1. Which of the following are required to create a domain controller successfully? (Choose all that apply.) 2. Hi-tech .com has two Active Directory forests named Hi-tech.com and vervoks.com. The company network has three DNS servers named Hi-tech A, Hi-tech B, and Hi-tech C. The DNS servers are configured as shown in the table: A. Create a copy of the _msdcs.Hi-tech.com zone on the Hi-tech C server. 3. The hi-tech.com domain contains a GPO named Corporate Help Desk, linked to the Clients OU, and a GPO named Sydney Support linked to the Sydney OU within the Clients OU. The Corporate Help Desk GPO includes a restricted groups policy for the Administrators group that specifies the Members Of This Group setting to be HI-TECH\Help Desk. The Sydney Support GPO includes a restricted groups policy for the HI-TECH \Sydney Support group that specifies This Group Is A Member Of Administrators. A computer named DESKTOP234 joins the domain in the Sydney OU. Which of the following accounts will be a member of the Administrators group on DESKTOP234? (Choose all that apply.) 4. You are hired as the network administrator in your company. Your company network consists of a single Active Directory domain. All domain controllers run Windows Server 2008. Some of the Lightweight Directory Access Protocol (LDAP) clients are using the largest amount of CPU resources on a domain controller. You need to identify those. What should you do to achieve this task? A. Execute the Active Directory Diagnostics Data Collector Set a review the Active Directory report 5. A large company has just merged with yours. This organization has recently converted its internal network from IPv4 addressing to IPv6 to support a number of new network applications that required it. You must now begin to plan for IPv6 support on your own internal network. You are creating training materials for your junior networking staff. Which of the following features is built into IPv6 that was not required in IPv4? 6. You want to deploy security settings to multiple servers by using Group Policy. The settings need to apply the user rights that you have configured and validated on a server in your test environment. Which tool should you use? 7. You are hired as the network administrator in your company. Your company has an Active Directory forest. You want to install an Enterprise certification authority (CA) on a stand-alone server. When you try to add Active Directory Certificate Services (AD CS) role,you find that the Enterprise CA option is not available. You have to install the AD CS role as an Enterprise CA. 8. You want to deploy security settings to multiple servers by using Group Policy. The settings need to configure services, firewall rules, and audit policies appropriate for servers in your enterprise that act as file and print servers. Which tool would be the best choice for you to use? 9. You are hired as the network administrator in your company. You company has a server that's runs Windows Server 2008. Active directory forest is configured at the functional level. To enable users to have a database services on the server, you install Microsoft SQL server 2005 and implement Active Directory Rights Management Service (AD RMS). While testing the server, you attempt to open the AD RMS administration website. You receive an error message saying:" SQL Server does not exist or access is denied". 10. Your company, mycompany.com, is merging with the yourcompany.com company. The details of the merger are not yet complete. You need to gain access to the resources in the yourcompany.com company before the merger is completed. What type of trust relationship should you create? 11. You created a security policy by using the Security Configuration Wizard. Now you want to deploy the settings in that security policy to the servers in your Servers OU. Which of the following steps are required? (Choose two. Each correct answer is a part of the solution.) 12. You are hired as the network administrator in your company. The headquarters of your company is located in New York. Now your company builds its branch in Washington. You are assigned to deploy and implement a Read-only Domain Controller (RODC) at the branch office. You deploy a RODC that runs Windows Server 2008. 13. You are a support professional for Hi-tech, Ltd. The domain's administrators have distributed a custom console with the Active Directory Users and Computers snap-in. When you open the console and attempt to reset a user's password, you receive Access Denied errors. You are certain that you have been delegated permission to reset passwords for users. What is the best solution? 14. You want to deploy an application by using Group Policy to client computers in the headquarters and in a branch office. The branch office is connected to the headquarters with a wide area network connection that is 364 kbps. What steps must you take to deploy the software? (Choose two. Each correct answer is part of the solution.) 15. You are hired as the network administrator in your company. The headquarters of your company is located in New York. Now your company builds its branch in Washington. There is a single-domain Active Directory forest in your company. All servers run Windows Server2008. Server01 and Server02 work as the Domain Controller in the main office while Server03 works as a Windows Server 2008 read-only domain controller (RODC) in the branch office. All domain controllers hold the DNS Server role and are configured as Active Directory-integrated zones. The DNS zones only allow secure updates. 16. You are hired as the network administrator in your company. All the servers in your company run windows 2008. The network of your company consists of an Active Directory forest that contains one domain. There is an Active Directory-integrated zone with two Active Directory sites in the domain. Each site contains two domain controllers. All domain controllers are configures as DNS servers. 17. Your boss just informed you that your company will be participating in a joint venture with a partner company. He is very concerned about the fact that a trust relationship needs to be established with the partner company. He fears that an administrator in the other company might be able to masquerade as one of your administrators and grant himself privileges to resources. You assure him that your network and its resources can be protected from an elevated privilege attack. Along with the other security precautions that you will take, what will you tell your boss that will help him rest easy about the upcoming scenario? 18. In your domain, the Employees OU contains all user accounts. Each site has an OU within which a Sales OU contains accounts for the computers in the Sales department at that site. You want to deploy an application so that it is available to all users in the organization's Sales departments. Which methods can you use? (Choose all that apply.) 19. You are hired as the network administrator in your company. Your company has an Active Directory forest with six domains. The company has 5 sites. The company requires a new distributed application that uses a custom application directory partition named ResData for data replication. The application is installed on one member server in five sites. You need to configure the five member servers to receive the ResData application directory partition for data replication. What should you do? 20. You are hired as the network administrator in your company. Your company network has an Active Directory forest that contains one parent domain and one child domain. The child domain has two domain controllers that run Windows Server 2008. All user accounts from the child domain are migrated to the parent domain. The child domain is scheduled to be decommissioned. You need to remove the child domain from the Active Directory forest. What are two possible ways to achieve this goal? (Choose two answers. Each answer is part of the complete solution.) 21. Your organization consists of ten branch offices. Within your Active Directory, an Employees OU is divided into ten child OUs containing user accounts at each branch office. You want to deploy an application to users at four branches. The application should be fully installed before the user opens the application for the first time. Which steps should you take? (Choose four. Each correct answer is a part of the solution.) 