显示标签为“学习资料”的博文。显示所有博文
显示标签为“学习资料”的博文。显示所有博文

2009年4月6日星期一

Case Study: Graphic Design Institute

Exhibit, Existing Domain Model 

Exhibit, Existing Network Infrastructure 


Overview 
Graphic Design Institute is a graphical design company that creates animated graphics for several advertising companies and move theaters. 

The hours of operation are 8:00 A.M. to 5:00 P.M., Monday through Friday. 

Physical Locations 
The company’s main office is located in Los Angeles. The company has five branch offices in the 
following locations: 
  • Atlanta 
  • Dallas 
  • Denver 
  • New York 
  • San Francisco 

The number of users in each office is shown in the following table. 

Office                  Number of users 
Los Angeles           550 
Atlanta                300 
Dallas                 30 
Denver               210 

Planned Changes 
To meet new security and customer requirements, the company wants to implement a Windows Server 2003 Active Directory environment. 

Existing Environment 
Business Processes 
Graphic Design Institute consists of the following primary departments: 
  • Human Resources (HR) 
  • Finance 
  • Information Technology (IT) 
  • Advertising 
  • Movies 
  • Animation 
The IT department is responsible for all network management. 

Users often work on multiple projects at the same time. A strong administrative structure based on each user’s office location and department is being used. 

Infrastructure 
Directory Services 
The existing domains and trust relationships are shown in the Existing Domain Model exhibit. 

The company has one Windows 2000 domain located in the Los Angeles office. The name of the domain is graphicdesigninstitute.com. The domain is a Windows 20000 mixed-mode domain that contains Windows 2000 Server computers configured as domain controllers, Windows NT Server 4.0 computers configured as BDCs, and Windows 2000 Server computers configured as member servers. 

Currently, this domain is the only Active Directory domain. The domain consists of the following three top-level OUs: 
  • Movies 
  • Animation 
  • Advertising 
The default site configuration has been implemented in the existing Active Directory environment. 

Problem statements 
The following business problems must be considered: 
  • There is currently no enforcement of frequent password changes and logon hours. 
  • The ISP can only supply a single subnet, which consists of 32 IP addresses, for the Internet link. 
  • It is very difficult to manage users and groups and their necessary permissions. 
  • The finance and HR department cannot agree on a mutual security policy to implement. 
  • NetBIOS name resolution is saturating the WAN links. 
Interviews 
Chief Execute Offices 
Graphic Design Institute has lost a number of contracts due to deadlines that have not been met. Decreasing the amount of time we spend administering the network, along with increasing the amount of time we spend on customers, is my primary reason for requesting the upgrade of the entire network. 

Funds are available for critical hardware requirements. I do not want any downtime for users. I also want strict business hours enforced. Employees should not be at the office or work from home outside normal business hours. 

Chief Information Officer 
Currently, we have problems as a result of all the merges and acquisitions. I want all the servers to be installed with Windows Server 2003 to resolve these problems. I also want all client computers upgraded to Windows XP Professional over the next two years. 

The current IT response level is leading to a lot of lost production hours. Each office will continue to manage its own users and computers, with the exception of the finance and HR departments, which have their own requirements. We need to ensure that no production time is lost as a result of an interruption in the network connectivity. 

Network Administrator 
We are currently expected to resolve issues within 24 hours, although this sometimes is not achieved. Because most high-level administrative work can only be done when users are not in the office, network administrators often work after hours or on weekends. 

Domain administrators are responsible for managing the private IP addresses of every computer that belongs to their respective domains. 

Help desk staff exists in each branch office to assist users with software-related problems, as well as with basic network problems. Each domain has its own help desk staff with personnel located in each office. In the future, the help desk staff will be responsible for resetting passwords if users forget them. 

Office Worker 
Only selected users have Internet access. This prevents us from remaining competitive because we cannot perform the necessary research about new technologies or software available. 

Business Requirements 
Business Drivers 
The following business requirements must be considered: 
  • A single internal namespace is required to minimize administrative effort. 
  • A Web site exists outside the firewall to provide company contact information. 

Organizational Goals 
The following organizational requirements must be considered: 
  • The new design must accommodate the finance and HR departments, which have requirements not addressed by the company’s planned password policy. 
  • All computers must have the latest service packs and hot fixes installed. In addition, computers in the advertising department must be updated to have the latest versions of graphics and audio drivers installed. 

Security 
The following security requirements must be considered: 
  • Specific security groups must be set up to address security requirements. 
  • Security must be based on departments and groups of individuals within the departments. 
  • Users in the finance department need access to payroll information on a server named Payroll, which is located in the HR department. 
Customer Requirements 
The following customer requirements must be considered: 
  • A new service-level agreement that requires a response from the IT department to users within one hour must go into effect. 
  • Personal information about employees must remain secure. 
  • All client computers, regardless of office location, must be able to access all other computers. 
Technical Requirements 
Active Directory 
The following Active Directory requirements must be considered: 
  • The company requires a new Active Directory environment that enables the security requirements of various departments to be met. This must be accomplished by installing a Windows Server 2003 on all domain controllers. 
  • A completely decentralized administrative approach will be used. Each group of administrators will be responsible for its own departmental environment. 
  • Only one operations master role will be allowed per domain controller. This is required for fault tolerance. 
  • DNS replication of the forest root domain must be limited to forest domain controllers only. 
Network Infrastructure 
The following infrastructure requirements must be considered: 
  • A new Routing and Remote Access solution must be installed: 
  • A DHCP solution that is fault tolerant within each office must be implemented 
  • All WAN links must be fault tolerant 
  • Name resolution must be localized on the local network 

Graphic Design Institute (10 Questions) 


QUESTION NO: 1 
You are designing a strategy to address the requirements of the advertising department. What should you do? 

A. Create a GPO and link it to the Denver site. 
B. Create a GPO and link it to the Advertising OU. 
C. Create a GPO and link it to the graphicdesigninstitute.com domain. 
D. Configure the Default Domain Policy to have the No Override option. 
E. Use block inheritance to prevent the GPO from applying to members of the advertising department. 

QUESTION NO: 2 
You are deploying a NetBIOS name resolution strategy to meet the business and technical requirements. What should you do? 

A. Install one WINS server in each branch office. Configure the WINS servers to use push/pull replication with the WINS server in Los Angeles. Configure all computers to have the IP address of the local WINS server. 
B. Install two additional WINS servers in Los Angeles. Configure the WINS servers to use push/pull replication. Configure all computers to have the IP addresses of the WINS servers. 
C. Install the DNS Server service on one domain controller on each branch office. Configure the DNS server to forward all unanswered queries to the WINS server. Configure all computers to have the IP address of the DNS servers. 
D. Configure the DNS servers in each branch office to forward all unanswered queries to a local WINS server. Configure all computers to have the IP addresses of the DNS server in 
graphicdesigninstitute.com forest root. 

QUESTION NO: 3 
You are designing a DHCP strategy to meet the business and technical requirements. What should you do? 

A. Install one DHCP server in each branch office and one DHCP server in Los Angeles. 
B. Install one DHCP server in each branch office and two DHCP servers in Los Angeles. 
C. Install two DHCP servers in each branch office and one DHCP server in Los Angeles. 
D. Install two DHCP servers in each branch office and two DHCP servers in Los Angeles. 

QUESTION NO: 4 
You are designing a DNS strategy to meet the business and technical requirements. What should you do? 

A. Install the DNS Server service on all domain controllers. Create Active Directory-integrated zones. Replicate the zones to all DNS servers in the forest. 
B. Install the DNS Server service on all domain controllers. Create Active Directory-integrated zones. Replicate the zones to all DNS servers in the domain. 
C. Install the DNS Server service on all domain controllers. Create primary zones and secondary zones. 
D. Create application partitions for the different zones on one domain controller. Configure replication to occur on all DNS servers. 

QUESTION NO: 5 
You need to identify the number of servers that will be used specifically for operations master roles. How many servers should you recommend? 

A. 5 
B. 11 
C. 14 
D. 17 
E. 20 

QUESTION NO: 6 
You are designing a strategy to provide Internet access to all users. What should you do? 

A. Configure Internet Connection Sharing on all client computers. 
B. Configure Automatic Private IP Addressing (APIPA) on all client computers. 
C. Configure one server as a Routing and Remote Access VPN server. 
D. Configure one server as a Routing and Remote Access NAT router. 

QUESTION NO: 7 
You are designing an Active Directory forest structure to meet the business and technical requirements. What should you do? 

A.Create a single forest that has one domain. Use OUs to separate the departments. 
B. Create a single forest that has multiple domains to represent every department. 
C. Create a single forest that has three domains: one for finance, one for HR, and one for the remaining departments. 
D. Create multiple forests that have a single domain in each forest to represent the departments. 

There are a number of reasons that you might need to define multiple domains. These reasons include the following: 
  • You need to implement different domain-level security policies. 
  • You need to provide decentralized administration. 
  • You need to optimize replication traffic across WAN links more than you can by dividing a domain into multiple sites. 
  • You need to provide a different namespace for different locations, departments, or functions. 
  • You need to retain an existing Windows NT domain architecture. 
  • You want to put the schema master in a different domain than the domains that contain users or other resources. 
QUESTION NO: 8 
You are designing a WAN implementation strategy to meet the business and technical requirements. What should you do? 

A. Configure a demand-dial router. 
B. Create multiple Active Directory site links. 
C. Configure a VPN connection between each branch office. 
D. Install an Internet Authentication Service (IAS) server in each branch office. 

QUESTION NO: 9 
You are designing a strategy to provide the required security for the Payroll server. You need to identify the actions that you should perform to achieve this goal. What should you do? 
Move, and arrange the actions in the proper order. Use only actions that apply. 


QUESTION NO: 10 
You are designing a password management solution to meet the business and technical requirements. 
Which two actions should you perform? (Each correct answer presents part of the solution.) (Choosetwo.) 

A. Delegate the password management controls to the help desk staff. 
B. Delegate the password management controls to the Domain Users group. 
C. Configure the Default Domain Policy to enforce password expiration settings. 
D. Configure the Default Domain Controller Policy to enforce password expiration settings. 

2009年4月3日星期五

Case Study: Northwind Traders

Existing Network Infrastructure Exhibit 


Overview 
Northwind Traders is a stockbroker company in Northern Europe. The company provides advice and the resources to buy and sell stocks for individual investors. 

Currently, the company operates between the hours of 8:00 A.M. and 6:00 P.M. 
However, with the upcoming changes, business hours will be expanded. 

Physical locations 
The company’s main office is located in Stockholm. The company has two branch offices in the following locations: 
  • Helsinki 
  • Copenhagen 
The company plans to establish a new branch office in Oslo
The number of users in each location is shown in the following table. 
Location           Number of users 
Stockholm                350 
Helsinki                    100 
Copenhagen             150 
Oslo                         15 

Planned Changes 
All stock trading is currently done by telephone or fax. 

The company wants to provide a Web site to allow customers to trade directly by using the Internet. It is also providing a new Web application named NewApp to trade stocks. 

To support this new environment, the company will upgrade its servers to Windows Server 2003. 

Existing Environment 
Business Processes 
Each office of Northwind Traders has its own IT staff. 

The company currently hosts a mainframe application that tracks customers’ stock traders. Each office uses its own instance of this application. 

Stock trades that have been initiated by telephone must be recorded within two hours of the call. 

Infrastructure 
Directory Services 
Currently, the company is using a Windows NT 4.0 domain infrastructure consisting of three domains, one for each office. The information about these domains is not well documented. 

All links between offices are highly reliable. 

All IT staff is members of the Domain Admins group in their own domain. 

All domain controllers run Windows NT Server 4.0 with the latest service pack and security fixes installed. 

Network Infrastructure 
The existing network infrastructure is shown in the Existing Network Infrastructure Exhibit. 

The local network in each office is a 10/100-Mbps Ethernet network. 

Client computers run Windows NT Workstation 4.0 and Windows 98. There are also *** missing *** 

Problem Statements 
The following business problems must be considered: 
  • Currently, employees need to remember different user names and password for different computers and offices. The company wants a single sign-on process in the new environment, which will also help to improve security. 
  • In the last year, the company had some instances of data being compromised. The company wants to be able to trace which computer used which IP address at the time that the compromise occurred. The company wants to be able to store this information for at least one month. 
Chief Executive Officer 
I want customers of Northwind Traders to be able to trade stocks more directly. Because migration can take months, we need our employees to be able to access both the current environment and the new environment during migration. However, after the migration is completed, employees should not be allowed to log on to the current environment. 

Chief Information Officer 
I want to introduce a new application named NewApp. NewApp is multitier application that will run on the Windows Server 2003 computers. NewApp will enable us to provide our customers with a tool to trade stocks online. 

NewApp will be hosted on computers in the Stockholm and Oslo offices. The NewApp Web servers will be accessible from the Internet. The NewApp database servers will be accessible from all sites. 

Business requirements 
Business Drivers 
The following business requirements must be considered: 
  • Northwind Trders will use an Internet Web site hosted as www.northwindtraders.com
  • For the internal DNS name, the company wants to use a contiguous namespace. 
  • For internal name resolution, all computers are required to first use a local DNS server. 
  • NewApp needs to be highly available. Maximum downtime of this application and its services will be one hour per month. 
  • Because the customer transactions are increasing, the company wants to increase productivity and service levels without employing more traders. 
  • The company wants to test the disaster recovery model at least once a year. 
  • During this test, only the password changes and resource access will be tested. 
Organizational Goals 
The following organizational requirements must be considered: 

Currently there is no information about how much bandwidth is needed for…. 
*** MISSING *** 

Security 
The following security requirements must be considered: 
  • Employees need access to customer data. The company needs to secure the customer data. 
  • All IT staff is trusted. However, only a selected group of IT staff will have access to customer data.  
  • To secure the stock transactions as much as possible, we need all customers to use client certificates for all Web-based stock trading. 
  • The company wants to be able to grant and revoke certificates. 
  • All NewApp database servers need a common set of security settings. 
  • The maximum downtime of NewApp services is specified for one hour. If a downtime of NewApp services in Stockholm of more than one hour is anticipated, administrators must recover NewApp at the disaster recovery location. 
Technical requirements 
Active Directory 
The following Active Directory requirements must be considered: 
  • Employee accounts and resources must be securely separated from the customer account and resources. 
  • Web servers will not be part of a domain. 
  • The company will use centralized authentication for Routing and Remote access. 
  • IT management has decided to use a common namespace for all domains. 
  • To make company-wide Active Directory changes, administrators from both the customer environment and the corporate environment must agree. 
  • New hardware will be purchased for all Windows Server 2003 domain controllers. 
  • The OU structure must align with the new administrative model. 
Network Infrastructure 
The following infrastructure requirements must be considered: 
  • Front-end servers of NewApp will be a Network Load Balancing array of single processor servers. 
  • Back-end servers of NewApp will be a cluster of eight-way 64-bit servers. 
  • The company’s ISP does not allow updates to DNS made by customers. The company wants to manage its own namespace. 
  • The company has only a limited number of public IP addresses. It can use these addresses only when needed. 
  • Logon traffic across WAN links needs to be minimized. 
  • All client computers will be upgraded to Windows XP Professional. 
  • The company wants to create a disaster recovery location in the Oslo Office. 
  • Employees who have remote access will be allowed to access only the NewApp servers when they connect from outside the office. The different remote access requirements are shown in the following table. 

 Northwind Traders (7 Questions) 


QUESTION NO: 1 
You are designing a strategy for migrating to the new environment. Which two factions from your current environment will affect your migration strategy? (Each correct answer presents part of the solution. (Choose two.) 

A. Trusts between domains 
B. Number of BDC s in each domain 
C. Users and resources in each domain 
D. Current hardware for domain controllers 
E. Current amount of replication traffic over WAN links 

QUESTION NO: 2 
You are designing an OU structure for IT staff at the branch offices. What should you do? 

A. Create an OU for the NewApp Web servers. Assign the IT staff at the branch offices user rights to this OU. 
B. Create an OU for the NewApp data servers. Assign the IT staff at the branch offices user rights to this OU. 
C. Create an OU for the IT staff at each branch office. Place network administrators at the branch offices in these OUs. 
D. Create an OU for each branch office. Place local servers in the OU for their respective office. Assign the IT staff at the branch offices user rights to these OUs. 

QUESTION NO: 3 
You are designing the Active Directory domain structure for the company. You need to create a diagram that shows the appropriate structure. What should you do? 
Move the appropriate domains to the correction location in the answer tree. 


QUESTION NO: 4 
You are designing a migration strategy to create user IDs for all company users in the new environment. What should you do? 

A. Create a script that uses Active Directory Services Interfaces (ADSI) to import all user account into the new environment. 
B. Create new accounts for all users. Create a trust relationship between the existing environment and the new environment to enable access to resources in the existing environment. 
C. Import all user accounts into the new environment by using the Active Directory Migration Tool (ADMT). 
D. Import all user accounts into the new environment. Instruct users to no change their passwords during 
the migration phase so that they can access resources in the existing environment. 
Answer: A 

QUESTION NO: 5 
You are designing a security strategy for users who need remote access to the corporate network. What should you do? 

A. Configure Internet Authentication Service (IAS) for accounting. 
B. Configure the server running Routing and Remote Access to support L2TP. 
C. Configure the server running Routing and Remote Access to restrict dial-in traffic to the NewApp servers only. 
D. Create a separate account for remote access users. Configure these accounts to access the NewApp server only. 

QUESTION NO: 6 
You need to test your disaster recovery solution. Which role should you transfer to the disaster recovery location during the test? 

A. RID master 
B. Schema master 
C. PDC emulator master 
D. Domain naming master 

QUESTION NO: 7 
You are designing a strategy to ensure that the Web servers will be accessible from the Internet. You need to identify the appropriate IP configuration components that need to be used. What should you do? 

2009年4月1日星期三

Case Study: Blue Yonder Airlines

Existing Domain model Exhibit. 

Existing Network Infrastructure Exhibit. 

Planned Network Infrastructure Exhibit. 

Overview 

Blue Yonder Airlines provides air transportation services to locations throughout Australia. Services include executive-class travel and cargo delivery. 

Physical Locations 
The company’s main office is located in Sydney. The company has two branch offices in the following locations: 
  • Melbourne 
  • Perth 
Planned changes 
The company will open European branch offices in the following locations: 
  • Berlin 
  • Paris 
The Berlin office will serve as the regional office for Europe. 

In addition, the company plans to establish a new partnership with an application service provider (ASP) named Contoso, Ltd., which will be used to host the company’s air traffic control (ATC) application. 

The ATC application is an X.500 directory-enabled application that runs on Windows NT Server 4.0 computers in the Sydney office. The company plans to use a new version of the ATC application that will run on a Windows Server 2003 computer hosted by Contoso, Ltd. Only specified users will have access to this application. Users connect to this application by querying DNS for the application’s service record. This record is stored on a UNIX DNS server running the latest version of BIND. 

Contoso, Ltd., will create the required users in the domain that hosts the application and will provide this information as a file to Blue Yonder Airlines. No other connections to the Contoso, Ltd., network will be allowed except for access to the application itself. 

Existing Environment 
Business Processes 
Blue Yonder Airlines consists of the following primary departments: 
  • Finance 
  • Human resources (HR) 
  • Information Technology (IT) 
  • Air Traffic (ATC) 
  • Flight operations 
The IT department manages the entire network from the Sydney office or by traveling to the branch offices. All resources are located at the Sydney office and are accessed across the WAN links by users in the branch offices. 

Although the ATC department works closely with flight operations, it is still a separate department. 

The flight operations department consists of the following groups: 
  • Flight officers 
  • Manifest 
  • Catering 
Users in the Manifest group use an application named Manifest. The Manifest application consists of two versions: 
  • Passenger Manifest, which contains Passenger information. 
  • Cargo Manifest, which contains Cargo information. 
Users in the Sydney office use only Passenger Manifest. Users in the branch offices use only Cargo Manifest. Currently, access to the Manifest application is limited only by using NTFS permissions. 

Passenger Manifest runs on a server in the Sydney office. The information in Passenger must be current within the hour and must be available at all times to all users in the Manifest group. The information contained in the Passenger Manifest must never become publicly available. 

Infrastructure 
Directory Services 
The existing domains and trusts are displayed in the Existing Domain model exhibit. 

The LAN in each office consists of a 100-Mbps Ethernet network. No server computers are located in the branch offices. All IP addresses are statically configured for computers located in the branch offices. 

A Microsoft Exchange Server 2000 environment provides Outlook Web Access (OWA) to all users. A single Exchange Server 2000 front-end server computer in the Sydney office is allocated for OWA. 

Currently, the company does not have a public Web site. A Microsoft Internet Security and Acceleration (ISA) Server computer in the Sydney office is configured as a firewall and proxy server. The ISA Server computer is also used for publishing OWA to flight officers who connect to the network from outside the firewall. 

Flight officers use portable computers to access OWA via an ISP. No other intranet applications are currently available. 

Company policy states that client computers should run only Windows 2000 Professional or Windows XP Professional. However, this policy is currently not enforced. 

The existing hardware is shown in the following table. 


Problem Statements 
The following business problems must be considered: 
  • The ATC application uses the inetOrgPerson class when authenticating to the X.500 directory-enabled database that the application uses for authentication. 
  • The existing GPOs result in extremely lengthy logon times for users in the branch offices. Members of the Administrators group are currently excluded from the GPO that forces password changes. 
  • The current dial-up solution results in expensive long-distance calls and only supports OWA. Currently, an on-site user must send the information to flight officers via an e-mail message because the Manifest application requires that users map to drive T to operate. 
  • Existing airline security requirements specify that only smart card authentication should be used for the administration of servers by network administration. 
Interviews 
Chief Execute Officer 
Blue Yonder Airlines has experienced consistent growth since its startup in 1997. However, this year the market has leveled off and we need to expand our services to Europe. We anticipate substantial growth over the next two years. 

Our current offices are located near the major airports in Australia. Each office provides all airline-related administrative features for its respective location. The only exception is network administration, which is provided by the Sydney office. If network administrators are needed in one of the branch offices, they are provided air transportation by our company. 

Chief Information Officer 
Our company plans to establish a Web site named www.blueyonderairlines.com that will include an online booking system for our customers. Blueyonderairlines.com is already registered to the company and is used for e-mail addresses. This must not change. 

I am concerned about security risks of the new Web site. Our DNS information must remain secure. The Manifest group must still remain a separate group for security purposes

All servers must be upgraded to Windows Server 2003 to meet the new airline security requirements and to ease the management concerns we are currently facing. We are planning a hardware refresh within the next year to upgrade all computers to a minimum of 1 GB of RAM and seven SCSI hard disk drivers per server. 

I anticipate that 300 new devices will be added to the network in the Sydney office over the next two years. 

Network administrator 
The WAN links are unreliable and can fail for hours at a time. We cannot copy large files because of this, and there are bandwidth problems related to slow links and unreliability. 

Fault tolerance for the domains will be required for instances when the WAN links are down or when a single server fails. 

We have adequate hardware, but performance for our existing Windows 2000 Server computer is inadequate. 

The Exchange 2000 Server computer has excessively high processor utilization once a day. The high utilization lasts for almost an hour and users report that processing is very slow during this time. There cannot be servers in branch offices because of smart card authentication requirement. 

A separate network administrator will be appointed to manage the Manifest application. The NetBIOS name of the corp.bloueyonderairlines.com domain is Airlines. Some applications still rely on this NetBIOS name to operate. 

Currently, if service packs or new applications need to be installed on computers in the branch offices, a network administrator has to fly to that location. We do this because users do not have permissions to install software on their computers. 

Flight Officer 
Our network is generally performing adequately. However, I frequently have to make long-distance calls to the office to establish a dial-up connection. Often I do not get a connection because of a busy tone, and when I do get a connection I frequently get disconnected. 

Office Worker 
It takes more than five minutes to log on to the network, and when I finally log on to the network, my computer tries to automatically install software that eventually fails. However, I have noticed that my computer seems to respond better after this occurs. 

I have to remember too many passwords. Currently, there are three: one for the domain, one for access to the ATC application, and one for access to the Manifest application. 

Business requirements 
Business Drivers 
The following business requirements must be considered: 
  • Blue Yonder Airlines wants to establish a public Web site that is available 24 hours a day, seven days a week. New customers must be able to access this Web site by using a single URL. 
  • Internal users must be able to access resources by providing their respective user names and passwords once per session. 
  • Managers in the finance department are dissatisfied with the high number of expense claims they receive from flight officers for dial-up connections to the ISP. 
Organizational Goals 
The following organizational requirements must be considered: 
  • The new branch offices will be established in Berlin and Paris. 
  • The new offices will connect to each other by means of a permanent WAN link. 
  • The new offices will share a new WAN link to the Sydney office. 
  • The expected number of new users in these offices is 100. 
  • A new European administrative group will be established to manage these users and their resources. 
Security 
The following security requirements must be considered: 
  • Flight officers must be able to access secure data from any company office or from any remote location. 
  • Flight officers and users of the Manifest application must be able to access Manifest data. 
Customer Requirements 
The following customer requirements must be considered 
  • User accounts must be created correctly in Active Directory and must be able to use all features of Active Directory and the ATC application simultaneously. 
  • Faster name resolution is required when connecting to internal servers and external Web sites. 
Technical requirements 
Active Directory 
The following Active Directory requirements must be considered: 
  • The Manifest application requires administration to meet European legal requirements. 
  • Software deployment and security settings are different for users in each department. As users travel between locations, their user information must always be available locally. 
  • Each branch office needs to resolve all NetBIOS names even if a WAN link goes down. 
  • The browser settings must be distributed to computers by using GPOs. 
  • The company’s administrative model will change to a decentralized model with the addition of a second administrative group in Europe. Both administrative groups require smart card authentication for server administration. 
  • VPN access is required for flight officers only. 
Network infrastructure 
The following infrastructure requirements must be considered: 
  • The planned network is shown in the Planned Network Infrastructure exhibit. 
  • Redundancy for any service must be provided if a single service fails. 
  • A WAN link from the newly established Berlin office will connect to the Sydney office. Another WAN link will connect the Paris office with the Berlin office. 
  • User’s reports of lengthy logon times must be resolved. 
  • Daily updates of antivirus software must be executed for all desktop computers. 
Blue Yonder Airlines (11 Questions) 

QUESTION NO: 1 
You are designing a strategy for the placement of servers to meet the business and technical 
requirements. What should you do? 


QUESTION NO: 2 
You are designing a top-level OU structure to meet the business and technical requirements. Which topevel OU or OUs should you use? (Choose all that apply.) 

A. ATC 
B. Paris 
C. Berlin 
D. Sydney 
E. Manifast 
F. Human Resources 

QUESTION NO: 3 
You are designing an authentication solution to meet the security needs of the network administrators. You install an enterprise certification authority (CA). Which three additional actions should you take? 
(Each correct answer presents part of the solution. Select three). 

A. Enroll each administrative account for a smart card authentication certificate. 
B. Configure autoenrollment for computer authentication certificates. 
C. Install a smart card reader on each server computer. 
D. Install a smart card reader on each network administrator’s computer. 
E. Configure each administrative account to require a smart card for interactive logon. 
F. Configure the Default Domain Policy GPO to require smart cards for interactive login. 

QUESTION NO: 4 
You are designing a domain naming strategy for the new environment. Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.) 

A. Register airlines.com as a new domain name. 
B. Register manifest.airlines.com as a new domain name. 
C. Register manifest.blueyonderairlines.com as a new domain name. 
D. Maintain the existing blueyonderairlines.com registered domain name. 
E. Use the UPN suffix of airlines.com for all new users. 
F. Use the UPN suffix of blueyonderairlines.com for all new users. 

QUESTION NO: 5 
You are designing a site topology for the new Active Directory environment. What should you do? 

A. Create one site for all offices. Place the subnets for the four branch offices and the Sydney main office in this site. 
B. Create two sites: one site for the four branch offices and one site for the Sydney main office. Place the subnets for the branch offices in one site. Place the subnet for the Sydney main office in the other site. 
C. Create three sites: one site for the four branch offices, one site for the Sydney main office, and one site for the Sydney satellite offices. 
D. Create four sites: one for the Melbourne and Perth branch offices, one site for the Berlin and Paris branch offices, one site for the Sydney main office, and one site for the Sydney satellite offices. 
E. Create five sites; one site for the Melbourne branch office, one site for the Perth branch office, one site for the Berlin branch office, one site for the Paris branch office, and one site for the Sydney main office. Place the subnets for each branch office and the Sydney main office in their respective sites. 

QUESTION NO: 6 
You are designing a strategy to enable the ATC application to successfully resolve computer names. Which name resolution method should you use? 

A. DNS 
B. WINS 
C. Hosts file 
D. Lmhosts file 

QUESTION NO: 7 
You are designing a DNS implementation strategy to meet the business and technical requirements. What should you do? 

A. Configure a domain controller in each branch office to contain a secondary zone of the contoso.com domain. 
B. Configure the DNS Server service on a domain controller in each office. Configure an Active Directory-integrated zone to replicate to all DNS servers. 
C. Configure an Active Directory-integrated zone on a domain controller in Sydney. Configure this zone to replicate to all domain controllers. 
D. Configure a primary zone for blueyonderairlines.com on a domain controller in Sydney. Configure a secondary zone on another DNS server in Sydney. 

QUESTION NO: 8 
You are designing a strategy to meet the security and financial requirements related to the Manifest application. What should you do? 

A. Configure a VPN server in Sydney. 
B. Configure a VPN server in each branch office. 
C. Configure a dial-up server in Sydney 
D. Configure a dial-up server in each branch office. 

QUESTION NO: 9 
You are designing the placement of the PDC emulator operations master role. In which location or locations should you place the role? (Choose all that apply.) 

A. Sydney 
B. Melbourne 
C. Perth 
D. Berlin 
E. Paris 

QUESTION NO: 10 
You are designing a strategy to improve the performance and reliability of the domain controllers. What should you do? 

A. Create one RAID-5 volume. 
B. Create two RAID-5 volumes. 
C. Create one mirrored volume and two RAID-5 volumes. 
D. Create two mirrored volumes and one RAID-5 volume. 

QUESTION NO: 11 
You are designing an IP address management strategy to address the anticipated growth of the company and to meet the business and technical requirements. What should you do? 

A.Install one DHCP server in each branch office and in Sydney. On each server, create duplicate scopes that contain the necessary scope options. Configure the scopes to assign all of the available IP addresses to each office. 
B. Install one DHCP server in each branch office and in Sydney. On each server, create duplicate scopes that contain the necessary scope options. Configure the scopes to assign half of the available IP addresses to each office. 
C. Install two DHCP servers in each branch office and in Sydney. Authorize one server in each office. On each server, create duplicate scopes that contain the necessary scope options. Configure the scope to assign half of the available IP addresses to each office. 
D. Install two DHCP servers in each branch office and in Sydney. Authorize both servers in each office. On each server, create duplicate scopes that contain the necessary scope options. Configure the scope to assign half of the available IP addresses to each office. 

2009年3月30日星期一

Case Study: Woodgrove Bank

Overview 
Woodgrove Bank is a financial institution that operates in the Netherlands. The company’s primary business is providing residential and commercial mortgages. 

The Company wants to offer its customers secure Internet access to a mortgage management application. 

Physical Location 
The Company's main office is located in Amsterdam. The Company has two branch offices in the 
following Locations:  
  • Utrecht 
  • The Hague 
The Company has 200 local banks that are located throughout the Netherlands. The number of users in each location is shown in the following: 

Location Number of Users 
1. Amsterdam 2,500 
2. Utrecht 650 
3. The Hague 800 
4. Each Local Bank 10-100 

Planned Changes 
The Company wants to convert its mortgage management application to a multitier application named NewApp. 

To support this new environment, the company will upgrade its servers to Windows Server 2003. 

Business Processes 
The Amsterdam office and each branch office has its own IT staff in addition, most of the larger local banks have their own IT staff. 

Currently, Local bank employees have access to their local resources and to resources at the Amsterdam office. Each office uses it own instance of a business-critical mortgage application. 

The IT staff at the Amsterdam office includes a development team. The development team is responsible for developing and testing NewApp. 

Infrastructure 
Directory Services 

The Relevant portion of current domain structure is shown in the Existing Domain Model exhibit :


The Company has a Windows NT 4.0 environment that has more that 200 domains; each domain has a two-way trust relationship with the domain at Amsterdam office. 

Currently, Domain administrators manage their own domains. Each Location that has a local 
administrator currently manages its own users and resources. In addition, these administrators share responsibility for administrating ring locations that do not have an IT staff. 

Network Infrastructure 
Domain Controllers vary from single processor servers at 700Mhz to processor Quad server at 1.5 GHz. 

Client Computers run Windows 98, Windows NT Workstation 4.0 and Windows 2000 professional. There are also some Unix Client Computers. 

Managers are issued portable Computers that contain confidential business information. These portable computers are equipped with smart card readers. Managers use portable computers to establish VPN connections to the Amsterdam office when they travel. 

Problem Statements 
The following business problems must be considered: 
  • Employees at local banks are often unable to serve customers because of failure of the mortgage application. The failure sometimes lasts many hours because there is nobody available to fix it. 
  • The Development team has access to the occasionally, unapproved changes that are made to the application, resulting in unnecessary downtime. 
  • Deployment of new operating systems takes a long time because network administrators have to each local bank. 
Chief Executive Officer 
I want Woodgroove bank to be visible on the Internet. I want NewApp to be easily accessible to our customers by using the Internet. 

The newly designed environment will help to minimize the amount of administrative effort for all IT-related operational tasks. 

For business reasons, I will not allow domain upgrades. 

Officer Worker 
Currently, it is sometimes difficult to access the information I need. For different information, I have to remember different passwords. In the new environment, I want to have one account and one password. 

Business Requirements 
Business Drivers 
The following business requirements must be considered: 

  • Woodgroove Bank wants their company name to be visible on the Internet with. 
  • Customers must be able to access mortgage information 24 hours a day, seven days a week. 
  • The Company wants to reduce the costs of managing branch offices. 


Organizational Goals 
The following organizational requirement must be considered 
  • Bank employees need to be able to make a secure connection from their homes to the corporate network. 
  • The company currently has 1 million customers. About half of them have mortgages. In the next 5 years, the infrastructure must be able to accommodate at least 2 million customers, with about 1 million customers having mortgages. 
Security 
The following security requirement must be considered 
  • Bank employees must have access to resources at the Amsterdam office, their local banks, and NewApp. 
  • The Company must ensure that servers can be easily restored when one or more servers fail, with minimum loss of data and minimum downtime. 
  • The Company needs the highest possible secure authentication method for all computers that contain confidential information. 
NewApp Requirements 
The following NewApp requirement must be considered 
  • NewApp is a web-based application that contains tools that are used by customers and tools that are used by employees. 
  • Employees from all locations will connect to the web servers to access NewApp. 
  • NewApp stores customer information in Active Directory by using custom classes and attributes. 
  • NewApp stores mortgage information in the NewApp database. 
  • Developers need to be able to test the NewApp schema modifications without affecting any other servers. 
  • NewApp must be available 24 hours a day, seven days a week. 
  • Because of national legal requirements, the server that contains mortgage information requires several security settings that are different from those on the NewApp application servers. 

Technical Requirements 
Active Directory 
The following Active Directory requirement must be considered 
  • Active Directory must be deployed to support NewApp. 
  • All domain controllers in the new environment must run Windows Server 2003. 
  • Administration of Active Directory will not be performed at the local banks. 
  • Each user should be authenticated locally when possible. 
  • Domain Controllers will be placed in all locations that support more than 50 users. 
Network Infrastructure 
The following Network Infrastructure requirement must be considered 
The planned network is shown in the planned Network Infrastructure exhibit. 
Network Infrastructure Exhibit: 

Planned Exhibit: 


Bandwidth between the Amsterdam office and the branch offices is not an issue. However, some local banks report that there are slow response times to the branch offices or to the Amsterdam office. 

The company uses some legacy applications that are heavily dependent on NetBios name resolution. These applications will also be used after the migration. 

The Company needs to use the smallest subnets possible in each location because of planned future expansion to include many additional branch offices. 

VPN servers will be placed at the Amsterdam office only. 

It is crucial to ensure 24-hour availability of the VPN servers. 

Dial-up servers exist in each branch office to allow network administrators to administer each branch office in the event of WAN link failure. 

Management of all remote access must be centralized. 


Woodgrove Bank (9 Questions) 

QUESTION NO 1: 
You are designing a forest structure to meet the business and technical requirements. How many forests should you create? 

A. One 
B. Two 
C. Three 
D. Four 

QUESTION NO 2 
You are designing an organizational unit (OU) structure to manage the New App servers. What should you do? 

A. Create one OU that includes both the web servers and the database servers. 
B. Create one OU that includes the web servers and one OU that includes the database servers. 
C. Create one OU that includes the web servers. Then Place the database servers in the Computer Containers. 
D. Place the web server and the database servers in the Domain Controller OU. 

QUESTION NO 3 
You are designing a new NETBIOS naming strategy for the corporate environment. Which domain name should you use? 

A. ad 
B. woodgrovead 
C. woodgrovebank 
D. woodgrovebank.com 

QUESTION NO 4 
You need to configure the security settings for the new app servers. Which two actions should you perform? (Each correct answer presents part of the solutions. (Choose two) 

A. Create a Group policy object (GPO) for the web servers. 
B. Create a Group policy object (GPO) for the database servers. 
C. Modify the Default Domain Policy. 
D. Modify the Default Domain Controllers Policy. 

QUESTION NO 5 
You are designing an Active Directory site infrastructure to meet the bussiness and technical requirements. What should you do? 

A. Create one site for each office and each local bank. 
B. Create one site for all offices. Create one site for all local banks. 
C. Create one site for Amsterdam. Create one site for all branch office and all local banks. 
D. Create one site for Amsterdam. Create one site for the Utercht brach office. Create one site for that Hague branch office. Place half the local banks in the utercht site and half the local banks in the Hague site. 
E. Create one site for Amsterdam. Create one site for the Utercht brach office. Create one site for each local bank that has more than 50 users. Place all the other local banks in the Amsterdam Site. 

QUESTION NO 6 
You are designing a strategy to ensure that DNS queries always take the most efficient route to get resolved. Which action or actions should you perform? (Choose all that apply) 

A. Configure conditional forwarding on the corporate DNS servers to point the development DNS servers. 
B. Configure conditional forwarding on the development DNS servers to point the corporate DNS servers. 
C. Configure conditional forwarding on the perimeter network DNS servers to point the corporate and development DNS servers. 
D. Configure forwarding on the corporate and development DNS servers to point the perimeter network DNS servers. 
E. Disable root hints on the perimeter network DNS Servers. 

QUESTION NO 7 
You are designing a remote access strategy to meet the business & technical requirements. Which authentication mechanism should you use? 

A. MS-CHAP v2. 
B. Internet Authentication service (IAS). 
C. Multilink & Bandwidth Allocation Protocol (BAP). 
D. Remote access policies on all servers running Routing & Remote Access. 

QUESTION NO 8 
You are designing the TCP/IP addressing scheme for the company. What should you do? 
To Answer, Drag the Appropriate subnet mask or masks to the correct location or locations in the work area. 


QUESTION NO 9 
You are designing a VPN Server strategy to meet the business and technical requirement. What should you do? 

A. Configure all client computers to point to a VPN server in Amsterdam. 
B. Configure all client computers to use Multilink Bandwidth Allocation Protocol (BAP). 
C. Create a network Load Balancing cluster of VPN servers. 
D. Create a shutdown script for the VPN servers to delete the host(A) resource record of the VPN sever from the DNS database when the VPN server are shutdown. 

2009年3月27日星期五

Case Study: Consolidated Messenger

Overview 
Consolidated Messenger is a transportation and express delivery company serving the continental United States. 

The company maintains a commitment to its customers to expedite deliveries within contracted guidelines and offers a 100 percent refund to the customers if the contract is not fulfilled. 

Physical Locations 
The company's main office is in Chicago. The company has two branch offices in the following locations:  
  • Boston 
  • San Diego 
Planned Changes 
The company is expanding its business into the Asian market by acquiring Contoso, ltd., which is an Asian import company located in San Francisco. Contoso, Ltd has established relationships with shipping companies and various retail firms in China. Furthermore, Contoso, Ltd. has a strong background in working with the governmental trade protocol in china. 

Consolidated Messenger is also planning changes to enable the office and the branch office to work together more effectively. 

Business Processes 
Consolidated Messenger consists of the following primary departments: 
  • Accounting 
  • Customer service 
  • Delivery 
  • Human Resources (HR) 
  • Information Technology (IT) 
  • Management 
The company has a decentralized IT structure. The Chicago office and each branch office have its own IT staff. 

Each office maintains its resources separately. Each office is using the same delivery tracking database, named Deliveries, but information is not shared between the three offices. 

Each office uses an application named TrackingApp to update the tracking database. 

Every morning, delivery personnel receive a printed list of deliveries to be made for the day. They can contact the appropriate office for additional information, as needed. 

Infrastructure 
Directory Services 

The existing domain model is shown in the Existing Domain Model exhibit. 


Consolidated Messenger has Windows NT 4.0 domains in the branch offices. The Chicago office has a Windows 2000 Active Directory domain named ad.consolidatedmessenger.com 


The domain for the Chicago office contains four toplevel organizational units (OUs) named Accounting, Customer Service, Human Resources, and Delivery. The network consists of a single Active Directory site. 

Contoso, Ltd., has a Windows NT4.0 domain in its San Francisco office. 

Network Infrastructure: 
The company's existing network infrastructure is shown in the Existing Network Infrastructure exhibit. 



Client computers in the accounting, IT and management departments, at Consolidated Messenger, run either Windows 2000 professional or Windows XP professional. Client computers in the customer service department run windows 98. 

Client computers at Contoso, Ltd runs either Windows 98 or Windows NT workstation 4.0. 

Consolidated Messenger has a web site hosted by an ISP in Chicago. The web site, named www.consolidatedmessenger.com, is available for Internet customers to place orders or track deliveries. 

Contoso, Ltd., also has a web site, named www.contoso.com, which provides information to users about Contoso, Ltd. It is hosted by an ISP in San Francisco. The ISP in San Francisco has DNS on a Unix Server. 

The IP address in use for Consolidated Messenger is shown in the Network addresses exhibit. 

 

Problem Statements 
The following business problems must be considered: 
  • Consolidated Messenger needs to create a better delivery tracking mechanism for the existing offices. Currently, each office provides point-to-point delivery as orders come in. 
  • They are functioning adequately, but there is room for improved operational efficiency. For example, the Chicago office sometimes delivers into the northeast, which overlaps with the territory of the Boston office. Both the Chicago office and the Boston office might deliver to the west coast, which is the territory of the San Diego office. A centralized database is required to make tracking delivers more efficient. 
  • When Consolidated Messenger implements a centralized version of the Delivers database, there must be a way to ensure continuous access to up to date delivery data, regardless of WAN status. 
  • Consolidated Messenger wants to provide a better solution for delivery personnel to access 
  • information about scheduled deliveries, than printed delivery lists. 
  • Consolidated Messenger will need to bring Contoso, ltd, up to its technology standards. Contoso, ltd., does not use much technology. Although there is a Windows NT 4.0 domain present, there is a network administrator and there has been a great deal of turnover in this job. As a result, there is not adequate security for its computers. It does not adequately track Shipments, Inventory, Payable, or Receivable. Although Contoso, ltd. uses a spreadsheet application for its inventory listings it is still primarily a paperbased company. 
Chief Executive Office 
With the acquisition of Contoso, ltd., by Consolidated Messenger, I am concerned that it should be a part of our overall business model, yet remain separate because it is a new venture. This is a positive addition to our current line of business. I want to be sure that have a method for clearly tracking the contributions that Contoso, ltd., makes to our business. 

Chief Information Officer 
I have two major goals for our Deliveries database. First, I want a method for integrating the data between the offices. Second, I want a directory services structure that provides a more straight forward model for maintenance. 

I also want an improved user experience when accessing centralized resources in the Chicago office. Additionally, I have strong reservations regarding the inexperience of the new IT staff to be hired in the San Francisco office. I want to make sure that we are monitoring their activities. 

I foresee substantial expenditure for upgrading desktop computers, and salaries for a new IT staff in the Contoso, Ltd., division. We need to provide sufficient access to Contoso, Ltd.; however, we need to spend only the money necessary to achieve this goal. 

Managers, Contoso, Ltd 
I am unsure if the restrictions imposed by our new parent company will benefit the business of Contoso, Ltd. On the other hand, I fully recognize that being part of a larger company can provide us with more financial stability. 

Business Requirements 
The following business requirement must be considered:  
  • Contoso, Ltd., will be a separate division within Consolidated Messenger, maintaining its line of business because Contoso Ltd., is a new endeavor, Consolidated Messenger has elected to keep the namespace separate so that the internal staff will not be confused. 
  • The duplication of effort in maintaining the Deliveries database between Consolidated Messenger branch offices must be reduced. 
  • Contoso needs to replace spreadsheets. The database, to be named Inventory, will be created and administered in the Chicago office. The IT staff in the Chicago office will be responsible for the maintenance of this database, and will be replicated from the San Francisco office to the Chicago office. It is anticipated that database replication will exceed the available bandwidth provided by the VPN connection between the San Francisco office and the Chicago office. 
Organizational Goals 
The following organizational requirements must be considered: 
  • Integrating the separate database into a single nationwide database is extremely important to the business. 
  • Delivery workers will begin using PDAs to download delivery information from the Deliveries database. As a result, they will discontinue telephone check in for delivery information. As each delivery is completed, the customer will sign the PDA. At the end of each day, the delivery information will be batch uploaded from each PDA to the Deliveries database either from a company office or, if delivery personnel are too far away from a company office, a remote connection.  
  • Each office must support wireless access for PDAs 
Security 
The following security requirements must be considered: 
  • Appropriate permissions to trackingapp, the Deliveries database, and other resources will need to be established for users based on that user's job function. Job functions include customer service, delivery personnel, accounting, and management. 
  • The IT staff in the Chicago office will audit administrative activity in all domains, particulary in Contoso,Ltd., domain, this includes interactive logons; shutdowns and restarts of domain controllers; changes to security logging; and changes to user and group accounts. 
Tchnical Requirements 
Active Directory 
The following Active Directory requirements must be considered: 
  • Enterprise Active Directory administration will take place in the Chicago office. Additionally, the IT staff in the Chicago office has the primary responsibilities for administration of the Deliveries database. 
  • Each current Consolidated Messenger domain will undergo an in place upgrade. Contoso, Ltd., will be added to the forest, but will maintain its separate namespace. The Contoso, Ltd., domain will be named ad.contoso.com. Their will be a single forest design with a minimum number of domains. 
  • Upgrading the Windows NT 4.0 domains in the Boston and San Diego offices must be optimized to reduce the need for network administrators to travel between offices. 
  • Permissions must be maintained. Additional groups can be created for the Deliveries database, as needed. 
  • User and group accounts for Contoso, Ltd. will be recreated. However, desktop settings for Contoso, Ltd., users must be preserved. 
Network Infrastructure 
The following Infrastructure requirements must be considered: 
  • All Contoso, Ltd., client computers will run Windows XP Professional. Consolidated Messenger has decided to migrate the user settings from the existing Contoso, Ltd., client computers to ease the transition. 
  • The Deliveries database is a missioncritical resource for Consolidated Messenger. Database access for the Deliveries databases must be maintained in the event that WAN connectivity is lost. 
  • All domain controllers will be configured as DNS servers. Client computers will be configured to point to the local DNS server.  
  • DNS zones must be secured. 
  • VPNs will be implemented in all locations to support remote access for wireless devices. 
  • Remote access policies will be centralized. 
  • A single DHCP server will be configured in each office. In the event of a DHCP server failure, client computers must be able to obtain an IP address. 

Consolidated Messenger (9 Questions) 

QUESTION NO: 1 
You are designing the DNS zone to support the Active Directory domain for Contoso.Ltd. Which two actions should you perform? (Each Correct answer presents part of the solution. Choose two). 

A. Create ad.contoso.com as a standard primary DNS Zone. 
B. Create ad.contoso.com as an Active DirectoryIntegrated DNS Zone. 
C. Enable only authorized client computers to update DNS. 
D. Configure a zone transfer between the DNS server at the ISP and the DNS servers at Contoso.Ltd. 

QUESTION NO: 2 
Exhibit 

You are designing the Active Directory Infrastructure for the new forest to meet the business and technical requirements. What should you do? 

A. Choose forest model A. 
B. Choose forest model B. 
C. Choose forest model C. 
D. Choose forest model D. 

QUESTION NO: 3 
You are designing a strategy for adding the additional hardware necessary to support Contoso, Ltd. What should you do? 
A. Add a T1 Wan Link Between Chicago and San Francisco. 
B. Add a T3 Wan Link Between Chicago and San Francisco. 
C. Add a Basic ISDN Connection between Chicago and San Francisco. 
D. Configure HighSpeed modems in Chicago and San Francisco to support demand-dial routing. 

QUESTION NO: 4 
You are designing a client computer upgrade strategy for Contoso.Ltd. What should you do? 
A. Use the ldifde command to migrate user settings. 
B. Use the User State Migration Tool (USMT) to Migrate user settings. 
C. Create trust relationships between the Chicago domain and the San Francisco domain. Use the Active Directory Migration Tool (ADMT) to migrate user settings. 
D. Create trust relationships between the forest root domain and the San Francisco domain. Use the Active Directory Migration Tool (ADMT) to migrate user settings. 

QUESTION NO: 5 
You are designing a DNS Name resolution strategy for the client computer in the customer service department. What are the two possible ways to achieve the goal? (Each Correct answer presents a complete solution. (Choose two) 

A. Create a reverse lookup zone in DNS for each new Domain. 
B. Add a WINS lookup record to the DNS forward lookup zone. 
C. Add a WINS reverse record to the DNS reverse lookup zone. 
D. Enable Dynamic updates for DownLevel client computers on each DHCP server. 
E. Install the Active Directory Client on All Computers in the Customer service department. 

QUESTION NO: 6 
You are designing DNS implemetation Strategy for the new Infrastruce. Which two actions should you perform? (Each correct answer represents part of the solution. Choose two). 
A. Create a Stub Zone in each domain of the root zone. 
B. Create a _msdcs subdomain in a new zone on the root domain. 
C. Replicate the _msdcs subdomain across the roor domain. 
D. Replicate the _msdcs subdomain to the ForestDNS zone applciation partition. 
E. Configure a zone transfer of the _msdcs subdomain to secondary zone on all DNS servers in the forest. 

QUESTION NO: 7 
You are designing a remote access strategy to meet the business and technical Requirement. What should you do? 

A. Configure each server running Routing and Remote Access as a RADIUS Client. 
B. Add a Remote Access policy to each server running Routing and Remote Access. Configure the Access method as VPN access. 
C. Add a Remote Access policy to each server running Routing and Remote Access. Configure the Access method as dialup access. 
D. Add a Remote Access policy to each server running Routing and Remote Access. Configure the Access method as wireless access. 

QUESTION NO: 8 
You are designing a DNS implementing strategy to meet the business and technical requirement. Which type of zone should you use? 

A. Sub Zones 
B. Standard Primary Zones 
C. Secondary Zones 
D. Active DirectoryIntegrated Zones 

QUESTION NO: 9 
You are designing a strategy to perform inplace upgrade of domain controller in Boston and San Diego. Which method should you use? 

A. adprep 
B. sysprep 
C. Answer File 
D. Remote Installtion Services (RIS)