100 TOP ACTIVE DIRECTORY Interview Questions and Answers PDF 2017
100 TOP ACTIVE DIRECTORY Interview Questions and Answers PDF 2017
100 TOP ACTIVE DIRECTORY Interview Questions and Answers PDF 2017
Tag: 100 TOP ACTIVE DIRECTORY Interview Questions and Answers pdf
by iqatts on June 6, 2017
7. Where is the AD database held ? Define what other folders are related to AD?
By default AD data base is stored in c:\windows\ntds\NTDS.DIT. SYSVOL & NETLOGON are other folders related to AD DS.
9. Define what is the Netlogon folder in AD DS and Define what is it used for?
The NETLOGON share is pointing to %SystemRoot%\sysvol\sysvol\{DOMAIN}\scripts folder on DC, and its main purpose is for
storing logon scripts.
http://interviewquestionstutorials.com/tag/100-top-active-directory-interview-questions-and-answers-pdf/ 1/7
10/12/2017 100 TOP ACTIVE DIRECTORY Interview Questions and Answers pdf 2017
By default %SystemRoot%\sysvol\sysvol\{DOMAIN}\scripts is empty. When we are deployed any script via GPO that is the default
location for storing the script.
By default sysvol includes 2 folders, the scripts folder is shared with the name NETLOGON
1. Members of this group have full control of all domains in the forest.
2. By default, this group is a member of the Administrators group on all domain controllers in the forest.
3. By default, the Administrator account is a member of this group.
4. Because this group has full control of the forest, add users with caution.
Domain Admins :
11. Where are the Windows NT Primary Domain Controller (PDC) and its Backup Domain Controller (BDC) in Server
2003 ?
The Active Directory replaces them. Now all domain controllers share a multimaster peer-to-peer read and write relationship that hosts
copies of the Active Directory.
15. Define whats the number of permitted unsuccessful logons on Administrator account?
Unlimited. Remember, though, that its the Administrator account, not any account thats part of the Administrators group.
16. Define whats the difference between guest accounts in Server 2003 and other editions?
More restrictive in Windows Server 2003.
17. How many passwords by default are remembered when you check Enforce Password History Remembered?
Users last 6 passwords.
18. Can GC Server and Infrastructure place in single server If not explain why ?
As a general rule, the infrastructure master should be located on a nonglobal catalog domain controller that has a direct connection
object to some global catalog in the forest, preferably in the same Active Directory site. Because the global catalog server holds a partial
replica of every object in the forest, the infrastructure master, if placed on a global catalog server, will never update anything, because it
does not contain any references to objects that it does not hold.
http://interviewquestionstutorials.com/tag/100-top-active-directory-interview-questions-and-answers-pdf/ 2/7
10/12/2017 100 TOP ACTIVE DIRECTORY Interview Questions and Answers pdf 2017
But there are exceptions to this general rule. Two exceptions to the do not place the infrastructure master on a global catalog server
rule are:
Single domain forest:
In a forest that contains a single Active Directory domain, there are no phantoms, and so the infrastructure master has no work to do.
The infrastructure master may be placed on any domain controller in the domain, regardless of whether that domain controller hosts
the global catalog or not.
Multidomain forest where every domain controller in a domain holds the global catalog:
If every domain controller in a domain that is part of a multidomain forest also hosts the global catalog, there are no phantoms or work
for the infrastructure master to do. The infrastructure master may be put on any domain controller in that domain.
24. Define what is the Recommended Maximum Number of Domain Controllers in a Domain ?
To ensure reliable recovery of SYSVOL, we recommend a limit of 1200 domain controllers per domain.
Ring Topology: With intrasite replication, the KCC creates a ring topology that defines the replication paths within a site. In a
ring topology, each domain controller in a site has two inbound and outbound replication partners. The KCC creates the ring so
that there is no greater than three hops between domain controllers in a site.
Full Mesh Topology: This topology is typically utilized in small organizations where redundancy is extremely important and the
number of sites is quite small. A full mesh topology is quite expensive to manage and is not scalable.
Hub And Spoke Topology: This topology is typically implemented in large organizations where scalability is important and
redundancy is less important. In this topology, one or multiple hub sites exist that have slower WAN connections to multiple spoke
sites. The hub sites are usually connected to each other through high speed WAN connections.
http://interviewquestionstutorials.com/tag/100-top-active-directory-interview-questions-and-answers-pdf/ 3/7
10/12/2017 100 TOP ACTIVE DIRECTORY Interview Questions and Answers pdf 2017
Hybrid Topology: The hybrid topology is a combination of any of the above topologies.
AD FS 2.0 is a downloadable Windows Server 2008 update that is the successor to AD FS 1.0, which was first delivered in Windows
Server 2003 R2, and AD FS 1.1, which was made available as a server role in Windows Server 2008 and Windows Server 2008 R2.
Previous versions of AD FS are referred to collectively as AD FS 1.x.
ADMGS provides this web service interface for Windows Server 2003 SP2 and Windows Server 2008 domain controllers (DCs). The
service lets Server 2008 R2 AD PowerShell cmdlets and other applications work against the DCs with ADMGS installed.
Administrators can use the enhanced Active Directory Administrative Center GUI to customize Active Directory Administrative Center
to suite their particular directory service administering requirements.
You can filter or exclude results from AD DS BPA reports that you do not need to see. You can also perform AD DS BPA tasks by using
either the Server Manager graphical user interface (GUI) or cmdlets in the Windows PowerShell command-line interface.
http://interviewquestionstutorials.com/tag/100-top-active-directory-interview-questions-and-answers-pdf/ 4/7
10/12/2017 100 TOP ACTIVE DIRECTORY Interview Questions and Answers pdf 2017
Starting with Windows Server 2003, the ability to replicate discrete changes to linked multivalued properties was introduced as a
technology called Linked Value Replication (LVR). To enable LVR, you must increase the forest functional level to at least Windows
Server 2003 interim. Increasing the forest functional level changes the way that group membership (and other linked multivalued
attributes) is stored in the database and replicated between domain controllers. This allows the number of group memberships to
exceed the former recommended limit of 5,000 for Windows 2000 or Windows Server 2003 at a forest functional level of Windows
2000.
So far, testing in this area has yet to reveal any new recommended limits to the number of members in a group or any other linked
multivalued attribute. Production environments have been reported to exceed 4 million members, and Microsoft scalability testing
reached 500 million members.
36. Where does the AD database is held? Define what other folders are related to AD?
AD database is saved in %systemroot%/ntds. In the same folder, you can also see other files; these are the main files controlling the AD
structures they are
dit
log
res 1.log
log
chk
37. Define what is PDC emulator and how would one know whether PDC emulator is working or not?
PDC Emulators: There is one PDC emulator per domain, and when there is a failed authentication attempt, it is forwarded to PDC
emulator. It acts as a tie-breaker and it controls the time sync across the domain.
These are the parameters through which we can know whether PDC emulator is working or not.
http://interviewquestionstutorials.com/tag/100-top-active-directory-interview-questions-and-answers-pdf/ 5/7
10/12/2017 100 TOP ACTIVE DIRECTORY Interview Questions and Answers pdf 2017
Intrasite replication in Active Directory takes place between domain controllers within the same site. This makes intrasite replication an
uncomplicated process. When changes are made to the replica of Active Directory on one particular domain controller, the domain
controller contacts the remainder of the domain controllers within the site. The domain controller checks the information it contains
against information hosted by the other domain controllers. To perform this analysis, the domain controller utilizes logical sequence
numbers. Intrasite replication utilizes the Remote Procedure Call (RPC) protocol to convey replication data over fast, reliable network
connections. With intrasite replication, replication data is not compressed.
Intersite replication takes place between sites. Intersite replication can utilize either RPC over IP or SMTP to convey replication data.
This type of replication has to be manually configured. Intersite replication occurs between two domain controllers that are called
bridgeheads or bridgehead servers. The role of a bridgehead server (BS) is assigned to at least one domain controller in a site. A BS in
one site deals with replicating changes with other BSs in different sites. You can configure multiple bridgehead servers in a site. It is
only these BSs that replicate data with domain controllers in different domains by performing intersite replication with its BS partners.
With intersite replication, packets are compressed to save bandwidth. This places additional CPU load on domain controllers assigned
the BS role. BSs should therefore be machines that have enough speed and processors to perform replication. Intersite replication takes
place over site links by a polling method which is every 180 minutes by default.
ACTIVE DIRECTORYFaqs ::
{ Add a Comment (http://interviewquestionstutorials.com/active-directory-job-interview-questions-answers/#respond) }
2017 Interview Questions and Answers - Tutorials - Developed by Interview Questions Tutorials (http://interviewquestionstutorials.com/)
http://interviewquestionstutorials.com/tag/100-top-active-directory-interview-questions-and-answers-pdf/ 6/7
10/12/2017 100 TOP ACTIVE DIRECTORY Interview Questions and Answers pdf 2017
http://interviewquestionstutorials.com/tag/100-top-active-directory-interview-questions-and-answers-pdf/ 7/7