CÔNG VIỆC CỦA CHÚNG TÔI

+ Đào tạo & hỗ trợ thi & Cấp chứng chỉ Ứng dụng CNTT cơ bản, nâng cao
+ Cung cấp dịch vụ Thiết kế - Lập trình web
+ Các giải pháp triển khai - quản trị hệ thống mạng doanh nghiệp
+ ĐÀO TẠO CHUYÊN NGHIỆP: LẬP TRÌNH (C, .Net, ASP.net, PHP, Thiết kế Đồ họa
Hiển thị các bài đăng có nhãn MCTS. Hiển thị tất cả bài đăng
Hiển thị các bài đăng có nhãn MCTS. Hiển thị tất cả bài đăng

Read-Only Domain Controller với Child Domain Controller

Child domain và Read- Only Domain là hai kỹ thuật ủy thác quyền quản trị cho các chi nhánh. Tùy theo mức độ mà người ta lựa chọn phương thức khác nhau. Với Read-Only Domain thường người ta dùng cho những chi nhánh, nơi mà khả năng đảm bảo bảo mật vật lý kém. Đối với Child Domain thì chúng ta có thể ủy thác hoàn toàn quyền quản trị một site đến một chi nhánh một các độc lập.
Mô hình thực hiện:

Một số câu hỏi Window Server 2003

Một số câu hỏi Window Server 2003



THUẬT NGỮ VIẾT TẮT
1. AD: Active Directory
2. DN: Distinguished Name
3. GUID: Globally Unique Identifier
4. RDN: Relative Distinguished Name
5. UPN User Pricipal Name
6. CN: Common Name
7. DC: Domain Component Name
8. OU: Organizational Unit Name
9. DHCP: Dynamic Host Configuration Protocol
10. DNS: Domain Name System
11. WHQL: Windows Hardware Quality Labs


ACTIVE DIRECTORY-DOMAIN
1. Trong 1 hệ thống mạng, có nhiều đối tượng được lưu trữ trong một Directory như: File Server, Printers, Fax Servers, Applications, Database, Users
2. AD là bộ sưu tập các thông tin về các tài nguyên (resource) của mạng như: File Server, Web Server, Printers, Applications, Database, User
3. Thông tin chứa trong AD được sử dụng cho việc quản lý và xử lý các tài nguyên của mạng
4. Mỗi GUID là 1 con số 128 bit, duy nhất cho mỗi Domain
5. AD có thể lưu trữ phân bố trên nhiều máy
6. Các đối tượng (Object) lưu trữ trong AD: User, Printers, Server, Database, Groups, Computer và các chính sách về an ninh được tổ chức thành đối tượng
7. Class là 1 nhóm logic các đối tượng trong AD
8. Forest gồm 1 nhóm hay tổ chức phân cấp của nhiều cây domain độc lập hoàn toàn
9. Cấu trúc vật lý là hoàn toàn khác với cấu trúc logic của AD
10. Site gồm 1 hay nhiều mạng IP được nối với nhau bằng đường truyền đáng tin cậy có tốc độ cao (>128 kbs)
11. Không có sự liên quan giữa cấu trúc vật lý và cấu trúc domain
12. Không gian tên của domain và site không có sự liên hệ
13.Tất cả các domain controller trong 1 domain phải duy trì 1 bản sao đầy đủ của AD
14. Không có domain controller đóng vai trò master trong việc nhân bản, các domain controller là bình đẳng
15. Một domain là một nhóm logic các mạng máy tính có thể chia sẻ CSDL trung tâm
16. Trong 1 domain, Directory nằm trong một môi trường được cấu hình gọi là domain controller
17. Ưu điểm của của domain là cung cấp 1 quá trình đăng nhập để có thể xử lý tài nguyên mạng mà họ được phép
18. Mỗi domain có 1 chính sách an ninh riêng và các quyền được cung cấp bởi Administrator
19. GUID không thay đổi khi có sự thay đổi trong AD
20. Trong site cần mất 5 phút để sao lưu các domain controller


HỆ ĐIỀU HÀNH WINDOWS SERVER
1. Windows Server 2003 phiên bản mạnh nhất là Data Center Edition
2. Trong Windows Server 2003 có phiên bản Web Edition
3. Server core (Win 2008) không bán rời mà đi kèm như một tùy chọn cài đặt trong phiên bản Stadard, Enterprise, Datacenter, Web
4. Windows server cho phép lồng không giới hạn


