Active Directory Users, Groups & Organizational Units Flashcards
7 cards from real MCTS 70-640 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Active Directory Users, Groups & Organizational Units flashcards as text
What is the primary purpose of an Organizational Unit (OU) in Active Directory?
Answer: To organize objects and delegate administrative control
OUs serve two main purposes: logically organizing directory objects and enabling granular delegation of administrative control without granting domain-wide rights.
Which command-line tool is used to move an Active Directory user object from one OU to another?
Answer: DSMOVE
DSMOVE is the directory service command used to move or rename Active Directory objects, including relocating users between OUs.
When multiple GPOs are linked to the same OU, what determines the order in which they are processed?
Answer: Link order configured in GPMC
The link order set in the Group Policy Management Console determines GPO precedence; higher link order numbers are processed first, with lower numbers (higher priority) applied last.
What is the effect of disabling a user account in Active Directory?
Answer: The user cannot log on but the account and memberships remain intact
Disabling an account prevents authentication while preserving all account attributes, group memberships, and permissions, allowing easy re-enablement when needed.
What is the primary function of the 'Manager' attribute on an Active Directory user object?
Answer: Stores an informational reference enabling the Direct Reports list
The Manager attribute is informational, linking a user to their manager's AD account and enabling the Direct Reports view in tools like Outlook and the Address Book.
Which Active Directory feature enables different password and lockout policies for different users or groups within a single domain?
Answer: Fine-Grained Password Policy
Fine-Grained Password Policies, configured via Password Settings Objects (PSOs), allow multiple password policies within one domain — overcoming the single-policy-per-domain limitation.
Which file format does the LDIFDE tool use when importing or exporting Active Directory objects?
Answer: LDIF (LDAP Data Interchange Format)
LDIFDE uses the LDAP Data Interchange Format (LDIF), a standard text format for representing directory entries that supports complex operations like adds, modifies, and deletes.