Create and Manage Group Policy Flashcards

1
Q

Which tool do you use to edit a local Group Policy on a computer?

A

you can open and edit a GPO by using the Group Policy Editor

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How can domain administrators disable the processing of local GPOs on clients that are running Windows client and Windows Server operating systems?

A

by enabling the Turn Off Local Group Policy Objects Processing policy setting in a domain GPO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which user can always change permissions on an object, even when that user is denied all access to the object?

A

The user or group that is the owner of the object

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How do you export AppLocker rules from a GPO in one domain to another GPO in another domain?

A

Export the AppLocker rules from the source GPO to an XML file. Import the XML file with Group Policy Editor on the destination GPO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Which user feature protects the computer from the unauthorized installation of any software?

A

User Account Control (UAC)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the path to the central store that is used to store and replicate Windows policy files on a domain controller?

A

%logonserver%\sysvol\%userdnsdomain%\policies\PolicyDefinitions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the scope of the Restore-GPO cmdlet when restoring GPO backups?

A

It only restores GPO backups to the original domain where the GPO was saved

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

After creating ADMX files to define registry-based policy settings on all client computers in the domain, what should you do to ensure that the custom ADMX file for the Chinese language is automatically available to all Group Policy administrators in the domain?

A

Create an ADML file and copy it to the SYSVOLl\domain\policies\PolicyDefinitions[MUIculture] folder on the domain controller.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the two enforcement options that can be set on the enforcement of AppLocker executable rules, Windows Installer rules, script rules, and packaged app rules?

A

Enforce Rules and Audit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Which GPO setting manages mapped drives, scheduled tasks, environment variables, printer mappings, and Start menu settings?

A

Preferences

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What should you do to allow AppLocker rules to test what software will be affected by the rules when they are implemented?

A

Set enforcement to Audit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

If you have multiple local GPOs on a Windows Server 2012 server, in what order are the local GPOs processed?

A
  1. Local Group Policy
  2. Administrators and Non-Administrators Group Policy
  3. User-specific Local Group Policy
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the term for the folder that is created in the SYSVOL folder of an Active Directory domain controller and is used to provide a centralized storage location for ADMX and ADML files for the domain?

A

central store

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What type of AppLocker rules are available to configure in a GPO for Windows 8.1 or Windows Server 2012 R2 computers?

A

packaged app rules, executable rules, Windows Installer rules, and script rules

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

When editing a Group Policy, which Flexible Single Master Operations (FSMO) role contains the version of the Group Policy that is being edited?

A

PDC emulator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What type of condition would you apply to an AppLocker rule to restrict users from running a specific version number of a program?

A

a file hash rule

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What does the Block all connections setting on a Firewall profile block?

A

Blocks all connections, regardless of any firewall rules that explicitly allow the connection

18
Q

What does the Block setting on a Firewall profile block?

A

Blocks all connections that do not have firewall rules that explicitly allow the connection

19
Q

Which Hyper-V features can be accessed by members of the Hyper-V Administrators group?

A

Members of the Hyper-V Administrators have complete and unrestricted access to all features of Hyper-V.

20
Q

What path on a domain controller contains the Group Policy files?

A

%SystemRoot%\SYSVOL\Domain\Policies\GPOGUID path, where GPOGUID is the GUID of the Group Policy container.

21
Q

What does the Allow setting on a Firewall profile allow?

A

Allows the connection, unless there is a firewall rule that explicitly blocks the connection

22
Q

Which service, if stopped, with will prevent AppLocker policies from being enforced?

A

the Application Identity service

23
Q

Which ports and protocols should you enable on the Windows Firewall for a Windows Server 2012 R2 acting as a VPN server to allow inbound L2TP connections?

A

UDP port 500 and 4500 as well as IP Protocol ID 50

24
Q

How does an administrator repair or change permissions on a file in which the administrator has been denied permissions?

A

The administrator should take ownership of the file

25
Q

Which firewall rules should be configured to allow ping commands to work?

A

the correct echo rules, such as “File and Printer Sharing (Echo Request - ICMPv4-In)”

26
Q

Which command is used to configure one or many servers with an SCW-generated policy?

A

Scwcmd

27
Q

What type of condition would you apply to an AppLocker rule to restrict users from running software from a specific software vendor?

A

a publisher rule

28
Q

Which firewall profile is applied when a computer is connected to a network in which the computer’s domain account does not reside, such as a home network?

A

Private profile

29
Q

To specify the Accounts:Rename Administrator account policy to rename the local Administrator account on a computer to a different name, what path in a GPO must you search for the policy?

A

Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\Security Options

30
Q

Which firewall profile is applied when a computer is connected to a domain through a public network?

A

Public profile

31
Q

What type of AppLocker rule would you use to control an application from the Windows store?

A

a packaged app rule

32
Q

What type of condition would you apply to an AppLocker rule to restrict users from installing software in a particular location?

A

a path rule

33
Q

If you upgrade a computer that is using Software Restriction Policies to Windows Server 2012 R2 or Windows 8.1, and then implement AppLocker rules, which set of policies is enforced?

A

only the AppLocker rules are enforced

34
Q

Which firewall profile is applied when a computer is connected to a network in which the computer’s domain account resides?

A

Domain profile

35
Q

Which group can reduce the number of users that belong to the local Administrators group while providing users with access to Hyper-V?

A

Hyper-V Administrators

36
Q

What PowerShell cmdlet would you use to display the settings that have been enabled in a particular GPO?

A

the Get-GPOReport cmdlet

37
Q

What parameter of the Import-GPO cmdlet will create the destination GPO if the GPO does not exist?

A

-CreateIfNeeded

38
Q

Which ports and protocols should you enable on the Windows Firewall for a Windows Server 2012 R2 acting as a VPN server to allow inbound PPTP connections?

A

TCP port 1723 and IP Protocol ID 47

39
Q

Which type of GPO allows you to create a baseline from which you can build GPOs?

A

A Starter GPO

40
Q

How can you copy AppLocker rules to another computer?

A

Export the AppLocker rules from a GPO or local security policy to an XML file, and import the XML file to another GPO or another local security policy

41
Q

Which ports and protocols should you enable on the Windows Firewall for a Windows Server 2012 R2 acting as a VPN server to allow inbound SSTP connections?

A

TCP Port 443

42
Q

Which local group(s) membership on a member server allows the user to back up and restore files and directories on the server?

A

Membership in the Administrators OR Backup Operators groups