MCSE真題:11月70-217新增考題

  1.you are the network administrator for blue sky airlines. you are implementing a windows 2000 network consisiting of five sites in the blueskyairlines.com domain.
there are 15.000 users in chicago, 5.000 users in los angles; 2.000 users in miami, 10.000 users in new york, and 2.000 users in seattle. you are designing the structure of the dns servers. you want to allow secure dynamic updates to dns in chicago,los angeles, and new york, you want full dns replication to occur in all the sites. you do not want the miami site to have an editable copy of the dns zone.
how should you configure the dns servers to accomplish these goals?
to answer, click the select and place button, and then drag the letter indicating the appropriate server type to each site.next drag the number indicating the appropriate zone type to each site. two sites have been partially completed for you.(notes. zone types and server types can be used more than once.)
 
2. your company’s network consists of two windows 2000 domains:contoso.com and newyork.contoso.com. the newyork.contoso.com domain contains three organizational units(ous):sales,marketing,and finance. you are a member of the domain admins group in newyork.contoso.com.
an employee named maria can reset passwords for the finance ou.maria will be moving to the sales ou and no longer needs access to the finance ou.
a. in the delegation of control wizard. specify that maria cannot reset passwords for the domain controller to which maria’s user account authenticates.
b. clear the trust computer for delegation check box in the properties for the domain controller to which maria’s user account authenticates.
c. in the security properties of the finance ou, remove maria’s right to reset passwords.
d. copy maria’s user account to sales ou.and then delete the account.

3. you are the administrator of your company’s windows 2000 network. the network consists of a single domain,which contains all company user and computer accounts.
a new corporate policy states that no employees can have access to the network by means of connections. you discover that some employees have configured their windows 2000 computes as remote access servers.
you want to ensure that employees cannot configure their computers to use rouing and remote access. what should you do first?
a. configure the default domain group policy object (gpo) to disable the routing and remote access service.
b. create a remote access policy that allows only approved routing and remote access servers to establish connections.
c. configure the default domain group policy object (gpo) to proibit the configuration of connection sharing.
d. configure the default domain group policy object (gpo) to prohibit the connecting and disconnecting of a remote access connection.
4.you are the administrator of your company’s network. the network consists of a single dns domain. a windows nt server 4.0 computer named server1 hosts the primary dns zone for the domain.
you install a new wndows 2000 server computer named server2 to function as the first domain controller in the network. server2 contains a secondary zone for the domain. during the installation of active directory, you choose to manually update dns so that it contains the active directory resource records. you need to import these records from server2 into dns.
what should you do?
a. import the contents of the netlogon.dns file to the standard primary zone file on server1, and then restart the dns server service on both servers.
b. import the contents of the netlogon.dns file to the standard secondary zone file on server2, and then restart the dns server service on both servers.
c. import the contents of the root.dns file to the standard primary zone.file on server1,and then restart the net logon service on both servers.
d. import the contents of the root dns file to the standard secondary zone file on server2,and then restart the net logon service on both servers.

5.you are the administrator of your company’s windows 2000 network. the network contains 10 windows 2000 server computers. you need to create a strict network security policy . you create a security template named hisecsrvr.inf
a. schedule the secedit/analyze/db config.sdb/cfg hisecsrvr.inf/quiet command and the secedit/configure /db config.sdb /quiet command to run on each server.
b. in the local security policy on each server, export the local policy settings to the hisecsrvr.inf file. and then move the template to the %systemroot%\system32\secunty folder on each server.
c. schedule the poledit/analyze /db config.sdb /cfg hisecsrvr.inf/quiet command and the poledit/configure /db config.sdb /quiet command to run on each server.
d. in the local security policy on each server,export the effective policy settings to the hisecsrvr.inf file, and then move the template to the %systemroot%”\system32\security folder on each serve.
6. you are the administrator of a windows 2000 network. your network consists of five sites in one domain. the chicago.los angeles, and new york sites will have dns running on their domain controllers. miami and seattle will have dns running on dedicated member servers.
you want to allow client computers in the chicago, los angeles, and new york sites to perform secure dynamic updates to the dns servers. you want to configure your dns servers so that each site has a replicated copy of the dns zone.
what should you do?
to answer, click the select and place button, and then drag the appropriate zone type to each site.(note: zone types can be used more than once.)


1.you are the network administrator for blue sky airlines. you are implementing a windows 2000 network consisiting of five sites in the blueskyairlines.com domain.
there are 15.000 users in chicago, 5.000 users in los angles; 2.000 users in miami, 10.000 users in new york, and 2.000 users in seattle. you are designing the structure of the dns servers. you want to allow secure dynamic updates to dns in chicago,los angeles, and new york, you want full dns replication to occur in all the sites. you do not want the miami site to have an editable copy of the dns zone.
how should you configure the dns servers to accomplish these goals?
to answer, click the select and place button, and then drag the letter indicating the appropriate server type to each site.next drag the number indicating the appropriate zone type to each site. two sites have been partially completed for you.(notes. zone types and server types can be used more than once.)
 
2. your company’s network consists of two windows 2000 domains:contoso.com and newyork.contoso.com. the newyork.contoso.com domain contains three organizational units(ous):sales,marketing,and finance. you are a member of the domain admins group in newyork.contoso.com.
an employee named maria can reset passwords for the finance ou.maria will be moving to the sales ou and no longer needs access to the finance ou.
a. in the delegation of control wizard. specify that maria cannot reset passwords for the domain controller to which maria’s user account authenticates.
b. clear the trust computer for delegation check box in the properties for the domain controller to which maria’s user account authenticates.
c. in the security properties of the finance ou, remove maria’s right to reset passwords.
d. copy maria’s user account to sales ou.and then delete the account.