Free AZ-800 Exam Braindumps (page: 12)

Page 12 of 66

SIMULATION
You need to ensure that the minimum password length for members of the BranchAdmins group is 12 characters. The solution must affect only the BranchAdmins group.

To complete this task, sign in the required computer or computers.

  1. See Explanation section for answer.

Answer(s): A

Explanation:

Create a new fine-grained password policy.
In the following procedure you will create a new fine-grained password policy using the UI in ADAC.
To create a new fine grained password policy.

Step 1: Right click the Windows PowerShell icon, click Run as Administrator and type dsac.exe to open ADAC.

Step 2: Click Manage, click Add Navigation Nodes and select the appropriate target domain in the Add Navigation Nodes dialog box and then click OK.

Step 3: Click Manage, click Add Navigation Nodes and select the appropriate target domain in the Add Navigation Nodes dialog box and then click OK.

Step 4: In the Tasks pane, click New, and then click Password Settings.
Fill in or edit fields inside the property page to create a new Password Settings object. The Name and Precedence fields are required.

In our case:
Minimum password length: 12



Step 5: Under Directly Applies To, click Add, type BranchAdmin, and then click OK.


Reference:

https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/get-started/adac/introduction-to-active-directory-administrative-center-enhancements--level-100-#bkmk2_test_fgpp1



SIMULATION
You need to configure a Group Policy preference to ensure that users in the organizational unit (OU) named Server Admins have a shortcut to a folder named \\srv1.contoso.com\data on their desktop when they sign in to the computers in the domain.

To complete this task, sign in the required computer or computers.

  1. See Explanation section for answer.

Answer(s): A

Explanation:

Create Desktop Shortcuts on Domain Computers via GPO.
Step 1: Open the Group Policy Management Console (gpmc.msc).

Step 2: Right-click an AD container (Organizational Unit) you want to apply a shortcut creation policy. In this case right-click on the OU Server Admins.



Step 3: Select Create a GPO in this domain, and Link it here..

Step 4: Go to the Group Policy Preferences section: User Configuration –> Preferences -> Windows Settings -> Shortcuts. Click it and select New -> Shortcut;



Step 5: Create a new shortcut item with the following settings:
Name: Something
Target Type: File System Object (you can select a URL or a Shell object here)
Location: Desktop
Target Path: \\srv1.contoso.com\data


Reference:

http://woshub.com/create-desktop-shortcuts-group-policy/



SIMULATION
You plan to promote a domain controller named DC3 in a site in Seattle.
You need to ensure that DC3 only replicates with DC1 and DC2 between 8 PM and 6 AM.

To complete this task, sign in the required computer or computers.

  1. See Explanation section for answer.

Answer(s): A

Explanation:

Step 1: Create a site link between Seattle and the site in which DC1 and DC2 are located (if the site link does not already exist. If the site link already exists, then skip Step 1).

Step 2: To open Active Directory Sites and Services, click Start, click Administrative Tools, and then click Active Directory Sites and Services.
Open Active Directory Sites and Services.

Step 3: In the console tree, click the intersite transport folder that contains the site link for which you are configuring intersite replication availability.

Step 4: In the details pane, right-click the site link whose schedule you want to configure, and then click Properties.

Step 5: Click Change Schedule.

Step 6: Select the block of time during which you want replication to be either available or not available, and then click Replication Not Available or Replication Available, respectively.
Change the schedule to: from 8 PM to 6 AM.

Note: Site link
Site links are Active Directory objects that represent logical paths that the KCC uses to establish a connection for Active Directory replication. A site link object represents a set of sites that can communicate at uniform cost through a specified intersite transport.

All sites contained within the site link are considered to be connected by means of the same network type. Sites must be manually linked to other sites by using site links so that domain controllers in one site can replicate directory changes from domain controllers in another site. Because site links do not correspond to the actual path taken by network packets on the physical network during replication, you do not need to create redundant site links to improve Active Directory replication efficiency.

When two sites are connected by a site link, the replication system automatically creates connections between specific domain controllers in each site that are called bridgehead servers.


Reference:

https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc770712(v=ws.10)
https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/get-started/replication/active-directory-replication-concepts



SIMULATION
You need to ensure that DC2 is the schema master for contoso.com.

To complete this task, sign in the required computer or computers.

  1. See Explanation section for answer.

Answer(s): A

Explanation:

Seize operations master roles
You cannot use AD DS snap-ins to seize operations master roles. Instead, you must use either the ntdsutil.exe command-line tool or Windows PowerShell to seize roles.

To seize or transfer the FSMO roles by using the Ntdsutil utility, follow these steps:

Step 1: Sign in to a member computer, in our case DC2, that has the AD RSAT tools installed, or a DC that is located in the forest where FSMO roles are being transferred.

Step 2: Select Start > Run, type ntdsutil in the Open box, and then select OK.

Step 3: Type roles, and then press Enter.
Note:
To see a list of available commands at any one of the prompts in the Ntdsutil utility, type ?, and then press Enter.

Step 4: Type connections, and then press Enter.

Step 5: Type connect to server <servername>, and then press Enter.

Step 6: At the server connections prompt, type q, and then press Enter.

Step 7: To seize the role: Type seize <role>, and then press Enter.
In our case we type: size schema master.

Step 8: At the fsmo maintenance prompt, type q, and then press Enter to gain access to the ntdsutil prompt. Type q, and then press Enter to quit the Ntdsutil utility.


Reference:

https://learn.microsoft.com/en-us/troubleshoot/windows-server/identity/transfer-or-seize-fsmo-roles-in-ad-ds



Page 12 of 66



Post your Comments and Discuss Microsoft AZ-800 exam with other Community members:

Samuel commented on August 18, 2024
I successfully finished this exam. Thank you for your support.
SOUTH AFRICA
upvote

Barry Hilton commented on February 02, 2024
This looks like the exam
Anonymous
upvote

Saint Pierre commented on October 24, 2023
i would give 5 stars to this website as i studied for az-800 exam from here. it has all the relevant material available for preparation. i got 890/1000 on the test.
Anonymous
upvote

Saint Pierre commented on October 24, 2023
I would give 5 stars to this website as I studied for AZ-800 exam from here. It has all the relevant material available for preparation. I got 890/1000 on the test.
Anonymous
upvote

Rob commented on September 13, 2023
Great Material
UNITED STATES
upvote

Garchirs commented on August 04, 2023
Thanks for the help, this allowed me to get my az800cert
Anonymous
upvote

Nicole commented on February 08, 2023
It is very easy to make the purchase and download the files. So far all looks good. I am happy.
UNITED STATES
upvote