Escrito por estudiantes que aprobaron Inmediatamente disponible después del pago Leer en línea o como PDF ¿Documento equivocado? Cámbialo gratis 4,6 TrustPilot
logo-home
Document preview thumbnail
Vista previa 4 fuera de 52 páginas
Examen

B.2.1 AZ-800 Domain 1: Deploy and Manage Active Directory Domain Services (AD DS) in On-Premises and Cloud Environments| Answered Correctly_ 2025/26.

Document preview thumbnail
Vista previa 4 fuera de 52 páginas

B.2.1 AZ-800 Domain 1: Deploy and Manage Active Directory Domain Services (AD DS) in On-Premises and Cloud Environments Date: 10/6/2025, 1:43:20 PM Time Spent: 28:25 Score: 65% Passing Score: 80% 10/12/25, 8:23 PM Individual Response A1!b2@C !@#$%^&* MYP@SSWORD My Password Correct Explanation My Password is a valid Azure AD password. The following character types are allowed in an Azure AD password: a-z A-Z 0-9 @ # $ % ^& * - _ ! + = [ ] { } | : ' , . ? / ` ~ " ( ) ; Blank space The following password restrictions apply to Azure AD: Unicode characters cannot be used. Passwords must use at least three of the following: symbols, numbers, uppercase letters, and lowercase letters. A minimum of eight characters is required. A maximum of 256 characters can be used. Azure AD provides a global banned password list based on ongoing security analysis. An administrator cannot edit the default list, but can add up to 100 banned words for a custom banned password list. Related Content 6.8.1 Understanding Hybrid Identities 8.3.1 Password Policies 8.3.2 Configure and Manage AD DS Passwords 8.3.3 Configure and Manage AD DS Passwords Facts 8.3.4 Configure and Manage AD DS Passwords Question 1 Correct 10/12/25, 8:23 PM Individual Response 10/12/25, 8:23 PM Individual Response Account Operators group Administrators group on the local computer Correct Domain Admins group Enterprise Admins group Explanation To join a computer to a domain, you must be a member of the Administrators group on the local computer or be given the necessary rights. Members of the Account Operators, Domain Admins, and Enterprise Admins groups can create a computer account, but only members of the Administrators group on the local computer can join the computer to a domain. Related Content 6.1.1 Active Directory Overview 6.1.2 Active Directory Facts 7.1.3 Organizational Unit Facts 7.2.1 Active Directory Computers 7.2.2 Create and Manage Computer Accounts 7.2.3 Computer Account Facts 7.2.4 Create Computer Accounts 7.3.1 Active Directory Users 7.3.2 Create User Accounts 7.3.3 User Templates 7.3.4 Manage User Accounts 7.3.5 Manage User Accounts with PowerShell 7.3.6 Change User Account UPN Suffix Question 2 Correct 10/12/25, 8:23 PM Individual Response 7.3.8 User Account Facts 7.3.9 User Account Management Facts 7.3.10 Create User Accounts 7.3.11 Manage User Accounts 7.4.1 Active Directory Groups 7.4.2 Create and Manage Groups 7.4.3 Manage Group Membership 7.4.4 Group Facts 7.4.5 Create Global Groups 7.4.6 Create a Distribution Group 7.4.7 Change the Group Scope 7.4.8 Implement a Group Strategy 7.5.4 Service Account Facts 7.6.1 Bulk Operations 7.6.2 Perform Bulk Operations 7.6.3 Bulk Operations Facts 7.7.1 Delegation of Control 7.7.2 Delegate Control 7.7.4 Rights Delegation Facts 7.7.7 Perform Authoritative Restore 7.7.8 Delegate Administrative Control 8.7.1 Restricted Groups 8.7.2 Manage Groups with Group Policy 8.7.3 Restricted Group Facts 8.7.4 Configure Restricted Groups resourcesquestionsq_act_dir_computers_administrators_local_ 10/12/25, 8:23 PM Individual Response domain to use the Power Saver power plan when undocked. You have specified the appropriate power plan in the Advanced Settings tab of the Power Options Group Policy preference and have set it as the active power plan. Click on the option you must enable to apply the preference only to undocked notebook systems. Explanation Group Policy preferences allow you to specify criteria that determine whether a preference will be applied or not. Targeting is granular, with a user interface for each type of targeting item. In this example, you would mark Item-level targeting and click Targeting. Then you would click New ItemPortable Computer and mark Undocked. This would cause the preference to be applied only to portable notebook systems that are in an undocked state. The Stop processing items in this extension if an error occurs option will stop processing of remaining preference items in the same category inside the current GPO, if an error occurs. The Run in logged-on user's security context (user policy option) setting changes the default user context. The Remove this item when it is no longer applied option removes preference settings when the user or computer falls out of the scope of management. The Apply once and do not reapply option causes the preference to be applied once and never again. Related Content 8.9.1 Group Policy Preferences 8.9.2 Manage Group Policy Preferences 8.9.3 Preferences Facts 8.9.4 Configure Power Options in a GPO 8.9.5 Deploy Desktop Shortcuts in a GPO Question 3 Correct 10/12/25, 8:23 PM Individual Response 10/12/25, 8:23 PM Individual Response the accounting, manufacturing, sales, and administration departments. You also have smaller OUs within each department OU, such as the ITAdmins OU in the Administration OU. You need to follow the principle of least privilege as you use the Delegation of Control wizard to complete the following: Give one user in each OU the rights necessary to manage user accounts in their OU. Give your assistants in the ITAdmins group rights to manage passwords for all users in the domain. Which of the following approaches can you use as you delegate control? Make the user in each OU a member of the UserAdmin group. Correct Create a PasswordAdmin OU in the ITAdmins OU. In each department OU, delegate control to the UserAdmin OU to perform user account tasks. In the domain, delegate control to the PasswordAdmin group to perform password tasks. Explanation If you make these groups members of the Domain Admins group, they will have more rights than you want them to have. You can only use the Delegation of Control wizard to assign rights to users of groups; you cannot assign rights to OUs. Related Content 6.1.1 Active Directory Overview 6.1.2 Active Directory Facts 7.1.3 Organizational Unit Facts 7.2.1 Active Directory Computers 7.2.2 Create and Manage Computer Accounts 7.2.3 Computer Account Facts 7.2.4 Create Computer Accounts Question 4 Correct 10/12/25, 8:23 PM Individual Response 7.3.2 Create User Accounts 7.3.3 User Templates 7.3.4 Manage User Accounts 7.3.5 Manage User Accounts with PowerShell 7.3.6 Change User Account UPN Suffix 7.3.7 Perform an Offline Domain Join 7.3.8 User Account Facts 7.3.9 User Account Management Facts 7.3.10 Create User Accounts 7.3.11 Manage User Accounts 7.4.1 Active Directory Groups 7.4.2 Create and Manage Groups 7.4.3 Manage Group Membership 7.4.4 Group Facts 7.4.5 Create Global Groups 7.4.6 Create a Distribution Group 7.4.7 Change the Group Scope 7.4.8 Implement a Group Strategy 7.5.4 Service Account Facts 7.6.1 Bulk Operations 7.6.2 Perform Bulk Operations 7.6.3 Bulk Operations Facts 7.7.1 Delegation of Control 7.7.2 Delegate Control 7.7.4 Rights Delegation Facts 7.7.7 Perform Authoritative Restore 10/12/25, 8:23 PM Individual Response 8.7.1 Restricted Groups 8.7.2 Manage Groups with Group Policy 8.7.3 Restricted Group Facts 8.7.4 Configure Restricted Groups resourcesquestionsq_act_dir_delegate_control_approach_ 10/12/25, 8:23 PM Individual Response workstation in the domain. He needs to ensure that only specific users can change the system time. Which User Rights Assignment policy should he configure? Deny log on locally Change the system time Correct Access this computer from the network Load and unload device drivers Explanation Change the system time is the correct policy. By configuring this policy, John can specify which users or groups have the ability to change the system time on the workstation. The Access this computer from the network policy determines which users or groups can connect to the workstation from the network. It does not control who can change the system time. The Deny log on locally policy determines which users or groups are prevented from logging on directly at the workstation. It does not control who can change the system time. The Load and unload device drivers policy determines which users or groups can load or unload device drivers on the workstation. It does not control who can change the system time. Related Content 8.1.1 Group Policy Overview 8.1.2 Configure Local Policies 8.1.3 Group Policy Processing 8.1.4 Create and Link Group Policy Objects 8.1.5 Manage Group Policy Inheritance 8.1.6 Group Policy Categories Question 5 Correct 10/12/25, 8:23 PM Individual Response 8.1.8 Create and Link a GPO 8.1.9 Create a Starter GPO 8.2.1 Central Stores 8.2.2 Create a Central Store 8.2.3 Configure Group Policy Scope 8.2.4 Group Policy Management Facts 8.4.1 Audit Policies 8.4.2 Configure Audit Policies 8.4.3 Audit Policy Facts 8.4.4 Configure Audit Policies 8.5.1 User Rights 8.5.2 Manage User Rights 8.5.3 User Rights Facts 8.5.4 Configure User Rights 8.6.1 Security Options 8.6.2 Configure Security Options 8.6.3 Configure Security Options 8.6.4 Security Options Facts 8.6.5 User Account Control 8.6.6 Configure User Account Control 8.6.7 User Account Control Facts 8.6.8 Enforce User Account Control 8.7.2 Manage Groups with Group Policy 8.7.3 Restricted Group Facts 8.7.4 Configure Restricted Groups 8.8.1 AppLocker 10/12/25, 8:23 PM Individual Response 8.8.3 AppLocker Facts 8.8.4 Configure AppLocker 8.9.1 Group Policy Preferences 8.9.2 Manage Group Policy Preferences 8.9.3 Preferences Facts 8.9.4 Configure Power Options in a GPO 8.9.5 Deploy Desktop Shortcuts in a GPO resourcesquestionsq_gp_rights_user_ 10/12/25, 8:23 PM Individual Response account? A group-managed service account can be used on only one computer in a domain. Passwords for group-managed service accounts must be managed manually. A managed service account can be used by only one service on a given computer in a domain. A managed service account can be used on only one computer in a domain. Correct Explanation When using a managed service account, a managed service account can be used on only one computer (you must create at least one separate account per computer). Each account can be used by multiple services on a computer. However, you can also create separate accounts for each service. Group-managed service accounts function in a manner similar to managed service accounts. However, they extend that functionality to multiple servers, allowing the same domain user account to be used by services running on many systems in the domain. This enables many instances of a particular service to be managed from a single server. As with managed service accounts, passwords are managed and reset automatically. Related Content 6.1.1 Active Directory Overview 6.1.2 Active Directory Facts 7.1.3 Organizational Unit Facts 7.2.1 Active Directory Computers 7.2.2 Create and Manage Computer Accounts 7.2.3 Computer Account Facts 7.2.4 Create Computer Accounts 7.3.1 Active Directory Users Question 6 Correct 10/12/25, 8:23 PM Individual Response 7.3.3 User Templates 7.3.4 Manage User Accounts 7.3.5 Manage User Accounts with PowerShell 7.3.6 Change User Account UPN Suffix 7.3.7 Perform an Offline Domain Join 7.3.8 User Account Facts 7.3.9 User Account Management Facts 7.3.10 Create User Accounts 7.3.11 Manage User Accounts 7.4.1 Active Directory Groups 7.4.2 Create and Manage Groups 7.4.3 Manage Group Membership 7.4.4 Group Facts 7.4.5 Create Global Groups 7.4.6 Create a Distribution Group 7.4.7 Change the Group Scope 7.4.8 Implement a Group Strategy 7.5.4 Service Account Facts 7.6.1 Bulk Operations 7.6.2 Perform Bulk Operations 7.6.3 Bulk Operations Facts 7.7.1 Delegation of Control 7.7.2 Delegate Control 7.7.4 Rights Delegation Facts 7.7.7 Perform Authoritative Restore 7.7.8 Delegate Administrative Control 10/12/25, 8:23 PM Individual Response 8.7.2 Manage Groups with Group Policy 8.7.3 Restricted Group Facts 8.7.4 Configure Restricted Groups resourcesquestionsq_act_dir_service_accounts_group_vs_managed_diff_ 10/12/25, 8:23 PM Individual Response domain, so you have decided to implement AppLocker. You have created default rules and an executable rule that only allows the company's accounting application to run. When you test these rules, you find that you can still run any program on your test client. What should you do? (Select two. Each correct answer is part of the solution.) Ensure that the enforcement mode for executable rules is set to Enforce rules. Correct Ensure that the enforcement mode for executable rules is set to Audit only. Start the Application Information service on the client computers. Start the Application Identity service on the client computers. Correct Start the Application Management service on the client computers. Incorrect Explanation LabSim for Server Pro 2016, Section 8.8. To ensure that AppLocker rules are being enforced on the client: Start the Application Identity service on the client computers. This service is used to enforce AppLocker rules. Set the enforcement mode for executable rules to Enforce rules. Setting the enforcement mode to Audit only allows you to monitor AppLocker events, but blocked software is still allowed to run. Related Content 8.1.1 Group Policy Overview 8.1.2 Configure Local Policies 8.1.3 Group Policy Processing Question 7 Incorrect 10/12/25, 8:23 PM Individual Response 8.1.5 Manage Group Policy Inheritance 8.1.6 Group Policy Categories 8.1.7 Group Policy Facts 8.1.8 Create and Link a GPO 8.1.9 Create a Starter GPO 8.2.1 Central Stores 8.2.2 Create a Central Store 8.2.3 Configure Group Policy Scope 8.2.4 Group Policy Management Facts 8.4.1 Audit Policies 8.4.2 Configure Audit Policies 8.4.3 Audit Policy Facts 8.4.4 Configure Audit Policies 8.5.1 User Rights 8.5.2 Manage User Rights 8.5.3 User Rights Facts 8.5.4 Configure User Rights 8.6.1 Security Options 8.6.2 Configure Security Options 8.6.3 Configure Security Options 8.6.4 Security Options Facts 8.6.5 User Account Control 8.6.6 Configure User Account Control 8.6.7 User Account Control Facts 8.6.8 Enforce User Account Control 8.7.2 Manage Groups with Group Policy 10/12/25, 8:23 PM Individual Response 8.7.4 Configure Restricted Groups 8.8.1 AppLocker 8.8.2 Configure AppLocker 8.8.3 AppLocker Facts 8.8.4 Configure AppLocker 8.9.1 Group Policy Preferences 8.9.2 Manage Group Policy Preferences 8.9.3 Preferences Facts 8.9.4 Configure Power Options in a GPO 8.9.5 Deploy Desktop Shortcuts in a GPO resourcesquestionsq_gp_applock_app_identity_service_ 10/12/25, 8:23 PM Individual Response corporate office is located in Miami, and there are satellite offices in Boston and Chicago. There are Active Directory sites configured for all three geographic locations. The DefaultFirst-Site-Name was renamed the Miami site. Each location has a single IP subnet configured and associated with the appropriate site. Each office has several domain controllers. The Boston office has recently expanded to three additional floors in the office building that they are in. The additional floors each have their own IP subnet and are connected by a router. The domain controllers for the Boston office are all located on one floor and are in the same subnet. You notice that the users working on the new floors in the Boston office are sometimes authenticating to domain controllers from other locations. You need to make sure that all authentication traffic over the WAN links is kept to a minimum. What should you do? Create a new Active Directory site for each new floor in the Boston office and move at least one of the domain controllers into each new site. Create subnets for the new floors in the Boston office and link them to the Boston site. Correct Remove the DNS records for the domain controllers in the other sites from the Boston DNS servers. Incorrect Disable the bridge all sites option in the properties of IP inter-site transports. Explanation If a subnet object is not found that matches a machine's IP address, it will not be able to restrict authentication traffic to a specific site. The new Boston IP subnets would need to be added to the site for the correct authentication to work. Related Content 6.6.1 Active Directory Sites 6.6.2 Create and Manage Active Directory Sites 6.6.3 Site Facts Question 8 Incorrect 10/12/25, 8:23 PM Individual Response 6.6.5 Manage Sites and Subnets 6.7.1 Active Directory Replication 6.7.3 Active Directory Replication Facts 6.7.5 Configure Intrasite Replication 6.7.6 Configure Intersite Replication resourcesquestionsq_act_dir_sites_subnets_03_ 10/12/25, 8:23 PM Individual Response This morning, you noticed that a trust relationship you established with another forest has changed. You reconfigured the trust, but you want to be able to identify if this change happens again in the future. You want to configure auditing to track this event. Which auditing category should you enable? Object access events System events Policy change events Correct Logon events Process tracking events Explanation LabSim for Server Pro 2016, Section 8.4. Audit policy change events to track changes to user rights, trust relationships, IPsec and Kerberos policies, or audit policies. Object access auditing tracks access to files, folders, or printers. Process tracking auditing records actions taken by applications. Process tracking auditing is used mainly for program debugging and tracking. System events auditing tracks system shutdown, restart, and the starting of system services. It also tracks events that affect security or the security log. Logon auditing tracks log on or log off on the local system or when a network connection is made to a system. Related Content 8.1.1 Group Policy Overview 8.1.2 Configure Local Policies 8.1.3 Group Policy Processing Question 9 Correct 10/12/25, 8:23 PM Individual Response 8.1.5 Manage Group Policy Inheritance 8.1.6 Group Policy Categories 8.1.7 Group Policy Facts 8.1.8 Create and Link a GPO 8.1.9 Create a Starter GPO 8.2.1 Central Stores 8.2.2 Create a Central Store 8.2.3 Configure Group Policy Scope 8.2.4 Group Policy Management Facts 8.4.1 Audit Policies 8.4.2 Configure Audit Policies 8.4.3 Audit Policy Facts 8.4.4 Configure Audit Policies 8.5.1 User Rights 8.5.2 Manage User Rights 8.5.3 User Rights Facts 8.5.4 Configure User Rights 8.6.1 Security Options 8.6.2 Configure Security Options 8.6.3 Configure Security Options 8.6.4 Security Options Facts 8.6.5 User Account Control 8.6.6 Configure User Account Control 8.6.7 User Account Control Facts 8.6.8 Enforce User Account Control 8.7.2 Manage Groups with Group Policy 10/12/25, 8:23 PM Individual Response 8.7.4 Configure Restricted Groups 8.8.1 AppLocker 8.8.2 Configure AppLocker 8.8.3 AppLocker Facts 8.8.4 Configure AppLocker 8.9.1 Group Policy Preferences 8.9.2 Manage Group Policy Preferences 8.9.3 Preferences Facts 8.9.4 Configure Power Options in a GPO 8.9.5 Deploy Desktop Shortcuts in a GPO resourcesquestionsq_gp_audit_policy_change_events_ 10/12/25, 8:23 PM Individual Response Device IP address Device class Correct Device name Device MAC address Explanation The Devices Group Policy preference enables or disables devices based on a device class identifier. The device name, MAC