& Windows Server Administration – Real
Exam Questions with Verified Solutions |
GPOs, AD FS, AD RMS, PKI, Replication, &
Domain Controllers
Complete Q&A with Rationales for Windows
Server & AD Certification Success
SECTION A: GROUP POLICY OBJECTS (GPOs) (Questions 1-
30)
Question 1
You have configured new account policies in a GPO and linked it
to an OU containing user accounts. However, you find that the
account policies are not working. What is the issue?
A) The GPO is blocked from inheritance
B) The GPO is not linked to the domain
,C) The GPO was not replicated to all domain controllers
D) The GPO is enforced but conflicts with domain policy
Answer: B) The GPO is not linked to the domain
Rationale: Account policies (password policies, lockout policies,
and Kerberos policies) are domain-level settings. They must be
linked to the domain root, not an Organizational Unit (OU), in
order to take effect. GPOs linked to OUs cannot override or
modify account policies defined at the domain level—these are
strictly configured in the Default Domain Policy GPO or another
GPO linked at the domain level .
Question 2
What is the standard order in which Group Policies are applied?
A) Site-linked GPOs, Local policies, Domain-linked GPOs, OU-
linked GPOs
B) Local policies, Site-linked GPOs, Domain-linked GPOs, OU-
linked GPOs
C) Local policies, Domain-linked GPOs, Site-linked GPOs, OU-
linked GPOs
D) Domain-linked GPOs, Site-linked GPOs, OU-linked GPOs,
Local policies
,Answer: B) Local policies, Site-linked GPOs, Domain-linked
GPOs, OU-linked GPOs
Rationale: The standard order of GPO processing is LSDOU:
Local (computer's local policy) → Site → Domain →
Organizational Unit (OU). GPOs at each level are applied in
that order. Later policies overwrite earlier conflicting settings
unless "Enforced" or "Block Inheritance" settings are configured.
This hierarchical processing allows administrators to define broad
policies at higher levels and more specific policies at the OU
level .
Question 3
If multiple GPOs have the Enforced option set and have
conflicting settings, what happens?
A) The GPO with the most recent modification date wins
B) All GPOs are applied and settings are merged
C) The GPO that is highest in the Active Directory hierarchy has
the strongest precedence
D) The GPO with the highest priority number wins
, Answer: C) The GPO that is highest in the Active Directory
hierarchy has the strongest precedence
Rationale: When multiple GPOs have the Enforced option
enabled and contain conflicting settings, the GPO that is highest
in the Active Directory hierarchy (closest to the domain root)
maintains the strongest precedence. Enforced GPOs override any
Block Inheritance settings but do not override the natural
processing order—they simply prevent Block Inheritance from
affecting them. Among multiple enforced GPOs, the standard
LSDOU order still applies .
Question 4
What Group Policy feature allows you to select specific users or
computers based on a filtering criteria, such as whether or not a
laptop battery is present in a system?
A) WMI Filtering
B) Security Filtering
C) Item-level targeting
D) GPO Enforcement
Answer: C) Item-level targeting