Microsoft Certified Systems Engineer (MCSE) — Questions and Answers
Question 1: Which of the following could become an issue with automatic Windows updates?
- Automatic update download speeds are slower than manual update download speeds.
- The server may not receive the updates properly
- Some updates require the server to restart upon completion (Correct answer)
- The updates are often corrupted files
Correct answer: Some updates require the server to restart upon completion
Updates that necessitate a server restart run the risk of disrupting access to the service and lowering availability.
Question 2: A Windows Server 2003 DHCP server is not responding to client requests. You run 'netsh dhcp server show scope' and see the scope is active. What is the MOST likely cause?
- The DHCP server is not authorized in Active Directory (Correct answer)
- The default gateway is misconfigured on the scope
- The DNS server is offline
- The scope has no exclusion ranges defined
Correct answer: The DHCP server is not authorized in Active Directory
In an Active Directory environment, DHCP servers must be authorized; an unauthorized server silently drops all DCHP requests.
Question 3: Which of the following represents the appropriate amount of time for the client to send its initial DHCP Renewal message?
- 50% of lease duration (Correct answer)
- Immediately after receiving the lease
- 85% of lease duration
- After lease expiry
Correct answer: 50% of lease duration
In the DHCP (Dynamic Host Configuration Protocol) lease process, the first DHCP Renewal message is typically sent by the client when the lease is halfway through its duration. Therefore, if we consider the lease duration as a fixed time period, the client will send the first DHCP Renewal message when 50% of that lease duration has elapsed.
Question 4: Which of the following will assist Windows Server 2003 defragment the hard drive on a DC?
- Restarting the DC in DS Restore mode and using zip db.
- Running Scandisk on the DC
- Running a defragment tool on the DC
- Restarting the DC in DS Restore mode and using compact db. (Correct answer)
Correct answer: Restarting the DC in DS Restore mode and using compact db.
Make sure the stated DC is not active. Use the compress db argument in the ntdsutil command to restart the DC in DS Restore mode.
Question 5: What Active Directory partition is replicated to all domain controllers in the entire forest?
- Domain partition
- Schema partition (Correct answer)
- Application partition
- Configuration partition
Correct answer: Schema partition
The schema partition contains the blueprint of all Active Directory objects and is replicated to every domain controller in the forest.
Question 6: You configure a Windows Server 2003 DNS server to forward unresolved queries to your ISP's DNS servers. However, you want the server to attempt root hints resolution if all forwarders fail. Which setting achieves this?
- Enable 'Do not use recursion for this domain' is unchecked (allow fallback to root hints) (Correct answer)
- Configure conditional forwarding for the '.' (root) zone
- Add the ISP DNS IPs as additional root hints entries
- Set the forwarder timeout to 0 seconds
Correct answer: Enable 'Do not use recursion for this domain' is unchecked (allow fallback to root hints)
When 'Do not use recursion for this domain' is unchecked on the Forwarders tab, Windows DNS falls back to root hints if all configured forwarders are unreachable.
Question 7: You are planning a Windows Server 2003 environment for a company with 500 users. Which server role should you deploy to centrally manage software updates across all client computers?
- Systems Management Server (SMS)
- Group Policy Software Installation
- Software Update Services (SUS) (Correct answer)
- Windows Update
Correct answer: Software Update Services (SUS)
Software Update Services (SUS) is the Microsoft solution for centrally managing and distributing Windows updates to client computers in a managed environment.
Question 8: What does enabling 'Restrict CD-ROM access to locally logged-on user only' accomplish in Windows Server 2003?
- Prevents network users from accessing the local CD-ROM drive (Correct answer)
- Encrypts all data written to CD-ROM
- Audits all CD-ROM access attempts
- Disables AutoRun for CD-ROM drives
Correct answer: Prevents network users from accessing the local CD-ROM drive
This security setting ensures that only the user physically logged on at the console can access the CD-ROM, preventing remote users from reading sensitive media.
Question 9: Which feature of Windows Server 2003 IPSec allows you to require encryption for all traffic between two specific servers?
- Windows Firewall with exceptions
- TCP/IP filtering
- Network Monitor capture filter
- IPSec policy with Require Security rule (Correct answer)
Correct answer: IPSec policy with Require Security rule
An IPSec policy configured with a 'Require Security' action mandates that all communications matching the filter rule use encrypted, authenticated IPSec connections.
Question 10: What is the purpose of the Resultant Set of Policy (RSoP) tool in Windows Server 2003?
- Tests firewall rule effectiveness
- Creates new Group Policy Objects
- Displays the effective Group Policy settings applied to a user or computer (Correct answer)
- Analyzes IPSec security associations
Correct answer: Displays the effective Group Policy settings applied to a user or computer
RSoP shows the net result of all GPOs applied to a user or computer, factoring in inheritance, filtering, and precedence, useful for troubleshooting policy application.
Question 11: What design consideration makes a hub-and-spoke Active Directory site topology preferable over a full mesh?
- Reduced number of replication connections in large site environments (Correct answer)
- Support for more than 100 sites
- Faster replication convergence
- Automatic failover when the hub goes down
Correct answer: Reduced number of replication connections in large site environments
A hub-and-spoke topology reduces the number of site link objects and replication connections needed, simplifying management in large multi-site environments.
Question 12: Which Windows Server 2003 service must be running for IPSec policy to be applied to network traffic?
- Security Accounts Manager
- Remote Registry
- IPSec Policy Agent (IPSECPOL) (Correct answer)
- Windows Management Instrumentation
Correct answer: IPSec Policy Agent (IPSECPOL)
The IPSec Policy Agent service (also called IPSECPOL or PolicyAgent) retrieves and enforces IPSec policies on the local computer.
Question 13: A Windows Server 2003 VPN server must support both PPTP and L2TP/IPSec clients simultaneously. Which firewall ports must be open for PPTP to function correctly?
- TCP 1723 and GRE (IP Protocol 47) (Correct answer)
- TCP 443 and UDP 4500
- TCP 1723 and UDP 500
- UDP 1701 and ESP (IP Protocol 50)
Correct answer: TCP 1723 and GRE (IP Protocol 47)
PPTP uses TCP port 1723 for the control channel and GRE (IP Protocol 47) for encapsulated data tunnels.
Question 14: Which Windows Server 2003 service is responsible for dynamic registration of DNS records for domain-joined computers?
- Computer Browser service
- DNS Server service
- Netlogon service (Correct answer)
- DHCP Client service
Correct answer: Netlogon service
The Netlogon service registers domain controller SRV records and client A records in DNS during domain join and startup.
Question 15: What is the default site link cost in Active Directory Sites and Services?
- 50
- 100 (Correct answer)
- 1
- 200
Correct answer: 100
The default cost for a new site link in Active Directory Sites and Services is 100; lower cost links are preferred for replication.
Question 16: What is the effect of setting the LAN Manager Authentication Level to 'Send NTLMv2 response only. Refuse LM & NTLM'?
- Disables all network authentication
- Enables Kerberos for legacy systems
- Allows only smart card logon
- Forces all authentication to use NTLMv2, blocking weaker LM and NTLM protocols (Correct answer)
Correct answer: Forces all authentication to use NTLMv2, blocking weaker LM and NTLM protocols
This setting maximizes NTLM security by refusing the weaker LM and NTLMv1 authentication protocols, requiring all clients to use NTLMv2.
Question 17: You suspect that an attacker is performing repeated failed logon attempts against a service account. Which policy should you configure to limit this?
- Account Lockout Policy: Account lockout threshold (Correct answer)
- Audit Policy: Audit account logon events
- User Rights Assignment: Deny logon locally
- Password Policy: Minimum password length
Correct answer: Account Lockout Policy: Account lockout threshold
The Account Lockout Threshold setting locks an account after a specified number of consecutive failed logon attempts, blocking brute-force attacks.
Question 18: DHCPACK is used to notify a client when a renewal request is being declined by the DHCP.
- True
- False (Correct answer)
Correct answer: False
The DHCP notifies a client when it rejects their request for renewal by sending them a negative acknowledgment.
Question 19: Which DNS record type is responsible for defining the mail servers that accept email for a domain?
- NS (Name Server)
- TXT (Text)
- MX (Mail Exchanger) (Correct answer)
- SRV (Service Locator)
Correct answer: MX (Mail Exchanger)
MX records specify the hostname(s) of mail servers responsible for accepting SMTP email for a domain, along with their preference values.
Question 20: A user reports they cannot access a shared folder on a Windows Server 2003 member server. NTFS permissions grant the user Read access, but Share permissions are set to Everyone: Full Control. What is the effective permission?
- Full Control
- No Access
- Write
- Read (Correct answer)
Correct answer: Read
When accessing resources over the network, the effective permission is the most restrictive combination of NTFS and Share permissions; here, NTFS Read is more restrictive than Share Full Control, so the result is Read.
Question 21: Which certificate type is required for EFS recovery agents in a Windows Server 2003 PKI environment?
- SSL/TLS Server certificate
- EFS Recovery Agent certificate (Correct answer)
- Computer certificate
- Code Signing certificate
Correct answer: EFS Recovery Agent certificate
The EFS Recovery Agent certificate grants designated accounts the ability to decrypt EFS-protected files if the original encrypting user's key is lost.
Question 22: You need to move a user account from OU=Sales to OU=Marketing within the same domain. Which tool provides the simplest method?
- Ldifde export and reimport
- Delete and recreate the account
- Use Dcpromo to rebuild the OU structure
- Drag and drop in Active Directory Users and Computers (Correct answer)
Correct answer: Drag and drop in Active Directory Users and Computers
In Active Directory Users and Computers, you can simply drag a user object from one OU to another or right-click and select Move.
Question 23: You are planning the migration of a Windows NT 4.0 WINS infrastructure to Windows Server 2003. During the transition, both WINS servers will coexist. What must you configure to ensure WINS database consistency?
- Configure replication partnerships between the NT 4.0 and Server 2003 WINS servers (Correct answer)
- Export the NT 4.0 WINS database and import it into Server 2003 WINS
- Configure all clients to use both WINS servers simultaneously
- Promote the Server 2003 WINS server to primary and demote the NT 4.0 server
Correct answer: Configure replication partnerships between the NT 4.0 and Server 2003 WINS servers
Configuring WINS replication partnerships between the two servers ensures that registrations on either server are replicated to the other during coexistence.
Question 24: What security measure does Smart Card logon provide that standard password authentication does not?
- Two-factor authentication requiring physical possession of the card (Correct answer)
- Automatic session timeout
- Prevention of all phishing attacks
- Faster logon processing
Correct answer: Two-factor authentication requiring physical possession of the card
Smart card logon implements two-factor authentication by requiring both the physical smart card and a PIN, making credential theft much harder.
Question 25: When designing a VPN solution for remote access, which protocol provides the strongest security using SSL/TLS?
- PPTP
- IPSec tunnel mode
- L2TP
- SSTP (Correct answer)
Correct answer: SSTP
SSTP (Secure Socket Tunneling Protocol) uses SSL/TLS over port 443, making it highly firewall-friendly and providing strong encryption.
Question 26: A remote user connecting via L2TP/IPSec reports authentication failures even though their credentials are correct. The VPN server logs show IKE negotiation failures. What should you check first?
- Whether the remote access policy grants the correct hours of access
- Whether PPTP port 1723 is open on the firewall
- Whether machine certificates are installed on both client and server (Correct answer)
- Whether the user account dial-in permission is set to Allow
Correct answer: Whether machine certificates are installed on both client and server
L2TP/IPSec requires machine certificates for IKE authentication; missing or mismatched certs cause IKE negotiation to fail.
Question 27: UNIX-based DHCP servers cannot be set up in the network once Active Directory has been implemented. T/F?
- False (Correct answer)
- True
Correct answer: False
In the Active Directory system, Windows-based and UNIX-based DHCP servers coexist.
Question 28: When sizing a domain controller for a branch office, which factor is MOST important to consider?
- Number of users and logon frequency (Correct answer)
- Monitor resolution
- Disk color and form factor
- UPS battery capacity
Correct answer: Number of users and logon frequency
The number of concurrent users and how frequently they authenticate directly determines the CPU, memory, and network load a branch office DC must handle.
Question 29: You need to enable DNS dynamic updates for a Windows Server 2003 DNS zone but want to restrict updates to only domain-joined computers authenticated in Active Directory. Which zone type supports this requirement?
- Stub zone with dynamic updates enabled
- Active Directory-integrated zone with secure dynamic updates (Correct answer)
- Secondary zone configured to accept updates
- Primary zone with dynamic updates enabled
Correct answer: Active Directory-integrated zone with secure dynamic updates
Active Directory-integrated zones with secure dynamic updates only allow authenticated computers to register or update DNS records.
Question 30: Which Windows Server 2003 feature allows administrators to restrict which software can run on a computer?
- Windows Defender
- AppLocker
- Software Restriction Policies (Correct answer)
- DEP (Data Execution Prevention)
Correct answer: Software Restriction Policies
Software Restriction Policies use rules based on certificate, hash, path, or zone to control which applications are allowed or denied from running.
Microsoft Certified Systems Engineer (MCSE)
The MCSE certification validates expertise in designing, implementing, and administering Microsoft Windows Server 2003 network infrastructure, Active Directory, and security environments. It requires passing a series of exams covering networking, server administration, infrastructure design, and security.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds