Test Bank, Lesson 17 Maintaining Active Directory

Multiple Choice

1) What function does the CSVDE tool perform?

a. It decrypts and encrypts Active Directory information.

b. It exports/imports Active Directory information.

c. It exports/imports data from Event Viewer.

d. It extracts Event Viewer information into CSV files.


2. If a single domain controller’s AD database becomes corrupt, which type of restore should you perform on it?

a. authoritative

b. nonauthoritative

c. explicit

d. full



3. To perform an authoritative restore, into what mode must you reboot the domain controller?

a. Repair

b. Safe

c. Command line with networking



4. What is a GUID?

a. a unique identifier for a snapshot

b. a special file permission

c. an Active Directory object ID

d. a group-user ID in Active Directory


5. What utility first appeared in Windows Server 2008 R2 that allows you to undelete Active Directory containers and objects?

a. the Active Directory Lost and Found folder

b. the Active Directory Recycle Bin

c. the Active Directory Undelete utility

d. Active Directory Snapshots



6. By default, how often does Active Directory “garbage collection” occur?

a. every 45 minutes

b. every 2 hours

c. every 8 hours

d. every 12 hours


7. After you undelete a user account with the LDP utility, what action do you need to perform?

a. Remove the old identifier.

b. Re-establish user to domain trust.

c. Reset the user’s password.

d. Restore the user-owned objects from a backup.



8. In interactive mode, what aspect of AD can you check with the ntdsutil integrity command?

a. low-level database corruption

b. fragmentation levels

c. accuracy of entries

d. completeness of entries


9. What is the proper procedure for removing a domain controller from Active Directory?

a. Shut down the domain controller and manually remove it from AD.

b. Use dcdemo to demote the domain controller.

c. Uninstall Active Directory Domain Services.

d. Enter the DSRM and delete Active Directory.


10. Which of the following ntdsutil commands cleans up metadata?

a. metadata defrag

b. metadata restore

c. metadata cleanup

d. metadata repair



11. To perform an authoritative restore of an object or subtree, what bit of information do you need to know about the object?

a. its formal name

b. its exact location

c. its OU and proper name

d. its distinguished name


12. When you do an authoritative restore process, a back-links file is created. What is a back-links file?

a. a reference to an attribute within another object

b. a reference to metadata

c. a pointer to the object’s OU

d. a reference to a distinguished name location



13. Before you can use the Active Directory Recycle Bin, what two actions do you have to perform?

a. You have to remove the System Recycle Bin.

b. You have to enable the AD Recycle Bin.

c. You have to set the AD forest to Windows Server 2003 or higher.

d. You have to set the AD forest to Windows Server 2008 R2 or higher.


14. Windows Server 2012 introduces a new time-saving feature when performing tasks such as AD defragmentation. What is that feature?

a. The DSRM console

b. The ntdsutil command-line utility

c. Active Directory Maintenance Mode

d. Restartable Active Directory Domain Services


15. Which utility do you use to defragment Active Directory?



c. ntdsutil

d. defrag


Short Answer


16. List two primary differences between CSVDE and LDIFDE.


17. List two options for data backup.



18. List the three internal tables that make up the ntds.nit database file.


19. What information does the ntds.nit file contain?


20. What is the SYSVOL?



21. What does the SYSVOL folder contain?


Best Answer


22. Why is backup of the Active Directory database so important?

a. Backup of all data is a good idea.

b. Backup is a standard practice in large companies.

c. Backup is needed in case of corruption, deletion, or other failure.

d. Backup is an insurance policy for data and should be performed regularly.


23. Why is backing up the Windows system state necessary?

a. It’s needed to perform a full system restore.

b. It’s a precautionary move against failure.

c. It’s standard practice to do so.

d. In some commercial third-party software backup programs, it’s mandatory.


24. An Active Directory snapshot is actually what kind of backup?

a. a shadow copy

b. a simple file copy

c. a compressed (zipped) copy

d. a file copy plus metadata

25. Why can you not modify snapshots?

a. They are encrypted.

b. They are compressed and zipped.

c. They are read-only.

d. They are binary files.



Build List


26. Order the following steps required to back up the system state and Active Directory.

a. Select Custom Backup Configuration.

b. Enter a path for the remote backup destination.

c. Select Add System State.

d. Open the Windows Server backup console.

e. Select Different Options from the Backup Once Wizard.

f. Select Remote shared for the destination.

g. Select the Backup Once action.


27. Order the following steps required to perform a restore the system state.

a. Log on as the local administrator.

b. Open the Windows Server Backup console.

c. Enter the path to the backup.

d. Select the Backup Date that you want to use for the restore.

e. Select the Recover action.

f. Reboot the domain controller and open the Windows Advanced Options menu.

g. Select Confirmation and then select Recover.

h. Select Perform an authoritative restore of Active Directory files.

i. Select A backup stored on another location.

j. Select System state for the Recovery Type.

k. Select Directory Services Restore Mode.

l. Select Remote shared folder.


28. Order the following steps required to create an Active Directory snapshot.

a. Execute ntdsutil and then snapshot.

b. Open a command prompt with administrative privileges.

c. Execute the create command.

d. Execute activate instance ntds.



29. Order the following steps required to mount an Active Directory snapshot.

a. Exit ntdstutil.

b. Execute the list all command to see a list of snapshots.

c. Execute dsamain -dbpath c:\$snap_datetime_volumec$\windows\ntds\ntds.dit -ldapport 50000.

d. Open a command prompt with administrative privileges.

e. Execute the snapshot command.

f. Execute activate instance ntds.

g. Execute mount {GUID} of the snapshot.

h. Execute ntdsutil.


Repeated Answer


30. What is the name of the physical database file in which all directory data is stored?

a. edb.chk

b. temp.edb

c. ntds.nit

d. edb.log



31. Which file is used to track the point up to which transactions in the log file have been committed?

a. edb.chk

b. temp.edb

c. ntds.nit

d. edb.log


32. What is the name of the file into which directory transactions are written before being committed to the database file?

a. edb.chk

b. temp.edb

c. ntds.nit

d. edb.log


33. Which file is used as a scratch pad to store information about in-progress large transactions and to hold pages pulled out of ntds.dit during maintenance operations?

a. edb.chk

b. temp.edb

c. ntds.nit

d. edb.log


