The administrator account can be renamed or disabled but can't be deleted
By default, user account names are case sensitive
The ability to force a user to be disconnected after log on hours expire is a group policy setting
Members of the Backup Operators group can log on locally to shut down domain controllers
User account names in Active Directory need only be unique inside their container
Why would some users be denied to log on after 5 pm, while others are still using the terminals after 5 pm?
The users were logged on prior to 5 pm
What is the character that can be used in a user account name:
If the Unlock Account check box is selected under a user account's Properties dialog box, what does this mean?
The user has too many failed log on attempts and is locked out
By default, a user's profile is created...
When the user first logs on
Where are user profiles stored by default in Windows Server 2008?
How do you change a profile into a mandatory profile?
Rename Ntuser.dat to Ntuser.man
What is a super mandatory profile?
A profile that requires a user's mandatory profile be available, or they will not be able to log on
Which of the following is not a benefit of using roaming profiles?
You've received a call from an employee about permissions on a shared folder, having found he can no longer access the resource. After checking the folder, you find that the group the employee is in is part of the resource's DACL, but seems to have no effect on the group's permissions. The group's permission entry is the only entry in the DACL. What is wrong?
The group has been converted from a security group to a distribution group
Which statement is false?
Global groups can be members of any global group in the forest
What is Microsoft's best practices recommendation for the structure of group scope nesting?
Where are local groups stored?
In the local SAM database
A seasoned intern, has been given a new assignment. They must be able to log on locally to DCs, manage some services, manage shared resources, back up and restore files, shutdown DCs, format hard drives, and change the system time. In order to give them only the rights and permissions necessary to complete these tasks, what domain local group will you add to them to?
Which group matches the following description? This universal group is found only on DCs in the forest root domain. Members have full control over forest wide operations. This group is a member of the Administrators group on all DC's.
At about what interval does a computer change its computer account password?
Which command line tool finds and displays objects in Active Directory that meet specified criteria?
Which command line tool removes, or deletes, objects from Active Directory?
Which of the below utilities uses comma-separated values to bulk import or export Active Directory data?
Which command line tool displays an object's properties onscreen by default, but can redirect output to a file?
This command line tool modifies existing Active Directory objects
A _____ is a group created in the local SAM database on a member server or workstation or a stand-alone computer.
A universal group can be converted to a domain local group, provided it's not a member of a _____
A domain local group can be converted to a universal, provided no _____ is a member.
Domain Local Group
The _____ command displays an object's properties onscreen by default, but the output can be redirected to a file.
The _____ group is a built-in default group and has no default rights or permissions.
An Active Directory object that usually represents a person for information purposes only, much like an address book entry
A group type used when you want to group users together, mainly for sending e-mails to several people at once
A property of a group that determines the reach of a group's application in a domain or a forest
A group type that's the main Active Directory object administrators use to manage network resource access and grant rights to users
A user account that's copied to create users with common attributes