โ† All MCTS Flashcard Decks

Windows Server 2008 Active Directory Flashcards

7 cards from real MCTS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Windows Server 2008 Active Directory flashcards as text
  1. A Read-Only Domain Controller (RODC) is deployed in a branch office. Which of the following is true about password caching on an RODC?

    Answer: No passwords are cached unless explicitly allowed by the Password Replication Policy

    By default, RODCs do not cache passwords; administrators must explicitly configure the Password Replication Policy to allow specific accounts to be cached.

  2. What is the minimum forest functional level required to use Active Directory Federation Services (AD FS) with claims-based authentication in Windows Server 2008?

    Answer: Windows Server 2008

    AD FS with full claims-based authentication features requires the Windows Server 2008 forest functional level at minimum.

  3. Which command-line tool can be used to join a Server Core installation to an Active Directory domain?

    Answer: netdom join

    The 'netdom join' command is used to join a computer to a domain from the command line, including on Server Core installations.

  4. An administrator wants to prevent a specific GPO from applying to members of the 'Executives' security group in an OU. Which method should be used?

    Answer: Set 'Deny Apply Group Policy' permission for the Executives group on the GPO

    Setting 'Deny Apply Group Policy' permission for a security group on a GPO prevents that GPO from applying to members of that group.

  5. What is the default tombstone lifetime for deleted Active Directory objects in Windows Server 2008?

    Answer: 180 days

    Windows Server 2008 increased the default tombstone lifetime to 180 days (from 60 days in earlier versions) to support longer disconnected domain controller scenarios.

  6. Which Active Directory object type represents a collection of computers, users, or other groups that can be assigned permissions or used for email distribution?

    Answer: Group

    Active Directory Groups are used to organize users, computers, and other groups for permission assignment and, as distribution groups, for email.

  7. When demoting a domain controller using dcpromo, what happens if the domain controller being demoted is the last DC in the domain?

    Answer: The domain is deleted and all objects in it are removed

    Demoting the last DC in a domain with dcpromo /forceremoval deletes the domain and all its objects from the forest.