Subscribe to Windows IT Pro

 

Get Newsletters

  • Get the Latest News
  • Product Updates
  • Helpful Tricks
  • Productivity Tips

Subscribe Now!

August 25, 2000 12:00 AM

Certifiable Q&A for August 25, 2000

Windows IT Pro
InstantDoc ID #15447
Rating: (0)

Welcome to Certifiable, your exam prep headquarters. Here you'll find questions about some of the tricky areas that are fair game for the certification exams. Following the questions, you'll find the correct answers and explanatory text. We change the questions biweekly.

Test Questions (August 25, 2000)
Test Answers (August 25, 2000)

Questions (August 25, 2000)

The following questions cover topics similar to those you can find on Exam 70-216: Implementing and Administering a Microsoft Windows 2000 Network Infrastructure and Exam 70-217: Implementing and Administering a Microsoft Windows 2000 Directory Services Infrastructure.

Question 1
You are the sole administrator of a Windows 2000 network that uses static IP addresses on all clients. You want to move toward dynamic allocation, and you plan to install DHCP.

Your network currently uses the private address range 192.168.1.0/24, and you have 240 hosts, of which 10 servers will retain their fixed IP addresses. Once you have installed the DHCP Server Service on Win2K, how can you minimize administration while ensuring no unnecessary network downtime during the migration?

  1. Create a DHCP Scope for all of 192.168.1.0/24 with exclusions for the servers. Configure each client in turn to use DHCP.
  2. Create a DHCP Scope for all of 192.168.1.0/24 with exclusions for all servers currently in use. Delete each server exclusion immediately after its clients are configured to use DHCP.
  3. Create a scope for all of 10.0.0.0/24 on the DHCP Server. Configure clients to use DHCP. Do not change the IP configuration on any servers.
  4. Install RRAS and configure a router to route between 10.0.0.0/24 and 192.168.1.0/24 on the same network adapter. Create a scope for all of 10.0.0.0/24 on the DHCP Server. Configure clients to use DHCP. Do not change the IP configuration on any servers.

Question 2
You are the administrator of your company’s Windows 2000 domain. You suspect that there have been attempts to breach security on the domain's Win2K Professional computers using "brute force" attacks on the local administrator accounts. Win2K Pro computer accounts reside in Organizational Units (OUs) according to department. You take the following actions in the default domain controller's Group Policy Object (GPO):

  • Set the "Account Lockout Threshold" to one invalid logon attempt
  • Set the "Reset account lockout after" to 15 minutes
  • Set the "Maximum security log size" to 150KB
  • Enable "Shut down the computer when the security audit log is full"

These actions help you achieve which of the following goals? (Choose all that apply).

  1. View all security logs from one computer.
  2. Prevent individual security logs from exceeding 150KB on workstations.
  3. Ensure that security events are always audited and never lost.
  4. Require at least 10 minutes between failed logon attempts.

Answers (August 25, 2000)

Answer to Question 1
The correct answer is B—create a DHCP Scope for all of 192.168.1.0/8 with exclusions for all computers currently in use; delete each server exclusion immediately after its clients are configured to use DHCP.

Answer A causes network problems because no client addresses are excluded from the range available to the DHCP server. The first client configured for DHCP is likely to receive an IP address that another client computer is already using, causing a loss of connectivity. Remember that when you change a TCP/IP configuration in Win2K, the change occurs immediately, without rebooting.

Answer C is incorrect because DHCP servers can't assign addresses from network IDs other than their own without the use of superscopes. Answer D is incorrect for the same reason (although it looks more promising than C because of the step that configures routing between the subnets in use).

Answer B is the only option that ensures no network downtime. In fact, a usual step in this process is to renumber the servers so that they have consecutive IP addresses (e.g., 192.168.1.1 to 192.168.1.10) and create the DHCP scope for the rest of the subnet.

Answer to Question 2
The correct answer is A—view all security logs from one computer. Using Win2K, you can remotely view security logs from any computer using the Event Viewer Microsoft Management Console (MMC) snap-in. Limiting the log size to 150KB and shutting the computer down when the log is full ensures that no log events are lost and that the file does not exceed the specified size. The 10 minute delay between failed logon attempts is ensured by locking users out after one incorrect logon, and not resetting the count for 15 minutes.

Answers B, C, and D would be correct if the GPO change actually applied to the Win2K Pro computers. As it is, changing the default domain controller's GPO only enforces these settings on the domain controllers in the domain, and not those computers.

Related Content:

ARTICLE TOOLS

Comments
  • habib
    11 years ago
    Aug 22, 2001

    i just ask a question that how can we assign an IP Address if there is no DHCP Server available(using any language as c++)answer me quite affectively and as early as possible

  • Adam Wood
    12 years ago
    Sep 05, 2000

    As a couple of readers have correctly pointed out, there's a tiny (but important) error in answer B of question 1.

    It should start "Create a DHCP Scope for all of 192.168.1.0/24" and not have a /8 mask on the Scope. This should now have been fixed in the article.

  • Jonathan Barker
    12 years ago
    Aug 30, 2000

    Shouldn't Question 1, Answer B be 192.168.1.0/16? Last time I checked, the range for private intranets was 192.168.0 to 192.168.255, and that's a 16 bit mask. (RFC 1918)

  • Matt Ostiguy
    12 years ago
    Aug 26, 2000

    For Question 1, on the Aug. 25th questions, why does the correct answer have the CIDR netmask of /8? A DHCP scope of 192.168.1.0/8 would give out 192.0.0.1 as the first address, I would expect.

You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

White Papers

Get your Windows 7 deployment off to the right start by implementing PC lockdown. A locked-down environment is easier and cheaper to support since users are less likely to make unnecessary changes to the core system configuration - read more here!

Essential Guides

Is your iSCSI "lossy"? The reality is that most off-the-shelf Ethernet hardware deployed for iSCSI can lose packets, resulting in slow performance or application downtime. Learn how to assess your current iSCSI infrastructure and engineer an advanced iSCSI SAN infrastructure.

Web Seminars

What's the best way to keep your network safe from malware? In this web seminar, security expert Greg Shields suggests an alternative method to the traditional blacklisting approach that is common with anti-virus and anti-malware solutions.

eLearning Series

We bring the experts direct to you to share their real-world perspective and expertise. During each event, three sessions stream in real time, so you can learn, ask questions, and get solutions.
Upcoming event: Getting the Most with Exchange 2010 with Paul Robichaux

Subscribe to Windows IT Pro!

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.