22. Robin is managing an Active Directory environment of a medium-size company. He is troubleshooting a problem with the Active Directory. One of the administrators made an update to a user object and another reported that he had not seen the changes appear on another DC. It was more than a week since the change was made Robin checks the problem by making a change to another Active Directory object. Within a few hours, the change appears on a few DCs, but not on all of them. Which of the following is a possible cause for this problem? 23. You are hired as the network administrator in your company. In your company there's a server named Server01 that runs Windows Server 2008. You company has an Active Directory forest with single domain. Server01 works as the Domain Controller with Active Directory Federation Services (AD FS) role installed. Some other applications are also hosted on its perimeter network. The organization wants single sign-on to all applications hosted on perimeter network. 24. You are hired as the network administrator in your company. In your company there's a server named Server01 that runs Windows Server 2008. You company has an Active Directory forest with single domain. Server01 works as the Domain Controller with Active Directory Federation Services (AD FS) role installed. Server01 is configured as a DNS server. You have to record all inbound DNS queries to server01. 25. You are concerned that an individual is trying to gain access to computers by logging on with valid domain user names and a variety of attempted passwords. Which audit policy should you configure and monitor for such activities? 26. You want to audit changes to attributes of user accounts used by administrators in your organization. When a change is made, you want to see both the previous and changed values of the attribute. What must you do to achieve your goal? 27. You are hired as the network administrator in your company. Your company has an Active Directory domain which runs Windows Server 2008. A user attempts to log on to the domain from the client computer using his account. He receives the following message: 28. Darien is a new member of the Web Services team at your company. He is going to be responsible for running and testing scripts for an in-house homegrown application which requires a special application that is deployed via Group Policy. The first time he logs on to the domain he does not receive the software package. You verify that his user account is in the proper OU. What could be causing Darien not to receive the GPO with the software policy? 29. Your organization includes 10 file servers, which have computer accounts in the Servers OU of your domain. A GPO named Server Configuration is linked to the Servers OU. On five of the servers, a folder called Confidential Data exists. You have hired a team of consultants to assist on a project, and you want to ensure that those consultants cannot access the Confidential Data folder. You configure permissions on the folder to prevent access by consultants, and you want to audit any attempt by consultants to open or manipulate the folder. Which steps must you take? (Choose three. Each correct answer is part of the solution.) 30. Hi-tech has an Active Directory forest with single domain. Some other applications are also hosted on its perimeter network. The organization wants single sign-on to all applications hosted on perimeter network. The company has a domain member server with Active Directory Federation Services (AD FS) role installed. 31. You are an administrator at Tailspin Toys. Your Active Directory domain includes an OU called Service Accounts that contains all user accounts. Because you have configured service accounts with passwords that never expire, you want to apply a password policy that requires passwords of at least 40 characters. Which of the following steps should you perform? (Choose all that apply. Each correct answer is part of the solution.) 32. As an administrator at You are hired as the network administrator in your company. Your company, you have installed an Active Directory forest that has a single domain. You have installed an Active Directory Federation services (AD FS) on the domain member server. What should you do to configure AD FS to make sure that AD FS token contains information from the active directory domain? 33. SueyDog Enterprises will soon be deploying Microsoft Office Communicator into its environment. All of its DCs are running Windows Server 2008. Their administrator, Matthew, is attempting to prepare for the new product by creating a GPO and exploring the available settings. He creates a new policy and proceeds to expand each section of the policy, looking for the section containing the Microsoft Office Communicator settings. He can't seem to locate the settings for Microsoft Office Communicator. What should Matthew do to gain the settings he seeks? 34. You want to configure account lockout policy so that a locked account will not be unlocked automatically. Rather, you want to require an administrator to unlock the account. Which configuration change should you make? 35. You are the administrator for a nationwide company with over 5,000 employees. Your main office has approximately 4,500 employees, while your company's ten remote offices have 50 users each residing in them. You are often unaware of the physical security in place at these offices. However, since there is a fairly sizable amount of users at each office, you need to provide them with directory services. What is the BEST option to use for directory services when security is often an unknown? 36. You are hired as the network administrator in your company. Your company has an Active Directory forest. There is one main office and branch office in two different locations. Both of the locations have an organizational unit. Hi-tech has instructed you to ensure that the branch office administrators are able to create and apply GPOs only to their respective organizational unit. Which two actions should you perform to achieve this task? 37. As you evaluate the password settings objects in your domain, you discover a PSO named PSO1 with a precedence value of 1 that is linked to a group named Help Desk. Another PSO, named PSO2, with a precedence value of 99, is linked to a group named Support. 38. You are hired as the network administrator in your company. Your company has an Active Directory domain running Windows Server 2008. The Finance OU (organizational unit) contains an OU for computers, an OU for groups and an OU for users. As per company policy, you perform daily backups. Another administrator mistakenly deletes the groups OU. You have to restore the Groups OU without affecting users and computers in the Finance OU. What should you do to achieve this task? 39. You work for a large hospital. The main users in the hospital are nurses and doctors. Because they are always on the go, you set up kiosk stations throughout the hospital for them to log on to and check Web mail or access applications. The kiosks share one user logon and the nurses and doctors use their personal accounts to gain access to resources via a browser interface which prompts them for credentials. One morning a nurse logs onto a kiosk machine and is greeted by extremely offensive wallpaper. How would you utilize Group Policy to prevent this from happening in the future? 40. You want to obtain a log that will help you isolate the times of day that failed logons are causing a user's account to be locked out. 41. You are hired as the network administrator in your company. You are assigned to relocate the existing user and computer objects in your company to different organizational units. What are two possible ways to achieve this goal? (Each correct answer presents a complete solution. Choose two.) 42. You want to keep track of when users log on to computers in the human resources department of Adventure Works. Which of the following methods will enable you to obtain this information? 43. You are hired as the network administrator in your company. Your company has an Active Directory domain which runs Windows Server 2008. A user attempts to log on to the domain from the client computer using his account. He receives the following message: 44. The CIO has asked you to configure a GPO that will ensure that antivirus software is installed on every computer in the company. You are the most senior administrator in the company and have full access to every computer, and to Active Directory. Your company has a single domain and site. Which one of the following actions do you take? 45. Your domain consists of five domain controllers, one of which is running Windows Server 2008. All other DCs are running Windows Server 2003. What must you do before installing a read-only domain controller? 46. You have opened a command prompt, using Run As Administrator, with credentials in the Domain Admins group. You use the Dsrm command to remove an OU that had been created accidentally by James, a member of the Administrators group of the domain. You receive the response: Dsrm Failed: Access Is Denied. What is the cause of the error? 47. You are hired as the network administrator in your company. Your company has an Active Directory forest. There is a main office and five branch offices. Each branch office has an organizational unit and a child organizational unit called Accounts. The Accounts organizational unit contains all users and computers of the accounts department. You are directed to install Peachtree application only on the computers in the finance organizational unit. To install the application, you create a GPO named FinanceApp. What should you do next to achieve this task? 48. During a recent burglary at a branch office of Tailspin Toys, the branch office RODC was stolen. Where can you find out which users' credentials were stored on the RODC? 49. You are hired as the network administrator in your company. Your company has an Active Directory forest containing eight linked GPOs. One of the eight GPOs publishes applications to user objects. One of the user reports that the application is not available for installation. You have to identity whether the GPO is applied. What should you do to achieve this task? 50. Your company decided not to renew the license agreement for its contact management software. The software is deployed on systems across many client computers in the company. A single GPO was configured to install the software, and was linked into multiple places in the Active Directory hierarchy to accommodate the various user groups that needed the program. You've gone into the GPO and removed the published object for the software. Now, the object is gone from the GPO but the application is still installed on the client computers. Which one of the following most likely explains what happened? 51. Next week, five users are relocating to one of the ten overseas branch offices of Litware, Inc. Each branch office contains an RODC. 52. You are hired as the network administrator in your company. Your company has a group of consultants. All consultants belong to a global group named TempWorkers. You were advised to place three file servers in a new organizational unit named Secureserv. These file servers contain confidential data located in shared folders. After placing the file servers, you need to record any failed attempts made by the consultants to access confidential data. Which of the following two actions should you perform to achieve this task? 53. You are hired as the network administrator in your company. Your company has an organizational unit called subproduction. The organizational unit has a child organizational unit called Research. You create a GPO named Software Deployment and link it to the Production organizational unit. You create a shadow group for the Research organizational unit. You need to deploy an application to users in the subproduction organizational unit. You also need to ensure that the application is not deployed to users in the Research organizational unit. What are two possible ways to achieve this goal? (Choose two answers. Each answer is part of the complete solution) 54. You are an administrator for Hi-tech, Ltd. Your organization has decided to move to Windows Server 2008 and, because of your past experience, you have decided to create a new server implementation instead of upgrading your existing infrastructure. After the new infrastructure has been created, you will move all data-accounts, directory settings, and more-to the new forest you will implement with Windows Server 2008. You have been asked to create the initial forest structure. This forest includes a root domain, a global child production domain, and a domain tree. The forest is named with a .net extension, and the domain tree uses a .ms extension to differentiate it from the production forest. You successfully create the forest root domain and the child domain, but when you come to the domain tree, you find that you cannot locate the domain tree option. What could be the problem? 55. This morning you deployed an application by assigning it to computers, and then many of the applications failed. On some systems the application installed just fine, on others it only partially installed, and on still others it failed very early in the process. You figured out what went wrong, and have modified the MSI file. Which one of the following should you do to correct the problem? 56. You are an administrator for Hi-tech, Ltd. Your organization has decided to move to Windows Server 2008 and, because of your past experience, you have decided to create a new server implementation instead of upgrading your existing infrastructure. After the new infrastructure has been created, you will move all data-accounts, directory settings, and more-to the new forest you will implement with Windows Server 2008. You have been asked to create the initial forest structure. This forest includes a root domain, a global child production domain, and a domain tree. The forest is named with a .net extension, and the domain tree uses a .ms extension to differentiate it from the production forest. You successfully create the forest root domain and the child domain, but when you come to the domain tree, you find that you cannot create the delegation, no matter which options you try or which credentials you provide. 57. You are hired as the network administrator in your company. All servers in your company run Windows Server 2008. The company has a single Active Directory domain. Server01 and Server02 work as the domain controllers with DNS server role installed. You plan to install a new DNS server named Server03 on the perimeter network. Server01 is configured to forward all unresolved name requests to Server03. You discover that the DNS forwarding option is unavailable on Server02. 58. You are hired as the network administrator in your company. Your company has an Active Directory domain with an organizational unit called Sales. This organizational unit hosts two global security groups named Sales directors and Sales executives. Hi-tech has instructed you to apply desktop restrictions to the sales executives group. However, the desktop restrictions should not be applied to the Sales directors group. You create a GPO named Desktop Lockdown and link it to the Sales organizational unit. What should you do next? 59. You are an administrator at Trey Research. The Trey Research forest consists of three domains, each of which includes two domain controllers running Windows Server 2003. You want to upgrade one of the domain controllers to Windows Server 2008. What must you do first? 60. You work for a small accounting firm. Recently your boss, the owner of the company, read an article about weaknesses in password security. He's asked that you require everyone in the company to change his or her password every 30 days, and to have to use at least 12 different passwords per year. Which of the following settings do you configure in the Default Domain Policy? (Select all that apply.) 61. You are hired as the network administrator in your company. Your company has an Active Directory forest that contains Windows Server 2008 domain controllers and DNS servers. All client computers run Windows XP. You need to use your client computers to edit domain-based GPOs by using the ADMX files that are stored in the ADMX central store. What should you do? 62. You are an administrator at Hi-tech, Ltd. The domain was built using Windows Server 2008 domain controllers. You want to improve authentication at a remote site by promoting a member server at the site to a read-only domain controller. There is no IT support at the site, so you want the site's manager to perform the promotion. You do not want to give her administrative credentials in the domain. Which steps must you or the manager take? (Choose all that apply. Each correct answer is part of the solution.) 63. You are working in a Windows Server 2008 PKI and going over various user profiles that are subject to deletion due to company policy. The public keys for these users are stored under Documents and Settings\Administrator\System Certificates\My\Certificates and the private keys would be under Documents and Settings\Administrator\Crypto\RSA. You possess copies of the public keys in the registry, and in Active Directory. What effect will the deletion of the user profile have on the private key? 64. You are hired as the network administrator in your company. Your company has a network with a single Active Directory domain. 65. You want to promote a server to act as a domain controller, but you are concerned about the replication traffic that will occur during the promotion and its impact on the slow link between the server's site and the data center where all other domain controllers are located, so you choose to promote the server, using a backup of the directory from another domain controller. What must you do to create the installation media? 66. You are hired as the network administrator in your company. Your company has an Active Directory forest with a single domain. The domain has Windows Server 2008 at its functional level. You are instructed to create a global distribution group and add users to it. 67. You are an administrator at Hi-tech, Ltd. The hi-tech.com domain consists of two sites. At the headquarters, one domain controller, named SERVER01, is a GC server and performs all five operations master roles. The second domain controller at the headquarters is named SERVER02. SERVER02 is not a GC and performs no operations master roles. At the branch office, the domain controller is named SERVER03, and it is a GC server. Which change to the operations master role placement must you make? 68. You want to enable your help desk to reset user passwords and unlock user accounts. 69. You are hired as the network administrator in your company. Your company network consists of a single Active Directory domain. The functional level of the forest is Windows Server 2008. You need to create multiple password policies for users in your domain. What should you do? 70. You are an administrator at Hi-tech, Ltd. The forest consists of two domains, hi-tech.com and windows.hi-tech.com. Currently, SERVER02.windows.hi-tech.com performs all five operations master roles. You are going to decommission the windows.hi-tech.com domain and move all accounts into hi-tech.com. You want to transfer all operations masters to SERVER01.hi-tech.com. Which operations masters do you transfer? (Choose all that apply.) 71. You are browsing your company's e-commerce site using Internet Explorer 7 and have added a number of products to the shopping cart. You notice that there is a padlock symbol in the browser. By right clicking this symbol you will be able to view information concerning the site's: 72. You are hired as the network administrator in your company. Your company has an Active Directory forest which runs Windows Server 2008. It has branch offices all around the world. The forest includes finance organizational units for an office in the following locations: 73. You are an administrator at Hi-tech, Ltd. The hi-tech.com domain has five domain controllers. You want to move all domain operations masters to SERVER02.hi-tech.com. Which masters do you move? (Choose all that apply.) 74. Hi-tech.com has an Active Directory forest that hosts client computers running Windows Vista and Windows XP. Hi-tech .com has directed you to ensure that users are able to install approved application updates on their computers. Which of the following two actions should you perform to achieve this task? (Choose two answers. Each answer is part of the complete solution) 75. You are an administrator at Trey Research. Your domain consists of three domain controllers, two running Windows Server 2008 and one running Windows Server 2003. The forest root domain has two domain controllers, both running Windows Server 2003. You want to replicate SYSVOL in your domain, using DFS-R. What steps must you take? (Choose all that apply. Each correct answer is part of the solution.) 76. You are hired as the network administrator in your company. Your company has a network that consists of a single Active Directory domain. Windows Server 2008 is installed on all domain controllers in the network. You are instructed to capture all replication errors from all domain controllers to a central location. What should you do to achieve this task? 77. You are the administrator of your company's Windows Server 2008-based network and are attempting to enroll a smart card and configure it at an enrollment station. Which of the following certificates must be requested in order to accomplish this action? 78. You are hired as the network administrator in your company. Your company has file server located in an organizational unit named Salaries. The files servers have salaries files in a folder named salaries. You create a GPO. You have to track which employees access the salaries files on the file servers. What should you do you achieve this task? 79. You are hired as the network administrator in your company. Your company has an Active Directory forest. All domain controllers run Windows Server 2008 and are configured as DNS servers. You have an Active Directory-integrated zone for Hi-tech .com. You have a Unix-based DNS server. You need to configure your Windows Server 2008 environment to allow zone transfers of the Hi-tech .com zone to the Unix-based DNS server. What should you do in the DNS Manager console? 80. You want to configure Active Directory so that replication of logon scripts is managed using DFS-R. Which command do you use? 81. Two users, Dave and Dixine, wish to communicate privately. Dave and Dixine each own a key pair consisting of a public key and a private key. A public key was used to encrypt a message and the corresponding private key was used to decrypt. What is the major security issue with this scenario? 82. You are hired as the network administrator in your company. Your company has a domain controller that runs Windows Server 2008. 83. Client computers in a branch office are performing poorly during logon. You notice that the computers report that their logon server is a domain controller in a remote site rather than the domain controller in the branch office itself. Which of the following could cause this problem? 84. You are hired as the network administrator in your company. Your company has a single Active Directory domain and two domain controllers which run Windows Server 2008. Due to a problem, you need to reset the Directory Services Recovery Mode (DSRM) password on one domain controller. What tool should you use to achieve this task? 85. You are responsible for performing backups on the DCs on your network. Your boss has requested that you conduct system state backups to DVD. How do you accomplish this? 86. You are hired as the network administrator in your company. Your company has an Active Directory domain called ad. Hi-tech .com. 87. You are adding a read-only domain controller to a branch office location. You want to ensure that clients in the branch office are likely to authenticate with the RODC. What is required? (Choose all that apply.) 88. You are the network administrator at your company. The Active Directory database file on one of your DCs is corrupt. You decide to perform a nonauthoritative restore on the DC. You reboot the server into DSRM and try to log on as the domain administrator but you cannot. You need to get this DC back up and functioning as soon as possible. What can you do to achieve this? 89. As an administrator at You are hired as the network administrator in your company. Your company, you create 200 new user accounts. 90. The Web development team has requested that you implement a new Web server in a DMZ that will be used for presenting Web sites to customers. Which of the following is NOT a reason for using Windows Server 2008 Core Server? 91. A branch office is connected to the data center with a slow link that is not reliable. You want to ensure that the domain controller in the branch is able to authenticate users when it cannot contact a global catalog server. Which of the following should you configure? 92. You are the domain administrator for your company. Your network consists of multiple DCs at multiple sites. A DC at your local site is having problems with replicating. You need to know when this DC last attempted to perform an inbound replication on the Active Directory partitions. How would you accomplish this? 93. You are hired as the network administrator in your company. Hi-tech .com runs Window Server 2008 on all of its servers. It has a single Active Directory domain and it uses Enterprise Certificate Authority. The security policy at Hi-tech .com makes it necessary to examine revoked certificate information. You need to make sure that the revoked certificate information is available at all times. 94. You are hired as the network administrator in your company. Your company has a server that runs Windows Server 2008. The Enterprise Root CA is also installed on the server. The Security policy prevents port 443 and port 80 from being opened on domain controllers and on the issuing CA. You have to allow users to request certificates from a web interface. To do that, you install AD CS role. What should you do next? 95. You are the administrator at Hi-tech, Ltd. The Hi-tech forest consists of three domains, each with four domain controllers. You are preparing to demote a domain controller in the forest root domain. You want to be sure that you do not permanently destroy any Active Directory partitions. Which of the following Active Directory partitions might exist only on that domain controller? (Choose all that apply.) 96. You are hired as the network administrator in your company. Your company has an Active Directory domain. As an administrator, you plan to install the Active Directory Certificate Service (AD CS) role on a member server running Windows Server 2008. You have to make sure that the Account Operators group is able to issue smartcard credentials without being able to revoke certificate. Which of the following three actions should you perform to achieve this task? 97. You are hired as the network administrator in your company. Your company employs Windows Server 2008 Enterprise certificate authority (CA) to issue certificates. You're instructed to implement key archival. What should you do to achieve this task? 98. You are the domain administrator for your company. At your site you have a single DC that also acts as an application server. From 10:00 a.m. to 4:00 p.m., users complain about slow logons to the network and that accessing resources from this DC is incredibly slow during most of the workday. You log on to the DC, pull up the Task Manager, and notice that a process called CustApp.exe is using just more than 90% of the CPU cycles. The application must remain running during the day, but you also need to resolve the slow logon issues. There is no money in the budget for additional hardware. What is the best way to handle this situation? 99. You are hired as the network administrator in your company. Your company has a server that runs Windows Server 2008. Primarily this server has certification services configured as a stand-alone Certification Authority (CA). As per company policy, you are required to audit changes to the CA configuration setting and the CA security settings. Which two actions should you perform to achieve this task? (Choose two answers. Each answer is part of the complete solution) 100. You are hired as the network administrator in your company. Your company has an Active Directory domain. As an administrator, you plan to install the Active Directory Certificate Service (AD CS) role on a member server running Windows Server 2008. You have to make sure that the Account Operators group is able to issue smartcard credentials without being able to revoke certificate. 101. You are an administrator at a large university, and you have just been sent an Excel file containing information about 2,000 students who will enter the school in two weeks. 102. You want to configure all the existing domain controllers in your forest as global catalog servers. Which tools can you use to achieve this goal? (Choose all that apply.) 103. The network infrastructure at Trey Research prevents direct IP connectivity between the data center and a research ship at sea. What must you do to support replication between the data center and the ship? 104. You are hired as the network administrator in your company. Your company has servers that run Windows Server 2008. You administer 2 servers named SERVER01 and SERVER02. You have installed the enterprise root certification authority (CA) on SERVER01 and Online Responder role service on SERVER02. You want the SERVER01 to support the online responder. What should you do to configure online responder on SERVER01? 105. You want to initiate replication manually between two domain controllers to verify that replication is functioning correctly. Which of the following tools can you use? (Choose all that apply.) 106. You are hired as the network administrator in your company. Your company runs Window Server 2008 on all of its servers. It has a single Active Directory domain and it uses Enterprise Certificate Authority. The security policy at Hi-tech.com makes it necessary to examine revoked certificate information. You need to make sure that the revoked certificate information is available at all times. 107. You want to raise the domain functional level of a domain in the hi-tech.com forest. Which tool can you use? (Choose all that apply.) 108. You are an administrator of the hi-tech.com domain. You want to add a read-only domain controller to a domain with one Windows Server 2003 domain controller and one Windows 2008 domain controller. Which of the following must be done before adding a new server as an RODC? (Choose all that apply. Each correct answer is part of the solution.) 109. You have just finished upgrading all domain controllers in the hi-tech.com domain to Windows Server 2008. Domain controllers in the subsidiary.hi-tech.com domain will be upgraded in three months. You want to configure fine-grained password policies for several groups of users in hi-tech.com. What must you do first? 110. You are an administrator at Wingtip Toys, which has just acquired Tailspin Toys. You have created a one-way outgoing trust to enable users in the tailspintoys.com domain to access resources that have been moved into the wingtiptoys.com domain. Some users from tailspintoys.com are able to access the resources successfully, but other users are reporting that they are unable to gain access to the resources. You discover that the users having problems have worked for Tailspin Toys for eight or more years and that their accounts were migrated from a Windows NT 4.0 domain. What must you do to enable them to gain access to the resources? (Choose all that apply.) 111. You are a systems administrator for hi-tech.com. You have been requested to compact the database on one of the two DCs for the forest root domain. However, when you try to stop the AD DS service, you find that you cannot stop it on the server you are working on. What could be the problem? 112. You are hired as the network administrator in your company. All the servers in your company run windows 2008. The network of your company consists of a single Active Directory domain. There are two Active Directory-integrated zones named CO1.com and CO2.com in the domain. All domain controllers are configures as DNS servers. The company has instructed you to make sure that a user is able to modify records in Hi-tech es.com while preventing the user to modify the SOA record in CO2.com zone. What should you do to achieve this task? 113. You are hired as the network administrator in your company. Your company network consists of a single Active Directory domain. Ten domain controllers are present in the domain. All domain controllers run Windows Server 2008 and are configured as DNS servers. 114. You are a systems administrator at hi-tech.com. As you log on to a DC to perform maintenance, you get the impression that server response is sluggish. You want to verify what is going on. Which tool should you use? (Choose all that apply.) 115. You are an administrator at a large university. Which command can be used to delete user accounts for students who graduated? 116. You have a Windows Server 2003 R2 domain currently running in your organization. You would like to install a read-only domain controller into your Directory Services structure, but you do not want to completely upgrade your domain to Windows Server 2008 Directory Services just yet. What do you need to do in order to add an RODC? 117. Hi-tech .com has a single Active Directory domain called int. Hi-tech .com. You have installed domain controllers with a DNS server role. The domain controllers run Windows Server 2008. Every computer in the domain and non-domain members, register their DNS records dynamically. You want only the domain members to register their DNS records dynamically. What should you do to configure int. Hi-tech .com? 118. You want to create a user object with Windows PowerShell. Which of the following must you do? 119. You are hired as the network administrator in your company. Your company has a network consisting of an Active Directory forest named ebd.com. All servers have Windows Server 2008. All domain controllers are configured as DNS servers. The ebd.com DNS zone is stored in ForestDnsZones Active directory partition. A member server contains a standard primary DNS zone for eb.ebd.com. You need to make sure that all domain controllers can resolve names for eb.ebd.com. What should you do to achieve this task? 120. You want to create a user object with a single command. Which of the following should you do? 121. You are hired as the network administrator in your company. In your company there's a server named Server01 that runs Windows Server 2008. Server01 works as a Domain Controller is configured as DNS server in a single Active Directory domain. The domain contains one Active Directory-integrated DNS zone. 122. Which of the following Directory Services administration tools can be used in a Windows Server 2008 Lightweight Directory Services installation? 123. Which of the following lines of Windows PowerShell code are necessary to create a user object in the People OU? (Choose all that apply. Each correct answer is a part of the solution.) 124. You are the administrator for a nationwide company with over 5,000 employees. Your main office has approximately 4,500 employees, while the company's ten remote offices have 50 users residing in each. You are often unaware of the physical security in place at these offices. However, since there is a fairly sizable amount of users at each office, you must provide them with directory services. 125. You are hired as the network administrator in your company. In your company there's a server named Server01 that runs Windows Server 2008. Server01 is configured as DNS server and has 4 Active DirectoryCintegrated zones. For auditing purposes, you have to provide copies of the zone files of the DNS server to the security audit group. What should you do to achieve this task? 126. You want to set the Office property of ten users in two different OUs. The users currently have the Office property configured as Miammi. You recently discovered the typographic error and want to change it to Miami. What can you do to make the change? (Choose all that apply.) 127. You are hired as the network administrator in your company. In your company there are two servers named Server01 and Server02 that run Windows Server 2008. Server01 works as a Domain Controller and is configured as DNS server in a single Active Directory domain. Server02 is a member of the domain as the standard secondary zone with DNS Server role installed. 128. BitLocker is a new technology that is available in Windows Server 2008 as well as Windows Vista. Which is NOT an advantage of using BitLocker? 129. You want to move a user from the Paris OU to the Moscow OU. Which tools can you use? (Choose all that apply.) A. Move-Item 130. Hi-tech .com has a main office and a branch office. All servers in both offices run Windows Server 2008. The offices are connected through a MAN link. Hi-tech .com has an Active Directory domain that hosts a single domain called maks. Hi-tech .com. There is a domain controller in the maks. Hi-tech .com domain called Server01 . It is located in the main office. You have configured Server01 as a DNS server for maks. Hi-tech .com DNS zone. It is configured as a standard primary zone. You are instructed to install a new domain controller called Server02 in the branch office. After installing the domain controller, you install DNS on Server02 . You want to ensure that the DNS service on Server02 can update records and resolve DNS queries in the event of a MAN link failure. What should you do to achieve this objective? 131. A user reports that she is receiving a logon message that states, "Your account is configured to prevent you from using the computer. 132. You are the administrator for a nationwide company that currently runs Windows Server 2008 DNS and are reviewing the resource records in your Active Directory-integrated DNS zone. You notice there are hostnames that do not meet your company's naming convention and verify that the computers are not members of your Active Directory domain. What must you do to ensure these hosts cannot create records in your DNS zone? 133. Hi-tech .com has a single Active Directory domain. You have configured all domain controllers in the network as DNS servers and they run Windows Server 2008. A domain controller named Server01 has a standard Primary zone for Hi-tech .com and a domain controller named Server02 has a standard secondary zone for Hi-tech .com. You have to make sure that the replication of the Hi-tech .com zone is encrypted so you might not loose any zone data. What should you do to achieve this task? 134. You are hired as the network administrator in your company. Your company has a main office and a branch office that are configured as a single Active Directory forest. The functional level of the Active Directory forest is Windows Server 2003. There are four Windows Server 2003 domain controllers in the main office. You need to ensure that you are able to deploy a read-only domain controller (RODC) at the branch office. Which two actions should you perform?(Choose two answers. Each answer is a part of the complete solution.) 135. Trey Research has recently acquired Litware, Inc. Because of regulatory issues related to data replication, it is decided to configure a child domain in the forest for Litware users and computers. The Trey Research forest currently contains only Windows Server 2008 domain controllers. The new domain will be created by promoting a Windows Server 2008 domain controller, but you might need to use existing Windows Server 2003 systems as domain controllers in the Litware domain. Which functional levels will be appropriate to configure? 136. A new project requires that users in your domain and in the domain of a partner organization have access to a shared folder on your file server. Which type of group should you create to manage the access to the shared folder? 137. Your domain includes a global distribution group named Company Update. It has been used to send company news by e-mail to its members. You have decided to allow all members to contribute to the newsletter by creating a shared folder on a file server. What must you do to allow group members access to the shared folder? 138. You are hired as the network administrator in your company. Your company has servers that run Windows Server 2008. There are 2 domain controllers installed on the network. An Active Directory database is installed on the D volume of a domain controller. You want to move the Active Directory database to a new volume. What should you do to achieve this task? 139. You are creating a new standard primary zone for the company you work for, Name Resolution University, using the domain nru.corp. 140. Which of the following can be used to remove members from a group? (Choose all that apply.) 141. Hi-tech .com has a single Active Directory domain named ad. Hi-tech .com. Windows Server 2008 is installed on all domain controllers. 142. You are using Dsmod to add a domain local group named GroupA to a global group named GroupB. You are receiving errors. Which command will solve the problem so that you can then add GroupA to GroupB? (Choose all that apply.) 143. Hi-tech .com has a network consisting of a single Active Directory domain. All domain controllers run Windows Server 2003. Hi-tech .com instructs you to upgrade all domain controllers to Windows Server 2008. After upgrading the domain controllers, you need to ensure that the ebsysvolume share replicates by using DFS Replication (DFS-R). What should you do to achieve this task? 144. You have removed WINS from your environment, but still have at least one legacy PC and application that requires NetBIOS resolution. What solution can you use in place of WINS to address NetBIOS resolution? 145. Your management has asked you to produce a list of all users who belong to the Special Project group, including those users belonging to groups nested into Special Project. Which of the following can you use? 146. You are hired as the network administrator in your company. In your company there are two servers named server01 and server02 that runs Windows Server 2008. servers named Hi-tech A and Hi-tech B. DNS servers are configured as shown in the table: A. Delete the .(root) zone from Hi-tech B. Configure conditional forwarding on Hi-tech B. 147. Your company is conducting a meeting for a special project. The data is particularly confidential. The team is meeting in a conference room, and you have configured a folder on the conference room computer that grants permission to the team members. You want to ensure that team members access the data only while logged on to the computer in the conference room, not from other computers in the enterprise. What must you do? 148. Hi-tech.com has an Active Directory forest which runs Windows Server 2008. It has branch offices all around the world. The forest includes finance organizational units for an office in the following locations: 149. You've just created a new zone in DNS on a Windows Server 20083-based computer. You check the zone and notice that the only records in it are the SOA and NS RRs. Checking the configuration, you see that the zone is configured to accept dynamic updates. 150. You want to allow a user named Mike Danseglio to add and remove users from a group called Special Project. Where can you configure this permission? 151. You are hired as the network administrator in your company. Your company has a single Active Directory domain. The domain controllers run Windows Server 2003. You are instructed to upgrade all domain controllers to Windows Server 2008. To accomplish this task, you have to configure the Active Directory environment to support multiple password policies application. 152. Which of the following groups can shut down a domain controller? (Choose all that apply.) 153. Your company has offices in North America and Europe. It has an Active Directory forest with two domains. You are assigned the task to reduce the time required to authenticate users from labs.eul.hi-tech.com domain when they access resources on eng.na.hi-tech.com domain. What should you do to achieve this task? 154. You want to require all new computer accounts created when computers join the domain to be placed in the Clients OU. Which command should you use? 155. You are hired as the network administrator in your company. Your company has an Active Directory domain. Another administrator at the company attempts to log on to a computer that was offline for 12 weeks. While accessing the computer, administrator receives an error message that authentication has failed. What should you do to ensure that the administrator can log on to the computer? 156. A DNS server, Aspen, has been successfully resolving queries but with the wrong information. You use the Monitoring function in the DNS Management Console for Aspen and test the simple and recursive queries. Both work fine. What is the most likely cause of the problem? 157. You are logged on as Administrator to SERVER02, one of four domain controllers in the hi-tech.com domain that run Server Core. You want to demote the domain controller. Which of the following is required? 158. You want to prevent nonadministrative users from joining computers to the domain. What should you do? 159. You are hired as the network administrator in your company. Your company has a main office and ten branch offices. It has an Active Directory forest that hosts a single domain. Each office has one domain controller and they are configured as an Active Directory site. 160. You want to join a remote computer to the domain. Which command should you use? 161. You are hired as the network administrator in your company. Your company has purchased a new application to deploy on 200 computers. You are instructed to deploy the application on all 200 computers. To install the application, you have to modify the registry on each target computer before installing the application. Registry modifications are in a file that has an .adm extension. 162. You have been tasked with designing a new Windows Server 2008 Active Directory forest. The network is currently a combination of Windows 2000 Professional, Windows XP, Windows Vista, and Macintosh clients. You want to reduce the administration of IP addresses. Which of the following services would you implement to accomplish this? 163. Your manager has just asked you to create an account for DESKTOP234. Which of the following enables you to do that in one step? 164. You are hired as the network administrator in your company. The headquarters of your company is located in New York. Now your company builds its branch in Washington. The branch office in Washington is configured as a separate Active Directory site and has an Active Directory domain controller. You disable an account that has administrative rights. You need to immediately replicate the disabled account information to all sites. 165. Your hardware vendor has just given you an Excel worksheet containing the asset tags of computers that will be delivered next week. 166. You are hired as the network administrator in your company. The headquarters of your company is located in New York. The main office has an existing Active Directory site named Site1. Now your company builds its branch in Washington. You are assigned to deploy and implement a new Active Directory site and name Site2. To configure Active Directory replication between Site1 and Site2, you install a new domain controller and create the site link between Site1 and Site2. What should you do next to achieve this task? 167. Your network contains a mix of Windows 2003 and Windows Server 2008. You have three domain controllers running Windows Server 2003. Your file server, print server, and Exchange server are running Windows 2000 Server. Your DNS, DHCP, and WINS servers are running Windows Server 2008. All of your clients are running Windows XP Professional with Service Pack 2. All machines, other than the servers that require a static IP address, are configured as DHCP clients with the default settings. Your DNS server has been configured to allow dynamic updates. Which of the following records will be registered in DNS automatically? (Choose all that apply.) 168. Hi-tech .com has an Active Directory domain called es. Hi-tech .com. Hi-tech .com has a subsidiary company named Woksworks Inc. 169. A server administrator reports Failed To Authenticate events in the event log of a file server. What should you do? 170. You are hired as the network administrator in your company. Your company has an Active Directory domain. All servers in the Active Directory run Windows Server 2008. The domain runs Enterprise Root certification authority (CA). You have to make sure that only administrators can sign code. 171. A computer has permissions assigned to its account to support a system service. It also belongs to 15 groups. The computer is being replaced with new hardware. The new hardware has a new asset tag, and your naming convention uses the asset tag as the computer name. What should you do? (Choose all that apply. Each correct answer is a part of the solution.) 172. You are hired as the network administrator in your company. The headquarters of your company is located in New York. Now your company builds its branch in Washington. The branch office in Washington is configured as a separate Active Directory site and has an Active Directory domain controller. You are assigned to deploy and implement a new application which requires a local Global Catalog server to support at the branch office. Which tool should you use to configure the domain controller as a Global Catalog server? (Each correct answer presents part of the solution. Choose two.) 173. You have just installed a Windows Server 2008 domain controller in your environment. Which of the following default containers holds the default groups? 174. Your enterprise recently created a child domain to support a research project in a remote location. Computer accounts for researchers were moved to the new domain. When you open Active Directory Users And Computers, the objects for those computers are displayed with a down-arrow icon. What is the most appropriate course of action? 175. You are hired as the network administrator in your company. Your company has a domain controller that runs Windows Server 2008. 176. Your organization has one Active Directory domain in the Active Directory forest. You are responsible for creating accounts for all users in your domain. Your company just bought another company with 5000 user accounts, and you are required to create their new user accounts without using a third-party tool. Which of the following commands should be used to achieve this? 177. Litware, Inc., has three business units, each represented by an OU in the litwareinc.com domain. The business unit administrators want the ability to manage Group Policy for the users and computers in their OUs. Which actions do you perform to give the administrators the ability to manage Group Policy fully for their business units? (Choose all that apply. Each correct answer is a part of the solution.) 178. You are hired as the network administrator in your company. Your company has a main office and 15 branch offices. An Active Directory site with one domain controller is installed in each office. Only domain controllers in the main office are configured as global Catalog servers. On the domain controllers in the branch offices, you need to deactivate the Universal Group Membership Caching (UGMC) option. However, you need to deactivate UGMC on a certain level. 179. You are the administrator for a nationwide company with over 5,000 employees. Your director tells you your company has just signed into a partnership with another organization, and that you will be responsible for ensuring that authentication can occur between both organizations without the need for additional sign-on accounts. Your boss mentions that the partner has a variety of Directory Services installed throughout their organizations. 180. You are hired as the network administrator in your company. Your company has two active directory forests called Eb1.com and Eb2.com. Both forests have domain controllers that run Windows Server 2008. Windows Server 2008 is running on the domain functional level on Eb1.com. The domain functional level of Eb2.com is Windows Server 2003 Native mode. As per instructions, you configure an external trust between Eb1.com and Eb2.com. To achieve this, you need to enable the Kerberos AES encryption option. 181. You are an administrator at Hi-tech, Ltd. The hi-tech.com domain has a child domain, es.hi-tech.com, for the branch in Spain. 182. You are hired as the network administrator in your company. Your company has an Active Directory domain and two domain controllers named Server01 and Server02. The Server01 hosts the Schema Master Role. Suddenly the Server01 fails. To rectify the problem, you log on to Active Directory using administrator account. You are trying to transfer the Schema Master Operations role. 183. You are at a branch office of your company assisting a user on his PC. While assisting the user, you receive a phone call from your boss who wants to know why all the users are required to change their passwords the first time they log on? What would be the best way to answer his question? 184. You are an administrator at Hi-tech, Ltd. At a recent conference, you had a conversation with administrators at Fabrikam, Inc. You discussed a particularly successful set of configurations you have deployed using a GPO. The Fabrikam administrators have asked you to copy the GPO to their domain. Which steps can you and the Fabrikam administrators perform? 185. You are hired as the network administrator in your company. Your company has an Active Directory domain and two domain controllers named Server01 and Server02. The Server01 hosts the Schema Master Role. Suddenly the Server01 fails. To rectify the problem, you log on to Active Directory using administrator account. You are trying to transfer the Schema Master Operations role. 186. You want to deploy a GPO named Northwind Lockdown that applies configuration to all users at Northwind Traders. However, you want to ensure that the settings do not apply to members of the Domain Admins group. How can you achieve this goal? (Choose all that apply.) 187. Lisa works as a branch office administrator for your organization. She receives a call from her manager, Dina, asking which of the following characteristics make up a strong password. Which one is correct? 188. You want to create a standard lockdown desktop experience for users when they log on to computers in your company's conference and training rooms. You have created a GPO called Public Computers Configuration with desktop restrictions defined in the User Configuration node. What additional steps must you take? (Choose all that apply. Each correct answer is a part of the solution.) 189. You are hired as the network administrator in your company. Your company has an Active Directory domain. For regular checkups, you log on to the domain controller and open Microsoft Management Console (MMC). The Active Directory Schema snap-in is not available. What should you do to access the Active Directory Schema snap-in? 190. SERVER02 is running Server Core. It is already configured with the AD DS role. You want to add Active Directory Certificate Services (AD CS) to the server. What must you do? 191. A user calls the help desk at your organization and reports problems that you suspect might be related to changes that were recently made to Group Policy. You want to examine information regarding Group Policy processing on her system. Which tools can you use to gather this information remotely? (Choose all that apply.) 192. You are hired as the network administrator in your company. Your company has instructed you to decommission domain controllers that host all forest-wide operations master roles. Before you start taking down these domain controllers, you want to transfer all forest-wide operation master roles to another domain. Which two roles should you transfer to achieve this objective? (Choose two answers. Each answer is a part of the complete solution) 193. Which of the following options require administrative privileges to change the password? 194. You are the administrator at Hi-tech, Ltd. The hi-tech.com domain has five GPOs linked to the domain, one of which configures the password-protected screen saver and screen saver timeout required by corporate policy. Some users report that the screen saver is not launching after 10 minutes as expected. How do you know when the GPO was applied? 195. You are hired as the network administrator in your company. Your company has an Active Directory domain and two domain controllers named Server01 and Server02 . The Server01 hosts the Schema Master Role. Suddenly the Server01 fails. To rectify the problem, you log on to Active Directory using administrator account. You are trying to transfer the Schema Master Operations role. 196. The hi-tech.com domain contains a GPO named Corporate Help Desk, linked to the Clients OU, and a GPO named Sydney Support linked to the Sydney OU within the Clients OU. 197. You are hired as the network administrator in your company. In your company there's a server named server01 that runs Windows Server 2008. An instance of Active Directory Lightweight Directory Service (AD LDS) runs on Server01. You have to create new organizational units in the AD LDS application directory partition. 198. You are attempting to describe the purpose of a template account to a co-worker. What should you tell them? 199. The hi-tech.com domain contains a GPO named Corporate Help Desk, linked to the Clients OU, and a GPO named Sydney Support linked to the Sydney OU within the Clients OU. 200. You are hired as the network administrator in your company. Your company has a single Active Directory domain. All the domain controllers run Windows Server 2003. You install Windows Server 2008 on a server. You need to ensure that the new server is added as a domain controller in the domain. What should you do to achieve this task? 201. Which of the following are required to create a domain controller successfully?(Choose all that apply.) 202. You are hired as the network administrator in your company. All the servers in your company run windows 2008. The network of your company consists of a single Active Directory domain. There are two Active Directory-integragted zones named CO1.com and CO2.com in the domain. All domain controllers are configures as DNS servers. The companyn has instructed you to make sure that a user is able to modify records in Hi-tech as.com while preventing the user to modify the SOA record in CO2.com zone. What should you do to achieve this task? 203. You are the administrator for a nationwide company with over 5,000 employees. Your main office has approximately 4,500 employees ,which the company's ten remote offices have 50 users residing in each. You are often unaware of the physical security in place at these offices. However,since there is a fairly sizable amount of users at each office, you must provide them with directory services. 204.Trey Research has recently acquired Litware, Inc. Because of regulatory issues related to data replication, it is decided to configure a child domain in the forest for Litware users and computers. The Trey Research forest currently contains only Windows Server 2008 domain controllers. The new domain will be created by promoting a Windows Server 2008 domaincontroller, but you might need to use existing Windows Server 2003 systems as domain controllers in the Litware domain.Which functional levels will be appropriate to configure? 205. Hi-tech .com has an Active Directory domain called es. Hi-tech .com. Hi-tech .com has a subsidiary company named Woksworks Inc. 206. SERVER02 is running Server Core. It is already configured with the AD DS role. You want to add Active Directory Certificate Services (AD CS) to the server. What must you do? (责任编辑:mcse2008) |



