Active Directory Infrastructure Design Flashcards
6 cards from real 70-413 Exam practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Active Directory Infrastructure Design flashcards as text
What is the recommended approach when designing an AD DS environment where two divisions require completely separate security boundaries?
Answer: Multiple forests with forest trusts
Multiple forests provide the strongest security isolation because each forest has its own schema, configuration, and administrative boundary.
Which trust type improves authentication performance by creating a direct trust path between two domains in the same forest that are not directly connected?
Answer: Shortcut trust
Shortcut trusts create a direct Kerberos trust path between domains, bypassing the need to traverse the full domain tree hierarchy.
When planning AD DS site link costs, what factor should primarily drive the cost values you assign?
Answer: Available network bandwidth between sites
Site link costs should inversely reflect available bandwidth so that replication traffic is directed over the most efficient network paths.
Which Active Directory feature introduced in Windows Server 2008 R2 allows administrators to restore accidentally deleted objects while preserving all attributes?
Answer: Active Directory Recycle Bin
The Active Directory Recycle Bin allows full recovery of deleted objects including all linked and non-linked attributes without requiring a restore from backup.
What is the minimum forest functional level required to enable the Active Directory Recycle Bin?
Answer: Windows Server 2008 R2
The Active Directory Recycle Bin feature requires the forest functional level to be raised to Windows Server 2008 R2 or higher.
Which command-line tool is used to seize FSMO roles when the current role holder is permanently unavailable and cannot be brought back online?
Answer: ntdsutil
The ntdsutil command-line tool is used to seize (forcibly transfer) FSMO roles from a domain controller that is permanently offline.