Apple 9L0-611 Exam -

Free 9L0-611 Sample Questions:

Q: 1 Which information is included in a ticket-granting ticket (TGT) from the key distribution center (KDC)?
A. the public key for the KDC
B. the time the TGT was issued
C. the user account's crypt password
D. the service key for all supported kerberized services
Answer: B

Q: 2 Which three are Mac OS X Open Directory plug-ins that can request data from a directory service?
C. Bonjour
D. AppleTalk
E. Active Directory
F. BSD Flat File and NIS
Answer: B, E, F

Q: 3 Which is a valid concern when using the Archive feature in Open Directory services on Mac OS X Server v10.4?
A. The archive does not include the local NetInfo database or configuration file
B. The archive contains all of the account passwords and should not be left unsecured
C. You cannot archive a copy of the Open Directory data while the Open Directory master is in service
D. Kerberos must be reconfigured after restoring from an archive, because the archive does not include Kerberos data.
Answer: B

Q: 4 You are promoting Open Directory services on a computer running Mac OS X Server v10.4 from Standalone Server to Open Directory Master.Which statement about the administrator account is true?
A. The primary administrator account in the local NetInfo database is copied to the LDAP database and used as the primary administrator account for the LDAP database.
B. A new administrator account with the name "diradmin" is created in the LDAP database and assigned the password from the root accont in the local NetInfo database.
C. The root account in the local NetInfo database is copied to the LDAP database and used as the primary administrator account for the LDAP database.
D. A new administrator account is created in the LDAP database, and you assin it a name and password
Answer: C

Q: 5 You have configured Mac OS X client computers to retrieve user account information from an Active Directory server, and additional directory data from a Mac OS X Server. Which is a valid concern for this configuration?
A. A modification to the Active Directory schema is necessary
B. The ability to manage individual user accounts in Mac OS X is sacrificed.
C. A Mac OS X computer cannot access two directory servers simultaneously
D. A configured directory on Mac OS X Server must be added to the Active Directory domain
Answer: B

Q: 6 Review the following command then complete the statement below: Id apsearch -LLL -x -H Idap:// -b dc=example, dc=com "(objectClass=apple-group)" cn objectClass The last two options in this command, cn and objectClass, specify the _____
A. LDAP entries to exclude from the results
B. Attributes to return in the results
C. Search filter
D. Search base
Answer: B

Q: 7 What file on a Mac OS X computer is used to specify the location of the key distribution center (KDC) and the Kerberos realm?
A. /Library/Preferences/ Kerberos
B. ~/Library/Preferences/Kerberos.plist
C. /etc/Kerberos/Kerberos.cof
D. /etc/krb.conf
Answer: A

Q: 8 You are troubleshooting an Open Directory LDAP server. Which step will allow you to gather troubleshooting information from the server?
A. Start a lapd with the flag -d 99.
B. Turn on verbose logging in Server Admin
C. Start directoryServices with the flag - debug
D. Edit/etc/hostconfig. To contain LDAPARGS =;-d;
Answer: A

Q: 9 In an Open Directory user record, what value should the NFSHome Directory attribute contain?
A. the local file system path to the user's home folder
B. the IP address of the NFS server providing network home folder
C. the URL used to mount the share point containing the user's home folder
D. the ID for the mount record that mounts the share point providing the user's home folder
Answer: A

Q: 10 When you set up Mac OS X Server to work with a Kerberos key distribution center (KDC), which file is highly sensitive and should be readable only by root?
B. Kerberos.conf
C. Krb5.keytab
D. Key.pem
Answer: C

Q: 11 What authentication token does a client present when accessing a kerberized service?
A. the user's password
B. a client-generated service ticket
C. a service ticket obtained from the key distribution center (KDC)
D. a ticket-generating ticket (TGT) obtained from the key distribution center (KDC)
Answer: C

Q: 12 Which statement is NOT true Password Server replication in Mac OS X Server v10.4?
A. Password Server engages in a multimaster replication scheme.
B. Confilicts in the Password Server database replicas are resolved using slapd.access
C. The replication process is entirely encrypted between each Password Server process.
D. Password Server refers to /var/db/authserver/authserverreplicas to determine if the last synchronization was successful.
Answer: B

Q: 13 You need to configure several Mac OS X computers to bind to an LDAP server that is not running on a Mac OS X computer. This is the first time that you have used this LDAP server. What should be your FIRST step?
A. In the LDAP plug-in in Directory Access, create mappings to supplement required user account attributes that are not on the LDAP database.
B. Use an LDAP browsing tool to verify the connection settings and identify the structure and format of the data stored on the server.
C. Create a new LDAP configuration in Directory Access and determine the connection settings through experimentation
D. Have the server system administrator modify the schema to support missing attributes that are required by Mac OS X
Answer: B

Q: 14 Review the following partial mount record, then answer the question below:
VFSLinkDir: /Network/Servers/
VFSopts: net url==afp://
VSFType: url|
You use dsc 1 to view a mount record provided by an LDAP server. How is the share point mounted?
A. statically, using NFS
B. statically, using AFP
C. dynamically, using AFP
D. dynamically, using NFS
Answer: D

Q: 15 You disable anonymous binding on the Mac OS X Server LDAP server by ________
A. adding this line to the /etc/hostconfig file:LDAPSERVER_BINDANON=-NO
B. adding this line to the /etc/openldap/slapd.conf file.disallow bind_anon
C. adding this line to the etc/openldap/ldap.conf file:disallow anon_binding
D. issuing this command to the server.sudo NeST -setLDAPConfig "BIND_ANON" off
Answer: B

Q: 16 Which statement about the dsc 1 command line utility is true?
A. dsc1 makes requests through lookupd.
B. dsc 1 has a plug-in architecture for compatiability
C. dsc1 makes requests through DirectoryService
D. dsc1 can be run when computer is in single-user mode.
Answer: C

Q: 17 Chris is logged into a Mac OS X computer using a non-admin network user account provided by Mac OS X Server v10.4. The user account is configured to use an Open Directory password. When Chris tries to connect to an AFP server that is configured to use only Kerberos authentication, an "Authenticate to Kerberos " dialog appears, requesting a name realm, and password Chris enters the user account name and password again and click OK. The same dialog reappears. What can a local system administrator do to resolve Chris's issue?
A. Tell Chris to log on to the client computer with a secure shadow hash.
B. Enable the Kerberos v5 plug-in in Directory Access on the client computer
C. Use kdestroy to destroy any existing tickets in the cache on the client computer
D. Ensure that the date, time and time zone on the Mac OS X client and on the key distribution center (KDC) are synchronized.
E. Tell Chris to cancel the "Authenticate to Kerberos " dialog connect to the AFP server as guest, and assume the connection is secure
Answer: D

Q: 18 What are three to provide data that is missing from a third-party LDAP server to support Mac OS X client?
A. Repurpose existing fields in the directory schema.
B. Modify the server's search path to exclude/NetInfo/root
C. Create local mappings with static and variable attributes
D. Remove unused objectClasses from the local directory schema.
E. Remove unused objectClasses from the local directory schema
F. Enable Option 95 to assure communication with the DHCP server
G. Modify the schema for the directory on the third-party LDAP server
Answer: A, C, F

Q: 19 You are configuring your Mac OS X computer to authenticate at the login window through an LDAP server. Which Open Directory user attribute are you NOT required to map to an LDAP user attribute?
A. Unique ID
C. RealName
D. RecordName
Answer: B

Q: 20 You are setting up a new server. When the role in Open Directory services on a computer running Mac OS X Server v10.4 is configured to be a standalone server,____
A. directory data is stored in the local LDAP database
B. directory data is stored in the local NetInfo database
C. Password Server is used for password authentication
D. Kerberos service is provided for local accounts only
Answer: B