address, and IP address are not used to enable or disable devices using Group Policy preferences. Related Content 8.9.1 Group Policy Preferences 8.9.2 Manage Group Policy Preferences 8.9.3 Preferences Facts 8.9.4 Configure Power Options in a GPO 8.9.5 Deploy Desktop Shortcuts in a GPO resourcesquestionsq_gp_preferences_device_ Question 10 Correct 10/12/25, 8:23 PM Individual Response Organizational units have been created for the accounting, sales, and shipping departments. User and computer accounts for each department are in their respective OUs. Mary Hurd is a manager in the sales department. Mary is a member of the Managers global group. This group also has members from other organizational units. The Managers group has been given the read share permission to the Reports shared folder. Mary's user account (mhurd) has also been given the change share permission to the Reports shared folder. You need to create several new user accounts that have the same group membership and permission settings as the mhurd user account. How can you complete this configuration with the least amount of effort? Copy the mhurd user account. Make the new user account a member of the Managers group. Assign the group the Read and Change Share permissions to the Reports shared folder. Copy the mhurd user account. Assign the Managers group the Read and Change share permissions to the Reports shared folder. Copy the mhurd user account. Assign the new account the Read and Change Share permissions to the Reports shared folder. Copy the mhurd user account. Assign the new account the change share permission to the Reports shared folder. Correct Copy the mhurd user account. Make the new user account a member of the Managers group. Assign the new account the Change Share permission to the Reports shared folder. Explanation Question 11 Correct 10/12/25, 8:23 PM Individual Response 1. Copy the existing user account, assigning a new name and password. 2. Assign permissions to the new user account to match the existing account. When you copy a user account, group memberships are retained, so you do not need to make the new account a member of any groups. Permissions granted to the original account are not copied. Therefore, you will need to manually assign any permissions. In this scenario, you would not want to assign additional permissions to the group because that would give other group members more permissions than they need. Related Content 6.1.1 Active Directory Overview 6.1.2 Active Directory Facts 7.1.3 Organizational Unit Facts 7.2.1 Active Directory Computers 7.2.2 Create and Manage Computer Accounts 7.2.3 Computer Account Facts 7.2.4 Create Computer Accounts 7.3.1 Active Directory Users 7.3.2 Create User Accounts 7.3.3 User Templates 7.3.4 Manage User Accounts 7.3.5 Manage User Accounts with PowerShell 7.3.6 Change User Account UPN Suffix 7.3.7 Perform an Offline Domain Join 7.3.8 User Account Facts 7.3.9 User Account Management Facts 7.3.10 Create User Accounts 7.3.11 Manage User Accounts 7.4.1 Active Directory Groups 7.4.2 Create and Manage Groups 10/12/25, 8:23 PM Individual Response 7.4.4 Group Facts 7.4.5 Create Global Groups 7.4.6 Create a Distribution Group 7.4.7 Change the Group Scope 7.4.8 Implement a Group Strategy 7.5.4 Service Account Facts 7.6.1 Bulk Operations 7.6.2 Perform Bulk Operations 7.6.3 Bulk Operations Facts 7.7.1 Delegation of Control 7.7.2 Delegate Control 7.7.4 Rights Delegation Facts 7.7.7 Perform Authoritative Restore 7.7.8 Delegate Administrative Control 8.7.1 Restricted Groups 8.7.2 Manage Groups with Group Policy 8.7.3 Restricted Group Facts 8.7.4 Configure Restricted Groups resourcesquestionsq_act_dir_users_copy_account_ 10/12/25, 8:23 PM Individual Response marketing, and transportation. Each division has a global security group containing the user accounts for division managers. You want to have a single group that can be used for granting access to resources to all of your organization's managers. What should you do? (Select two. Each selection is a complete solution.) Create a global distribution group called AllMgrs and make each of the existing division managers group a member. Incorrect Create a domain local security group called AllMgrs and make it a member of the existing Division Manager groups. Create a universal distribution group called AllMgrs and make each of the existing Division Manager groups a member. Create a universal security group called AllMgrs and make each of the existing Division Manager groups a member. Correct Create a domain local distribution group called AllMgrs and make it a member of the existing Division Manager groups. Create a global security group called AllMgrs and make each of the existing Division Manager groups a member. Correct Explanation You should create either a global security or universal security group and make the existing division manager groups a member. The existing groups are global security groups, and they can be a member of another global group in the same domain or a universal group in any domain. Groups of the distribution type cannot be used to grant permissions, and domain local groups cannot be a member of a global group. Related Content 7.4.4 Group Facts Question 12 Incorrect 10/12/25, 8:23 PM Individual Response resourcesquestionsq_act_dir_groups_create_global_security_group_sol_ 10/12/25, 8:23 PM Individual Response department, shares a computer with two other users. One day, Rodney notices that some of his documents have been deleted from the computer's local hard drive. You restore the documents from a recent backup. Rodney now wants you to configure the computer, so he can track all users who delete his documents in the future. You enable auditing of successful object access events in the computer's local security policy. Rodney then logs on and creates a sample document. To test auditing, you then log on and delete the document. However, when you examine the computer's security log, no auditing events are listed. How can you make sure an event is listed in the security log whenever one of Rodney's documents is deleted? Edit the advanced security properties of the folder containing Rodney's documents. Configure an auditing entry for the Everyone group. Configure the entry to audit success of the Modify permission. Edit the advanced security properties of the folder containing Rodney's documents. Configure an auditing entry for the Everyone group. Configure the entry to audit