All Matches
Solution Library
Expert Answer
Textbooks
Search Textbook questions, tutors and Books
Oops, something went wrong!
Change your search query and then try again
Toggle navigation
FREE Trial
S
Books
FREE
Tutors
Study Help
Expert Questions
Accounting
General Management
Mathematics
Finance
Organizational Behaviour
Law
Physics
Operating System
Management Leadership
Sociology
Programming
Marketing
Database
Computer Network
Economics
Textbooks Solutions
Accounting
Managerial Accounting
Management Leadership
Cost Accounting
Statistics
Business Law
Corporate Finance
Finance
Economics
Auditing
Hire a Tutor
AI Tutor
New
Search
Search
Sign In
Register
study help
business
mcitp windows server 2008
Questions and Answers of
Mcitp Windows Server 2008
Click Start, point to Administrative Tools, and then click Server Manager. LO.1
Under Roles Summary, click Add Roles. LO.1
Use the Add Roles Wizard to add the Web Server (IIS) role. LO.1
In Internet Information Services (IIS) Manager, expand the server name in the console tree and, in the server Home page, under IIS, double-click Authentication to open the Authentication page. LO.1
In the Authentication page, right-click Active Directory Client Certificate Authentication, and then choose Enable. LO.1
Enable client authentication for the website that is hosting AD RMS. In IIS Manager, expand the server name in the console tree, expand Sites, and then expand the website that is hosting AD RMS. By
In the console tree, expand _wmcs, right-click either the certification virtual directory(to support RACs) or the licensing virtual directory (to support user licenses), and then choose Switch To
Right-click certification.asmx or license.asmx, as appropriate, and then choose Switch To Features View. LO.1
In the Home page, double-click SSL Settings, and choose the appropriate client certificates setting (Accept or Require).Accept client certificates if you want clients to have the option to supply
Click Apply. If you want to use client authentication for both certification and licensing, repeat this procedure but select the alternate virtual directory the second time. LO.1
Close IIS Manager. If you are using an AD RMS cluster, repeat the procedure for every other server in the cluster.Your next task is to force the authentication method to use Client Certificate
Open an elevated command prompt, and change the directory to %windir%\System32\Inetsrv\Config. LO.1
Enter notepad applicationhost.config and locate the section similar to Default Web Site/_wmcs/Certification/Certification.asmx. LO.1
Add a new line under windowsAuthentication enabled=”true”. In this line, type:clientCertificateMappingAuthentication enabled="true" LO.1
If you want to allow only smart card authentication, ensure that SSL client authentication with IIS is required. Add a new line under windowsAuthentication enabled=”true.”In this line,
Change windowsAuthentication enabled="true"to windowsAuthentication enabled="false" LO.1
Click File, choose Save, and then close Notepad. LO.1
At the command prompt, enter iisreset.Note that running iisreset from a command prompt will restart the services associated with IIS.Again, if you are using an AD RMS cluster, you repeat the
In the Run box, type adsiedit.msc. LO.1
If this is the first time you have used the ADSI Edit console on your test network, rightclick ADSI Edit, and then choose Connect To. Type contoso.internal in the Name box, and then click OK. LO.1
Double-click contoso.internal. LO.1
Double-click DC=contoso,DC=internal. LO.1
Double-click CN=System. LO.1
Right-click CN=Password Settings Container. Choose New. Choose Object, as shown in Figure 4-18.FIGURE 4-18 Creating a password settings object LO.1
In the Create Object dialog box, ensure that msDS-PasswordSettings is selected. Click Next. LO.1
In the Value box for the CN attribute, type PasswdSettings01. Click Next. LO.1
In the Value box for the msDS-PasswordSettingsPrecedence attribute, type LO.1
In the Value box for the msDS-PasswordReversibleEncryptionEnabled attribute, type FALSE. Click Next. LO.1
In the Value box for the msDS-PasswordHistoryLength attribute, type 6. Click Next. LO.1
In the Value box for the msDS-PasswordComplexityEnabled attribute, type TRUE. Click Next. LO.1
In the Value box for the msDS-MinimumPasswordLength attribute, type 6. Click Next. LO.1
In the Value box for the msDS-MinimumPasswordAge attribute, type 1:00:00:00. Click Next. LO.1
In the Value box for the msDS-MaximumPasswordAge attribute, type 20:00:00:00.Click Next. LO.1
In the Value box for the msDS-LockoutThreshold attribute, type 2. Click Next. LO.1
In the Value box for the msDS-LockoutObservationWindow attribute, type 0:00:15:00.Click Next. LO.1
In the Value box for the msDS-LockoutDuration attribute, type 0:00:15:00. Click Next. LO.1
Click Finish. 22. Open Active Directory Users and Computers, choose View, and then choose Advanced Features. LO.1
Expand contoso.internal, expand System, and then select Password Settings Container. LO.1
In the details pane, right-click PasswdSettings01. Choose Properties. LO.1
On the Attribute Editor tab, select msDS-PSOAppliesTo, as shown in Figure 4-19.FIGURE 4-19 Selecting an attribute to edit 26. Click Edit. LO.1
Click Add Windows Account. LO.1
In the Enter The Object Names To Select box, type special_password. Click Check Names. LO.1
Click OK. The Multi-valued Distinguished Name With Security Principal Editor dialog box should look similar to Figure 4-20.FIGURE 4-20 Adding the special_password global security group to PSO1 LO.1
Click OK, and then click OK again to close the PasswdSettings01Properties dialog box. LO.1
Test your settings by changing the password for the Don_Hall account to a noncomplex, six-letter password such as simple. LO.1
You are planning the deployment of an important computer-aided design (CAD)application to a select group of users within your organization. You need to ensure that the application will be removed
What steps should you take to securely deploy the new RODC in Saskatchewan? LO.1
How should you configure delegated authority for the administrator in Saskatchewan? LO.1
What type of servers should be used in the branch offices? LO.1
What type of domain controllers should be used in the branch offices? LO.1
What privileges should the administrators in the branch offices be granted? LO.1
How can you improve security on the operating system and data files that reside on the domain controllers in Syracuse? LO.1
How should you satisfy the need for a stronger password policy for users in Schenectady? LO.1
At a minimum, what technology should you use to meet the need to assemble team websites? LO.1
Which technology should you use to meet the goals for department file shares? How should you meet the requirement to avoid intersite communication for department share queries? LO.1
Which technology should you use to meet the requirement to protect confidential email? LO.1
Which feature should you use to meet the requirement for database servers? LO.1
It is a high priority to deliver current information to employees about the validity of certificates issued to partners. Which method should you use to enable employee computers to check for
Will placing an RODC in the Argentina location meet the requirements? LO.1
Will placing a global catalog server in the Argentina location meet the requirements? LO.1
Will using a hybrid AD DS replication topology meet the requirements? LO.1
Will using a hub and spoke AD DS replication topology meet the requirements? LO.1
Will creating a new organizational forest for Wingtip Toys meet the requirements? LO.1
Will joining the Wingtip Toys computers to the existing Tailspin Toys forest meet the requirements? LO.1
You have a single AD DS forest with a single domain that is using the hub and spoke replication topology. Where should you place the server that holds the PDC emulator operations master role?A. In
Which replication topology would you use if your network consists of faster network connections between major computing hubs and slower links connecting branch offices?A. Single site model B. Ring
Which of the following uses intrasite replication only?A. Single site model B. Multiple sites model C. Hub and spoke replication topology D. Full mesh replication topology LO.1
Where will RODCs be placed as part of the design?An RODC will be placed in the Argentina location because of the lack of physical security in this location. LO.1
Where will global catalog servers be placed as part of the design?Global catalog servers are required in each location except the Argentina location because of the lack of physical security there.
Where will the regional domain controllers be placed as part of the design?The placement of regional domain controllers for the remote offices will be as follows:■ The domain controllers for the
Where will the forest root domain controllers be placed as part of the design?The forest root domain controllers will be placed in the U.S. location. This is the only location that has users for the
What will the replication schedule design be for each site link?The replication schedule design for each site link will be as follows:The U.S.–Canada site link will have a default replication
What will the cost of each site link be?There are no requirements to have diverse costs on the site links. Therefore, the cost of each site link can remain at the default of 100. LO.1
Which site links are required to facilitate the replication design?The following site links are required for the replication design:U.S.–Canada U.S.–Mexico U.S.–Italy Argentina–Mexico LO.1
Which replication topology will be used for the replication design?The hub and spoke replication topology will be used for the replication design. It’s best suited for this design because the
Log on to your client computer, Melbourne, on the contoso.internal domain by using the Kim_Akers account. LO.1
From Control Panel, access Network And Sharing Center. If you are not using Classic View, first click Network And Internet, and then click Network And Sharing Center.Click Change Adapter Settings.
Right-click the interface that connects to your private network and choose Properties. LO.1
If a UAC dialog box appears, click Continue. LO.1
Select Internet Protocol Version 6 (TCP/IPv6) and click Properties. LO.1
Configure a static site-local IPv6 address, fec0:0:0:fffe::a. LO.1
Configure a DNS server address, fec0:0:0:fffe::1. The Properties dialog box should look similar to Figure 1-16. LO.1
Click OK. Close the Local Area Connections Properties dialog box. LO.1
Close the Network Connections dialog box. LO.1
Close Network And Sharing Center.NOTE VIRTUAL MACHINES If you are using a virtual machine to implement your server and client on the same computer, it is a good idea to close your virtual machine and
Open the command console on the client computer. Enter ping fec0:0:0:fffe::1. You should get the response from the domain controller shown in Figure 1-17.FIGURE 1-17 Pinging the domain controller
Enter ping glasgow. Note that the domain controller hostname resolves to the IPv6 address. LO.1
Log off from the client computer. LO.1
Log on to your domain controller, using the Kim_Akers account. LO.1
Open the command console on your domain controller. LO.1
Enter ping fec0:0:0:fffe::a. You should get the response shown in Figure 1-18. LO.1
Enter netsh interface ipv6 show neighbors. Figure 1-19 shows the fec0:0:0:fffe::a interface as a neighbor on the same subnet as the domain controller.FIGURE 1-19 Showing the domain controller
If necessary, log on to the domain controller by using the Kim_Akers account. LO.1
If the Initial Configuration Tasks window opens when you log on, click Add Roles.Otherwise, from Administrative Tools, open Server Manager, right-click Roles in the console tree, and choose Add
The Add Roles Wizard starts. If the Before You Begin page appears, click Next. LO.1
Select the DHCP Server check box, as shown in Figure 1-20, and click Next. On the Introduction To DHCP Server page, click Next. LO.1
On the Select Network Connection Bindings page, ensure that only the 10.0.0.11 IPv4 interface check box is selected for DHCP. Click Next. LO.1
On the Specify IPv4 DNS Server Settings page, verify that the domain is contoso.internal and the Preferred DNS Server IPv4 Address is 10.0.0.11. Click Next. LO.1
On the Specify IPv4 WINS Settings page, verify that WINS Is Not Required For Applications On This Network is selected. Click Next. LO.1
On the Add Or Edit DHCP Scopes page, you can define only IPv4 scopes, so the scope list should be empty. Click Next. LO.1
Showing 1 - 100
of 123
1
2