70-219 考题中文翻译版(1)
添加时间: 2007-4-2 1:07:42 作者: 微软认证参考 阅读次数:105 来源: http://www.d9soft.com
Your company is asked to provide consulting, development, and integration services for a company named Contoso Research. As a part of this project you will implement Windows 2000. All client computers that currently run Windows will be upgraded to Windows 2000 Professional. Wherever possible, the Windows NT 4.0 domain controller environment will be fully upgraded to Windows 2000 Server.
Background:
Contoso Research is a military research company that operates from several locations in the United States.
Most of the company's business comes from contracts from the United States government and military.
Its headquarters and primary IT center is in Washington, D.C. The company is distributed as follows
Research facilities
Boston, Massachusetts
Denver, Colorado
San Diego, California
San Francisco, California
Seattle, Washington
St. Petersburg, Florida
St. Petersburg, Florida
Washington, D.C.
The Denver, San Diego, San Francisco, and Seattle facilities were originally a separate company named
Parnell Aerospace. These facilities became a part of Contoso Research when they were purchased in 1997.
These facilities still use the Parnell Aerospace name, and Parnell Aerospace still maintains its identity as a separate company. Contoso Research is likely to acquire another company in the near future.
Problem Statement:
Chief Executive Officer (CEO):
Because we are primarily a military research contractor working on a variety of classified projects, our primary concern is security. We purchased Parnell Aerospace in 1997, but in many respects it still operates as a separate company. We are attempting to eliminate duplicated work within the two companies as much as possible. We are also in the process of developing common operating practices.
For the purposes of shared research, we allow our government and military customers to access some of
our data.
When we bought Parnell Aerospace, we needed to restructure our entire network security structure. We need to be able to support our growth plans without needing to perform this type of restructuring again.
Chief Information Officer (CIO):
In some cases, to avoid the need to replace existing hardware, we will use other operating systems rather than Windows 2000.
Rather than build more than one directory service, we want an integrated directory service. To work toward accomplishing this goal, we will be migrating Microsoft Exchange Server 5.5 to Exchange 2000 Server.
All account administration currently needs to be performed from our IT centers. We want to remove
this limitation. We also want a security infrastructure that will not need to be restructured when the
accounts database reaches 40 MB.
Our current arrangement of trust relationships is cumbersome to manage. The current Windows NT 4.0
domain structure requires several domains for delegation of administration. We eventually want to have
a global IT facility that uses common software, standards, and procedures. This consolidation will
begin during the Windows 2000 upgrade, but we do not expect to complete it during the upgrade. We
want the IT facilities to be controlled from one location as necessary. However, we also want to be able
to delegate certain tasks without necessarily needing to create domains for them.
We are concerned that Microsoft Windows 95 and Windows 98 do not offer enough security at the
client computer level. We want to increase our control and continue to standardize our client computers
and applications in all departments.
We want to standardize our security and management environment throughout the company as much as
possible.
We must minimize the disruption caused by the Windows 2000 upgrade, and the upgrade must not
compromise our security.
History:
Contoso Research has a diverse server environment. The company uses mainframe, UNIX, Novell,
Macintosh, Banyan VINES, and Microsoft servers.
The current Windows NT 4.0 domain structure was configured in 1997, after the purchase of Parnell
Aerospace, in an attempt to try to integrate the IT structures of the two companies. The network based
on Windows NT 4.0 was configured as a coexisting server structure, and migration and interoperability
were gradually implemented. Since then, all service packs up to Service Pack 7 have been applied to
Windows NT 4.0. The goal of this migration is to finally remove all of the remaining Banyan VINES
and Novell server
Existing IT Environment:
General:
Contoso Research uses 25,000 personal computers.
The distribution of users is shown below:
Boston 2,900
Denver 4,200
San Diego 1,900
San Francisco 3,600
Seattle 2,400
St. Petersburg 2,600
Washington, D.C. 7,400
There are currently two Windows NT 4.0 account domains. All user accounts are in these domains.
There is one resource domain in each of the seven geographic locations. There are account domains in
Washington, D.C., and San Francisco. BDCs are distributed throughout the company as needed. At the
Washington location, there are two domain controllers running custom applications that will not run on
Windows 2000. During the upgrade process, these domain controllers will remain on computers that
run Windows NT 4.0. These domain controllers will be migrated at a later date.
Network Infrastructure:
There is a 44.736-Mbps line from San Francisco to the primary IT center in Washington, D.C. This line
is used primarily for business applications. The 44.736-Mbps line has an average available bandwidth
of 35 percent. There are 1.544-Mbps lines from Washington, D.C., to Denver, Boston, St. Petersburg,
Seattle, and San Diego. There are also 1.544-Mbps lines from San Francisco to San Diego, Denver,
and Seattle. The WAN links will be upgraded if more bandwidth is needed.
Each location has one internal DNS server to manage the current UNIX environment. The current
internal implementation of DNS does not support SRV records, dynamic update, Unicode characters, or
incremental zone transfer. The IT staff members who currently maintain the DNS servers manage both
the UNIX environment and the Windows NT Server environment. The external DNS systems for both
the Contoso Research Web site and the Parnell Aerospace Web site are currently hosted on third-party ISP
servers. The DNS modifications required for Windows 2000 will be designed to use the existing
internal DNS structure.
IT Infrastructure:
The primary IT center is in Washington, D.C. There is also a major IT center in San Francisco. In many
ways, the San Francisco research facility operates as an independent business unit. Since 1997, the IT
department has been creating an increasingly centralized IT management structure. All account
management is performed in Washington, D.C., and San Francisco. All Windows 2000 operations
masters will remain in their default locations. The departments that must be supported by the IT
infrastructure include the following:
Administration
Financial
Human resources - managed as a single group by I
Management
Public relations
Real estate
Information technology (IT)
Sales and marketing
Research
Aerospace
Biological
Chemical
electrical
Mechanical
Policies and application specifications are defined at the Washington, D.C., and San Francisco IT
centers. These two locations also provide telephone support for each department. Additionally, there is
an IT department at each geographic location. These local IT departments report directly to the global
technical support center. At the local offices, the IT staff is divided by departments and departmental
responsibilities.
Security:
Currently, the two domains have different security policies for password length and complexity, and for
account lockout. These policies will not be changed after the Windows 2000 upgrade project is
completed. Accounts will be created at the Washington, D.C., and San Francisco facilities. The rights
for resetting passwords and changing attributes will be delegated to local IT administrators.
IT administrators give these users rights by adding global groups to local groups. There will be four
levels of administrators for day-to-day operations:
Enterprise administrators will be a small group contained in a separate top-level domain to
manage the entire organization.
Domain administrators will be granted rights to the entire domain.
Branch administrators will be granted rights for operations at the physical locations.
Departmental administrators will have localized rights based on their specific roles.
The departmental and branch administrators of resource domains are not granted administrative rights
for the corresponding account domains.
Group Policy Goals:
Group Policy will be centrally managed from Washington, D.C., as much as possible. Initially, Group Policy will be designed to redirect folders, to minimize logon time, to define logon scripts, to set security, and to allow specific software to be made available for installation in departments where users have the ability to install software.