failure of the Delete permission. Configure the local security policy to audit successful system events. Configure the local security policy to audit failed system events. Configure the local security policy to audit failed object access events. Edit the advanced security properties of the folder containing Rodney's documents. Configure an auditing entry for the Everyone group. Configure the entry to audit the success of the Delete permission. Correct Explanation Question 13 Correct 10/12/25, 8:23 PM Individual Response Object access events occur when a user accesses any object with its own access control list (such as a file, folder, registry key, or printer). In addition to enabling auditing of these types of events, you must also edit the properties of the specific objects you want to audit and define what type of access to the object you will audit. You configure auditing using special permissions (such as Delete) rather than the less advanced permissions (such as Modify, which includes the Delete special permission). In this scenario, you should audit the successful exercise of the permission. Related Content 8.1.1 Group Policy Overview 8.1.2 Configure Local Policies 8.1.3 Group Policy Processing 8.1.4 Create and Link Group Policy Objects 8.1.5 Manage Group Policy Inheritance 8.1.6 Group Policy Categories 8.1.7 Group Policy Facts 8.1.8 Create and Link a GPO 8.1.9 Create a Starter GPO 8.2.1 Central Stores 8.2.2 Create a Central Store 8.2.3 Configure Group Policy Scope 8.2.4 Group Policy Management Facts 8.4.1 Audit Policies 8.4.2 Configure Audit Policies 8.4.3 Audit Policy Facts 8.4.4 Configure Audit Policies 8.5.1 User Rights 8.5.2 Manage User Rights 8.5.3 User Rights Facts 10/12/25, 8:23 PM Individual Response 8.6.1 Security Options 8.6.2 Configure Security Options 8.6.3 Configure Security Options 8.6.4 Security Options Facts 8.6.5 User Account Control 8.6.6 Configure User Account Control 8.6.7 User Account Control Facts 8.6.8 Enforce User Account Control 8.7.2 Manage Groups with Group Policy 8.7.3 Restricted Group Facts 8.7.4 Configure Restricted Groups 8.8.1 AppLocker 8.8.2 Configure AppLocker 8.8.3 AppLocker Facts 8.8.4 Configure AppLocker 8.9.1 Group Policy Preferences 8.9.2 Manage Group Policy Preferences 8.9.3 Preferences Facts 8.9.4 Configure Power Options in a GPO 8.9.5 Deploy Desktop Shortcuts in a GPO resourcesquestionsq_gp_audit_advanced_security_properties_ 10/12/25, 8:23 PM Individual Response If the WAN link is down, users will be unable to log on. For this reason, implement this model only if the branch site is connected to the main site with reliable WAN links. The administrative overhead of this model is greater because administrators must manually add users (or preferably groups) to the allowed list. Correct This model poses some security risk because passwords are replicated to the RODCs. Incorrect Password management is facilitated because most users can have their passwords cached on demand. Explanation The administrative overhead of few accounts cached administrative model is greater because administrators must manually add users (or preferably groups) to the allowed list. If the WAN link is down, users will be unable to log on. For this reason, implement the no accounts cached administrative model only if the branch site is connected to the main site with reliable WAN links. The most accounts cached administrative model poses some security risk because passwords are replicated to the RODCs and password management is facilitated because most users can have their passwords cached on demand. Related Content 6.3.1 Read-Only Domain Controllers (RODCs) 6.3.2 Install an RODC 6.3.3 Manage an RODC 6.3.4 Configure the Password Replication Policy 6.3.5 RODC Facts 6.3.6 Password Replication Policy Facts 6.3.7 Create RODC Accounts Question 14 Incorrect 10/12/25, 8:23 PM Individual Response resourcesquestionsq_act_dir_rodc_password_few_cached_ 10/12/25, 8:23 PM Individual Response the Restore files and directories policy. Which of the following is the tool you must use to make changes to this policy? Group Policy Management Editor User Rights Policy Editor Local Group Policy Editor Correct Local Security Policy Editor Incorrect Explanation LabSim for Server Pro 2016, Section 8.5. Use the Local Group Policy Editor to manage rights on a standalone server. This tool allows you to make changes to the settings of policies, such as the Restore files and directories policy, pertaining to the local system only. You would use the Group Policy Management Editor program to make changes to the settings of policies that you want to apply to all computers in the domain. There are no tools called Local Security Policy Editor or User Rights Policy Editor. Related Content 8.1.1 Group Policy Overview 8.1.2 Configure Local Policies 8.1.3 Group Policy Processing 8.1.4 Create and Link Group Policy Objects 8.1.5 Manage Group Policy Inheritance 8.1.6 Group Policy Categories 8.1.7 Group Policy Facts 8.1.8 Create and Link a GPO 8.1.9 Create a Starter GPO Question 15 Incorrect 10/12/25, 8:23 PM Individual Response 8.2.2 Create a Central Store 8.2.3 Configure Group Policy Scope 8.2.4 Group Policy Management Facts 8.4.1 Audit Policies 8.4.2 Configure Audit Policies 8.4.3 Audit Policy Facts 8.4.4 Configure Audit Policies 8.5.1 User Rights 8.5.2 Manage User Rights 8.5.3 User Rights Facts 8.5.4 Configure User Rights 8.6.1 Security Options 8.6.2 Configure Security Options 8.6.3 Configure Security Options 8.6.4 Security Options Facts 8.6.5 User Account Control 8.6.6 Configure User Account Control 8.6.7 User Account Control Facts 8.6.8 Enforce User Account Control 8.7.2 Manage Groups with Group Policy 8.7.3 Restricted Group Facts 8.7.4 Configure Restricted Groups 8.8.1 AppLocker 8.8.2 Configure AppLocker 8.8.3 AppLocker Facts 8.8.4 Configure AppLocker 10/12/25, 8:23 PM Individual Response 8.9.2 Manage Group Policy Preferences 8.9.3 Preferences Facts 8.9.4 Configure Power Options in a GPO 8.9.5 Deploy Desktop Shortcuts in a GPO resourcesquestionsq_gp_rights_local_ 10/12/25, 8:23 PM Individual Response Directory domain. There is one main office in New York and several branch offices, including one in Chattanooga, TN. All of the clients in Chattanooga, TN, are configured using DCHP and obtain addresses in the 172.16.0.0/16 subnet with the scope ranging from 172.16.3.1 to 172.16.3.254. There are two domain controllers in the Chattanooga office named TNDC1 and TNDC2. TNDC1 has