Lesson 02 Exercises for Configuring Network Services Questions and Answers Flashcards

1
Q

Question 1 : You are the network administrator for a midsize computer company.

You have a single Active Directory forest, and your DNS servers are configured as Active Directory Integrated zones.

When you look at the DNS records in Active Directory, you notice that there are many records for computers that do not exist on your domain.

You want to make sure that only domain computers register with your DNS servers.

What should you do to resolve this issue?

Set dynamic updates to None.

Set dynamic updates to Nonsecure And Secure.

Set dynamic updates to Domain Users Only.

Set dynamic updates to Secure Only.

A

Set dynamic updates to Secure Only.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Question 2 : You are the network administrator for a large company that has one main site and one branch office.

Your company has a single Active Directory forest, ABC.com.

You have a single domain controller (ServerA) in the main site that has the DNS role installed.

ServerA is configured as a primary DNS zone.

You have decided to place a domain controller (ServerB) in the remote site and implement the DNS role on that server.

You want to configure DNS so that, if the WAN link fails, users in both sites can still update records and resolve any DNS queries.

How should you configure the DNS servers?

Configure ServerB as a secondary DNS server. Set replication to occur every five minutes.

Configure ServerB as a stub zone.

Configure ServerB as an Active Directory Integrated zone and convert ServerA to an Active Directory Integrated zone.

Convert ServerA to an Active Directory Integrated zone and configure ServerB as a secondary zone.

A

Configure ServerB as an Active Directory Integrated zone and convert ServerA to an Active Directory Integrated zone.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Question 3 : You are the network administrator for a small company with two DNS servers: DNS1 and DNS2.

Both DNS servers reside on domain controllers.

DNS1 is set up as a standard primary zone, and DNS2 is set up as a secondary zone.

A new security policy was written stating that all DNS zone transfers must be encrypted.

How can you implement the new security policy?

Enable the Secure Only setting on DNS1.

Enable the Secure Only setting on DNS2.

Configure Secure Only on the Zone Transfers tab for both servers.

Delete the secondary zone on DNS2. Convert both DNS servers to use Active Directory Integrated zones.

A

Delete the secondary zone on DNS2. Convert both DNS servers to use Active Directory Integrated zones.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Question 4 : You are the network administrator for a Windows Server 2012 R2 network.

You have multiple remote locations connected to your main office by slow satellite links.

You want to install DNS into these offices so that clients can locate authoritative DNS servers in the main location.

What type of DNS servers should be installed in the remote locations?

Primary DNS zones

Secondary DNS zones

Active Directory Integrated zones

Stub zones

A

Stub zones

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Question 5 : You are the network administrator for Stellacon Corporation.

Stellacon has two trees in its Active Directory forest, stellacon.com and abc.com.

Company policy does not allow DNS zone transfers between the two trees.

You need to make sure that when anyone in abc.com tries to access the stellacon.com domain, all names are resolved from the stellacon.com DNS server.

What should you do?

Create a new secondary zone in abc.com for stellacon.com.

Configure conditional forwarding on the abc.com DNS server for stellacon.com.

Create a new secondary zone in stellacon.com for abc.com.

Configure conditional forwarding on the stellacon.com DNS server for abc.com.

A

Configure conditional forwarding on the abc.com DNS server for stellacon.com.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Question 6 : You are responsible for DNS in your organization.

You look at the DNS database and see a large number of older records on the server.

These records are no longer valid.

What should you do?

In the zone properties, enable Zone Aging and Scavenging.

In the server properties, enable Zone Aging and Scavenging.

Manually delete all of the old records.

Set Dynamic Updates to None.

A

In the zone properties, enable Zone Aging and Scavenging.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Question 7 : You are the network administrator for the ABC Company.

Your network consists of two DNS servers named DNS1 and DNS2.

The users who are configured to use DNS2 complain because they are unable to connect to Internet websites.

The following table shows the configuration of both servers:

*IMAGE STATES
DNS1
_msdcs.abc.comabc.com
DNS2
.(root)_msdcs.abc.cmabc.com

The users connected to DNS2 need to be able to access the Internet.

What needs to be done?

Build a new Active Directory Integrated zone on DNS2.

Delete the .(root) zone from DNS2 and configure conditional forwarding on DNS2.

Delete the current cache.dns file.

Update your cache.dns file and root hints.

A

Delete the .(root) zone from DNS2 and configure conditional forwarding on DNS2.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Question 8 : Your company consists of a single Active Directory forest.

You have a Windows Server 2012 R2 domain controller that also has the DNS role installed.

You also have a Unix- based DNS server at the same location.

You need to configure your Windows DNS server to allow zone transfers to the Unix-based DNS server.

What should you do?

Enable BIND secondaries.

Configure the Unix machine as a stub zone.

Convert the DNS server to Active Directory Integrated.

Configure the Microsoft DNS server to forward all requests to the Unix DNS server.

A

Enable BIND secondaries.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Question 9 : You are the network administrator for your organization.

A new company policy states that all inbound DNS queries need to be recorded.

What can you do to verify that the IT department is compliant with this new policy?

Enable Server Auditing - Object Access.

Enable DNS debug logging.

Enable server database query logging.

Enable DNS Auditing - Object Access.

A

Enable DNS debug logging.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Question 10 : Your IT team has been informed by the compliance team that it needs copies of the DNS Active Directory Integrated zones for security reasons.

You need to give the Compliance department a copy of the DNS zone.

How should you accomplish this goal?

Run dnscmd /zonecopy.

Run dnscmd /zoneinfo.

Run dnscmd /zoneexport.

Run dnscmd /zonefile.

A

Run dnscmd /zoneexport.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly