Active Directory Users, Groups & Organizational Units Flashcards
7 cards from real MCTS 70-640 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Active Directory Users, Groups & Organizational Units flashcards as text
Which Active Directory group type can be used to assign permissions to resources such as file shares and printers?
Answer: Security group
Only Security groups can be used to control access to resources; Distribution groups are used solely for email distribution and have no security token.
In the AGDLP best-practice model for group nesting, what does the letter 'L' represent?
Answer: Domain Local group
AGDLP stands for Accounts → Global groups → Domain Local groups → Permissions; the 'L' represents Domain Local groups where resource permissions are assigned.
A Global group from DomainA is nested inside a Domain Local group in DomainB. What is the primary benefit of this configuration?
Answer: DomainA users gain access to DomainB resources
Nesting a DomainA Global group into a DomainB Domain Local group follows AGDLP, granting DomainA users access to resources protected by the DomainB Domain Local group.
What must occur before you can convert a Universal security group to a Global group?
Answer: Remove all members from other domains
Global groups can only contain members from their own domain, so any cross-domain members must be removed before converting a Universal group to Global.
Which PowerShell cmdlet is used to create a new group object in Active Directory?
Answer: New-ADGroup
New-ADGroup is the correct PowerShell cmdlet for creating Active Directory group objects, following the standard Verb-ADNoun naming convention.
Which wizard in Active Directory Users and Computers allows an administrator to grant specific administrative permissions over an OU to a designated user or group?
Answer: Delegation of Control Wizard
The Delegation of Control Wizard allows administrators to delegate specific AD tasks over an OU without granting broader domain-level permissions.
At what minimum domain functional level must a domain operate to support Password Settings Objects (PSOs) for fine-grained password policies?
Answer: Windows Server 2008
Fine-Grained Password Policies using PSOs require the domain functional level to be set to Windows Server 2008 or higher.