Day 10 Flashcards

1
Q

DSQuery.exe

A

an extremely powerful command-line tool that allows you to query and manage Active Directory objects

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

LDIFDE.exe

LDAP Data Interchange Format Directory Exchange

A

used for object creation, queries, and modification of Active Directory objects.

pulls report of active directory database

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Group policy

A

the primary purpose of Group policy is to apply policy settings to computers and users in an active directory domain

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Group Policy Objects (GPOs)

A

a collection of settings that efficiently apply user and computer configurations for the domain.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

GPO’s can be linked to:

A

sites
domain’s
OU’s

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Two default GPO’s

A

Default domain policy–policy for the domain an dis linked to the domain

default domain controllers policy–domain controller policy and is linked to the domain controller’s OU

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

SYSVOL (System Volume)

A

a collection of folders that exist on each domain controller to store elements of GPOs and domain public files

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

SYSVOL subfolders

A

machine–contains registry settings to be applied to computer HKEY_Local_Machine settings

User–contains registry settings to be applied to the user’s HKEY_Current_USER settings

user and machine folders are created at install time and other folders are created as needed when policy is set

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Group policy has two settings:

A

computer configuration–group policies can be applied during the computer’s startup/shutdown and affect all users who log into the computer

user configuration- user configuration settings customize the user’s environment at the user level

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

group policy processing order

A
  1. local policies
  2. Site GPO’s
  3. Domain GPO’s
  4. OU GPO’s
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Exception to processing order

A
#no override- previously processed policies are not overwritten
#block policy inheritance- policy settings will not inherit from above
#GPO disabled
#Permissions
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

security templates

A

a collection of predefined policy settings in a single file. predefined templates provide a policy starting point and may be customized to meet organizational requirements

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

User accounts

A

local-user account that can only be authenticated by the local machine. These accounts exist in local system’s SAM

#Built in-automatically created.  There are local and domain built in accounts
###administrator
###guest
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

user profiles

A

HKU registry key contains the user environment settings for the user that has interactively logged on to the system.

HKCU registry key is used for configuration settings and changes while the user is logged on.

ntuser.dat is the user profile file.

changes are saved to profile at logoff

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

ntuser.man

A

changing ntuser.dat to ntuser.man will make the profile mandatory and does not save changes at logoff

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

local user profile

A

stored on the local system

17
Q

roaming user profile

A

roaming profiles are stored on a network share

18
Q

group accounts

A

used to manage account permissions more efficiently by adding user, computer, and even other group accounts into a single group

19
Q

two types of domain groups

A

security groups– used for assigning permissions

distribution groups–used for email distribution lists

20
Q

domain local groups and domain global groups

A
#Domain local groups---assigned to resources within a domain
#Domain Global Group-used anywhere in the forest.
21
Q

best practise for managing group membership

A

1 add user accounts as members of global groups
2 add global groups as members of domain local groups
3. assign permissions to domain local groups
A->GG->DLG

22
Q

the following groups are of a global scope.

They are located in Users container by default

A

Domain Admins
Domain Guests
Domain Users
Enterprise Admins

23
Q

The following groups are of a domain local scope.

They are located in the Built-in container by default

A

Account operators
administrators
backup operators
Users

24
Q

Special identity groups

A

conditional groups whose memberships cannot be manually assigned.
Authenticated users
Creator Owner
Everyone