Techiebird: Latest Active Directory Interview Questions
Techiebird: Latest Active Directory Interview Questions
Techiebird: Latest Active Directory Interview Questions
TechieBird
Home | Windows | Network | Interview Questions | Database | Virtualization | Knowledge Base | Contact Us
Quick Links
Windows 2003 KB
Windows 2008 KB
Windows 2012 KB
Exchange Q&A
Virtualization
Network Interview
Questions
SQL Interview
Questions
Windows Admin
Interview Q&A
Windows Forum
Other Links
DNS FAQ's
DHCP FAQ's
Active Directory
FAQ's
AD History
Configuring New
Domain
Deleted Object
Recovery in AD
Domain controllers and Sites. Domain controllers are physical computers which is running Windows Server
operating system and Active Directory data base. Sites are a network segment based on geographical
location and which contains multiple domain controllers in each site.
> What are the logical components of Active Directory ?
Domains, Organizational Units, trees and forests are logical components of Active Directory.
> What are the Active Directory Partitions ?
Active Directory database is divided into different partitions such as Schema partition, Domain partition, and
Configuration partition. Apart from these partitions, we can create Application partition based on the
requirement.
> What is group nesting ?
Adding one group as a member of another group is called 'group nesting'. This will help for easy
administration and reduced replication traffic.
> What is the feature of Domain Local Group ?
Domain local groups are mainly used for granting access to network resources.A Domain local group can
contain accounts from any domain, global groups from any domain and universal groups from any domain.
For example, if you want to grant permission to a printer located at Domain A, to 10 users from Domain B,
then create a Global group in Domain B and add all 10 users into that Global group. Then, create a Domain
local group at Domain A, and add Global group of Domain B to Domain local group of Domain A, then, add
Domain local group of Domain A to the printer(of Domain A) security ACL.
>How will you take Active Directory backup ?
Active Directory is backed up along with System State data. System state data includes Local registry,
COM+, Boot files, NTDS.DIT and SYSVOL folder. System state can be backed up either using Microsoft's
default NTBACKUP tool or third party tools such as Symantech NetBackup, IBM Tivoli Storage Manager etc.
NetDom Command
Replmon Command
NTDS Utility Guide
In multimaster replication method, replication conflicts can happen. Objects with replication conflicts will be
stored in a container called 'Lost and Found' container. This container also used to store orphaned user
accounts and other objects.
FSMO Guide
FSMO Failure
No one installs Active Directory in a cluster. There is no need of clustering a domain controller. Because
Active Directory provides total redundancy with two or more servers.
Network KB
Knowledge Base
Home
Active Directory Recycle bin is a feature of Windows Server 2008 AD. It helps to restore accidentally
deleted Active Directory objects without using a backed up AD database, rebooting domain controller or
restarting any services.
Read only domain controller (RODC) is a feature of Windows Server 2008 Operating System. RODC is a
read only copy of Active Directory database and it can be deployed in a remote branch office where
physical security cannot be guaranteed. RODC provides more improved security and faster log on time for
the branch office.
IIS 6.0
RAID Levels
www.techiebird.com/ad12.html
> How do you check currently forest and domain functional levels? Say both GUI and Command
line.
1/3
22/10/2013
RPC Guide
line.
To find out forest and domain functional levels in GUI mode, open ADUC, right click on the domain name
and take properties. Both domain and forest functional levels will be listed there. TO find out forest and
domain functional levels, you can use DSQUERY command.
> Which version of Kerberos is used for Windows 2000/2003 and 2008 Active Directory ?
Hyper-V
Print Server
BitLocker
PowerShell
FQDN can be expanded as Fully Qualified Domain Name.It is a hierarchy of a domain name system which
points to a device in the domain at its left most end. For example in system.
Planning Trust
Creating Trust
www.techiebird.com/ad12.html
2/3
22/10/2013
> Which FSMO role directly impacting the consistency of Group Policy ?
PDC Emulator.
> I want to promote a new additional Domain Controller in an existing domain. Which are the
groups I should be a member of ?
You should be a member of Enterprise Admins group or the Domain Admins group. Also you should be
member of local Administrators group of the member server which you are going to promote as additional
Domain Controller.
> Tell me one easiest way to check all the 5 FSMO roles ?
Use netdom query /domain:YourDomain FSMO command. It will list all the FSMO role handling domain
controllers.
Recommend this on Google
GET
FR EE
PAYMENT
GAT EWAY
Previous Questions
Comments
Name
Enter your comment here
Comment
by Htm l C om m e nt Box
www.techiebird.com/ad12.html
3/3