有人请你的公司为名为Contoso Research的公司提供咨询,发展和整合的服务。作为这项工程的一部分那样你将实现windows 2000的安装。
当前运行windows的客户计算机都将被升级为windows 2000 professional.
假如可能,windows nt 4.0域控制器环境将被完全升级Windows 2000服务器。
背景:
Contoso Research是分布在美利坚合众国各地的军事研究公司。
大部分公司业务来自政府和军队的订单。
其总部和IT中心位于华盛顿D.C市
公司分布如下
研究基地
波士顿——马萨诸塞
丹佛——科罗拉多
圣地亚哥——加利福尼亚
旧金山——加利福尼亚
西雅图——华盛顿
圣彼得斯堡——佛罗里达
圣彼得斯堡——佛罗里达
华盛顿D.C市
位于丹佛,圣地亚哥,旧金山和西雅图的研究基地原来是被命名为帕内尔航空和宇宙航行空间的公司,本来和总公司没有关联。
当他们(帕内尔航空和宇宙航行空间公司)在1997年被收购的时候,这些研究基地成为Contoso Research公司的一部分。
这些研究基地还使用“帕内尔航空和宇宙航行空间公司”的名字,并且,帕内尔航空和宇宙航行空间如同与总公司没有联系的公司那样,还维
持其同一性。
Contoso Research有可能在不远的将来收购另一个公司。
问题陈述:
首席业务领导人(CEO):
因为我们主要解决各种分类的工程的军事的调查。所以,我们主要的关心是 安全 。
我们在1997年购买了帕内尔航空和宇宙航行空间,但是,在很多方面它象没有联系的公司那样运作着。
我们试图在公司的范围内尽可能地减少重复的工作。
另外, 我们在发展共同操作的实践。为了分享调查结果,我们允许政府和军队顾客访问一些我们的数据。
当我们收购帕内尔航空和宇宙航行空间的时候,我们需要重新构建我们整个 网络 安全结构。
我们要是现在的网络架构能够跟上我们发展的计划,而不需要再一次的重组。
信息采编者主要的(CIO):
在一些情况下,为了避免更换目前使用的硬件,我们将使用其他的操作系统而不是视窗2000。
我们想得到整合的目录服务,而不是一个以上的目录服务
为了完成这项工作,我们将把exchange 5.5移植到exchange 2000服务器上。
当前,全部账户 管理 都必须在IT中心进行。
我们想除掉这一限制。
我们同样希望我们的账户数据库在达到40mb时,不需要下部基础构建进行重构。
目前我们(域之间)的信赖关系管理是笨重的。
现在的Windows NT 4.0域结构有好几个域需要进行授权管理。
我们想使用全局共同的软件设备,标准,程序。
这一合并将在windows 2000升级期间里开始,但是,我们不打算在升级期间里完成它。
我们想使IT研究基地尽量接受单一定点的管理。
不过,当没有必要为某些任务建立域的时候,我们也想可以为某些任务进行委派。
我们担心Microsoft Windows 95和98在客户机这一级上不能提供足够的 安全 。
我们想增强我们的控制,继续使我们的客户计算机和应用程序在所有部门中标准化。
我们想使我们安全和 管理 环境尽可能地标准化。
我们必须把windows 2000升级过程中引起的中断减少到最小,并且,升级不可以影响到我们的安全。
历史:
Contoso Research有多种多样的服务器环境。
公司使用mainframe,UNIX,novell,macintosh,banyan VINES和 微软 公司服务器。
现在的Windows NT的4.0域结构组建于1997年。当时Contoso reseach 收购了“帕内尔航空和宇宙航行空间公司”。当时的目的是要整合这两个公
司的IT结构。
基于Windows NT 4.0的 网络 被设置为共存的服务结构,并且,迁移和互用性逐渐地被实现了。
从那个时候以来,全部service pack都已经被Windows NT 4.0应用了。
这次迁移的目的是要最终移除所有的banyan和novell服务器。
目前环境:
梗概:
Contoso Research使用25,000台个人的计算机。
用户的分布如下:
波士顿2,900
丹佛4,200
圣地亚哥1,900
旧金山 3,600
西雅图 2,400
圣彼得斯堡 2,600
华盛顿D.C市 7,400
当前有两个Windows NT的4.0域。
全部用户账户都在这些域里。
每个地理位置上都有一个资源域
华盛顿D.C市和旧金山有账户域。
BDC分布在公司的各个地方。
在华盛顿,有两个域控制器运行着与windows 2000不兼容的客户程序。
在升级过程中,这些域控制器将继续在Windows NT 4.0的计算机上保留。
这些域控制器将稍后被迁移。
网络基础设施:
从旧金山到华盛顿D.C市的IT中心有44.736 Mbps的线路。
这条线将首先用于商务应用。
44.736 Mbps的线路平均有35 %的可以利用的带宽。
从华盛顿D.C市到丹佛,波士顿,圣彼得斯堡,西雅图和圣地亚哥有1.544 Mbps的线路。
从旧金山到圣地亚哥,丹佛和西雅图, 有1.544 Mbps的线。
如果要更多的带宽的话,线路将会被升级。
每个地方都为了管理现在的UNIX环境,都有1台内部的DNS服务器。
现在的DNS不支持SRV记录,动态更新,Unicode特性或增量区域传输。
当前维持DNS服务器的职员同时管理UNIX环境和Windows NT服务器环境。
为Contoso Research Web站点和帕内尔航空和宇宙航行空间站点提供外部DNS系统的是第三方的Internet服务提供商的服务器。
为实现win2000而进行的对DNS的修改修改将基于目前的内部的DNS结构。
基础设施:
主IT中心位于华盛顿D.C市
另外, 在旧金山也有一个IT中心。
就很多方面而言,旧金山研究机构如同独立的商务单位那样运作。
自从1997年以来的,IT部门已经趋向于集中化管理结构。
全部账户管理都在华盛顿D.C市和旧金山中被实行。
全部windows 2000个操作主控都将留在他们的原来的地方。
必须得到IT部门技术支持的部门如下:
管理部
财政 部
人力 资源——如同单一的集团那样由我管理
厂方
公共宣传部
不动产部
信息技术(IT)
市场营销部
研究部
航空和宇宙航行空间部
生物学部
化学部
电子部
机械部
策略和应用说明在华盛顿D.C市和旧金山的IT中心。
这些两个地方也为每个部门提供电话技术支持。
另外,在每个地理学上的位置都有IT部门。
这些当地IT部门直接向全局技术支持中心报告。
在地方的办公室,IT职员依据部门和部门职责被分配。
安全:
当前,两个域的口令长度和复合状态,以及账户锁定有不同的安全策略。
在windows 2000升级工程被完成之后,这些策略将不被改变。
账户将在华盛顿D.C市和旧金山被建立。
设置口令和改变属性的权限将授予当地的IT部门管理员。
IT管理者通过把全局组加入本地组来赋予用户权限。
为了日常管理,有四个等级的管理员:
企业 管理者将是一个小的集团,管理整个组织,最高水平的域。
域管理员对域有完全的权限。
枝管理员对其所在物理位置由管理的权限。
部门的管理者的权限根据他们本身的角色限于局部。资源域的部门和枝域的管理者对其相应的账户域没有权限。
组策略的目的:
集组策略将尽量在华盛顿D.C市实现。
开始时,集团政策将被设计为对文件夹进行重定向,把登录上网时间减少到最小、定义登录上网脚本、设置安全,允许有安装软件的能力的用户安装特定的软件。
上一篇文章: 70-210 考题回忆(1) 下一篇文章: 70-059TCP/IP 4.0 试题回顾(2)(1)
相关文章:

