MCSE真题11月70-217新增考题
A. Configure the Default Domain Group Policy object (GPO) to disable the Routing and Remote access service.
B. Create a remote access policy that allows only approved routing and remote access servers to establish connections.
C. Configure the Default Domain Group Policy object (GPO) to proibit the configuration of connection sharing.
D. Configure the default domain group policy object (GPO) to prohibit the connecting and disconnecting of a remote access connection.
4.You are the administrator of your company’s network. The network consists of a single DNS domain. A windows NT server 4.0 computer named server1 hosts the primary DNS zone for the domain.
You install a new wndows 2000 server computer named server2 to function as the first domain controller in the network. Server2 contains a secondary zone for the domain. During the installation of active directory, you choose to manually update DNS so that it contains the Active directory resource records. You need to import these records from server2 into DNS.
What should you do?
A. Import the contents of the Netlogon.dns file to the standard primary zone file on server1, and then restart the DNS server service on both servers.
B. Import the contents of the Netlogon.dns file to the standard secondary zone file on server2, and then restart the DNS server service on both servers.
C. Import the contents of the root.dns file to the standard primary zone.file on Server1,and then restart the Net Logon service on Both servers.
D. Import the contents of the Root dns file to the standard secondary zone file on Server2,and then restart the Net logon service on both servers.
5.You are the administrator of your company’s windows 2000 network. The network contains 10 windows 2000 server computers. You need to create a strict network security policy . You create a security template named Hisecsrvr.inf
A. Schedule the secedit/analyze/DB config.sdb/CFG hisecsrvr.inf/quiet command and the secedit/configure /DB config.sdb /quiet command to run on each server.
B. In the local security policy on each server, export the local policy settings to the Hisecsrvr.inf file. And then move the template to the %systemroot%\system32\secunty folder on each server.
C. Schedule the poledit/analyze /DB config.sdb /CFG hisecsrvr.inf/quiet command and the poledit/configure /DB config.sdb /quiet command to run on each server.
D. In the Local security Policy on each server,export the effective policy settings to the Hisecsrvr.inf file, and then move the template to the %systemroot%\system32\security folder on each serve.
6. You are the administrator of a windows 2000 network. Your network consists of five sites in one domain. The Chicago.Los Angeles, and New York sites will have DNS running on their domain controllers. Miami and Seattle will have DNS running on dedicated member servers.
You want to allow client computers in the Chicago, Los Angeles, and New York sites to perform secure dynamic updates to the DNS servers. You want to configure your DNS servers so that each site has a replicated copy of the DNS zone.
What should you do?
To answer, click the select and place button, and then drag the appropriate zone type to each site.(Note: zone types can be used more than once.)