Group Policy Object (GPO) Core
GPO Scoping & Advanced Filtering
Software & Desktop Management
Certificate Services (AD CS) & PKI
AD Federation (AD FS) & Rights Management (AD RMS)
100

Active Directory processes GPOs in this specific four-step order.

What is Local, Site, Domain, and Organizational Unit (LSDO)?

100

This GPO option takes the highest precedence and will prevail over conflicting settings, applying to child containers even if they block inheritance.

What is the Enforce option?

100

This software component is used for the installation, maintenance, and removal of software on Windows systems.

What is the Windows Installer (MSI)?

100

This type of CA requires Active Directory Domain Services and is typically used to issue certificates to internal organization users and servers.

What is an Enterprise CA?

100

This Active Directory role allows administrators to configure Single Sign-On (SSO) for web-based applications across organizations.

What is Active Directory Federation Services (AD FS)?

200

Computer configuration settings are processed when this happens, while user configuration settings are processed when a user logs on.

What is when the computer starts and powers off?

200

This filtering method uses the WMI Query Language (WQL) to control who or what a GPO applies to based on hardware or OS properties.

What is WMI filtering?

200

This type of file is used by administrators to deploy customized MSI files.

What is an MSI transform file?

200

This file format is the only one that can be used to export a certificate along with its private key.

What is Personal Information Exchange (PKCS #12)?

200

In an AD FS relationship, the organization that owns the data/resources is the Resource Organization, while the one containing the user accounts is called this.

What is the Account Organization?

300

This command-line tool is used to manually refresh Group Policy settings

What is gpupdate?

300

This mechanism is used to assign user policies to computer objects, ensuring specific settings apply to anyone who logs onto that machine.

What is Group Policy loopback processing?

300

This feature allows an administrator to redirect the content of a user's local folder to a network location, often used alongside Offline Files.

What is Folder Redirection?

300

This digitally signed list contains all the certificates issued by a CA that have been invalidated before their expiration date.

What is a Certificate Revocation List (CRL)?

300

This Active Directory object holds the web address of the AD RMS certification cluster, and only one can exist per forest.

What is the Service Connection Point (SCP)?

400

Security settings are automatically reapplied to a client machine at this specific hourly interval, even if the GPO hasn't changed.

What is every 16 hours?

400

In Loopback processing, this mode combines the user settings defined in the computer's GPOs with the user's normal settings.

What is Merge mode?

400

When configuring registry-based Administrative Templates, these are the three available states.

What are Not Configured, Enabled, and Disabled?

400

To implement auto-enrollment for a certificate template, a user or computer must have the Auto-enroll permission plus these two other permissions.

What are Read and Enroll?

400

This specific AD RMS certificate is issued the first time a user attempts to access protected content and is used to identify that specific user.

What is a Rights Account Certificate (RAC)?

500

To run the Group Policy Results Wizard, these what must be available to access WMI on the target computer.

What is computer must be online, have administrative credentials, Windows XP or later, and WMI?

500

Introduced in Windows Vista and Server 2008, these XML-based files define Administrative Templates and can be stored in the Central Store.

What are ADMX files?

500

When editing Group Policy Preferences, pressing these two function keys will "Enable All" and "Disable All" editing states respectively.

What are F5 and F8?

500

 This component allows routers, switches, and other non-Windows network devices to be assigned digital certificates.

 What is the Network Device Enrollment Service (NDES)?

500

This AD RMS policy feature allows an administrator to automatically deny access to older, specific versions of client software.

What is Lockbox Version Exclusion?

M
e
n
u