Webcast for 70-640
07 August 08 11:47 AM | Garth Jones

These Webcast will be useful for those of you studying for 70-640 Exam

TechNet Webcast: Active Directory Inside Out (Part 01 of 11)—Active Directory Logical Concepts—Level 200

TechNet Webcast: Active Directory Inside Out (Part 02 of 11)—Active Directory Physical Concepts—Level 200

TechNet Webcast: Active Directory Inside Out (Part 03 of 11)—Active Directory Replication and the Operations Masters Role—Level 200

TechNet Webcast: Active Directory Inside Out (Part 04 of 11)—Installing and Managing DNS—Level 200

TechNet Webcast: Active Directory Inside Out (Part 05 of 11)—DNS Features and Configuration—Level 200

TechNet Webcast: Active Directory Inside Out (Part 06 of 11)—Interoperability and Migration from Novell Directory Services—Level 200

TechNet Webcast: Active Directory Inside Out (Part 07 of 11)—Migrating File Resources from NetWare to Active Directory 2003—Level 200

TechNet Webcast: Active Directory Inside Out (Part 08 of 11)—Deployment and Interoperability with NT 4.0 and Windows 2000—Level 200

TechNet Webcast: Active Directory Inside Out (Part 09 of 11)—Administration Features—Level 200

TechNet Webcast: Active Directory Inside Out (Part 10 of 11)—Replication Features and Forest to Forest Trusts—Level 200

TechNet Webcast: Active Directory Inside Out (Part 11 of 11)—Group Policy Management Console and Software Restriction—Level 200

 

 

source:

http://blogs.technet.com/johnbaker/archive/2008/04/05/active-directory-webcasts-series.aspx

70-298 Section 6.2 Q&A Bonus Answer
07 August 08 08:18 AM | Garth Jones

When is NTLM preferred over Kerberos, this method is used by many admins to test network connection?

 

Answer:

When IP address is used to map a network drive instead of the NetBIOS name. Example \\192.168.1.15\C$ vs \\EnhansoftDC\C$

Errata's for MS Press Windows 2008 exam prep books.
06 August 08 09:43 AM | Garth Jones

While reading the MS Press 70-640 book I noticed an error, so I went looking for the errata for this book, here are the erratas for

 

MCTS Self-Paced Training Kit (Exam 70-640): Configuring Windows Server® 2008 Active Directory comments and corrections

http://support.microsoft.com/kb/955243/en-ca

 

MCTS Self-Paced Training Kit (Exam 70-642): Configuring Windows Server® 2008 Network Infrastructure comments and corrections

http://support.microsoft.com/kb/953194/en-ca

 

MCTS Self-Paced Training Kit (Exam 70-643): Configuring Windows Server® 2008 Applications Infrastructure comments and corrections

http://support.microsoft.com/kb/951753/en-ca

 

MCITP Self-Paced Training Kit (Exam 70-646): Windows Server® Administration

<no errata yet>

 

MCITP Self-Paced Training Kit (Exam 70-647): Windows Server® Enterprise Administration

<no errata yet>

 

BTW I was right the answer is just "B" on page 888 for Question 2.

70-298 Section 6.2 Q&A Bonus
06 August 08 08:18 AM | Garth Jones

When is NTLM preferred over Kerberos, this method is used by many admins to test network connection?

70-298 Section 6.2 Q&A Answer
05 August 08 08:18 AM | Garth Jones

What does ktpass.exe do?

 

Answer:

ktpass.exe creates key pass files for UNIX workstations used to encrypt ticket requests.

70-298 Section 6.2 Q&A
04 August 08 08:17 AM | Garth Jones

What does ktpass.exe do?

70-640 Week 10 Q&A
04 August 08 08:14 AM | Garth Jones

Match up the IPv6 address types to their corresponding format

Types:

  1. Global unicast
  2. Link-local
  3. Loopback
  4. Site-local
  5. Unspecified

 

Format:

  1. ::
  2. ::1
  3. All others
  4. FE80::
  5. FEC0::
70-298 Section 6.1 Q&A Answer
03 August 08 08:19 AM | Garth Jones

Name all six trust types.

 

Answer:

  1. No trust   **** Personally I don't think this is a trust type but I didn't write this book so...
  2. Trusts between Domain in a Forest
  3. Shortcut trust
  4. External trust
  5. External trust with a non-windows kerberos realm
  6. forest trust
Q&As
02 August 08 12:14 PM | Garth Jones

70-298

Well all questions have be pre-posted and September 22nd will be the last Q&A for 70-298 exam.

 

70-640

I will continue to post the weekly Q&As for 70-640 and the last Q&A will be posted on Oct 17th. Remember that the exam review session are Oct. 20th and 27th and I will be leading those sessions.

 

70-649

Sometime this LONG weekend, I will start working on 70-649 exam and you may see some Q&A for that but it is unlikely, mostly because it is allot of work.

 

Remember to keep an eye on the forums for Q&A for other people or to post your own Q&A. http://owsug.ca/forums/default.aspx?GroupID=2

70-298 Section 6.1 Q&A
02 August 08 08:21 AM | Garth Jones

Name all six trust types.

70-298 aka I did it!
01 August 08 01:57 PM | Garth Jones

Well I did it this morning, I wrote and passed 70-298. With passing this exam I now have updated myself to MCSE on Window 2003. So what does this mean to my daily blog post for 70-298 exam. Nothing, almost all sections have already been pre-posted and the few that are not I will try to pre-post the Q&A to my blog this weekend.

With passing this exam it also means that I can finally can teach SMS 2003 and ConfigMgr 2007, Long story there. Yes, I’m a MCT, long story there too.

Just in case you care I now have these exam to write some time soon. 70-089, 400, 402 (if released), 403 (when/if released), 640, 642, 643, 646, 647, 652 (when out of beta).

Now the question is do I go after the Windows 2008,SMS 2k3 or OpsMgr 2k7 exam? Since 70-089 will not give me anything, so I will put that one on the back burner for now. So now it is down to 70-401 and 70-640 or 70-649? I will give it the LONG weekend to decide but I have a feeling that I will pick the 70-640 or 70-649 exam, most because I have a free exam voucher for either exam that expirers Oct 31 2008. I would write the 70-400 exam if the OpsMgr MVPs finished writing the study guide that they started but alas.... <Evil Grin>

Finally, for those of you thinking about writing exams, I only started updating my skills from MCSE NT4 to Win 2k3 in December 2007, Since then I have passed 70-401, 620 , 622, 431, 290, 291, 293, 294, and 298, that is almost one exam a month. If I can do it, anyone can.

 

Now it is time for a few Beers, plus it is a long weekend!

Filed under: , ,
70-640 Week 9 Q&A Answer
01 August 08 08:36 AM | Garth Jones

What are RODC and why are they more secure?

Answer:

RODC = Read-Only Domain Controllers

RODC maintains a small number of cache user accounts and therefore if compromised the affect is limited to those account only.

70-640 Week 10
01 August 08 08:27 AM | Garth Jones

I posted this early because of the long weekend. Have a great long weekend.

 

This weeks reading for the self study group is:

9.0 DNS and IPv6 13 38
9.1 Understanding and Installing Domian Name System 25  

70-298 Section 5.3 Q&A Bonus Answer
01 August 08 08:19 AM | Garth Jones

What SUS client log Event ID indicates, "Install success"?

Answer:

Event ID 19 indicates "Install success".

CREATE PROCEDURE permission denied in database 'SMS_XXX'
31 July 08 12:46 PM | Garth Jones

If you received this error message "CREATE PROCEDURE permission denied in database 'SMS_XXX'"

Create_SP

What this means is the "Create Procedure" permission is missing from "Webreport_approle" database role.

To Fix this issue, perform the following:

Open a Query window and execute the following SQL statement:

Grant Create Procedure to [Webreport_approle]

 

Now you are going to ask why does the Webreport_approle need this permission, the answer is it does and I will show why in another blog post.

70-298 Section 5.3 Q&A Bonus
31 July 08 08:20 AM | Garth Jones

What SUS client log Event ID indicates, "Install success"?

Count of Device by AD site
30 July 08 07:03 PM | Garth Jones

Select B.ADSite as 'AD Site', Count(B.ADSite) as 'Count'
from
(SELECT
  Case
   When R.AD_Site_Name0 = '' Then '<No AD Site>'
   When R.AD_Site_Name0 = NULL Then '<No AD Site>'
   When isnull(R.AD_Site_Name0,'one') = 'one' Then '<No AD Site>'
   else  R.AD_Site_Name0
  End as 'ADSite'--,
FROM v_R_System R) as B
Group by
B.ADSite
Order by
B.ADSite

Filed under: , , ,
70-298 Section 5.3 Q&A Answer
30 July 08 08:14 AM | Garth Jones

What is the command line for MBSA to use the SUS server instead MS catalog?

