primary zone on a domain controller in the forest root domain.

    D

    Create an Active Directory-integrated zone on a domain controller in the forest root domain.


    正确答案: C
    解析: 暂无解析

  • 第12题:

    单选题
    Your network contains an Active Directory forest.     You add an additional user principal name (UPN) suffix to the forest. You need to modify the UPN  suffix of all users.     You want to achieve this goal by using the minimum amount of administrative effort.     What should you use()
    A

    the Active Directory Domains and Trusts console

    B

    the Active Directory Users and Computers console

    C

    the Csvde tool

    D

    the Ldifde tool


    正确答案: D
    解析: 暂无解析