Microsoft MCSE: 70-291 Flashcards
7 cards from real MCSE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Microsoft MCSE: 70-291 flashcards as text
You need to delegate administrative control of a specific DNS zone to a junior administrator without giving them rights to other zones or the DNS server configuration. What is the correct approach?
Answer: Add the user to the DnsAdmins group for that zone's security descriptor only via the zone's ACL
DNS zones stored in AD or as files have individual security descriptors; granting write access at the zone ACL level limits the user to that specific zone.
A DHCP scope has the address range 192.168.1.1-192.168.1.254 with a /24 subnet mask. Several servers in this range have static IPs. How do you prevent DHCP from assigning those static addresses to clients?
Answer: Create exclusion ranges covering each server's static IP address
Exclusion ranges tell the DHCP server to skip specific addresses within the scope when allocating leases to clients.
You need to configure a Windows Server 2003 RAS server to assign IP addresses from a static pool rather than from a DHCP server. Where do you configure this?
Answer: RRAS server Properties > IP tab > Static address pool
The RRAS server's IP tab in its Properties dialog allows you to define a static pool of IP addresses assigned to remote clients instead of using DHCP.
Which DNS record type is responsible for defining the mail servers that accept email for a domain?
Answer: MX (Mail Exchanger)
MX records specify the hostname(s) of mail servers responsible for accepting SMTP email for a domain, along with their preference values.
During a network audit you discover that a Windows Server 2003 RRAS server is accepting connections from dial-up clients using PAP. This is a security risk. Without disrupting L2TP/IPSec clients, how do you disable PAP?
Answer: Uncheck PAP in the remote access policy Profile Authentication tab that applies to dial-up clients
Authentication methods are controlled per remote access policy profile, so unchecking PAP in the dial-up policy leaves L2TP/IPSec policies untouched.
You want Windows Server 2003 to automatically register its A and PTR records in DNS. The DNS zone does not allow unauthenticated dynamic updates. What must be true for dynamic registration to succeed?
Answer: The server must be joined to the domain and the zone must accept secure-only dynamic updates with the computer account having write permission
Secure dynamic updates require the computer to be domain-joined; its machine account authenticates via Kerberos to write records in the AD-integrated zone.
A Windows Server 2003 network uses both WINS and DNS. A client queries DNS for a host named 'fileserver' and gets NXDOMAIN, but WINS resolves it correctly. What DNS configuration allows DNS to fall back to WINS for unresolved single-label names?
Answer: Enable WINS lookup on the DNS zone's WINS tab by specifying the WINS server IP
The WINS tab on a DNS forward lookup zone enables DNS-to-WINS integration, causing the DNS server to query WINS when a name is not found in DNS.