Windows Server 2008 Active Directory Flashcards
7 cards from real MCTS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Windows Server 2008 Active Directory flashcards as text
An administrator needs to delegate control of an OU to a junior admin so they can reset passwords only. What is the best approach?
Answer: Use the Delegation of Control Wizard on the OU
The Delegation of Control Wizard allows granular permission delegation on OUs without granting broad administrative rights.
Which protocol does Active Directory use for directory queries and authentication by default?
Answer: LDAP
Active Directory uses LDAP (Lightweight Directory Access Protocol) on port 389 (or 636 for LDAPS) for directory queries and authentication.
What is a 'shortcut trust' in Active Directory used for?
Answer: Speeding up authentication between specific domains in a large forest
Shortcut trusts optimize the authentication path between specific domains within the same forest, reducing traversal through the trust hierarchy.
Which Windows Server 2008 feature allows you to install only the Active Directory components needed, without a full GUI, to reduce the attack surface?
Answer: Server Core installation
Server Core is a minimal Windows Server 2008 installation option that provides essential server roles without the full GUI, reducing the attack surface.
When a Group Policy Object (GPO) is linked to both a site and an OU, and they have conflicting settings, which GPO takes precedence by default?
Answer: OU GPO takes precedence over site GPO
GPOs are applied in LSDOU order (Local, Site, Domain, OU), so OU-linked GPOs are applied last and override conflicting settings from site or domain GPOs.
What is the purpose of the 'Infrastructure Master' FSMO role in Active Directory?
Answer: Updates cross-domain object references for group memberships
The Infrastructure Master updates references to objects in other domains (such as group memberships that span domains) to keep them current.
Which utility is used to perform an authoritative restore of Active Directory objects from backup?
Answer: Ntdsutil
Ntdsutil is used after a non-authoritative restore to mark specific objects as authoritative, ensuring they replicate to all other domain controllers.