بررسي يكي از نمونه سوالات امتحان 291-70
You manage one of your company's computers running Windows Server 2003 on which Routing and Remote Access is enabled. The computer is installed on the network at one of your company's branch offices, and it is configured as a demand-dial router. The server is configured to connect to a server running Windows Server 2003 at your company's main office that is also configured as a demand-dial router.
When you initially set up the demand-dial router at the branch office, the computer was not joined to a domain. Your domain administrators recently added the computer to your company's Active Directory domain, and the demand-dial router at the main office cannot establish a connection to your server.
You discover that your demand-dial router's computer account needs to be added to the RAS and IAS Servers security group. You ask a domain administrator to make this change.
What should you do to ensure that the demand-dial router at the main office can connect to your demand-dial router
?
1. Restart Routing and Remote access on your server.
2. Restart your server.<Correct>
3. Use the Secedit utility on your server.
4. >>Use the Netsh utility on your server.
Explanation : To ensure that the demand-dial router at the main office can connect to your demand-dial router, you should restart your server. When you restart the computer, the information from Active Directory that is cached on the computer will be updated. If you do not restart the computer, the cached information will be used and will not reflect the fact that the computer has been added to the RAS and IAS Servers group. Members of this group have the Read permission for the RAS and IAS Servers Access Check object in Active Directory.
.
You should not just restart Routing and Remote Access on your server to ensure that the demand-dial router at the main office can connect to your demand-dial router. Restarting Routing and Remote Access will not update the cached Active Directory information.
You should not use the Secedit utility on your server to ensure that the demand-dial router at the main office can connect to your demand-dial router. You can use the Secedit utility to update Group Policy object (GPO) settings on a computer, but not to update group membership information. When a domain controller authenticates a computer upon startup, the domain controller issues a Ticket Granting Ticket (TGT) that contains information about the groups to which the computer belongs. You cannot use Secedit to update the TGT.
You should not use the Netsh utility on your server to ensure that the demand-dial router at the main office can connect to your demand-dial router. You can use the Netsh utility to view and manage configuration settings for Routing and Remote Access, but not to update group membership information. If you have permission to add accounts to the RAS and IAS Servers security group in a domain, you can use the Netsh utility to add a computer account to the group.
جالبه ، جواب شده "Restart your server" ، اين جوريش هم نديده بودم !
نظر شما چيه ؟
موضوعات مشابه: