Microsoft Certified Systems Engineer (MCSE) — Questions and Answers
Question 1: What tool in Windows XP allows an administrator to view and manage all running processes and their resource usage?
- Event Viewer
- Performance Monitor
- Computer Management
- Task Manager (taskmgr.exe) (Correct answer)
Correct answer: Task Manager (taskmgr.exe)
Task Manager provides a real-time view of running applications, processes, CPU usage, memory consumption, and network activity.
Question 2: Which command-line tool would you use to add a static route on Windows Server 2003 that persists after a reboot?
- netsh routing ip add persistentroute
- ipconfig /route add persistent
- route add -p (Correct answer)
- routemon add
Correct answer: route add -p
The 'route add -p' command adds a persistent static route to the Windows routing table that survives reboots.
Question 3: What is the purpose of a stub zone in Windows Server 2003 DNS?
- Forwards all queries to another DNS server
- Contains only NS, SOA, and A records of authoritative servers (Correct answer)
- Stores cached records from previous queries
- Resolves names without a full zone copy
Correct answer: Contains only NS, SOA, and A records of authoritative servers
A stub zone contains only the NS, SOA, and glue A records needed to identify the authoritative servers for a zone, reducing zone transfer traffic.
Question 4: You need to delegate the ability to reset passwords for users in the HR OU to a help desk group. Which tool should you use?
- Local Security Policy
- Active Directory Sites and Services
- Active Directory Users and Computers with the Delegation of Control Wizard (Correct answer)
- Group Policy Object Editor
Correct answer: Active Directory Users and Computers with the Delegation of Control Wizard
The Delegation of Control Wizard in Active Directory Users and Computers allows granular permission assignment, such as resetting passwords for a specific OU.
Question 5: What is the purpose of 802.1X authentication in a wired or wireless network security design?
- Requires devices to authenticate before gaining network access (Correct answer)
- Encrypts all data between the access point and client
- Assigns VLAN membership based on MAC address
- Provides DHCP address assignment for wireless clients
Correct answer: Requires devices to authenticate before gaining network access
802.1X is a port-based network access control standard that requires clients to authenticate (typically via RADIUS) before being granted network access.
Question 6: What does enabling 'Restrict CD-ROM access to locally logged-on user only' accomplish in Windows Server 2003?
- Encrypts all data written to CD-ROM
- Disables AutoRun for CD-ROM drives
- Prevents network users from accessing the local CD-ROM drive (Correct answer)
- Audits all CD-ROM access attempts
Correct answer: Prevents network users from accessing the local CD-ROM drive
This security setting ensures that only the user physically logged on at the console can access the CD-ROM, preventing remote users from reading sensitive media.
Question 7: You are configuring DHCP superscopes on Windows Server 2003. When is a superscope required?
- When you need to configure option 003 gateway on a per-class basis
- When multiple logical IP subnets exist on a single physical network segment (multinet) (Correct answer)
- When you want to reserve IP addresses for specific MAC addresses
- When DHCP clients span multiple physical subnets connected by a router
Correct answer: When multiple logical IP subnets exist on a single physical network segment (multinet)
A superscope groups multiple child scopes to serve clients on a multinet — a single physical segment hosting more than one logical subnet.
Question 8: You want Windows Server 2003 to automatically register its A and PTR records in DNS. The DNS zone does not allow unauthenticated dynamic updates. What must be true for dynamic registration to succeed?
- The server must be joined to the domain and the zone must accept secure-only dynamic updates with the computer account having write permission (Correct answer)
- The zone must be a standard primary zone stored in a flat file
- The DHCP server must perform proxy registration on behalf of all clients
- The DNS server must also be the PDC Emulator in the domain
Correct answer: The server must be joined to the domain and the zone must accept secure-only dynamic updates with the computer account having write permission
Secure dynamic updates require the computer to be domain-joined; its machine account authenticates via Kerberos to write records in the AD-integrated zone.
Question 9: What is the effect of setting the LAN Manager Authentication Level to 'Send NTLMv2 response only. Refuse LM & NTLM'?
- Enables Kerberos for legacy systems
- Forces all authentication to use NTLMv2, blocking weaker LM and NTLM protocols (Correct answer)
- Allows only smart card logon
- Disables all network authentication
Correct answer: Forces all authentication to use NTLMv2, blocking weaker LM and NTLM protocols
This setting maximizes NTLM security by refusing the weaker LM and NTLMv1 authentication protocols, requiring all clients to use NTLMv2.
Question 10: What does placing a Global Catalog server in each site accomplish?
- Enables DNS zone transfers between sites
- Eliminates the need to cross WAN links for universal group membership queries during logon (Correct answer)
- Provides DHCP failover capability
- Creates a backup domain controller
Correct answer: Eliminates the need to cross WAN links for universal group membership queries during logon
A local GC server ensures that universal group membership lookups during user logon do not require traversing slow WAN links to a remote site.
Question 11: Which Windows XP troubleshooting mode loads only basic files and drivers, bypassing startup programs?
- Safe Mode (Correct answer)
- Recovery Console
- Last Known Good Configuration
- Debugging Mode
Correct answer: Safe Mode
Safe Mode starts Windows XP with a minimal set of drivers and services, allowing troubleshooting of problems caused by faulty drivers or startup programs.
Question 12: What is the purpose of a conditional forwarder in Windows Server 2003 DNS?
- Forwards queries for specific domains to designated DNS servers (Correct answer)
- Replicates zone data between DNS servers
- Caches negative responses for faster resolution
- Resolves all external queries to a single ISP DNS server
Correct answer: Forwards queries for specific domains to designated DNS servers
Conditional forwarders direct DNS queries for specific domain namespaces to specified DNS servers, useful for resolving partner or subsidiary company domains.
Question 13: Your Windows Server 2003 network uses IPSec policies. You need to ensure that all communication between domain controllers and member servers is encrypted without requiring manual configuration on each server. What is the most efficient approach?
- Enable IPSec in the RRAS configuration on all servers
- Configure a local IPSec policy on each server individually
- Create a certificate-based IPSec rule in the Default Domain Policy
- Deploy an IPSec policy via Group Policy to an OU containing the servers (Correct answer)
Correct answer: Deploy an IPSec policy via Group Policy to an OU containing the servers
Deploying IPSec policy through Group Policy to an Organizational Unit is the most efficient method to consistently apply encryption settings across multiple servers.
Question 14: Which DNS record type is responsible for defining the mail servers that accept email for a domain?
- SRV (Service Locator)
- MX (Mail Exchanger) (Correct answer)
- TXT (Text)
- NS (Name Server)
Correct answer: MX (Mail Exchanger)
MX records specify the hostname(s) of mail servers responsible for accepting SMTP email for a domain, along with their preference values.
Question 15: You want to ensure that a critical application service restarts automatically if it crashes on Windows Server 2003. Where do you configure this?
- Group Policy > Computer Configuration
- Services MMC snap-in > service Recovery tab (Correct answer)
- Task Scheduler
- System Properties > Advanced
Correct answer: Services MMC snap-in > service Recovery tab
The Recovery tab in the Services console allows you to define actions (such as restart) for first, second, and subsequent failures of a service.
Question 16: A Windows Server 2003 DHCP server is not responding to client requests. You run 'netsh dhcp server show scope' and see the scope is active. What is the MOST likely cause?
- The DHCP server is not authorized in Active Directory (Correct answer)
- The DNS server is offline
- The default gateway is misconfigured on the scope
- The scope has no exclusion ranges defined
Correct answer: The DHCP server is not authorized in Active Directory
In an Active Directory environment, DHCP servers must be authorized; an unauthorized server silently drops all DCHP requests.
Question 17: Which Windows Server 2003 feature allows administrators to restrict which software can run on a computer?
- DEP (Data Execution Prevention)
- AppLocker
- Software Restriction Policies (Correct answer)
- Windows Defender
Correct answer: Software Restriction Policies
Software Restriction Policies use rules based on certificate, hash, path, or zone to control which applications are allowed or denied from running.
Question 18: What is the function of the WINS server in a Windows network?
- Manages DNS zone transfers
- Resolves NetBIOS names to IP addresses (Correct answer)
- Authenticates domain users
- Assigns IP addresses to clients
Correct answer: Resolves NetBIOS names to IP addresses
WINS (Windows Internet Name Service) provides dynamic NetBIOS name-to-IP address resolution for pre-Windows 2000 applications and legacy compatibility.
Question 19: When designing an Active Directory forest structure, what is the primary reason to create multiple forests?
- To support more than 1,000 users
- To maintain separate security boundaries (Correct answer)
- To enable multiple DNS namespaces
- To reduce replication traffic
Correct answer: To maintain separate security boundaries
Separate forests provide the strongest security boundary since administrative access cannot cross forest boundaries without explicit trusts.
Question 20: A client running Windows XP receives the IP address 169.254.x.x even though a DHCP server is reachable. After checking, you confirm the DHCP server has an active scope with available addresses. What is the MOST likely cause?
- The client's NIC driver is corrupt and must be reinstalled
- The DHCP relay agent is configured with an incorrect server IP
- The DHCP server is not authorized in Active Directory and is silently ignoring requests (Correct answer)
- The scope's lease duration has been set to zero
Correct answer: The DHCP server is not authorized in Active Directory and is silently ignoring requests
An unauthorized DHCP server in an AD domain does not respond to any DCHP Discover packets, causing clients to fall back to APIPA addresses.
Question 21: What is the recommended DHCP scope utilization threshold that should trigger adding a new scope or server?
- 100%
- 50%
- 80% (Correct answer)
- 95%
Correct answer: 80%
Microsoft recommends that when DHCP scope utilization reaches 80%, administrators should plan to expand the scope or deploy additional servers.
Question 22: Which Windows Server 2003 built-in group has the ability to manage security policy settings without being a member of Administrators?
- Account Operators
- Backup Operators
- Server Operators (Correct answer)
- Power Users
Correct answer: Server Operators
Server Operators can perform tasks like managing shared resources, starting and stopping services, and backing up/restoring files on domain controllers.
Question 23: Which command is used to apply a security template to a Windows Server 2003 system from the command line?
- secpol.msc /apply
- gpupdate /force
- secedit /configure /db temp.sdb /cfg hisecws.inf (Correct answer)
- netsh advfirewall set
Correct answer: secedit /configure /db temp.sdb /cfg hisecws.inf
The secedit command with the /configure switch applies a security template (.inf file) to the local system using a specified security database.
Question 24: Which utility is used to run dcpromo in answer-file mode for unattended domain controller promotion?
- netdom /promote
- dcpromo /answer:<filename> (Correct answer)
- ntdsutil /install
- dcdiag /install
Correct answer: dcpromo /answer:<filename>
The dcpromo /answer: switch allows unattended installation of Active Directory using a pre-configured answer file.
Question 25: A Windows Server 2003 network uses both WINS and DNS. A client queries DNS for a host named 'fileserver' and gets NXDOMAIN, but WINS resolves it correctly. What DNS configuration allows DNS to fall back to WINS for unresolved single-label names?
- Add a CNAME record in DNS pointing 'fileserver' to its WINS-registered name
- Configure the DNS suffix devolution policy on client computers
- Create a stub zone for the NetBIOS domain namespace
- Enable WINS lookup on the DNS zone's WINS tab by specifying the WINS server IP (Correct answer)
Correct answer: Enable WINS lookup on the DNS zone's WINS tab by specifying the WINS server IP
The WINS tab on a DNS forward lookup zone enables DNS-to-WINS integration, causing the DNS server to query WINS when a name is not found in DNS.
Question 26: You need to configure a Windows Server 2003 RRAS server so that remote access clients receive specific DNS and WINS server addresses that differ from the server's own settings. Where should these be configured?
- Client VPN connection properties on each remote computer
- RRAS server Properties > IP tab static address pool settings
- DHCP scope options for the remote access IP address range
- Remote Access Policy profile IP settings (Correct answer)
Correct answer: Remote Access Policy profile IP settings
The Remote Access Policy profile allows you to specify IP settings such as DNS and WINS server addresses that override DHCP-delivered options for remote clients.
Question 27: What does the 'Fast User Switching' feature in Windows XP allow?
- Rotates user accounts for shared workstations on a schedule
- Multiple users can be logged on simultaneously without the first user logging off (Correct answer)
- Switches between user accounts faster using cached credentials
- Enables automatic logon for designated accounts
Correct answer: Multiple users can be logged on simultaneously without the first user logging off
Fast User Switching allows multiple users to remain logged on at the same time, switching between sessions without closing applications or logging off.
Question 28: What security measure does Smart Card logon provide that standard password authentication does not?
- Automatic session timeout
- Prevention of all phishing attacks
- Faster logon processing
- Two-factor authentication requiring physical possession of the card (Correct answer)
Correct answer: Two-factor authentication requiring physical possession of the card
Smart card logon implements two-factor authentication by requiring both the physical smart card and a PIN, making credential theft much harder.
Question 29: Which security template in Windows Server 2003 provides the highest level of security but may break legacy application compatibility?
- compatws.inf
- hisecws.inf (Correct answer)
- securedc.inf
- setup security.inf
Correct answer: hisecws.inf
The hisecws.inf (High Security Workstation) template enforces strict security settings that may prevent older applications from running correctly.
Question 30: A remote office connects to headquarters via a VPN tunnel on Windows Server 2003 RRAS. Users report that internet browsing is very slow because all traffic routes through headquarters. How can you fix this without compromising security?
- Configure a local proxy server at the remote office for internet access
- Add a second VPN connection at the remote office for internet traffic
- Increase the WAN link bandwidth between the remote office and headquarters
- Enable split tunneling on the VPN client to route only corporate traffic through the VPN (Correct answer)
Correct answer: Enable split tunneling on the VPN client to route only corporate traffic through the VPN
Split tunneling allows VPN clients to send corporate traffic through the encrypted tunnel while routing internet traffic directly through the local connection.
Question 31: Which of the following has the ability to grant DHCP server authorization?
- Windows 2000 (Correct answer)
- Windows Server 2003 (Correct answer)
- Windows XP
- Windows NT Server 4.0
Correct answer: Windows 2000
Only operating systems that support ADS can allow DHCP, hence Windows 2000 and Windows Server 2003 are required.
Question 32: You need to publish a shared printer in Active Directory so users can search for it by location. What must be configured on the printer?
- The Location field must be filled in and the printer listed in AD (Correct answer)
- The printer must be connected to a print server in the root domain
- The printer must be TCP/IP connected
- The printer must support PostScript
Correct answer: The Location field must be filled in and the printer listed in AD
For location-based printer searches in Active Directory, the printer's Location attribute must be populated and the printer must be published in AD.
Question 33: Which protocol should be preferred over NTLM for authentication security in Windows Server 2003 environments?
- LAN Manager (LM)
- Kerberos v5 (Correct answer)
- PAP
- CHAP
Correct answer: Kerberos v5
Kerberos v5 provides mutual authentication, stronger cryptography, and ticket-based access control, making it more secure than NTLM for domain authentication.
Question 34: What is the MOST secure way to store the backup of a CA's private key?
- Network share with NTFS permissions
- Encrypted USB drive kept at the administrator's desk
- Backed up alongside regular server data
- Hardware Security Module (HSM) or encrypted offline media stored in a secure vault (Correct answer)
Correct answer: Hardware Security Module (HSM) or encrypted offline media stored in a secure vault
CA private keys should be protected by an HSM or stored on encrypted offline media in a physically secured location, as compromise of the CA key compromises the entire PKI.
Question 35: What type of attack does account lockout policy specifically help mitigate?
- ARP spoofing
- SQL injection
- Pass-the-hash
- Brute-force password guessing (Correct answer)
Correct answer: Brute-force password guessing
Account lockout policy limits the number of failed logon attempts before locking the account, making automated brute-force password guessing attacks ineffective.
Question 36: Which routing protocol is preferred for large enterprise networks due to its scalability and support for VLSM?
- BGP
- IGRP
- RIP v1
- OSPF (Correct answer)
Correct answer: OSPF
OSPF (Open Shortest Path First) is a link-state routing protocol that supports VLSM, scales to large networks, and converges faster than distance-vector protocols.
Question 37: You need to configure Windows Server 2003 RRAS to assign IP addresses to VPN clients from a specific pool rather than using DHCP. Where do you configure the static address pool?
- RRAS server Properties > IP tab (Correct answer)
- DHCP server scope exclusion range
- RRAS server Properties > General tab
- Remote Access Policy conditions
Correct answer: RRAS server Properties > IP tab
The IP tab of the RRAS server properties dialog allows you to define a static IP address pool that will be assigned to connecting VPN clients.
Question 38: A Windows Server 2003 DNS server is configured as the primary zone for contoso.com. You want to allow only specific secondary DNS servers to perform zone transfers. Where do you configure this restriction?
- Zone Properties > Zone Transfers tab (Correct answer)
- DNS Server Properties > Security tab
- Zone Properties > Name Servers tab
- DNS Server Properties > Interfaces tab
Correct answer: Zone Properties > Zone Transfers tab
The Zone Transfers tab in the zone's properties allows you to specify which servers are permitted to request zone transfers.
Question 39: A Windows Server 2003 server is a member of a workgroup, not a domain. Which account database is used for authentication?
- LDAP directory
- Kerberos KDC
- SAM database (Correct answer)
- Active Directory
Correct answer: SAM database
Workgroup computers use the local Security Accounts Manager (SAM) database rather than Active Directory for user authentication.
Question 40: Which Windows Server 2003 log file records successful and failed security events as configured by audit policy?
- Security log in Event Viewer (Correct answer)
- Application log in Event Viewer
- Directory Service log
- System log in Event Viewer
Correct answer: Security log in Event Viewer
The Security log in Event Viewer records audit events such as logon successes and failures, object access, and privilege use as configured by local or group policy.
Question 41: What is the function of the Remote Desktop feature in Windows XP Professional?
- Enables file sharing with remote computers
- Broadcasts the desktop to multiple viewers simultaneously
- Provides remote access to Command Prompt only
- Allows one remote user to control the local desktop session over the network (Correct answer)
Correct answer: Allows one remote user to control the local desktop session over the network
Remote Desktop (RDP) in Windows XP Professional allows a single remote user to log on and fully control the computer's desktop session over the network.
Question 42: You need to deploy a software application to all computers in a specific OU using Group Policy. Which Group Policy node should you use to assign the application to computers?
- User Configuration > Software Settings > Software Installation
- User Configuration > Windows Settings > Scripts
- Computer Configuration > Software Settings > Software Installation (Correct answer)
- Computer Configuration > Administrative Templates > System
Correct answer: Computer Configuration > Software Settings > Software Installation
Computer Configuration > Software Settings > Software Installation assigns software to computers regardless of which user logs on, ensuring all computers in the OU receive the application.
Question 43: DHCPACK is used to notify a client when a renewal request is being declined by the DHCP.
- True
- False (Correct answer)
Correct answer: False
The DHCP notifies a client when it rejects their request for renewal by sending them a negative acknowledgment.
Question 44: On a Windows 2003 Server, a user reports that it is difficult to access shares. He observes that he is unable to access the shares or determine which server folders are shared. What is the most probable cause of the problem?
- Sharing Security
- Security Policy (Correct answer)
- Local Profile
- NTFS Security
Correct answer: Security Policy
His problems are a result of a policy choice; the server should be set up so that file sharing is permitted by local security policy.
Question 45: What is the order of Group Policy application from lowest to highest priority?
- Local, Site, Domain, OU (Correct answer)
- OU, Domain, Site, Local
- Site, Local, Domain, OU
- Domain, Site, Local, OU
Correct answer: Local, Site, Domain, OU
Group Policy is applied in LSDOU order: Local, Site, Domain, OU — with later policies overwriting earlier ones by default.
Question 46: Which protocol does Windows Server 2003 RRAS use to advertise routing information to other routers on the network?
- WINS replication
- ARP
- RIP v2 (Correct answer)
- DHCP relay
Correct answer: RIP v2
Windows Server 2003 RRAS supports RIP version 2 as a dynamic routing protocol to exchange routing information with other routers.
Question 47: A branch office router needs to reach headquarters only when traffic is present, reducing WAN costs. Which RRAS feature should you configure?
- IPSec tunnel mode with continuous keepalives
- BGP dynamic routing over a permanent leased line
- Demand-dial routing with idle disconnect timeout (Correct answer)
- Persistent static routes with metric 1
Correct answer: Demand-dial routing with idle disconnect timeout
Demand-dial interfaces bring up the WAN connection only when routable traffic is detected and disconnect after the idle timeout, minimizing connection costs.
Question 48: Which Windows XP deployment method uses a master image captured from a reference computer and deployed to target computers?
- RIS (Remote Installation Services)
- Unattended setup with answer file
- Disk imaging (Sysprep + imaging tool) (Correct answer)
- Group Policy software deployment
Correct answer: Disk imaging (Sysprep + imaging tool)
Disk imaging uses Sysprep to prepare and generalize a master installation, which is then captured and deployed to multiple computers using imaging tools like Ghost or ImageX.
Question 49: Which certificate type is required for EFS recovery agents in a Windows Server 2003 PKI environment?
- SSL/TLS Server certificate
- Computer certificate
- Code Signing certificate
- EFS Recovery Agent certificate (Correct answer)
Correct answer: EFS Recovery Agent certificate
The EFS Recovery Agent certificate grants designated accounts the ability to decrypt EFS-protected files if the original encrypting user's key is lost.
Question 50: What is the difference between an IPSec transport mode and tunnel mode?
- Tunnel mode works only with L2TP
- Transport mode encrypts only the payload; tunnel mode encapsulates the entire IP packet (Correct answer)
- Transport mode creates new IP headers
- Transport mode is faster than tunnel mode
Correct answer: Transport mode encrypts only the payload; tunnel mode encapsulates the entire IP packet
IPSec transport mode encrypts and authenticates the payload only, while tunnel mode encapsulates the entire original IP packet inside a new IP header — used for VPNs.
Question 51: During a network security audit, you discover that NTLM authentication is being used for remote access connections instead of MS-CHAPv2. You want to enforce stronger authentication. Where do you configure this?
- RRAS server Properties > Security tab
- Remote Access Policy authentication methods (Correct answer)
- Local Security Policy on the RRAS server
- Network Connection Properties on client computers
Correct answer: Remote Access Policy authentication methods
Remote Access Policies define which authentication protocols are acceptable for VPN and dial-up connections to the RRAS server.
Question 52: A company uses WINS for NetBIOS name resolution. Two WINS servers must share the same name database. Which replication model ensures that each server immediately propagates name registrations to the other?
- Configure one server as push-only and the other as pull-only
- Configure each server as both a push partner and pull partner of the other (push/pull replication) (Correct answer)
- Use only pull replication triggered every 30 minutes
- Enable WINS proxy agents on both servers
Correct answer: Configure each server as both a push partner and pull partner of the other (push/pull replication)
Configuring both servers as mutual push/pull partners ensures immediate push notification of changes and periodic pull synchronization for reliability.
Question 53: Which Windows Server 2003 service acts as a RADIUS server to centralize network access authentication?
- Network Access Quarantine Control
- Routing and Remote Access Service (RRAS)
- Internet Authentication Service (IAS) (Correct answer)
- Certificate Services (CS)
Correct answer: Internet Authentication Service (IAS)
Internet Authentication Service (IAS) is Microsoft's RADIUS server implementation that centralizes authentication, authorization, and accounting for network access.
Question 54: Which Windows Server 2003 service translates NetBIOS names to IP addresses and is required in networks that still use legacy Windows applications relying on NetBIOS name resolution?
- RRAS
- DNS
- DHCP
- WINS (Correct answer)
Correct answer: WINS
Windows Internet Name Service (WINS) provides NetBIOS name-to-IP address resolution, which is required by legacy Windows applications that use NetBIOS naming rather than DNS.
Question 55: UNIX-based DHCP servers cannot be set up in the network once Active Directory has been implemented. T/F?
- True
- False (Correct answer)
Correct answer: False
In the Active Directory system, Windows-based and UNIX-based DHCP servers coexist.
Microsoft Certified Systems Engineer (MCSE)
The MCSE certification validates expertise in designing, implementing, and administering Microsoft Windows Server 2003 network infrastructure, Active Directory, and security environments. It requires passing a series of exams covering networking, server administration, infrastructure design, and security.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds