Guide 06 / 09 • Interview + practical learning

Active Directory

30 representative questions, English and Roman Urdu explanations, examples, exercises and original visual diagrams.

Beginner + intermediate4–6 hours daily30 questions

← Pack index and combined learning plan

How to use this guide

Read the short answer first, then explain the example without reading. Complete the practice task and collect evidence. The 50/40/30/20-question counts follow twice the higher estimates in your table; they are a preparation target, not a guaranteed employer question bank.

Pehle short answer parho, phir example apni zubaan mein samjhao. Practice task complete karke evidence rakho. Answers ratta laganay ke bajaye steps aur reasoning samjho.

Lab requirements: Disposable domain lab with supported Windows client/server VMs, snapshots and test accounts, or supplied output for table-top analysis. Diagnostic tools and AD module require appropriate permissions. Never practise FSMO seizure or disruptive recovery on a production domain.

Course outcomes / Aap kya kar saken ge

Beginner

  • Explain AD DS, DNS, groups and domain controllers
  • Interpret user states and troubleshoot basic access
  • Explain policy scope and read resultant policy evidence

AD, DNS, groups aur DC samjhao

User states aur basic access troubleshoot karo

GPO scope aur resultant evidence parho

Intermediate

  • Investigate recurring lockouts and permission failures
  • Troubleshoot GPO scope and replication dependencies
  • Interpret diagnostic outputs and identify escalation boundaries
  • Design group-based access and a coordinated account response

Lockout aur permissions investigate karo

GPO aur replication dependencies troubleshoot karo

Diagnostics interpret aur escalation decide karo

Group access aur account response design karo

Learning path and practice schedule

This is a suggested 84-hour topic plan: 24 beginner hours plus 60 additional intermediate hours. At 4–6 hours a day, allow approximately 4–6 study days for the beginner stage and 14–21 study days total for this guided course. These are planning estimates, not promises of independent workplace competence. Repeat stages if the practical checkpoints are weak. Related subjects overlap in the combined plan.

Daily routine: 4–6 hours

ActivityCore 4 hoursOptional extra 2 hours
Concepts and official tutorial60 minutes—
Hands-on lab or evidence exercise120 minutes90 minutes: a harder case or failed scenario
Interview answers aloud30 minutes30 minutes: mock interview and follow-ups
Review and evidence log30 minutes—

Roman Urdu: Roz aik ghanta concepts, do ghantay practical, aadha ghanta answers bol kar aur aadha ghanta review karo. Extra do ghantay hon to difficult lab aur mock interview karo. Har haftay chhay study days aur aik rest/catch-up day rakho.

Study time means focused work, excluding breaks. Allocate at least half to practical work. If no tenant or lab is available, analyse supplied data and diagrams, but record that limitation and revisit the task when you have access.

Stage and timeDirection and practiceResource / tutorialDeliverable in Roman Urdu
1. Beginner
8 hours
2–2 study days
Directory structure
Study domain, forest, OU, DC, group and DNS concepts. Build a diagram and explain authentication versus resource access.
AD DS overview
Active Directory Domain Services
Directory aur access ka map banao.
2. Beginner
8 hours
2–2 study days
Accounts and permissions
Work through user-state and share/NTFS examples. Use a disposable lab for read-only queries and approved test changes.
AD DS documentation
Active Directory Domain Services
User state aur effective permissions ke examples solve karo.
3. Beginner
8 hours
2–2 study days
Policy fundamentals
Link a safe policy in a lab or analyse a supplied example. Read resultant policy and explain scope and inheritance.
Group Policy processing
Group Policy processing
Policy scope aur applied/denied result explain karo.
4. Intermediate
20 hours
4–5 study days
Lockouts and access diagnosis
Use fictional or lab 4625/4740 evidence to trace likely sources. Compare group membership, logon session and resource permissions.
AD troubleshooting
AD DS troubleshooting
Lockout timeline aur access-denied report banao.
5. Intermediate
20 hours
4–5 study days
GPO and replication
Interpret gpresult, repadmin summaries and dcdiag output. Diagnose DNS, connectivity, authentication and SYSVOL consistency separately.
Replication and GPO troubleshooting
Troubleshooting AD replication
Diagnostics se cause narrow down karo.
6. Intermediate
20 hours
4–5 study days
Capstone and controlled operations
Complete a GPO failure plus recurring-lockout scenario. Explain role-holder and recovery risks without performing destructive operations.
Troubleshooting references
Group Policy application troubleshooting
Combined scenario aur mock interview complete karo.

Practical exit check

Beginner: Complete a basic task using documentation, explain the result and recognise when to escalate.

Intermediate: Complete a common scenario without a step-by-step answer, justify your checks, test an alternative explanation and verify the result. You may consult references as analysts do at work.

Beginner par documentation ke saath basic task karo. Intermediate par ready-made steps ke baghair scenario solve, reasoning explain aur result verify karo.

Visual explanations

Active Directory concept and evidence mapUsers + groupsDomain controllersDNS + authenticationPolicies + SYSVOLResource permissions
Original concept diagram. The three inputs on the left contribute to the central investigation or assessment, supporting the decision on the right. Relationships are conceptual, not a screenshot or an exhaustive deployment architecture.

Left ki information central analysis mein use hoti hai, phir decision ya response support hota hai.

Active Directory troubleshooting decision diagramYes / HaanNo / NahinGPO not appliedCheck resultant policyObject in scope?Check filters + replicationCorrect placement/link
Example troubleshooting decision. Use the branch that matches the observed evidence; complete verification after any corrective action.

Evidence ke mutabiq Yes ya No branch choose karo. Action ke baad result verify karo.

30 interview questions

Level labels indicate study focus, not a formal certification standard. Each short answer is a starting point for a 30–60 second response; expand with the example and your own honest experience.

30 questions shown
  1. What is Active Directory Domain Services?
  2. What is a domain controller?
  3. Domain versus forest versus OU: what is the difference?
  4. What is a security group versus distribution group?
  5. What are domain local, global and universal group scopes?
  6. What is AGDLP?
  7. Why is DNS important for AD?
  8. Kerberos versus NTLM: what is the difference?
  9. Why does time synchronisation matter?
  10. How do you troubleshoot an account lockout?
  11. Which events help investigate logon issues?
  12. How do you reset a password safely?
  13. Why is a disabled account different from a locked account?
  14. What is Group Policy?
  15. What is normal Group Policy processing order?
  16. How do you troubleshoot a GPO not applying?
  17. What does gpresult do?
  18. What does gpupdate do?
  19. What is loopback processing?
  20. What is a WMI filter?
  21. What is SYSVOL?
  22. How do you troubleshoot AD replication?
  23. What does repadmin /replsummary show?
  24. What is dcdiag used for?
  25. What are FSMO roles?
  26. Share versus NTFS permissions: what is the difference?
  27. How do you troubleshoot access denied?
  28. What are SPNs and why do they matter?
  29. What is a gMSA?
  30. How do you handle a suspected compromised AD account?
Beginner focus
Question 01 / 30

What is Active Directory Domain Services?

Short interview answer · English

A directory service storing identities and resources and supporting domain authentication and authorisation.

Why this matters · English explanation

It relies on infrastructure such as DNS and domain controllers.

Roman Urdu explanation
AD DS users aur resources ka directory hai jo domain login aur access mein madad karta hai.
Worked context / illustrative example
A domain user signs in and accesses an authorised file share.
Your practical task
Explain directory, authentication and access roles.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Active Directory Domain Services

Beginner focus
Question 02 / 30

What is a domain controller?

Short interview answer · English

A server running AD DS that hosts directory data and supports domain services.

Why this matters · English explanation

Multiple controllers improve resilience but need healthy replication.

Roman Urdu explanation
Domain controller AD data aur domain services provide karta hai. Multiple DCs ki replication healthy honi chahiye.
Worked context / illustrative example
Users contact a domain controller for supported authentication tasks.
Your practical task
Describe why one failing DC can cause inconsistent results.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Active Directory Domain Services

Beginner focus
Question 03 / 30

Domain versus forest versus OU: what is the difference?

Short interview answer · English

A domain is an administrative identity boundary within a forest; an OU organises objects for delegation and policy.

Why this matters · English explanation

An OU is not a security group.

Roman Urdu explanation
Domain aur forest directory structure hain; OU objects organise aur policy delegate karti hai. OU group nahin.
Worked context / illustrative example
Users are placed in an OU while group membership grants resource access.
Your practical task
Sketch a forest, domain and two OUs.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Active Directory Domain Services

Beginner focus
Question 04 / 30

What is a security group versus distribution group?

Short interview answer · English

Security groups can grant access; distribution groups serve mailing purposes.

Why this matters · English explanation

Group purpose, scope and membership must match the task.

Roman Urdu explanation
Security group access deti hai; distribution group mail distribution ke liye hoti hai.
Worked context / illustrative example
A file-share permission is assigned to a suitable security group.
Your practical task
Choose a group type for three requests.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Active Directory Domain Services

Intermediate focus
Question 05 / 30

What are domain local, global and universal group scopes?

Short interview answer · English

Scopes govern membership and where a group can be used across domain structures.

Why this matters · English explanation

Use documented scope rules instead of memorising a one-size-fits-all design.

Roman Urdu explanation
Group scope membership aur access usage define karti hai. Multi-domain context samajhna zaroori hai.
Worked context / illustrative example
A global role group is placed into a domain-local resource group.
Your practical task
Explain a simple single-domain grouping design.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Active Directory Domain Services

Beginner focus
Question 06 / 30

What is AGDLP?

Short interview answer · English

Accounts into Global groups, then Domain Local groups, then Permissions.

Why this matters · English explanation

It separates user roles from resource permissions in a common domain design.

Roman Urdu explanation
AGDLP mein users role group mein, phir resource group mein aur us par permissions hoti hain.
Worked context / illustrative example
Finance users enter a role group linked to a reports-access group.
Your practical task
Draw the relationship and explain a leaver removal.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Active Directory Domain Services

Beginner focus
Question 07 / 30

Why is DNS important for AD?

Short interview answer · English

Clients and controllers use DNS to locate domain services and resolve names.

Why this matters · English explanation

Incorrect DNS can break logon, policy and replication even when basic IP connectivity works.

Roman Urdu explanation
AD services locate karne ke liye DNS zaroori hai. Ping chalnay ka matlab AD healthy nahin.
Worked context / illustrative example
A client points only to external DNS and cannot locate domain services.
Your practical task
Describe resolver and service-record checks.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Troubleshooting AD replication

Beginner focus
Question 08 / 30

Kerberos versus NTLM: what is the difference?

Short interview answer · English

Kerberos uses tickets and domain infrastructure; NTLM is an older challenge-response mechanism used in supported fallback scenarios.

Why this matters · English explanation

Investigate why fallback occurs rather than assuming every successful login used Kerberos.

Roman Urdu explanation
Kerberos tickets use karta hai; NTLM older challenge-response hai. Fallback ki wajah investigate karo.
Worked context / illustrative example
A name or service configuration issue prevents expected Kerberos authentication.
Your practical task
Explain why successful access does not prove the intended protocol.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Active Directory Domain Services

Beginner focus
Question 09 / 30

Why does time synchronisation matter?

Short interview answer · English

Kerberos and other infrastructure components depend on acceptable time alignment.

Why this matters · English explanation

Check the domain time hierarchy and actual skew before changing settings.

Roman Urdu explanation
Time mismatch Kerberos aur infrastructure ko affect kar sakta hai. Domain time hierarchy check karo.
Worked context / illustrative example
A badly skewed client clock contributes to authentication failure.
Your practical task
Write read-only checks for time and source.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Active Directory Domain Services

Intermediate focus
Question 10 / 30

How do you troubleshoot an account lockout?

Short interview answer · English

Verify the user, review lockout evidence and locate repeated authentication attempts before unlocking repeatedly.

Why this matters · English explanation

Old credentials in tasks, services or devices can cause recurrence.

Roman Urdu explanation
Lockout source dhoondo. Old credentials service ya device mein hon to unlock ke baad phir lock ho sakta hai.
Worked context / illustrative example
A scheduled task repeatedly uses the user's old password.
Your practical task
List likely sources and evidence needed.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: AD DS troubleshooting

Intermediate focus
Question 11 / 30

Which events help investigate logon issues?

Short interview answer · English

Relevant Windows security events include failed logon 4625 and account lockout 4740 when auditing captures them.

Why this matters · English explanation

Interpret logon type, source and controller context; events may be distributed.

Roman Urdu explanation
4625 aur 4740 useful hain jab auditing enabled ho. Source aur logon type bhi dekho.
Worked context / illustrative example
A DC lockout event points towards a caller machine requiring further review.
Your practical task
Explain what one event can and cannot establish.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: AD DS troubleshooting

Intermediate focus
Question 12 / 30

How do you reset a password safely?

Short interview answer · English

Verify identity, check authority, use the approved process and securely communicate recovery details.

Why this matters · English explanation

Check service-account dependencies and hybrid effects where relevant.

Roman Urdu explanation
Identity verify aur authority check karke password reset karo. Service dependencies aur hybrid effects dekho.
Worked context / illustrative example
A human account reset is handled differently from a service account change.
Your practical task
Write a reset checklist and verification test.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Active Directory Domain Services

Beginner focus
Question 13 / 30

Why is a disabled account different from a locked account?

Short interview answer · English

Disabled status administratively prevents account use; lockout follows configured authentication-failure behaviour.

Why this matters · English explanation

Find the cause before reversing either state.

Roman Urdu explanation
Disabled admin action hai; lockout failed attempts ka result ho sakta hai. Wajah samajh kar action lo.
Worked context / illustrative example
A leaver account should not be enabled merely because a caller cannot sign in.
Your practical task
Compare recovery steps for the two states.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Active Directory Domain Services

Beginner focus
Question 14 / 30

What is Group Policy?

Short interview answer · English

A mechanism to centrally apply supported user and computer settings.

Why this matters · English explanation

Scope, precedence, filtering and replication influence the result.

Roman Urdu explanation
GPO central settings apply karti hai. Scope, filtering aur replication result ko affect kartay hain.
Worked context / illustrative example
A policy configures a supported security setting for computers in an OU.
Your practical task
Explain why an unrelated OU does not receive it.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Group Policy processing

Beginner focus
Question 15 / 30

What is normal Group Policy processing order?

Short interview answer · English

Local, site, domain and OU processing, with inheritance and precedence rules affecting the result.

Why this matters · English explanation

Enforcement, blocked inheritance and loopback can change practical outcomes.

Roman Urdu explanation
Normal order Local, Site, Domain, OU hai. Exceptions aur precedence bhi samajho.
Worked context / illustrative example
A more specific OU policy changes an inherited setting in a simple lab.
Your practical task
Explain order and one exception.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Group Policy processing

Intermediate focus
Question 16 / 30

How do you troubleshoot a GPO not applying?

Short interview answer · English

Check object location, link, scope, security filtering, applicability, replication and resultant policy evidence.

Why this matters · English explanation

Identify a scope issue before repeatedly forcing refresh.

Roman Urdu explanation
OU, link, filtering aur resultant policy check karo. Sirf gpupdate repeat karna enough nahin.
Worked context / illustrative example
A device sits in the wrong OU so the intended link does not apply.
Your practical task
Write a scope-first troubleshooting sequence.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Group Policy application troubleshooting

Intermediate focus
Question 17 / 30

What does gpresult do?

Short interview answer · English

It reports resultant policy information for the relevant user and computer context.

Why this matters · English explanation

Use it to identify applied and denied policies and compare with expectations.

Roman Urdu explanation
Gpresult effective policies dikhata hai. Applied aur denied policies ko expected result se compare karo.
Worked context / illustrative example
gpresult /r reports policy information; an HTML report can provide more detail.
Your practical task
Interpret a fictional denied-policy reason.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Group Policy application troubleshooting

Intermediate focus
Question 18 / 30

What does gpupdate do?

Short interview answer · English

It refreshes Group Policy processing; some changes still require logoff or restart.

Why this matters · English explanation

It does not fix an unlinked policy or broken replication.

Roman Urdu explanation
Gpupdate policy refresh karta hai; broken link ya replication khud fix nahin karta.
Worked context / illustrative example
A refreshed computer still lacks a policy because it is out of scope.
Your practical task
Explain when refresh is useful and when it is not.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Group Policy application troubleshooting

Intermediate focus
Question 19 / 30

What is loopback processing?

Short interview answer · English

A mode that changes user-policy application based on the computer's policy context.

Why this matters · English explanation

Merge and replace modes serve different scenarios and must be tested.

Roman Urdu explanation
Loopback mein user settings computer ke context se affect hoti hain. Merge aur replace alag hain.
Worked context / illustrative example
A shared kiosk applies specific user restrictions regardless of the signed-in user.
Your practical task
Explain why a kiosk may need loopback.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Group Policy processing

Intermediate focus
Question 20 / 30

What is a WMI filter?

Short interview answer · English

A condition used to determine GPO applicability based on supported system queries.

Why this matters · English explanation

Incorrect or slow filters can cause unexpected policy behaviour.

Roman Urdu explanation
WMI filter system condition ke mutabiq policy apply karti hai. Wrong filter policy miss kara sakta hai.
Worked context / illustrative example
A filter targets a particular supported system category.
Your practical task
Test true and false applicability cases.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Group Policy processing

Intermediate focus
Question 21 / 30

What is SYSVOL?

Short interview answer · English

A replicated domain share containing Group Policy files and scripts.

Why this matters · English explanation

Directory and SYSVOL replication are related but distinct mechanisms to investigate.

Roman Urdu explanation
SYSVOL policy files aur scripts rakhta hai. AD data aur SYSVOL replication ko alag verify karo.
Worked context / illustrative example
GPO metadata exists but its file content is inconsistent between controllers.
Your practical task
Explain the two parts of GPO consistency.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Troubleshooting AD replication

Intermediate focus
Question 22 / 30

How do you troubleshoot AD replication?

Short interview answer · English

Use replication status, event logs and dependency checks including DNS, connectivity, time and authentication.

Why this matters · English explanation

Diagnose errors before forcing synchronisation or making topology changes.

Roman Urdu explanation
Replication status aur logs dekho; DNS, network aur authentication check karo. Blind force sync mat karo.
Worked context / illustrative example
A network change blocks communication between two controllers.
Your practical task
Build a dependency-first investigation plan.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Troubleshooting AD replication

Intermediate focus
Question 23 / 30

What does repadmin /replsummary show?

Short interview answer · English

A summary of replication health and failures across controllers.

Why this matters · English explanation

Use detailed results and error codes for diagnosis; a summary is an entry point.

Roman Urdu explanation
Replsummary replication ka overview deta hai. Detail aur error code se cause dhoondo.
Worked context / illustrative example
repadmin /replsummary highlights a controller with failures.
Your practical task
Explain your next read-only checks.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Troubleshooting AD replication

Intermediate focus
Question 24 / 30

What is dcdiag used for?

Short interview answer · English

Running domain-controller diagnostic tests.

Why this matters · English explanation

Interpret individual test results and environment context rather than treating every warning equally.

Roman Urdu explanation
Dcdiag DC health tests chalata hai. Har warning ka impact aur context samjho.
Worked context / illustrative example
A DNS-related test failure prompts resolver and service-record investigation.
Your practical task
Match a failed test to a dependency check.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: AD DS troubleshooting

Intermediate focus
Question 25 / 30

What are FSMO roles?

Short interview answer · English

Specific directory operations roles assigned to controllers, including schema, domain naming, RID, PDC emulator and infrastructure.

Why this matters · English explanation

Role transfer and seizure require careful operational procedures.

Roman Urdu explanation
FSMO special directory roles hain. Transfer aur seizure sensitive operations hain.
Worked context / illustrative example
A planned maintenance activity considers the current role holders.
Your practical task
Name the five roles and explain when specialist escalation is needed.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Active Directory Domain Services

Intermediate focus
Question 26 / 30

Share versus NTFS permissions: what is the difference?

Short interview answer · English

Share permissions govern network-share access; NTFS permissions govern filesystem access.

Why this matters · English explanation

Effective network access reflects both layers and group membership.

Roman Urdu explanation
Share aur NTFS dono permissions network access ko affect karti hain. Membership bhi check karo.
Worked context / illustrative example
A user has share access but lacks the required folder permission.
Your practical task
Compute an effective-access example using both layers.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Active Directory Domain Services

Intermediate focus
Question 27 / 30

How do you troubleshoot access denied?

Short interview answer · English

Check identity, group membership, token freshness, share and NTFS permissions and explicit denies.

Why this matters · English explanation

Test the intended resource and avoid granting broad access as a shortcut.

Roman Urdu explanation
Identity, groups aur dono permission layers check karo. Broad access de kar issue hide mat karo.
Worked context / illustrative example
A new group membership has not reached the user's current logon session.
Your practical task
Explain verification after a membership change.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Active Directory Domain Services

Intermediate focus
Question 28 / 30

What are SPNs and why do they matter?

Short interview answer · English

Service Principal Names identify service instances for Kerberos authentication.

Why this matters · English explanation

Missing or duplicate registrations can cause authentication issues; changes need knowledgeable review.

Roman Urdu explanation
SPN Kerberos ko service identify karne mein madad deta hai. Missing ya duplicate SPN issue bana sakta hai.
Worked context / illustrative example
An application authenticates unexpectedly after an account or hostname change.
Your practical task
Explain what evidence to collect before changing SPNs.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Active Directory Domain Services

Intermediate focus
Question 29 / 30

What is a gMSA?

Short interview answer · English

A group Managed Service Account designed for supported service workloads with managed password handling.

Why this matters · English explanation

Host eligibility and application support must be planned.

Roman Urdu explanation
gMSA supported services ke password management mein madad karta hai. Har application support nahin karti.
Worked context / illustrative example
An approved service uses a gMSA rather than a shared human account.
Your practical task
Compare service identity ownership and credential maintenance.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: Active Directory Domain Services

Intermediate focus
Question 30 / 30

How do you handle a suspected compromised AD account?

Short interview answer · English

Preserve evidence, assess privileges and scope, coordinate containment and check related identity and endpoint activity.

Why this matters · English explanation

Account reset alone may not remove persistence or end all access.

Roman Urdu explanation
Evidence aur privileges check karo; identity aur endpoint activity joro. Sirf password reset complete response nahin.
Worked context / illustrative example
An admin account shows unexpected logons from a suspicious workstation.
Your practical task
Write a coordinated escalation and verification plan.

Evidence to save: your result or diagram, the checks used, one limitation and the next action. Jahan access na ho, table-top answer likho aur usay lab experience mat bolo.

Reference / further tutorial: AD DS troubleshooting

Quick revision sheet

Cover the answers and explain each question aloud. For scenarios use: Trigger → Evidence → Checks → Decision → Verification → Documentation.

Scenario answer mein trigger, evidence, checks, decision, verification aur documentation clear batao.

QuestionAnswer prompt
1. What is Active Directory Domain Services?A directory service storing identities and resources and supporting domain authentication and authorisation.
2. What is a domain controller?A server running AD DS that hosts directory data and supports domain services.
3. Domain versus forest versus OU: what is the difference?A domain is an administrative identity boundary within a forest; an OU organises objects for delegation and policy.
4. What is a security group versus distribution group?Security groups can grant access; distribution groups serve mailing purposes.
5. What are domain local, global and universal group scopes?Scopes govern membership and where a group can be used across domain structures.
6. What is AGDLP?Accounts into Global groups, then Domain Local groups, then Permissions.
7. Why is DNS important for AD?Clients and controllers use DNS to locate domain services and resolve names.
8. Kerberos versus NTLM: what is the difference?Kerberos uses tickets and domain infrastructure; NTLM is an older challenge-response mechanism used in supported fallback scenarios.
9. Why does time synchronisation matter?Kerberos and other infrastructure components depend on acceptable time alignment.
10. How do you troubleshoot an account lockout?Verify the user, review lockout evidence and locate repeated authentication attempts before unlocking repeatedly.
11. Which events help investigate logon issues?Relevant Windows security events include failed logon 4625 and account lockout 4740 when auditing captures them.
12. How do you reset a password safely?Verify identity, check authority, use the approved process and securely communicate recovery details.
13. Why is a disabled account different from a locked account?Disabled status administratively prevents account use; lockout follows configured authentication-failure behaviour.
14. What is Group Policy?A mechanism to centrally apply supported user and computer settings.
15. What is normal Group Policy processing order?Local, site, domain and OU processing, with inheritance and precedence rules affecting the result.
16. How do you troubleshoot a GPO not applying?Check object location, link, scope, security filtering, applicability, replication and resultant policy evidence.
17. What does gpresult do?It reports resultant policy information for the relevant user and computer context.
18. What does gpupdate do?It refreshes Group Policy processing; some changes still require logoff or restart.
19. What is loopback processing?A mode that changes user-policy application based on the computer's policy context.
20. What is a WMI filter?A condition used to determine GPO applicability based on supported system queries.
21. What is SYSVOL?A replicated domain share containing Group Policy files and scripts.
22. How do you troubleshoot AD replication?Use replication status, event logs and dependency checks including DNS, connectivity, time and authentication.
23. What does repadmin /replsummary show?A summary of replication health and failures across controllers.
24. What is dcdiag used for?Running domain-controller diagnostic tests.
25. What are FSMO roles?Specific directory operations roles assigned to controllers, including schema, domain naming, RID, PDC emulator and infrastructure.
26. Share versus NTFS permissions: what is the difference?Share permissions govern network-share access; NTFS permissions govern filesystem access.
27. How do you troubleshoot access denied?Check identity, group membership, token freshness, share and NTFS permissions and explicit denies.
28. What are SPNs and why do they matter?Service Principal Names identify service instances for Kerberos authentication.
29. What is a gMSA?A group Managed Service Account designed for supported service workloads with managed password handling.
30. How do you handle a suspected compromised AD account?Preserve evidence, assess privileges and scope, coordinate containment and check related identity and endpoint activity.

Capstone and assessment

Investigate a GPO application failure and recurring account lockout. Submit relevant diagnostic interpretation, source hypothesis, remediation proposal and verification steps.

Capstone mein evidence, reasoning aur verified result do. Jo cheez available nahin us ki limitation likho. Lab work ko production experience keh kar present mat karo.

AreaSelf-assessment target
Evidence and technical accuracyAll key claims supported by relevant records, outputs or diagrams
Investigation reasoningAt least one alternative explanation tested; gaps clearly identified
Practical deliveryTask outcome verified, including one negative or failure test
CommunicationExplain the case in two minutes and answer two unprepared follow-ups

This is a study assessment, not a vendor certification or guarantee of interview success. Repeat the task if you cannot explain why your checks were necessary.

Official references and tutorials

References provide deeper detail. Some pages are broad documentation hubs: navigate to the relevant feature and check current licensing, platform support and permissions. Guidance is paraphrased; diagrams and fictional examples are original study material.