Installing and Configuring Windows Server 2012

QUESTION NO: 17

Server 1 and Server2 host a load-balanced Application pool named AppPool1.

You need to ensure thatAppPool1 uses a group Managed Service Account as its identity.

Which 3 actions should you perform?

A. Install a domain controller that runs Windows Server 2012, Run the New-ADServiceAccountcmdlet, Modify the settings of AppPool1.

B. Configure the Security settings of the contoso.com zone.

C. Add a second legacy network adapter, and then run the Set-VMNetworkAdoptercmdlet.

D. From Windows Powershell, run Get-DNSServerDiagnostics.

Answer: A

Explanation:

For the application pool to use a group Managed Service account as its identity you will have to make sure that there is a domain controller where you can add the account and then modify the application pool accordingly. Thus you should use the New-ADServiceAccount on the domain controller that will create a new Active Directory service account.

Incorrect answers:

B: This is not a zone Security settings issue.

C: The Get/Set-VMNetworkAdapter cmdlet will set the VLAN tagging of an individual VMNetworkAdaper inside a Virtual Machine.

D: Executing this command will get DNS event logging details.

References:

http://technet.microsoft.com/en-us/library/ee617211.aspx

http://technet.microsoft.com/en-us/library/cc959303.aspx

http://technet.microsoft.com/en-us/library/jj649883(v=wps.620).aspx

Exam Ref 70-410: Installing and Configuring Windows Server 2012: Chapter 5: Install and Administer Active Directory, Objective 5.1 Install Domain Controllers, p. 251-256

QUESTION NO: 18

Your infrastructure divided in 2 sites. You have a forest root domain and child domain. There is only one DC on site 2 with no FSMO roles. The link goes down to site 2 and no users can log on.

What FSMO roles you need on to restore the access?

A. Infrastructure master

B. RID master

C. Domain Naming master

D. PDC emulator

Answer: D

Explanation:

The PDC emulator is used as a reference DC to double-check incorrect passwords and it also receives new password changes.

Incorrect answers:

A: This is not an infrastructure problem between the root and the child domain.At any time, there can be only one domain controller acting as the infrastructure master in each domain. The infrastructure master is responsible for updating references from objects in its domain to objects in other domains. The infrastructure master compares its data with that of a global catalog. Global catalogs receive regular updates for objects in all domains through replication, so the global catalog data will always be up to date. If the infrastructure master finds data that is out of date, it requests the updated data from a global catalog. The infrastructure master then replicates that updated data to the other domain controllers in the domain.

B: The RID master allocates sequences of relative IDs (RIDs) to each of the various domain controllers in its domain. At any time, there can be only one domain controller acting as the RID master in each domain in the forest. The RID master role is usually required in scenarios where there are multiple domain controllers. In the question it states that there is only one domain controller on the site with no FSMO roles.

C: Domain naming master is not used to reference and check passwords. The domain controller holding the domain naming master role controls the addition or removal of domains in the forest.

References:

http://technet.microsoft.com/en-us/library/cc773108(v=ws.10).aspx

Training Guide: Installing and Configuring Windows Server 2012: Chapter 4: Deploying Domain Controllers, Lesson 2: Deploying domain controllers using Server Manager, p. 158

QUESTION NO: 19

Your network contains an Active Directory domain named adatum.com. The domain contains the servers shown in the following table.

You need to ensure that you can use Server Manager on DC1 to manage DC2.

Which two tasks should you perform? (Each correct answer presents part of the solution. Choose two.)

A. Install Microsoft .NET Framework 4 on DC2.

B. Install Remote Server Administration Tools on DC1.

C. Install Remote Server Administration Tools on DC2.

D. Install Windows Management Framework 3.0 on DC2.

Answer: A, D

Explanation: In Windows Server 2012, you can use Server Manager to perform management tasks on remote servers. Remote management is enabled by default on servers that are running Windows Server 2012. To manage a server remotely by using Server Manager, you add the server to the Server Manager server pool.

You can use Server Manager to manage remote servers that are running Windows Server 2008 and Windows Server 2008 R2, but the following updates are required to fully manage these older operating systems.

Windows Management Framework 3.0 To use this release of Server Manager to access and manage remote servers that are running Windows Server 2008 or Windows Server 2008 R2, you must first install .NET Framework 4.0, and then install Windows Management Framework 3.0 on those servers.

Incorrect answers:

B: To be able to access and manage remote servers that are configured with Windows Server 2008 or 2008 R2 you need to install Microsoft.NET Framework4 as well as Windows Management Framework 3.0 to access and manage remote server.

C: With servers that run Windows Server 2008 and 2008 R2 you need to install Microsoft.NET Framework4 as well as Windows Management Framework 3.0 to access and manage remote servers.

Reference:

Training Guide: Installing and Configuring Windows Server 2012, Chapter 2: Deploying servers, p. 80

QUESTION NO: 20

Your network contains an Active Directory forest that contains two domains. The forest contains five domain controllers. The domain controllers are configured as shown in the following table.

You need to configure DC5 as a global catalog server.

Which tool should you use?

A. Active Directory Domains and Trusts

B. Active Directory Users and Computers

C. Active Directory Administrative Center

D. Active Directory Sites and Services

Answer: D

Explanation:

Active Directory Sites and Services can be used to Add or remove the global catalog read-only directory partitions from a domain controller in the site. Confirm that all read-only directory partitions have been replicated to the new global catalog server. As well as verify that the global catalog server is being advertised in Domain Name System (DNS).

References:

http://technet.microsoft.com/en-us/library/cc730868.aspx

http://technet.microsoft.com/en-us/library/cc770674.aspx

QUESTION NO: 21

In an isolated test environment, you deploy a server named Server1 that runs a Server Core Installation of Windows Server 2012. The test environment does not have Active Directory Domain Services (AD DS) installed.

You install the Active Directory Domain Services server role on Server1.

You need to configure Server1 as a domain controller.

Which cmdlet should you run?

A. Install-ADDSDomainController

B. Install-ADDSDomatn

C. Install-ADDSForest

D. Install-WindowsFeature

Answer: B

Explanation:

The ADDomain command gets an Active Directory domain.

Incorrect answers:

A: The ADDomainController command gets one or more Active Directory domain controllers based on discoverable services criteria, search parameters or by providing a domain controller identifier, such as the NetBIOS name.

C: The ADForest cmdlet gets the Active Directory forest specified by the parameters. You can specify the forest by setting the Identity or Current parameters.

D: The WindowsFeature command gets a feature.

References:

http://technet.microsoft.com/en-us/library/ee617224.aspx

http://technet.microsoft.com/en-us/library/ee617217.aspx

QUESTION NO: 22

Your network contains an Active Directory domain named contoso.com. The domain contains two domain controllers. The domain controllers are configured as shown in the following table.

In the perimeter network, you install a new server named Server1 that runs Windows Server 2012. Server1 is in a workgroup.

You need to perform an offline domain join of Server1 to the contoso.com domain.

What should you do first?

A. Transfer the PDC emulator role to DC1.

B. Run the djoin.exe command.

C. Run the dsadd.exe command.

D. Transfer the infrastructure master role to DC1.

Answer: B

Explanation:

The djoin command should be used for offline join in the perimeter network.

Incorrect answers:

A: Offline joining of a server to an existing domain is facilitated by executing the djoin command first. The PDC emulator is used as a reference DC to double-check incorrect passwords and it also receives new password changes.

C: This command is used to add the local computer to a domain or workgroup. In this scenario you need to join a server in the perimeter network to an existing domain.

D: You first need to run the djoin command to facilitate an offline domain join.At any time, there can be only one domain controller acting as the infrastructure master in each domain. The infrastructure master is responsible for updating references from objects in its domain to objects in other domains. The infrastructure master compares its data with that of a global catalog. Global catalogs receive regular updates for objects in all domains through replication, so the global catalog data will always be up to date. If the infrastructure master finds data that is out of date, it requests the updated data from a global catalog. The infrastructure master then replicates that updated data to the other domain controllers in the domain.

References:

Training Guide: Installing and Configuring Windows Server 2012: Chapter 5: Active Directory Administration, p. 187

Training Guide: Installing and Configuring Windows Server 2012: Chapter 4: Deploying Domain Controllers, Lesson 2: Deploying domain controllers using Server Manager, p. 157

QUESTION NO: 23 HOTSPOT

Your network contains an Active Directory domain named contoso.com.

You need to identify whether the Company attribute replicates to the global catalog.

Which part of the Active Directory partition should you view?

To answer, select the appropriate Active Directory object in the answer area.

Answer: <map><m x1="37" x2="394" y1="147" y2="185" ss="0" a="0" /></map>

Explanation:

An Active Directory Lightweight Directory Services (AD LDS) schema defines, using object classes and attributes, the types of objects and data that can be created and stored in an AD LDS directory. The schema can be extended with new classes and attributes, either by administrators or by the applications themselves. In addition, unneeded schema classes and attributes can be deactivated.

References:

http://technet.microsoft.com/en-us/library/cc771975.aspx

http://technet.microsoft.com/en-us/library/cc731547.aspx

QUESTION NO: 24

Your network contains an Active Directory forest named contoso.com. The forest contains a single domain. The domain contains two domain controllers named DC1 and DC2 that run Windows Server 2012.

The domain contains a user named User1 and a global security group named Group1.

You need to modify the SAM account name of Group1.

Which cmdlet should you run?

A. Add-AdPrincipalGroupMembership

B. Install AddsDomainControNer

C. Install WindowsFeature

D. Install AddsDomain

E. Rename-AdObject

F. Set-AdAccountControl

G. Set-AdGroup

H. Set-User

Answer: G

Explanation:

To modify the Security Accounts Manager (SAM) account name of a user, computer, or group, use the Set-ADUser, Set-ADComputer or Set-ADGroup cmdlet.

Incorrect answers:

A: The Add-ADPrincipalGroupMembership cmdlet adds a user, group, service account, or computer as a new member to one or more Active Directory groups.

B: The Install-ADDSDomainController cmdlet installs a domain controller in Active Directory.

Example: C:\PS>Install-ADDSDomainController -InstallDns -Credential (Get-Credential CORP\Administrator) -DomainName "corp.contoso.com"

C: Installs one or more Windows Server roles, role services, or features on either the local or a specified remote server that is running Windows Server 2012 R2. This cmdlet is equivalent to and replaces Add-WindowsFeature, the cmdlet that was used to install roles, role services, and features in Windows Server 2008 R2.

D: The Install-AddsDomain command installs a domain in Active Directory.

E: The Rename-ADObject cmdlet renames an Active Directory object.

F: The Set-ADAccountControl cmdlet modifies the user account control (UAC) values for an Active Directory user or computer account.

H: The Set-User cmdlet is used to modify user attributes in Active Directory.

References:

http://technet.microsoft.com/en-us/library/hh852319.aspx

http://technet.microsoft.com/en-us/library/hh974722.aspx

http://technet.microsoft.com/en-us/library/hh974723.aspx

QUESTION NO: 25

Your network contains an Active Directory domain named contoso.com. You have a Group Policy object (GPO) named GP1 that is linked to the domain. GP1 contains a software restriction policy that blocks an Application named App1.

You have a workgroup computer named Computer1 that runs Windows 8. A local Group Policy on Computer1 contains an Application control policy that allows App1.

You join Computer1 to the domain.

You need to prevent App1 from running on Computer1.

What should you do?

A. From Group Policy Management, add an Application control policy to GP1.

B. From Group Policy Management, enable the Enforced option on GP1.

C. In the local Group Policy of Computer1, configure a software restriction policy.

D. From Computer1, run gpupdate /force.

Answer: D

Explanation:

All GPO settings are processed in the following order:

1. Local Group Policy object—Each computer has exactly one Group Policy object that is stored locally. This processes for both computer and user Group Policy processing.

2. Site—Any GPOs that have been linked to the site that the computer belongs to are processed next.

3. Domain—Processing of multiple domain-linked GPOs is in the order specified by the administrator, on the Linked Group Policy Objects tab for the domain in GPMC.

4. Organizational units—GPOs that are linked to the organizational unit that is highest in the Active Directory hierarchy are processed first, then GPOs that are linked to its child organizational unit, and so on. Finally, the GPOs that are linked to the organizational unit that contains the user or computer are processed.

This order means that the local GPO is processed first, and GPOs that are linked to the organizational unit of which the computer or user is a direct member are processed last, **which overwrites settings in the earlier GPOs if there are conflicts.** (If there are no conflicts, then the earlier and later settings are merely aggregated.)

References:

http://technet.microsoft.com/en-us/library/cc785665(v=ws.10).aspx

Topic 14, Create and manage Active Directory users and computers

Automate the creation of Active Directory accounts; create, copy, configure, and delete users and computers; configure templates; perform bulk Active Directory operations; configure user rights; offline domain join; manage inactive and disabled accounts

QUESTION NO: 1

Your network contains an Active Directory domain named adatum.com. The domain contains several thousand member servers that run Windows Server 2012. All of the computer accounts for the member servers are in an organizational unit (OU) named ServersAccounts.

Servers are restarted only occasionally.

You need to identify which servers were restarted during the last two days.

What should you do?

A. Run dsquery computer and specify the -stalepwd parameter

B. Run dsquery server and specify the -o parameter.

C. Run Get-ADComputer and specify the lastlogon property.

D. Run Get-ADComputer and specify the SearchScope parameter

Answer: C

Explanation:

C. This command and this specific parameter must be executed to get one or more Active Directory computers lastLogondate .

Incorrect answers:

A. Finds computers in the directory that match search criteria that you specify.

B. Finds domain controllers according to specified search criteria.

D. Gets one or more Active Directory computers SearchScope Specifies the scope of an Active Directory search.

References:

http://technet.microsoft.com/en-us/library/cc732952(v=ws.10).aspx

QUESTION NO: 2

Your network contains an Active Directory domain named contoso.com. All servers run Windows Server 2012. The domain contains a server named Server1.

You open Review Options in the Active Directory Domain Services Configuration Wizard, and then you click View script.

You need to ensure that you can use the script to promote Server1 to a domain controller.

Which file extension should you use to save the script?

A. .pal

B. .bat

C. .xml

D. .cmd

Answer: B

Explanation:

Creating a batch file would be best practice because the process involved to promote a server to a domain controller involves several commands that can be configured into a batch file in a script.

Incorrect answers:

A: .pal file extensions will not be appropriate to save a script meant to promote a server to a domain controller.

C: Group policy tool use xml based files by default. You need to create a script and save it as a batch file in this scenario.

D: This is an inappropriate file extension to use under these circumstances.

References:

Exam Ref 70-410: Installing and Configuring Windows Server 2012: Chapter 5: Install and Administer Active Directory, Objective 5.1 Install Domain Controllers, p. 251-256

Exam Ref: 70-410: Installing and Configuring Windows Server 2012, Chapter 6: Create and manage Group Policy, Objective 6.3: Configure application restriction policies, p.342

Training Guide: Installing and Configuring Windows Server 2012: Chapter 4: Deploying Domain Controllers, Lesson 2: Deploying domain controllers using Server Manager, p. 146

QUESTION NO: 3 DRAG DROP

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1. Server1 runs Windows Server 2012 and is configured as the only domain controller.

You need to retrieve a list of all the user accounts. The list must include the last time each user was authenticated successfully.

Which Windows PowerShell command should you run?

To answer, drag the appropriate cmdlet or property to the correct locations to complete the PowerShell command in the answer area. Each cmdlet or property may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

Answer: <map><m x1="3" x2="155" y1="57" y2="77" ss="0" a="0" /><m x1="6" x2="153" y1="90" y2="112" ss="0" a="0" /><m x1="4" x2="154" y1="120" y2="147" ss="0" a="0" /><m x1="3" x2="157" y1="155" y2="179" ss="0" a="0" /><m x1="1" x2="156" y1="190" y2="214" ss="0" a="0" /><m x1="6" x2="154" y1="221" y2="247" ss="0" a="0" /><m x1="4" x2="157" y1="256" y2="284" ss="0" a="0" /><m x1="195" x2="350" y1="57" y2="89" ss="1" a="0" /><m x1="593" x2="745" y1="59" y2="86" ss="1" a="0" /><c start="1" stop="0" /><c start="5" stop="1" /></map>

Explanation:

The Get-ADUser cmdlet gets a user object or performs a search to retrieve multiple user objects.

lastLogondate is the correct parameter as the questions asks for the last time each user was authenticated successfully.

Incorrect answers:

The Get-ADComputer cmdlet gets a computer or performs a search to retrieve multiple computers.

The Set-ADComputer cmdlet modifies the properties of an Active Directory computer object. You can modify commonly used property values by using the cmdlet parameters.

References:

http://technet.microsoft.com/en-us/library/ee617241.aspx

QUESTION NO: 4

Your network contains an Active Directory domain named contoso.com.

Your company hires 500 temporary employees for the summer.

The human resources department gives you a Microsoft Excel document that contains a list of the temporary employees.

You need to automate the creation of user accounts for the 500 temporary employees.

Which tool or tools should you use?

A. The Set-ADUsercmdlet and the Add-Member cmdlet

B. The Import-CSV cmdlet and the New-ADUsercmdlet

C. ADSI Edit

D. Active Directory Users and Computers

Answer: B

Explanation:

The CSVDE is a command-line utility that can create new AD DS objects by importing information from a comma-separated value (.csv) file. This would be the least amount of administrative effort in this case especially considering that these would be temporary employees.

Incorrect answers:

A: This is not automated.

C: This is not the appropriate utility to use to automate the creation of user accounts.

D: This is not used to automate the creation of user accounts.

References:

Exam Ref 70-410: Installing and Configuring Windows Server 2012: Chapter 5: Install and administer Active Directory, Objective 5.2: Create and Manage Active Directory Users and Computers, p. 269

http://technet.microsoft.com/en-us/library/ee176874.aspx

QUESTION NO: 5 HOTSPOT

Your network contains an Active Directory domain named adatum.com.

You create an account for a temporary employee named User1.

You need to ensure that User1 can log on to the domain only between 08:00 and 18:00 from a client computer named Computer1.

From which tab should you perform the configuration?

To answer, select the appropriate tab in the answer area.

Answer: <map><m x1="144" x2="212" y1="81" y2="100" ss="0" a="0" /></map>

Explanation:

The User account properties contains the Logon Hours settings that you can use to change the hours that this selected object can log on to the domain. By default, domain logon is allowed 24 hours a day, 7 days a week. Note that this control does not affect the user's ability to log on locally to a computer using a local computer account instead of a domain account.

References:

http://technet.microsoft.com/en-us/library/dd145547.aspx

QUESTION NO: 6

Your network contains an Active Directory domain named contoso.com. The domain contains a file server named Server1 that runs Windows Server 2012. Server1 contains a shared folder named Share1. Share1 contains the home folder of each user.

All users have the necessary permissions to access only their home folder.

The users report that when they access Share1, they can see the home folders of all the users.

You need to ensure that the users see only their home folder when they access Share1.

What should you do from Server1?

A. From Windows Explorer, modify the properties of the volume that contains Share1.

B. From Server Manager, modify the properties of the volume that contains Share1.

C. From Server Manager, modify the properties of Share1.

D. From Windows Explorer, modify the properties of Share1.

Answer: C A

Explanation:

Share permissions apply to users who connect to a shared folder over the network. Share permissions do not affect users who log on locally, or log on using Remote Desktop.

You need to navigate from your Windows interface to open Computer Management from where you can assign the appropriate permissions regarding the properties of the volume where the home folders reside.

References:

http://technet.microsoft.com/en-us/library/cc726004.aspx

QUESTION NO: 7

Your network contains an Active Directory domain named contoso.com.

Your company hires 500 temporary employees for the summer.

The human resources department gives you a Microsoft Excel document that contains a list of the temporary employees.

You need to automate the creation of user accounts for the 500 temporary employees.

Which tool should you use?

A. The Add-Member cmdlet

B. ADSI Edit

C. The csvde.exe command

D. Active Directory Users and Computers

Answer: C

Explanation:

The CSVDE is a command-line utility that can create new AD DS objects by importing information from a comma-separated value (.csv) file. This would be the least amount of administrative effort in this case especially considering that these would be temporary employees.

Incorrect answers:

A: This is not automated.

B: This is not the appropriate utility to use to automate the creation of user accounts.

D: This is not used to automate the creation of user accounts.

References:

Exam Ref 70-410: Installing and Configuring Windows Server 2012: Chapter 5: Install and administer Active Directory, Objective 5.2: Create and Manage Active Directory Users and Computers, p. 269

QUESTION NO: 8

Your network contains an Active Directory domain named contoso.com.

An administrator provides you with a file that contains the information to create user accounts for 200 temporary employees.

The file is shown in the exhibit. (Click the Exhibit button.)

You need to automate the creation of the user accounts. You must achieve this goal by using the minimum amount of administrative effort.

Which tool should you use?

A. csvde

B. Net user

C. Ldifde

D. Dsadd

Answer: A

Explanation:

The CSVDE is a command-line utility that can create new AD DS objects by importing information from a comma-separated value (.csv) file. This would be the least amount of administrative effort in this case.

Incorrect answers:

B: This is possible but it involve more administrative than is used when making use of csvde.

C: LDIFDE is utility that can import AD DS information and use it to add, delete, or modify objects, in addition to modifying the schema, if necessary.

D. This command is used to add the local computer to a domain or workgroup.

References:

Exam Ref 70-410: Installing and Configuring Windows Server 2012: Chapter 5: Install and administer Active Directory, Objective 5.2: Create and Manage Active Directory Users and Computers, p. 269

QUESTION NO: 9

Your network contains an Active Directory domain named contoso.com.

You have a Group Policy object (GPO) named GPO1 that contains several user settings. GPO1 is linked to an organizational unit (OU) named OU1.

The help desk reports that GPO1App1ies to only some of the users in OU1.

You open Group Policy Management as shown in the exhibit. (Click the Exhibit button.)

You need to configure GPO1 to App1y to all of the users in OU1.

What should you do?

A. Modify the Security settings of GPO1.

B. Disable Block Inheritance on OU1.

C. Modify the GPO status of GPO1.

D. Enforce GPO1.

Answer: D

Explanation:

To have a GPO apply to all users the GGPO must be enforced.

Incorrect answers:

A: Just changing the security settings is not the same as applying a GPO.

B: Merely disabling the block Inheritance does not apply the GPO.

C: The GPO status will not apply the GPO to all users, you must enforce it.

References:

http://technet.microsoft.com/en-us/library/cc739343(v=ws.10).aspx

QUESTION NO: 10

Your network contains an Active Directory domain named adatum.com.

You discover that when users join computers to the domain, the computer accounts are created in the Computers container.

You need to ensure that when users join computers to the domain, the computer accounts are automatically created in an organizational unit (OU) named All_Computers.

What should you do?

A. From Ldp, configure the properties of the Computers container.

B. From Windows PowerShell, run the Move-ADObjectcmdlet.

C. From ADSI Edit, configure the properties of the Computers container.

D. From a command prompt, run the redircmp.exe command.

Answer: D

Explanation:

This command redirects the default container for newly created computers to a specified, target organizational unit (OU) so that newly created computer objects are created in the specific target OU instead of in All_Computers.

References:

http://technet.microsoft.com/en-us/library/cc770619.aspx

QUESTION NO: 11

Your network contains an Active Directory domain named contoso.com.

You log on to a domain controller by using an account named Admin1. Admin1 is a member of the Domain Admins group.

You view the properties of a group named Group1 as shown in the exhibit. (Click the Exhibit button.)

Group1 is located in an organizational unit (OU) named OU1.

You need to ensure that you can modify the Security settings of Group1 by using Active Directory Users and Computers.

What should you do from Active Directory Users and Computers?

A. From the View menu, select Users, Contacts, Groups, and Computers as containers.

B. Right-click OU1 and select Delegate Control.

C. From the View menu, select Advanced Features.

D. Right-click contoso.com and select Delegate Control.

Answer: C

Explanation:

From ADUC select view toolbar then select advanced features to access the Security Settings.

Incorrect answers:

A: Making use of Containers will not allow for the modification of Security Settings of a group.

B: One cannot delegate control over Active Directory OUs and their objects using ADAC. You need to use Active Directory Users and Computers. And delegating control will not ensure that you can change the Group Security settings either.

D: For this functionality you need to use Active Directory Domains and Trusts.

References:

Exam Ref 70-410: Installing and Configuring Windows Server 2012: Chapter 5: Install and Administer Active Directory, Objective 5.3 Create and manage Active Directory groups and Organization units, p. 289-291

Training Guide: Installing and Configuring Windows Server 2012, Chapter 5: Active Directory Administration, Lesson 1: Administering Active Directory Objects using ADAC, p. 196

http://searchwindowsserver.techtarget.com/tip/Viewing-advanced-settings-in-Active-Directory-Users-and-Computers

QUESTION NO: 12

Your network contains an Active Directory domain named contoso.com.

You discover that when you join client computers to the domain manually, the computer accounts are created in the Computers container.

You need to ensure that new computer accounts are created automatically in an organizational unit (OU) named Corp.

Which tool should you use?

A. net.exe

B. redircmp.exe

C. regedit.exe

D. dsadd.exe

Answer: B

Explanation:

Executing this command will redirect the default container for newly created computers to a specified, target organizational unit.

Incorrect answers:

A. This command is used to stop/start protocols.

C. This command will modify local registry entries.

D. This command will allow you to add specific types of objects to the directory.

References:

Training Guide: Installing and Configuring Windows Server 2012: Chapter 5: Active Directory Administration, p. 187

http://technet.microsoft.com/en-us/library/bb490949.aspx

http://technet.microsoft.com/en-us/library/cc770619(v=ws.10).aspx

http://technet.microsoft.com/en-us/library/cc753708(v=ws.10).aspx

Site Search:

Close

Close
Download Free Demo of VCE
Exam Simulator

Experience Avanset VCE Exam Simulator for yourself.


Simply submit your e-mail address below to get started with our interactive software demo of your free trial.


Enter Your Email Address

Free Demo Limits: In the demo version you will be able to access only first 5 questions from exam.