Answer:

Mbsacli /SUS Http://SMSUG_SUS

Network Report
29 July 08 08:36 AM | Garth Jones

Select Distinct
CS.Name0,
NIC.Description0,
NAC.IPAddress0,
NAC.DefaultIPGateway0
from
dbo.v_GS_COMPUTER_SYSTEM CS,
dbo.v_GS_NETWORK_ADAPTER NIC,
dbo.v_GS_NETWORK_ADAPTER_CONFIGUR NAC
Where
CS.ResourceID = NIC.ResourceID
and CS.ResourceID = NAC.ResourceID
and NAC.ServiceName0 = NIC.ServiceName0
and NAC.IPAddress0 != ''
and NAC.IPAddress0 != '0.0.0.0'
Order by
CS.Name0,
NIC.Description0,
NAC.IPAddress0,
NAC.DefaultIPGateway0

Filed under: , , ,
70-298 Section 5.3 Q&A
29 July 08 08:16 AM | Garth Jones

What is the command line for MBSA to use the SUS server instead MS catalog?

70-640 Week 9 Q&A
28 July 08 08:39 AM | Garth Jones

What are RODC and why are they more secure?

70-640 Week 9
28 July 08 08:26 AM | Garth Jones

This weeks reading for the self study group is:

8.1 Configuring Password and lockout Policies 13 38
8.2 Auditing Authentication 6
8.3 Configuring Read-Only Domain Controllers 19  

Why are Telephones 7 digits?
28 July 08 08:10 AM | Garth Jones

Our phone nomenclature system was originally systematized after much research on memory at Bell Labs (remember The Bell Telephone Company). The Bell researchers found that the optimum amount of easily remembered numbers was around 7, and that this was with the numbers in a 3/4 grouping. It was increased to 10 with the 3 digit area code prefix, figuring that the area code was seldom used anyway (at that time).

http://www.hastingsresearch.com//net/05-nomenclature.shtml

 

Now you are asking yourself why is he bring this up? The answer is simple did you know that LAN Manager used two 7 character chunks to create a password? Did you know that 2-seven character chunks are easier to break than one 14 character chuck? Did you know that using LM the first 7 character of a password are passed to the domain controller then the remaining 7 characters? This mean that a network sniffer would have to capture both packets to find out the password.

This is one of the main reason why it is recommend to have password of 8 character or better.

 

In Windows 2003 passwords can now be 128 characters long, how long is your password?

Filed under:
70-298 Section 5.2 Q&A Answer
28 July 08 08:07 AM | Garth Jones

What are the values and their meanings for the registry entry for AUOptions?

Answer:

2 = Notify of download and install

3 = Automatically download and notify

4 = Automatically download and schedule installation

 

Yes, there is no 0 or 1 options :-)

How many certified System Center people are there July 2008
27 July 08 06:09 PM | Garth Jones

Microsoft System Center Configuration Manager 2007: Configuration     486

Microsoft System Center Operations Manager 2007: Configuration         503

70-298 Section 5.2 Q&A
27 July 08 08:09 AM | Garth Jones

What are the values and their meanings for the registry entry for AUOptions?

70-298 Section 5.1 Q&A Answer
26 July 08 08:58 AM | Garth Jones

Rank the software updates in order of important's

  • Critical
  • Important
  • Low
  • Moderate

 

Answer:

  • Critical
  • Important
  • Moderate
  • Low
70-640 Week 8 Q&A Answer
25 July 08 08:14 AM | Garth Jones

Which of the following can be deployed via GPSI?

  • Batch file (.Bat)
  • Command File (.Com)
  • Executable (.Exe)
  • Visual Basic Scripting Edition (.Vbs)
  • Windows Installer (.Msi)
  • Windows PowerShell (.Ps1)
  • Windows Software Installation Settings file (.Zap)

 

Answer:

  • Windows Installer (.Msi)
  • Windows Software Installation Settings file (.Zap)

 

 

70-298 Section 5.1 Q&A
25 July 08 08:09 AM | Garth Jones

Rank the software updates in order of important's

  • Critical
  • Important
  • Low
  • Moderate
What is the most (arguably) secure password a local user can have on Windows 2003?
25 July 08 07:55 AM | Garth Jones

 

Chris M. might disagree with me on this but a blank password for a local account is arguably the most secure password that account can have! Now I’m sure that some of you will disagree but here is why.

1.      A local account using blank password in default setting in windows 2003 setup, can only logon locally.

2.      Again arguably all windows 2003 servers are in a secure location. Server room, etc.. If not and anyone can get access to the server then what does it matter if a local account has no password, since they will be able to re-boot the server and do whatever they like to it.     

Filed under:
More Posts Next page »