Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations TouchToneTommy on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Two 70-284 Questions

Status
Not open for further replies.

umbletech

IS-IT--Management
Jan 29, 2006
196
Hi All

Been studying for 70-284 using MOC, Exchange 24/7 and Sybex Mastering..

Exam's in 3 days time so any help greatly appreciated.

A few things I'm unclear about:

mailbox cleanup agent:

You can connect a deleted user's mailbox to their fresh AD account within 30 days. But I found a question that had this situation with the mailbox still showing in the store and the answer as:

C. Ask the Active Directory administrator to perform an Active Directory authoritative restore of the user object. With this explanation:

In this case the user account has been deleted along with the mailbox account. It is possible to recreate the user account and reconnect the mail to the new account, but in that case the new
account will have a new SID and would lose its permissions. Therefore, the administrator needs to perform an authoritative restore for the user account that was deleted.

Which is correct?

QUESTION NO: 3
You are the Exchange administrator for Contoso.
The Exchange organization contains a single server that runs Exchange Server 2003.

After a new written company security policy is implemented on the Exchange server, the SMTP virtual server is configured as shown in the Authentication dialog box in the exhibit.

Diagram shows 3 check boxes:
anonymous authentication
basic authentication
Integrated windows authentication (which is ticked)

External customers now report that they cannot send e-mail to Contoso from the Internet.

They receive error messages stating that they do not have permission to submit e-mail to your Exchange server.
What should you do?

A. Enable anonymous access.
B. Enable basic authentication.
C. Reconfigure the relay restrictions to allow all IP addresses to relay to the SMTP virtual server.
D. Specify that the NETWORK group has permission to submit messages to the SMTP virtual
server.

Answer: A

Explanation
By default, the SMTP virtual server allows only authenticated users to relay e-mail messages. This setting prevents unauthorized users from using your Exchange server to send e-mail
messages to external domains. If your server is secured for relay, only authenticated users can send mail to the Internet using your server. To allow external users to utilize the SMTP connector, you need to permit anonymous user access to SMTP connector.


I don't get it. Surely if exchange 2003 servers are relay secured (thank goodness) by default and you follow this reasoning then nobody would be able to send to them from the net and nobody would buy the product!!! If we follow A with no other restrictions haven't we just created an open relay?

covers relaying. Is the question meant to say that they're using your server as a mailserver. Ie. you've setup an smtp connector and allowed relaying from their domain?
 
For Q1 I'd say although you could recreate a new acocunt and then attach an existing mailbox to it it's far better to do an authoritative restore as you don't need to worry about permissions etc as well then. Least admin effort (a common phrase in questions) would certainly be an authoritative restore.
 
Assuming that the deleted mailbox retention period has not lapsed (MSExchange says 30 days, but be careful there as it's configurable)....

You could attach that mailbox to any non-mailbox enabled account - new or old.

Pat Richard, MCSE(2) MCSA:Messaging, CNA(2)
 
Mmm...so a line call. Thx gents - passed tody 850 - I'll take it. 70-284 next.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top