USER-GROUPS
1. Trong Windows 2003, sự xác thực 1 user trong domain dựa trên một user account chứa trong AD
2. Local user account cho phép user đăng nhập và xử lý nguồn tài nguyên chỉ tại nơi môi trường mà local user account nơi nó tạo ra.
3. Không nên tạo Local user account khi cần truy xuất nguồn tài nguyên của domain
4. Domain user account cho phép đăng nhập và truy xuất các nguồn tài nguyên mạng từ bất cứ nơi nào của mạng.
5. Quy ước tên: các ký tự không có giá trị trong user logo khi bạn sử dụng hệ thống trên MS Windows 2000 là: ^, [], /, =, +, ?, <>, @...Không phân biệt chữ hoa chữ thường. Có thể sử dụng tổ hợp phím các ký tự đặc biệt và các số để tạo ra định danh duy nhất.
6. Password có thể có độ dài đến 127 ký tự
7. User profile duy trì tính ổn định cho các user đối với desktop của user
8. Các nhóm domain local, Global, Universal có thể đặt trong chính loại nhóm của mình.
9. Global và Universal có thể đặt trong nhóm Domain local
10. Global có thể đặt trong nhóm Universal
11. Tạo cấu trúc phân cấp nhóm có thể lồng không giới hạn
12. Local groups là tập hợp các user account trên cùng một cùng computer
13. Local groups không thể là thành viên của bất kỳ nhóm nào
14. Local groups có thể chứa local user account của máy tính mà ta tạo ra local groups
15. Dùng local groups để cấp phép đến nguồn tài nguyên nằm trong computer mà local groups được tạo ta
16. Nên giảm tối đa cách lồng nhau, lồng cấo 1 là tốt nhất
17. Thành viên của global groups: chỉ nằm trong domain tạo global group, truy xuất nguồn tài nguyên chi trong một kỳ domain
18. Universal group: opermentship có thể thêm thành viên từ bất kỳ domain nào trong rừng, truy xuất nguồn tài nguyên trong domain bất kỳ
19. Domain local group: opermentship chứa thành viên trong bất kỳ nhóm nào, truy xuất nguồn tài nguyên chỉ trong 1 domain (nơi tạo domain local group)
20. Windows 2003 tạo ra local group trong local security database
21. Windows 2003 tạo các nhóm security tới phạm vi domain local chứa trong folder butin (trong Active User and Computer)


LƯU TRỮ
1. Một đĩa dùng basic storage còn gọi là basic disk
2. Home folder chứa các tiệp riêng cho từng user
3. FAT16 hỗ trợ tất cả HĐH
4. Mọi đĩa vật lý chỉ được phép sử dụng một trong 2 loại là: basic torage hoặc dynamic storage
5. Mỗi partition có thể chia thành nhiều ổ đĩa logic
6. Chỉ có 1 partition có thể là extended partition
7. Primary partition dùng để khởi động máy tính
8. Một trong các primary partition được đánh dấu để trở thành active partition
9. Chỉ có 1 extended partition trên một đĩa cứng
10. Một dynamic disk được chia thành các volume
11. Tổ chức dynamic disk có tốc độ truy xuất nhanh nhất là: striped

Trắc nghiệm MCSA, MCITP, MCTS #1

  •  
     
     
     
    1. 
    What allows businesses to define, manage, access, and secure network resources including files, printers, people, and applications?
    • A. 
      Directory service
    • B. 
      NT directory

  • 2. 
    A __________ is defined as one or more IP subnets that are connected by fast links.
    • A. 
      Domain
    • B. 
      Site

  • 3. 
    What contains the rules and definitions that are used for creating and modifying object classes and attributes within Active Directory?
    • A. 
      Configuration NC
    • B. 
      Schema NC

  • 4. 
    What shared folder exists on all domain controllers and is used to store Group Policy objects, login scripts, and other files that are replicated domain-wide?
    • A. 
      C$
    • B. 
      SYSVOL

  • 5. 
    What new Windows Server 2008 feature is a special installation option that creates a minimal environment for running only specific services and roles?
    • A. 
      Server Core
    • B. 
      Minimal Installation Option

  • 6. 
    What is the minimum amount of storage space required for the Active Directory installation files?
    • A. 
      250 MB
    • B. 
      200 MB

  • 7. 
    When modifying the schema, Microsoft recommends adding administrators to what group only for the duration of the task?
    • A. 
      Global Admins
    • B. 
      Schema Admins

  • 8. 
    When you install the forest root domain controller in an Active Directory forest, the Active Directory Installation Wizard creates a single site named __________.
    • A. 
      Default-First-Site-Name
    • B. 
      Default-Site-Name

  • 9. 
    What command-line tool used for monitoring Active Directory provides functionality that includes performing connectivity and replication tests?
    • A. 
      Dcdiag
    • B. 
      Netdiag

  • 10. 
    When replicating information between sites, Active Directory will designate a __________ server in each site to act as a gatekeeper in managing site-to-site replication.
    • A. 
      Bridgehead
    • B. 
      Masthead

  • 11. 
    What defines a chain of site links by which domain controllers from different sites can communicate?
    • A. 
      Site link chain
    • B. 
      Site link bridge

  • 12. 
    How many FSMO roles does Active Directory support?
    • A. 
      16
    • B. 
      5

  • 13. 
    How many RID Masters can a domain have?
    • A. 
      5
    • B. 
      1

  • 14. 
    What procedure is used only when you have experienced a catastrophic failure of a domain controller that holds a FSMO role and you need to recover that role?
    • A. 
      Role seizure
    • B. 
      Role separation

  • 15. 
    What special identity group contains all authenticated users and domain guests?
    • A. 
      Power Users
    • B. 
      Everyone

  • 16. 
    __________ name refers to each user’s login name.
    • A. 
      SAM account
    • B. 
      AD Name

  • 17. 
    You cannot manually modify the group membership of or view the membership lists of __________ groups.
    • A. 
      Domain local
    • B. 
      Special identity

  • 18. 
    What can be used to add, delete, or modify objects in Active Directory, in addition to modifying the schema if necessary?
    • A. 
      NSLOOKUP
    • B. 
      LDIFDE

  • 19. 
    Which of the following is a benefit of implementing a public key infrastructure (PKI)?
    • A. 
      Users no longer need to remember passwords.
    • B. 
      All information is stored on the smart card, making it difficult for anyone except the intended user to use or access it.

  • 20. 
    What method of authentication requires a smart card and a PIN to provide more secure access to company resources?
    • A. 
      Complex authentication
    • B. 
      Two-factor authentication

  • 21. 
    What dedicated workstation allows an administrator or another authorized user to preconfigure certificates and smart cards on behalf of a user or workstation?
    • A. 
      Smart card enrollment station
    • B. 
      Certification Authority (CA

  • 22. 
    Passwords for Windows Server 2008, Windows Vista, Windows Server 2003, and Microsoft Windows XP clients can be __________ characters in length.
    • A. 
      97
    • B. 
      64
    • C. 
      127
    • D. 
      142

  • 23. 
    What is a method of controlling settings across your network?
    • A. 
      Group Policy
    • B. 
      Active Directory

  • 24. 
    What contains all of the Group Policy settings that you wish to implement to user and computer objects within a site, domain, or OU?
    • A. 
      Group Policies
    • B. 
      Group Policy Settings
    • C. 
      Group Policy Objects

  • 25. 
    What allows the Group Policy processing order to circle back and reapply the computer policies after all user policies and logon scripts run?
    • A. 
      Reverse Processing
    • B. 
      Switchback Processing
    • C. 
      Loopback Processing

  • 26. 
    Local GPO settings are stored in what folder on a computer?
    • A. 
      %systemroot%/System32/GroupPolicy
    • B. 
      %systemroot%/System32/Drivers/GroupPolicy
    • C. 
      %systemroot%/System32/Drivers/Etc/GroupPolicy
    • D. 
      %systemroot%/System/GroupPolicy

  • 27. 
    What policies can be applied to one or more users or groups of users, allowing you to specify a more or less stringent password policy for this subset than the password policy defined for the entire domain?
    • A. 
      Fine-Tuned Password Policies
    • B. 
      Fine-Grained Password Policies
    • C. 
      Restricted Password Policies

  • 28. 
    Where can you configure the Group Policy refresh interval?
    • A. 
      Computer Configuration\\System\\Group Policy
    • B. 
      User Configuration\\Administrative Templates\\System\\Group Policy
    • C. 
      Computer Configuration\\Administrative Templates\\System\\Group Policy
    • D. 
      Computer Configuration\\Administrative Templates\\Group Policy

  • 29. 
    Microsoft Windows Server 2008 uses the Windows Installer with Group Policy to install and manage software that is packaged into what type of file?
    • A. 
      .exe
    • B. 
      .msi
    • C. 
      .mse
    • D. 
      .inf

  • 30. 
    Modifications to .msi files require transform files, which have the __________ extension.
    • A. 
      .msit
    • B. 
      .mse
    • C. 
      .msx
    • D. 
      .mst

  • 31. 
    When configuring Software Restriction policies, which option prevents any application from running that requires administrative rights, but allows programs to run that only require resources that are accessible by normal users?
    • A. 
      Unrestricted
    • B. 
      Restricted
    • C. 
      Basic User
    • D. 
      Disallowed

