QuestionQ1
Deploy and manage AD DSYour network contains an Active Directory Domain Services (AD DS) domain with two domain controllers named DC1 and DC2.
Active Directory Recycle Bin is disabled.
An organizational unit (OU) named Finance and its child objects were deleted from DC1, and the deletion replicated to DC2. DC1 has a system state backup from before the deletion, while changes to other AD DS objects were made after the backup.
You need to recover only the Finance OU and its child objects. The solution must ensure that the recovered objects replicate to DC2 and that unrelated AD DS changes are preserved.
What should you configure?
QuestionQ2
Deploy and manage AD DSYour network contains the Active Directory Domain Services (AD DS) forests shown in the following table.

You need to configure trust relationships as shown in the following table.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
| Statements | Yes | No |
|---|---|---|
| After both trusts are configured, contoso.com users can access the resources in adatum.com. | ||
| A single two-way forest trust between contoso.com and fabrikam.com satisfies the Contoso-Fabrikam access requirement. | ||
| A one-way external trust in which research.fabrikam.com trusts adatum.com satisfies the Adatum-Fabrikam access requirements. |
Community Discussion
QuestionQ3
Deploy and manage AD DSYour network includes an Active Directory Domain Services (AD DS) domain.
A Group Policy Object (GPO) named Security Baseline is linked to the domain, and its link is configured as Enforced.
A GPO named Kiosk Baseline is linked to an organizational unit (OU) named Kiosks.
Client computers in the Kiosks OU receive Group Policy settings from the Security Baseline GPO.
You need to ensure that computers in Kiosks receive settings from the Kiosk Baseline GPO. Security Baseline must continue to apply to other client computers in the domain.
What should you do?
Community Discussion
QuestionQ4
Deploy and manage AD DSYour network contains an Active Directory Domain Services (AD DS) domain called contoso.com.
The domain includes a user named User1 and two global security groups, Group1 and Group2. User1 belongs to both groups.
A Group Policy Object (GPO) named GPO1 is linked to the domain. GPO1 includes the following User Configuration preference items.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
| Statements | Yes | No |
|---|---|---|
| If User1 signs in from 10.20.5.20, drive S will be mapped. | ||
| If User1 is removed from Group1, after sign in, the user will NOT have drive S in File Explorer. | ||
| If User1 signs in to a client computer that does NOT have C:\Program Files\SalesApp\SalesApp.exe, the SalesApp shortcut is created once and is never recreated. |
Community Discussion
QuestionQ5
Deploy and manage AD DSOverview
Contoso, Ltd. has a main office in Seattle and two branch offices in Los Angeles and Montreal.
Existing Environment
AD DS Environment
The network includes an on-premises Active Directory Domain Services (AD DS) forest named contoso.com. The forest includes two domains: contoso.com and canada.contoso.com.
The forest includes the domain controllers shown in the following table.

All domain controllers are global catalog servers.
Server Infrastructure
The network includes the servers shown in the following table.

Server4 runs Windows Server and belongs to a workgroup. Windows Defender Firewall on Server4 uses the private profile.
Server2 hosts three virtual machines named VM1, VM2, and VM3.
VM3 is a file server that stores data in the volumes shown in the following table.

Group Policies
The contoso.com domain contains the Group Policy Objects (GPOs) shown in the following table.

Existing Identities
The forest includes the users shown in the following table.

The forest includes the groups shown in the following table.

Current Problems
When an administrator signs in to the VM2 console by using Virtual Machine Connection and disconnects without signing out, another administrator can connect to that console session as the currently signed-in user.
Requirements
Technical Requirements
Contoso identifies the following technical requirements:
- Change the replication schedule for all site links to 30 minutes.
- Promote Server1 to a domain controller in
canada.contoso.com. - Install and authorize Server3 as a DHCP server.
- Ensure that User1 can manage membership of all groups in
Contoso\OU3. - Ensure that Server4 can be managed from Server1 by using PowerShell remoting.
- Ensure that virtual machines can run on VM1.
- Require users to provide credentials when they connect to VM2.
- On VM3, enable Data Deduplication on every volume that supports the feature.
You need to meet the technical requirements for Server1.
Which users can currently perform the required tasks?

Community Discussion