###BeginCaseStudy###
Case Study: 7
Contoso, Ltd
Scenario:
You are an enterprise desktop support technician for Contoso, Ltd.
IP Addressing
Contoso has one office. The IP addressing for Contoso is configured as shown in the following table.
Active Directory Configuration
You have an Active Directory forest that contains one domain named contoso.com. All
domain controllers run Windows Server 2008 R2. An OU exists for each department in the
company. The MainOffice Users and Computers OU contains the OUs for each department in
the company. The Users OUs contains the user accounts for each department. The Computers
OUs contain the computeraccounts for each department. The Domain Controllers OU
contains the computer accounts for all domain controllers. The Servers OU contains the
computer accounts for all other servers. Custom Group Policy objects (GPOs) are linked to
each departmental OU, the Domain Controllers OU, and the Servers OU.
Server Configuration
The relevant servers are configured as shown in the following table.
A year ago, a Windows Server 2008 R2 VPN server was deployed. Ten sales users
participated in a pilot project to test the new VPN. The pilot project lasted two months. After
the pilot project, the VPN server was put into production. The VPN server allows
L2TP/IPSec-based VPN connections only. The VPN server requires certificate
authentication.
Printer Configuration
Network printers are located in a single room on each floor. Users can search Active
Directory to find printers that are nearby. Print1 is the print server for all printers.
Client Computer Configuration
Most users have desktop computers. Several users in the sales and management departments
have portable computers because they travel frequently. All client computers run Windows 7
Enterprise. The Windows Internet Explorer proxy settings are configured on all client
computers by using a GPO named GPO-IE. GPO-IE is linked to the domain. All users in the
company use a custom application named App1. App1 is manually installed on all client
computers. A new version of App1 is available. Some features in the new version of App1
are incompatible with the previous version of App1.
###EndCaseStudy###
The sales users that were part of the VPN server pilot project report that they can no longer
establish VPN connections to the internal network. You need to ensure that all authorized users can
establish VPN connections to the internal network. What should you request a domain administrator to do?
A.
Enable auto-renewal for certificates.
B.
Increase the lifetime of the Kerberos user ticket.
C.
Increase the lifetime of the Kerberos service ticket.
D.
Increase the certification validity period for the computer certificate template.