Company XYZ recently acquired a manufacturing plant from Company ABC which uses a different manufacturing ICS platform. Company XYZ has strict ICS security regulations while Company ABC does not. Which of the following approaches would the network security administrator for Company XYZ MOST likely proceed with to integrate the new manufacturing plant?
A. Convert the acquired plant ICS platform to the Company XYZ standard ICS platform solely to eliminate potential regulatory conflicts.
B. Require Company ABC to bring their ICS platform into regulatory compliance prior to integrating the new plant into Company XYZ's network.
C. Conduct a risk assessment of the acquired plant ICS platform and implement any necessary or required controls during integration.
D. Conduct a network vulnerability assessment of acquired plant ICS platform and correct all identified flaws during integration.
Answer: C

Your network contains two Active Directory forests named and
Each forest contains one domain.
A two-way forest trust exists between the forests.
You plan to add users from to groups in
You need to identify which group you must use to assign users in access to the
shared folders in
To which group should you add the users?
A. Group 2: Distribution Group - Domain Local.
B. Group 6: Distribution Group - Univeral.
C. Group 5: Security Group - Universal.
D. Group 1: Security Group - Domain Local.
E. Group 4: Distribution Group - Global.
F. Group 3: Security Group - Global.
Answer: F
This one is a bit tricky. According to Microsoft's advice we should put Users Accounts into a Global Group,
then add the Global Group to a Universal Group, and then add the Universal Group to a Domain Local
group which is used to assigned permissions to. Microsoft calls this AGUDLP. See the reference below.
So, the users need to be put in a Global Group (answer C ("Group 3: Security Group - Global")), but it's the
Universal Group that travels across the forest trust (answer E ("Group 5: Security Group - Universal")).
Another way of looking at the question might be that they're asking what kind of group actually is assigned
access to the shared folders. That would be a Domain Local security group, being answer A ("Group 1:
Security Group - Domain Local").
Because of Microsoft's advice I choose answer C ("Group 3: Security Group - Global"). But it could just as well be A or E.
Again, it's tricky one.
Best practices for using security groups across forests
By carefully using domain local, global, and universal groups, administrators can more effectively control access to resources located in other forests. Consider the following best practices:
-To represent the sets of users who need access to the same types of resources, create role-based global groups in every domain and forest that contains these users. For example, users in the Sales Department in ForestA require access to an order-entry application that is a resource in ForestB. Account Department users in ForestA require access to the same application, but these users are in a different domain. In ForestA, create the global group SalesOrder and add users in the Sales Department to the group. Create the global group AccountsOrder and add users in the Accounting Department to that group.
-To group the users from one forest who require similar access to the same resources in a different forest, create universal groups that correspond to the global group roles. For example, in ForestA,
create a universal group called SalesAccountsOrders and add the global groups SalesOrder and AccountsOrder to the group.
-To assign permissions to resources that are to be accessed by users from a different forest, create resource-based domain local groups in every domain and use these groups to assign permissions on the resources in that domain. For example, in ForestB, create a domain local group called OrderEntryApp. Add this group to the access control list (ACL) that allows access to the order entry application, and assign appropriate permissions.
-To implement access to a resource across a forest, add universal groups from trusted forests to the domain local groups in the trusting forests. For example, add the SalesAccountsOrders universal group from ForestA to the OrderEntryApp domain local group in ForestB.

What does the blinking yellow Activity/PoE LED indicate on an N-Series switch?
A. There is current transmitting/receiving and PoE power is off.
B. There is current transmitting/receiving and PoE power is on.
C. There is no current transmit/receive activity and PoE power is on.
D. There is no current transmit/receive activity and PoE power is off.
Answer: B

Regarding route introduction, the following describes the error?
A. bgp mportNetwork, Network generates routing support. Two ways are more precise.
B. By default, the default metric of the external route is imported. The OSPF 1, Type2 value is the
imported external route type.
After the route is imported to the C.
isis level-2 network level-1, , if the route is imported, the ring will
form a route.
C. Introducing a route in the route may cause a route OSPF IBGP ring
Answer: C

