โ† All MCM Flashcard Decks

Active Directory Flashcards

7 cards from real MCM practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Active Directory flashcards as text
  1. Which attribute in Active Directory stores the Kerberos principal name used for service authentication?

    Answer: servicePrincipalName

    The servicePrincipalName (SPN) attribute links a service to the account under which it runs, enabling Kerberos service ticket issuance.

  2. What is the effect of enabling 'Enforce password history' to 24 passwords in a Default Domain Policy?

    Answer: Users cannot reuse any of their last 24 passwords

    Setting password history to 24 prevents users from reusing any of their previous 24 passwords when they change their password.

  3. In a multi-domain AD forest, which type of group can contain members from any domain in the forest and be used to assign permissions in any domain?

    Answer: Universal group

    Universal groups can contain members from any domain in the forest and can be assigned permissions in any domain, making them ideal for forest-wide access.

  4. Which AD DS feature introduced in Windows Server 2012 allows read-only domain controllers to cache credentials for specific users?

    Answer: Password Replication Policy

    The Password Replication Policy (PRP) on RODCs controls which users' credentials are cached locally, limiting exposure if the RODC is compromised.

  5. What is the default interval for intra-site Active Directory replication after a change is made?

    Answer: 15 seconds

    By default, intra-site replication is triggered within 15 seconds of a change through the urgent replication notification mechanism between replication partners.

  6. Which PowerShell cmdlet can be used to check the replication status of all domain controllers in a forest?

    Answer: Get-ADReplicationFailure

    Get-ADReplicationFailure returns replication failure information for domain controllers, showing errors and their counts across the environment.

  7. What does the 'Protected Users' security group in Windows Server 2012 R2 and later prevent its members from using?

    Answer: NTLM, DES, RC4 Kerberos, and credential delegation

    Members of the Protected Users group cannot authenticate via NTLM, use DES or RC4 Kerberos encryption, use unconstrained delegation, or have credentials cached.