a static IP address of 172.16.2.3/16, and TNDC2 has a static IP address of 172.16.2.4/16. During an IT audit, you notice that users authenticated by TNDC2 experience significant logon delays. You order a new server to replace TNDC2. As a temporary fix, you would like to ensure that all users in the Chattanooga, TN, site are authenticated by TNDC1. The solution should enable users to be authenticated by TNDC2 only if TNDC1 fails. What should you do? Create a new Active Directory site. Create a new subnet object using the 172.16.2.4/32 subnet. Move TNDC2 to the new site. Correct Change the IP address on TNDC2 to 172.16.2.3/24. Incorrect Change the IP address on TNDC2 to 172.16.3.254/16. Create a new Active Directory site. Create a new subnet object using the 172.16.2.3/32 subnet. Move TNDC1 to the new site. Explanation Question 16 Incorrect 10/12/25, 8:23 PM Individual Response 172.16.2.4/32 subnet. Move TNDC2 to the new site. Active Directory sites control Active Directory replication and client access to site-aware applications such as Active Directory authentication or the Distributed File System (DFS). Clients will be directed to domain controllers on their own site for authentication. If no domain controller exists on the same site as the client computer, the client is directed to the site with the lowest site link cost. In this case, the way to prevent clients from authenticating to TNDC2 is to move the server to a different Active Directory site. However, since the 172.16.0.0 subnet is attached to the site, the server's IP address becomes a problem. By assigning a subnet with only the server's address and assigning it to a new site, you can effectively create a site within a site that contains only TNDC2. Since TNDC2 is in a different site than the clients, the only situation where TNDC2 will authenticate clients is if TNDC1 fails. You should not change the subnet mask for TNDC2 to /24. This would change the network ID of TNDC2. Clients would then need to cross a router in order to communicate with the domain controller, which would not work without serious modifications to the router. Additionally, this solution does not prevent clients from being authenticated by the server. Changing the server's IP address does not resolve the problem as it will remain on the same site as the client, and it could also cause an IP conflict since 172.16.3.254 is part of the DHCP scope at the site. You should not create a new site for TNDC1. This would take TNDC1 out of the same site as the clients and prevent them from being authenticated by TNDC1. All clients would then be authenticated by TNDC2, which is the opposite of the desired outcome. Related Content 6.6.1 Active Directory Sites 6.6.2 Create and Manage Active Directory Sites 6.6.3 Site Facts 6.6.4 Configure Sites 6.6.5 Manage Sites and Subnets 6.7.1 Active Directory Replication 6.7.3 Active Directory Replication Facts 6.7.5 Configure Intrasite Replication 6.7.6 Configure Intersite Replication 10/12/25, 8:23 PM Individual Response When applying Group Policy in Active Directory, which of the following is true? Group Policy settings must first be applied to the default container which holds the OU. Group Policy settings do not apply to any child OUs within a parent OU. Group Policy settings must be assigned to each appropriate object within the OU. Through inheritance, settings applied to the domain or parent OUs apply to all child OUs and objects within those OUs. Correct Explanation Through inheritance, Group Policy settings applied to the domain or parent OUs apply to all child OUs and objects within those OUs. Group Policy settings are automatically applied to every object within the OU. Group Policy settings cannot be applied to any default container. Group Policy settings apply to any child OUs within a parent OU. Related Content 6.1.1 Active Directory Overview 6.1.2 Active Directory Facts 7.1.3 Organizational Unit Facts 7.2.1 Active Directory Computers 7.2.2 Create and Manage Computer Accounts 7.2.3 Computer Account Facts 7.2.4 Create Computer Accounts 7.3.1 Active Directory Users 7.3.2 Create User Accounts 7.3.3 User Templates Question 17 Correct 10/12/25, 8:23 PM Individual Response 7.3.5 Manage User Accounts with PowerShell 7.3.6 Change User Account UPN Suffix 7.3.7 Perform an Offline Domain Join 7.3.8 User Account Facts 7.3.9 User Account Management Facts 7.3.10 Create User Accounts 7.3.11 Manage User Accounts 7.4.1 Active Directory Groups 7.4.2 Create and Manage Groups 7.4.3 Manage Group Membership 7.4.4 Group Facts 7.4.5 Create Global Groups 7.4.6 Create a Distribution Group 7.4.7 Change the Group Scope 7.4.8 Implement a Group Strategy 7.5.4 Service Account Facts 7.6.1 Bulk Operations 7.6.2 Perform Bulk Operations 7.6.3 Bulk Operations Facts 7.7.1 Delegation of Control 7.7.2 Delegate Control 7.7.4 Rights Delegation Facts 7.7.7 Perform Authoritative Restore 7.7.8 Delegate Administrative Control 8.7.1 Restricted Groups 8.7.2 Manage Groups with Group Policy 10/12/25, 8:23 PM Individual Response 8.7.4 Configure Restricted Groups resourcesquestionsq_act_dir_ou_group_policy_true_ 10/12/25, 8:23 PM Individual Response only one location. You have determined that you will have approximately 500 objects in your completed tree. Your company is organized with four primary departments, accounting, manufacturing, sales, and administration. Each area is autonomous and reports directly to the CEO. The managers in each department want to make sure that some management control of their users and resources remains in the department. Which of the following design plans will best meet these requirements? Use the Delegation of Control wizard to give a member of each OU enough rights to perform the necessary administrative tasks only in the appropriate OU. Correct Explain to the managers of each of the departments that best practices for an Active Directory tree of this size suggest that centralized administration is the most efficient method. Use the Delegation of Control wizard to make the department managers members of the Administrators group. Make the local group a member of the Administrators domain local group, giving the designated users the ability to manage department resources no matter where the resources are in the tree. Explanation Active Directory tree design can be impacted by many factors, including corporate politics. By creating four OUs, you have given each of the areas the desired autonomy. You can