MCSE真题11月70
1.You are the network administrator for Blue Sky Airlines. You are implementing a Windows 2000 network consisiting of five sites in the blueskyairlines.com domain.
There are 15.000 users in Chicago, 5.000 users in LOS Angles; 2.000 users in Miami, 10.000 users in New York, and 2.000 users in Seattle. You are designing the structure of the DNS servers. You want to allow secure dynamic updates to DNS in Chicago,LOS Angeles, And NEW York, You want full DNS replication to occur in all the sites. You do not want the Miami Site to have an editable copy of the DNS zone.
How should you configure the DNS servers to accomplish these goals?
To answer, Click the Select and Place button, and then drag the letter indicating the appropriate server type to each site.Next drag the number indicating the appropriate zone type to each site. Two sites have been partially completed for you.(Notes. Zone types and server types can be used more than once.)
2. Your company’s network consists of two windows 2000 domains:contoso.com and newyork.contoso.com. The newyork.contoso.com domain contains three organizational units(Ous):Sales,Marketing,and Finance. You are a member of the Domain Admins group in newyork.contoso.com.
An employee named Maria can reset passwords for the Finance OU.Maria will be moving to the Sales OU and no longer needs access to the Finance OU.
A. In the Delegation of Control wizard. Specify that Maria cannot reset passwords for the domain controller to which Maria’s user account authenticates.
B. Clear the Trust computer for delegation check box in the properties for the domain controller to which Maria’s user account authenticates.
C. In the security properties of the Finance OU, remove Maria’s right to reset passwords.
D. Copy Maria’s user account to sales OU.and then delete the account.1.你是蓝天航空公司的网络管理员。您正在实施一个Windows 2000网络,该网络由blueskyairline s.com域中的五个站点组成。
芝加哥有15000用户,洛杉矶有5000用户;迈阿密有2,000名用户,纽约有10,000名用户,西雅图有2,000名用户。您正在设计DNS服务器的结构。您希望允许对芝加哥、洛杉矶和纽约的DNS进行安全的动态更新,您希望在所有站点进行完整的DNS复制。您不希望迈阿密站点拥有DNS区域的可编辑副本。
您应该如何配置DNS服务器来实现这些目标?
要回答这个问题,请单击“选择并放置”按钮,然后将表示相应服务器类型的字母拖到每个站点上。接下来,将表示相应区域类型的数字拖到每个站点上。两个网站已经为你部分完成。(备注。区域类型和服务器类型可以多次使用。)
2。您公司的网络由两个windows 2000域组成:contoso.com和newyork.contoso.com。newyork.contoso.com域包含三个组织单位(ou):销售、营销和财务。您是newyork.contoso.com域管理员组的成员,
一位名叫Maria的员工可以重置财务ou的密码。Maria将转到销售OU,不再需要访问财务OU。[/ br/] A .在控制委派向导中。指定Maria不能为Maria的用户帐户验证的域控制器重置密码。
B .在Maria的用户帐户进行身份验证的域控制器的属性中,清除“信任委派计算机”复选框。
C .在财务OU的安全属性中,删除Maria重置密码的权利。
D .将Maria的用户帐户复制到销售OU,然后删除该帐户。
3. You are the administrator of your company’s windows 2000 network. The network consists of a single domain,which contains all company user and computer accounts.
A new corporate policy states that no employees can have access to the network by means of connections. You discover that some employees have configured their windows 2000 computes as remote access servers.
You want to ensure that employees cannot configure their computers to use Rouing and Remote Access. What should you do first?
A. Configure the Default Domain Group Policy object (GPO) to disable the Routing and Remote access service.
B. Create a remote access policy that allows only approved routing and remote access servers to establish connections.
C. Configure the Default Domain Group Policy object (GPO) to proibit the configuration of connection sharing.
D. Configure the default domain group policy object (GPO) to prohibit the connecting and disconnecting of a remote access connection.
4.You are the administrator of your company’s network. The network consists of a single DNS domain. A windows NT server 4.0 computer named server1 hosts the primary DNS zone for the domain.
You install a new wndows 2000 server computer named server2 to function as the first domain controller in the network. Server2 contains a secondary zone for the domain. During the installation of active directory, you choose to manually update DNS so that it contains the Active directory resource records. You need to import these records from server2 into DNS.
What should you do?
A. Import the contents of the Netlogon.dns file to the standard primary zone file on server1, and then restart the DNS server service on both servers.
B. Import the contents of the Netlogon.dns file to the standard secondary zone file on server2, and then restart the DNS server service on both servers.
C. Import the contents of the root.dns file to the standard primary zone.file on Server1,and then restart the Net Logon service on Both servers.
D. Import the contents of the Root dns file to the standard secondary zone file on Server2,and then restart the Net logon service on both servers.
5.You are the administrator of your company’s windows 2000 network. The network contains 10 windows 2000 server computers. You need to create a strict network security policy . You create a security template named Hisecsrvr.inf
A. Schedule the secedit/analyze/DB config.sdb/CFG hisecsrvr.inf/quiet command and the secedit/configure /DB config.sdb /quiet command to run on each server.
B. In the local security policy on each server, export the local policy settings to the Hisecsrvr.inf file. And then move the template to the %systemroot%\system32\secunty folder on each server.
C. Schedule the poledit/analyze /DB config.sdb /CFG hisecsrvr.inf/quiet command and the poledit/configure /DB config.sdb /quiet command to run on each server.
D. In the Local security Policy on each server,export the effective policy settings to the Hisecsrvr.inf file, and then move the template to the %systemroot%”\system32\security folder on each serve.
6. You are the administrator of a windows 2000 network. Your network consists of five sites in one domain. The Chicago.Los Angeles, and New York sites will have DNS running on their domain controllers. Miami and Seattle will have DNS running on dedicated member servers.
You want to allow client computers in the Chicago, Los Angeles, and New York sites to perform secure dynamic updates to the DNS servers. You want to configure your DNS servers so that each site has a replicated copy of the DNS zone.
What should you do?
To answer, click the select and place button, and then drag the appropriate zone type to each site.(Note: zone types can be used more than once.)
3.您是贵公司windows 2000网络的管理员。该网络由一个域组成,其中包含所有公司用户和计算机帐户。
一项新的公司政策规定,任何员工都不能通过连接的方式访问网络。您发现一些员工将他们的windows 2000计算机配置为远程访问服务器。
您希望确保员工无法将他们的计算机配置为使用路由和远程访问。你应该先做什么?
A .配置默认域组策略对象(GPO)以禁用路由和远程访问服务。
B .创建一个远程访问策略,只允许批准的路由和远程访问服务器建立连接。
C .配置默认域组策略对象(GPO)以提供连接共享的配置。
D .配置默认域组策略对象(GPO)以禁止远程访问连接的连接和断开。
4。您是公司网络的管理员。该网络由一个DNS域组成。一台名为server1的windows NT server 4.0计算机,它拥有域的主DNS区域。
您安装了一台名为server2的新的wndows 2000 server计算机,作为网络中的第一个域控制器。Server2包含域的辅助z one。在安装active directory的过程中,您选择手动更新DNS,以便它包含Active directory资源记录。您需要将这些记录从服务器2导入DNS。
你该怎么办?
A .将Netlogon.dns文件的内容导入到服务器1上的标准主区域文件中,然后在两台服务器上重新启动dns服务器服务。
B .将Netlogon.dns文件的内容导入到服务器2上的标准辅助区域文件中,然后在两台服务器上重新启动dns服务器服务。
C .将root.dns文件的内容导入到Server1上的标准primary zone.file,然后在两台服务器上重新启动Net Logon服务。
D .将根dns文件的内容导入到服务器2上的标准辅助区域文件中,然后在两台服务器上重新启动Net logon服务。
5。您是贵公司windows 2000网络的管理员。该网络包含10台windows 2000 server计算机。您需要制定严格的网络安全策略。创建一个名为Hisecsrvr.inf
A的安全模板。安排在每台服务器上运行secedit/analyze/DB config.sdb/ CFG hisecsrvr.inf/quiet命令和secedit/config/DB config . sdb/quiet命令。
B .在每台服务器上的本地安全策略中,将本地策略设置导出到Hisecsrvr.inf文件。然后将该模板移动到每台服务器上的% systemroot % \ system32 \ secunty文件夹中。
C .安排在每台服务器上运行poledit/analyze/DB config . sdb/CFG hisecsrvr.inf/quiet命令和poledit/config/DB config . sdb/quiet命令。
D .在每台服务器上的本地安全策略中,将有效的策略设置导出到Hisecsrvr.inf文件中,然后将模板移动到每台服务器上的% systemroot % " \ system32 \ security文件夹中。
6。您是windows 2000网络的管理员。您的网络由一个域中的五个站点组成。芝加哥。洛杉矶和纽约站点将在其域控制器上运行DNS。迈阿密和西雅图将有运行在专用成员服务器上的DNS。
您希望允许芝加哥、洛杉矶和纽约站点的客户端计算机对DNS服务器执行安全的动态更新。您希望配置DNS服务器,以便每个站点都有DNS区域的副本。
你该怎么办?
要回答这个问题,请单击“选择并放置”按钮,然后将适当的区域类型拖到每个站点上。(注意:区域类型可以多次使用。)
0条评论