  • 32. 
    What tab displays groups and users with permission to link, perform modeling analyses, or read Group Policy Results information?
    • A. 
      Linked Group Policy Objects
    • B. 
      Group Policy Inheritance
    • C. 
      Delegation
    • D. 
      Management

  • 33. 
    What setting will prevent policy settings from applying to all child objects at the current level and all subordinate levels?
    • A. 
      Block Policy Propagation
    • B. 
      Block Policy Inheritance
    • C. 
      Remove Policy Inheritance
    • D. 
      Remove Policy Propagation

  • 34. 
    How many WMI filters can be configured per GPO?
    • A. 
      One
    • B. 
      Two
    • C. 
      Three
    • D. 
      Five

  • 35. 
    To perform a System State restore in Windows Server 2008, you will boot the DC into what mode?
    • A. 
      Active Directory Restore
    • B. 
      Active Directory Maintenance
    • C. 
      Directory Services Maintenance
    • D. 
      Directory Services Restore

  • 36. 
    In Windows Server 2008, you must back up __________ rather than only backing up the System State data.
    • A. 
      Critical volumes
    • B. 
      System volumes
    • C. 
      MBR records
    • D. 
      MX records

  • 37. 
    To back up Active Directory, you must install what feature from the Server Manager console?
    • A. 
      Active Directory Backup Client
    • B. 
      Windows Backup Utility
    • C. 
      Windows Server Backup
    • D. 
      BackupExec

  • 38. 
    What is the process by which one DNS server sends a name resolution request to another DNS server?
    • A. 
      Resolution
    • B. 
      Translation
    • C. 
      Referral
    • D. 
      Propagation

  • 39. 
    What DNS server contains no zones and hosts no domains?
    • A. 
      Secondary domain controller
    • B. 
      Global catalog server
    • C. 
      Secondary DNS server
    • D. 
      Caching-only server

  • 40. 
    What Windows Server 2008 service can you use to protect sensitive data on a Windows network?
    • A. 
      AD FS
    • B. 
      AD FTP
    • C. 
      AD FSMO
    • D. 
      AD RMS

  • 41. 
    What enables network administrators and owners to configure access rights for users during the users’ entire lifecycle within an organization?
    • A. 
      Identity Lifecycle Management
    • B. 
      General Lifecycle Management
    • C. 
      Microsoft Lifecycle Management
    • D. 
      Lifecycle of Software Management

  • 42. 
    What are small physical devices on which a digital certificate is installed that are usually the size of a credit card or keychain fob?
    • A. 
      RSA SecureID
    • B. 
      Digital certificates
    • C. 
      Smart cards
    • D. 
      Biometric device

  • 43. 
    What service responds to requests from clients concerning the revocation status of a particular certificate, returning a digitally signed response indicating the certificate’s current status?
    • A. 
      Web Enrollment
    • B. 
      Web Responder
    • C. 
      Enterprise CA
    • D. 
      Online Responder

  • 44. 
    A Windows Server 2008 computer that has been configured with the Active Directory DS role is referred to as a __________.
    • A. 
      Domain controller
    • B. 
      Domain manager
    • C. 
      Global catalog
    • D. 
      DNS server

  • 45. 
    What protocol has become an industry standard that enables data exchange between directory services and applications?
    • A. 
      NTDS
    • B. 
      LDAP
    • C. 
      NDIS
    • D. 
      AD

  • 46. 
    What locator records within DNS allow clients to locate an Active Directory domain controller or global catalog?
    • A. 
      A records
    • B. 
      MX records
    • C. 
      SRV records
    • D. 
      SOA records

  • 47. 
    What is the process of replicating DNS information from one DNS server to another?
    • A. 
      Replication
    • B. 
      DNS push
    • C. 
      Zone transfer
    • D. 
      DNS update

  • 48. 
    What type of trust relationship allows you to create two-way transitive trusts between separate forests?
    • A. 
      Shortcut
    • B. 
      Cross-forest
    • C. 
      External
    • D. 
      Real

  • 49. 
    What type of zone is necessary for computer hostname-to-IP address mappings, which are used for name resolution by a variety of services?
    • A. 
      Primary lookup
    • B. 
      Secondary lookup
    • C. 
      Forward lookup
    • D. 
      Reverse lookup

  • 50. 
    What type of zone is necessary for computer hostname-to-IP address mappings, which are used for name resolution by a variety of services?
    • A. 
      Primary lookup
    • B. 
      Secondary lookup
    • C. 
      Forward lookup
    • D. 
      Reverse lookup

      Xem tại [http://www.proprofs.com/quiz-school/story.php?title=online-exam-practice-for-windows-server-2008-administration-modii-set-a
      ]