To configure the Mac OS X Server LDAP server for SSL, in addition to enabling the LDAP SSL option, what else must you do?
A. Enter the passphrase for the private key.
B. Enable SSL in Directory Access on the server.
C. Install the Cryptography Services package from the Admin Tools CD.
D. Install a private key and a signed certificate, and configure the server to use them.

Correct Answer: D Section: (none) Explanation
What file on a Mac OS X computer is used to specify the location of the key distribution center (KDC) and the Kerberos realm?
A. /Library/Preferences/
B. ~/Library/Preferences/Kerberos.plist
C. /etc/Kerberos/kerberos.conf
D. /etc/krb.conf

Correct Answer: A Section: (none)Explanation
You are using lookupd to query user account information. By default, which lookupd agents are used? (Choose THREE.)
A. NIAgent
B. DSAgent
C. DNSAgent
D. CacheAgent
E. BonjourAgent
F. AppleTalkAgent

Correct Answer: ABD Section: (none)Explanation
If you create an LDAP configuration in Directory Access that statically maps the local UniqueID attribute to #1007, what is the result?
A. All user accounts provided by that LDAP configuration will have a UniqueID of 1007.
B. The value of UniqueID for each user account on the LDAP server is GeneratedUID plus 1007.
C. UniqueID and GeneratedUID values for user accounts provided by that LDAP configuration on that computer are synchronized.
D. Each new user account created on that computer is assigned a UniqueID value, starting at 1007, and incrementing the UniqueID value by 1 for each new account.

Correct Answer: A Section: (none)Explanation
In an Open Directory master/replica configuration, the key distribution center (KDC) is replicated through ________.
A. kadmind
C. the Password Server
D. the Kerberos realm

Correct Answer: C Section: (none)Explanation Explanation/Reference:
You are configuring your Mac OS X computer to authenticate at the login window through an LDAP server. Which Open Directory user attribute are you NOT required to map to an LDAP user attribute?
A. UniqueID
B. MCXFlags
C. RealName
D. RecordName

Correct Answer: B Section: (none) Explanation
You are configuring Mac OS X client computers to access user records in a third-party directory. Without modifying the schema on the third-party directory, how can you provide valid mount records for network home folders?
A. Create a mount record in the local LDAP directory on the Mac OS X client.
B. Use Directory Access to map VFSType to apple-user-homeurl on each client computer.
C. Use the Active Directory schema rather than the RFC 2307 schema on the LDAP directory.
D. Supplement the third-party directory with a directory on Mac OS X Server to host the mount records.

Correct Answer: D Section: (none)Explanation
Your Mac OS X Server LDAP server provides LDAP mappings via DHCP.
How can clients obtain the schema mappings for your server?
A. The mappings are delivered as part of the DHCP OFFER packet.
B. Clients request the schema mappings via the MetaDirectory protocol.
C. Clients install the schema files at /etc/openldap/schema on the client computer.
D. Clients query the LDAP server for the mapping configuration entry at cn=macosxodconfig,cn=config.

Correct Answer: D Section: (none) Explanation
An administrator assigns a computer with Mac OS X Server v10.4 to the role of Open Directory replica. What information will the administrator NOT be prompted to provide about the Open Directory master being replicated?
A. IP address of the master
B. MAC address of the master
C. root password for the master
D. LDAP directory administrator user name on the master

Correct Answer: B Section: (none)Explanation
Chris is logged into a Mac OS X computer using a non-admin network user account provided by Mac OS X Server v10.4. The user account is configured to use an Open Directory password. When Chris tries to connect to an AFP server that is configured to use only Kerberos authentication, an uthenticate to Kerberos dialog appears, requesting a name, realm, and password.
Chris enters the user account name and password again, and clicks OK. The same dialog reappears.
What can a local system administrator do to resolve Chris issue?
A. Tell Chris to log on to the client computer with a secure shadow hash.
B. Enable the Kerberosv5 plug-in in Directory Access on the client computer.
C. Use kdestroy to destroy any existing tickets in the cache on the client computer.
D. Ensure that the date, time, and time zone on the Mac OS X client and on the key distribution center (KDC) are synchronized.
E. Tell Chris to cancel the uthenticate to Kerberos dialog, connect to the AFP server as guest, and assume the connection is secure.

Correct Answer: D Section: (none) Explanation
In a default configuration, what LDAP user name do clients enter in Directory Access to perform LDAP queries on Mac OS X Server Open Directory?
A. ldap
B. admin
C. cn=ldap,dc=example,dc=com
D. cn=admin,dc=example,dc=com
E. Nonehe default configuration allows anonymous binding.

Correct Answer: E Section: (none)Explanation
Which is a valid concern when using the Archive feature in Open Directory services on Mac OS X Server v10.4?
A. The archive does not include the local NetInfo database or configuration files.
B. The archive contains all of the account passwords and should not be left unsecured.
C. You cannot archive a copy of the Open Directory data while the Open Directory master is in service.
D. Kerberos must be reconfigured after restoring from an archive, because the archive does not include Kerberos data.

Correct Answer: B Section: (none)Explanation
You are troubleshooting an Open Directory LDAP server. Which step will allow you to gather troubleshooting information from the server?
A. Start slapd with the flag -d 99.
B. Turn on verbose logging in Server Admin.
C. Start DirectoryServices with the flag -debug.
D. Edit /etc/hostconfig to contain LDAPARGS=’-d’.

Correct Answer: A Section: (none)Explanation
As an administrator of an Open Directory master and its replicas, which command would you use to force a replication?
A. ldapd
B. syncd
C. slapconfig
D. slapd.access

Correct Answer: C Section: (none)Explanation
Mary logs in to Mac OS X v10.4 as an Active Directory user via Apple Active Directory plug-in. A network home folder has been configured for her account. By default, her home folder ________.
A. on the local volume is disabled
B. resides on an auto-mounted AFP volume from Mac OS X Server
C. is stored locally, but an SMB ome is mounted on the desktop
D. resides on the NFS volume provided by the Active Directory domain

Correct Answer: C Section: (none)Explanation