use the Delegation of Control wizard to give a trained administrator in each OU the ability to perform limited administrative tasks while giving yourself control over the remainder of the tree. Related Content 6.1.1 Active Directory Overview 6.1.2 Active Directory Facts 7.1.3 Organizational Unit Facts 7.2.1 Active Directory Computers Question 18 Correct 10/12/25, 8:23 PM Individual Response 7.2.3 Computer Account Facts 7.2.4 Create Computer Accounts 7.3.1 Active Directory Users 7.3.2 Create User Accounts 7.3.3 User Templates 7.3.4 Manage User Accounts 7.3.5 Manage User Accounts with PowerShell 7.3.6 Change User Account UPN Suffix 7.3.7 Perform an Offline Domain Join 7.3.8 User Account Facts 7.3.9 User Account Management Facts 7.3.10 Create User Accounts 7.3.11 Manage User Accounts 7.4.1 Active Directory Groups 7.4.2 Create and Manage Groups 7.4.3 Manage Group Membership 7.4.4 Group Facts 7.4.5 Create Global Groups 7.4.6 Create a Distribution Group 7.4.7 Change the Group Scope 7.4.8 Implement a Group Strategy 7.5.4 Service Account Facts 7.6.1 Bulk Operations 7.6.2 Perform Bulk Operations 7.6.3 Bulk Operations Facts 7.7.1 Delegation of Control 10/12/25, 8:23 PM Individual Response 7.7.4 Rights Delegation Facts 7.7.7 Perform Authoritative Restore 7.7.8 Delegate Administrative Control 8.7.1 Restricted Groups 8.7.2 Manage Groups with Group Policy 8.7.3 Restricted Group Facts 8.7.4 Configure Restricted Groups resourcesquestionsq_act_dir_delegate_control_department_design_plan_ 10/12/25, 8:23 PM Individual Response By the alphabetical order of the object names. By the date the objects were created. By the size of the objects. By physical location, organizational structure, and object type. Correct Explanation By physical location, organizational structure, and object type is the correct answer. OUs are typically organized by physical location (such as a country or city), organizational structure (such as the HR, Sales, and IT departments), and object type (such as user accounts or computers). They can also be organized by a hybrid of these factors. While it's possible to sort objects alphabetically in a view, this is not a typical way OUs are organized in Active Directory. The date objects were created is not typically a factor in how OUs are organized in Active Directory. The size of the objects is not a relevant factor in how OUs are organized in Active Directory. Related Content 6.1.1 Active Directory Overview 6.1.2 Active Directory Facts 7.1.3 Organizational Unit Facts 7.2.1 Active Directory Computers 7.2.2 Create and Manage Computer Accounts 7.2.3 Computer Account Facts 7.2.4 Create Computer Accounts 7.3.1 Active Directory Users 7.3.2 Create User Accounts Question 19 Correct 10/12/25, 8:23 PM Individual Response 7.3.4 Manage User Accounts 7.3.5 Manage User Accounts with PowerShell 7.3.6 Change User Account UPN Suffix 7.3.7 Perform an Offline Domain Join 7.3.8 User Account Facts 7.3.9 User Account Management Facts 7.3.10 Create User Accounts 7.3.11 Manage User Accounts 7.4.1 Active Directory Groups 7.4.2 Create and Manage Groups 7.4.3 Manage Group Membership 7.4.4 Group Facts 7.4.5 Create Global Groups 7.4.6 Create a Distribution Group 7.4.7 Change the Group Scope 7.4.8 Implement a Group Strategy 7.5.4 Service Account Facts 7.6.1 Bulk Operations 7.6.2 Perform Bulk Operations 7.6.3 Bulk Operations Facts 7.7.1 Delegation of Control 7.7.2 Delegate Control 7.7.4 Rights Delegation Facts 7.7.7 Perform Authoritative Restore 7.7.8 Delegate Administrative Control 8.7.1 Restricted Groups 10/12/25, 8:23 PM Individual Response 8.7.3 Restricted Group Facts 8.7.4 Configure Restricted Groups resourcesquestionsq_act_dir_ou_subtree_levels_ 10/12/25, 8:23 PM Individual Response contains three domain controllers and five-member servers. Your security policy states that all accounts should be locked out after three unsuccessful login attempts and that accounts must be reset only by an administrator. A GPO enforces these settings. On Monday morning, you receive a call from the help desk. There are seven users who are unable to log in to the domain. Upon further investigation, you notice all seven accounts have been locked out. You need to unlock the user accounts with the least amount of administrative effort while complying with your security policy. What should you do next? Using Active Directory Users and Computers, select Unlock Account for each account. Correct Change the Account lockout duration value to 0. Using Active Directory Users and Computers, highlight all seven accounts and select Unlock Account. Incorrect Change the Reset account lockout counter after value to 0. Change the Account lockout threshold value to 0. Explanation Using Active Directory Users and Computers, select Unlock Account for each account. This setting does not permit reset for more than one account at a time. This setting determines whether or not an account has been locked out. You should not change the GPO settings just to unlock an account. Because the account can only be unlocked by an administrator, the account lockout duration is already set to 0. Related Content 6.1.1 Active Directory Overview 6.1.2 Active Directory Facts 7.1.3 Organizational Unit Facts Question 20 Incorrect 10/12/25, 8:23 PM Individual Response 7.2.2 Create and Manage Computer Accounts 7.2.3 Computer Account Facts 7.2.4 Create Computer Accounts 7.3.1 Active Directory Users 7.3.2 Create User Accounts 7.3.3 User Templates 7.3.4 Manage User Accounts 7.3.5 Manage User Accounts with PowerShell 7.3.6 Change User Account UPN Suffix 7.3.7 Perform an Offline Domain Join 7.3.8 User Account Facts 7.3.9 User Account Management Facts 7.3.10 Create User Accounts 7.3.11 Manage User Accounts 7.4.1 Active Directory Groups 7.4.2 Create and Manage Groups 7.4.3 Manage Group Membership 7.4.4 Group Facts 7.4.5 Create Global Groups 7.4.6 Create a Distribution Group 7.4.7 Change the Group Scope 7.4.8 Implement a Group Strategy 7.5.4 Service Account Facts 7.6.1 Bulk Operations 7.6.2 Perform Bulk Operations 7.6.3 Bulk Operations Facts 10/12/25, 8:23 PM Individual Response 7.7.2 Delegate Control 7.7.4 Rights Delegation Facts 7.7.7 Perform Authoritative Restore 7.7.8 Delegate Administrative Control 8.7.1 Restricted Groups 8.7.2 Manage Groups with Group Policy 8.7.3 Restricted Group Facts 8.7.4 Configure Restricted Groups resourcesquestionsq_act_dir_users_unlock_ Copyright © CompTIA, Inc. All rights reserved. 10/12/25, 8:23 PM Individual Response

Vista previa del contenido

10/12/25, 8:23 PM Individual Response


B.2.1 AZ-800 Domain 1: Deploy and
Manage Active Directory Domain
Services (AD DS) in On-Premises and
Cloud Environments
Date: 10/6/2025, 1:43:20 PM
Time Spent: 28:25
Score: 65% Passing Score: 80%




https://labsimapp.testout.com/v6_0_695/index.html/productviewer/1197/B.2.1/f9d0e59e-a3f6-4489-b9dc-b4d5a65de41b/outline?nonce=EtJv9P0v_3l1WAvejdAMrS… 1/52

,10/12/25, 8:23 PM Individual Response


Question 1 Correct



Which of the following is a valid Azure AD password?


A1!b2@C

!@#$%^&*

MYP@SSWORD


My Password Correct


Explanation

My Password is a valid Azure AD password.

The following character types are allowed in an Azure AD password:

a-z
A-Z
0-9
@ # $ % ^& * - _ ! + = [ ] { } | \ : ' , . ? / ` ~ " ( ) ; < > Blank space

The following password restrictions apply to Azure AD:

Unicode characters cannot be used.
Passwords must use at least three of the following: symbols, numbers, uppercase letters,
and lowercase letters.
A minimum of eight characters is required.
A maximum of 256 characters can be used.
Azure AD provides a global banned password list based on ongoing security analysis. An
administrator cannot edit the default list, but can add up to 100 banned words for a
custom banned password list.

Related Content

6.8.1 Understanding Hybrid Identities

8.3.1 Password Policies

8.3.2 Configure and Manage AD DS Passwords

8.3.3 Configure and Manage AD DS Passwords Facts

8.3.4 Configure and Manage AD DS Passwords

https://labsimapp.testout.com/v6_0_695/index.html/productviewer/1197/B.2.1/f9d0e59e-a3f6-4489-b9dc-b4d5a65de41b/outline?nonce=EtJv9P0v_3l1WAvejdAMrS… 2/52

,10/12/25, 8:23 PM Individual Response

resources\questions\q_conf_active_passwords_azure_shc5.question.xml




https://labsimapp.testout.com/v6_0_695/index.html/productviewer/1197/B.2.1/f9d0e59e-a3f6-4489-b9dc-b4d5a65de41b/outline?nonce=EtJv9P0v_3l1WAvejdAMrS… 3/52

, 10/12/25, 8:23 PM Individual Response


Question 2 Correct



To join a computer to a domain, you must be a member of which of the following groups?


Account Operators group


Administrators group on the local computer Correct


Domain Admins group

Enterprise Admins group


Explanation

To join a computer to a domain, you must be a member of the Administrators group on the
local computer or be given the necessary rights.

Members of the Account Operators, Domain Admins, and Enterprise Admins groups can
create a computer account, but only members of the Administrators group on the local
computer can join the computer to a domain.

Related Content

6.1.1 Active Directory Overview

6.1.2 Active Directory Facts

7.1.3 Organizational Unit Facts

7.2.1 Active Directory Computers

7.2.2 Create and Manage Computer Accounts

7.2.3 Computer Account Facts

7.2.4 Create Computer Accounts

7.3.1 Active Directory Users

7.3.2 Create User Accounts

7.3.3 User Templates

7.3.4 Manage User Accounts

7.3.5 Manage User Accounts with PowerShell

7.3.6 Change User Account UPN Suffix

https://labsimapp.testout.com/v6_0_695/index.html/productviewer/1197/B.2.1/f9d0e59e-a3f6-4489-b9dc-b4d5a65de41b/outline?nonce=EtJv9P0v_3l1WAvejdAMrS… 4/52

Información del documento

Subido en
29 de enero de 2026
Número de páginas
52
Escrito en
2025/2026
Tipo
Examen
Contiene
Preguntas y respuestas
$18.99

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
MindCraft
3.8
(52)
Vendido
435
Seguidores
10
Artículos
2940
Última venta
7 horas hace




Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes