B. Combined Basic MSCE Exam “Skills Being Measured” (Exams 70-293, 70-294, 70-296)
B1. Planning and Implementing Server Roles and Server Security [Exams 70-293 and 70-296 only]
B1.1. Configure security for servers that are assigned specific roles. [Exams 70-293 and 70-296 only]
B1.2. Plan a secure baseline installation. [Exam 70-293 only]
B1.2.1. Plan a strategy to enforce system default security settings on new systems. [Exam 70-293 only]
B1.2.2. Identify client operating system default security settings. [Exam 70-293 only]
B1.2.3. Identify all server operating system default security settings. [Exam 70-293 only]
B1.3. Plan security for servers that are assigned specific roles. Roles might include domain controllers, Web servers, database servers, and mail servers. [Exams 70-293 and 70-296 only]
B1.3.1. Deploy the security configuration for servers that are assigned specific roles. [Exams 70-293 and 70-296 only]
B1.3.2. Create custom security templates based on server roles. [Exams 70-293 and 70-296 only]
B1.4. Evaluate and select the operating system to install on computers in an enterprise. [Exam 70-293 only]
B1.4.1. Identify the minimum configuration to satisfy security requirements. [Exam 70-293 only]
B2. Planning, Implementing, and Maintaining a Network Infrastructure [Exams 70-293 and 70-296 only]
B2.1. Plan a TCP/IP network infrastructure strategy. [Exam 70-293 only]
B2.1.1. Analyze IP addressing requirements. [Exam 70-293 only]
B2.1.2. Plan an IP routing solution. [Exam 70-293 only]
B2.1.3. Create an IP subnet scheme. [Exam 70-293 only]
B2.2. Plan and modify a network topology. [Exam 70-293 only]
B2.2.1. Plan the physical placement of network resources. [Exam 70-293 only]
B2.2.2. Identify network protocols to be used. [Exam 70-293 only]
B2.3. Plan an Internet connectivity strategy. [Exam 70-293 only]
B2.4. Plan network traffic monitoring. Tools might include Network Monitor and System Monitor. [Exam 70-293 only]
B2.5. Troubleshoot connectivity to the Internet. [Exam 70-293 only]
B2.5.1. Diagnose and resolve issues related to Network Address Translation (NAT). [Exam 70-293 only]
B2.5.2. Diagnose and resolve issues related to name resolution cache information. [Exam 70-293 only]
B2.5.3. Diagnose and resolve issues related to client configuration. [Exam 70-293 only]
B2.6. Troubleshoot TCP/IP addressing. [Exam 70-293 only]
B2.6.1. Diagnose and resolve issues related to client computer configuration. [Exam 70-293 only]
B2.6.2. Diagnose and resolve issues related to DHCP server address assignment. [Exam 70-293 only]
B2.7. Plan a host name resolution strategy. [Exams 70-293 and 70-296 only]
B2.7.1. Plan a DNS namespace design. [Exams 70-293 and 70-296 only]
B2.7.2. Plan zone replication requirements. [Exams 70-293 and 70-296 only]
B2.7.3. Plan a forwarding configuration. [Exams 70-293 and 70-296 only]
B2.7.4. Plan for DNS security. [Exams 70-293 and 70-296 only]
B2.7.5. Examine the interoperability of DNS with third-party DNS solutions. [Exams 70-293 and 70-296 only]
B2.8. Plan a NetBIOS name resolution strategy. [Exam 70-293 only]
B2.8.1. Plan a WINS replication strategy. [Exam 70-293 only]
B2.8.2. Plan NetBIOS name resolution by using the Lmhosts file. [Exam 70-293 only]
B2.9. Troubleshoot host name resolution. [Exam 70-293 only]
B2.9.1. Diagnose and resolve issues related to DNS services. [Exam 70-293 only]
B2.9.2. Diagnose and resolve issues related to client computer configuration. [Exam 70-293 only]
B3. Planning, Implementing, and Maintaining Routing and Remote Access [Exam 70-293 only]
B3.1. Plan a routing strategy. [Exam 70-293 only]
B3.1.1. Identify routing protocols to use in a specified environment. [Exam 70-293 only]
B3.1.2. Plan routing for IP multicast traffic. [Exam 70-293 only]
B3.2. Plan security for remote access users. [Exam 70-293 only]
B3.2.1. Plan remote access policies. [Exam 70-293 only]
B3.2.2. Analyze protocol security requirements. [Exam 70-293 only]
B3.2.3. Plan authentication methods for remote access clients. [Exam 70-293 only]
B3.3. Implement secure access between private networks. [Exam 70-293 only]
B3.3.1. Create and implement an IPSec policy. [Exam 70-293 only]
B3.4. Troubleshoot TCP/IP routing. Tools might include the route, tracert, ping, pathping, and NetSh commands and Network Monitor. [Exam 70-293 only]
B4. Planning, Implementing, and Maintaining Server Availability Exams 70-293 and 70-296 only]
B4.1. Plan services for high availability. [Exams 70-293 and 70-296 only]
B4.1.1. Plan a high availability solution that uses clustering services. [Exams 70-293 and 70-296 only]
B4.1.2. Plan a high availability solution that uses Network Load Balancing. [Exams 70-293 and 70-296 only]
B4.2. Identify system bottlenecks, including memory, processor, disk, and network related bottlenecks. [Exam 70-293 only]
B4.2.1. Identify system bottlenecks by using System Monitor. [Exam 70-293 only]
B4.3. Implement a cluster server. [Exam 70-293 only]
B4.3.1. Recover from cluster node failure. [Exam 70-293 only]
B4.4. Manage Network Load Balancing. Tools might include the Network Load Balancing Monitor Microsoft Management Console (MMC) snap-in and the WLBS cluster control utility. [Exam 70-293 only]
B4.5. Plan a backup and recovery strategy. [Exams 70-293 and 70-296 only]
B4.5.1. Identify appropriate backup types. Methods include full, incremental, and differential. [Exams 70-293 and 70-296 only]
B4.5.2. Plan a backup strategy that uses volume shadow copy. [Exams 70-293 and 70-296 only]
B4.5.3. Plan system recovery that uses Automated System Recovery (ASR). [Exams 70-293 and 70-296 only]
B5. Planning and Maintaining Network Security [Exams 70-293 and 70-296 only]
B5.1. Configure network protocol security. [Exam 70-293 only]
B5.1.1. Configure protocol security in a heterogeneous client computer environment. [Exam 70-293 only]
B5.1.2. Configure protocol security by using IPSec policies. [Exam 70-293 only]
B5.2. Configure security for data transmission. [Exam 70-293 only]
B5.2.1. Configure IPSec policy settings. [Exam 70-293 only]
B5.3. Plan for network protocol security. [Exam 70-293 only]
B5.3.1. Specify the required ports and protocols for specified services. [Exam 70-293 only]
B5.3.2. Plan an IPSec policy for secure network communications. [Exam 70-293 only]
B5.4. Plan secure network administration methods. [Exams 70-293 and 70-296 only]
B5.4.1. Create a plan to offer Remote Assistance to client computers. [Exams 70-293 and 70-296 only]
B5.4.2. Plan for remote administration by using Terminal Services. [Exams 70-293 and 70-296 only]
B5.5. Plan security for wireless networks. [Exams 70-293 and 70-296 only]
B5.6. Plan security for data transmission. [Exams 70-293 and 70-296 only]
B5.6.1. Secure data transmission between client computers to meet security requirements. [Exams 70-293 and 70-296 only]
B5.6.2. Secure data transmission by using IPSec. [Exams 70-293 and 70-296 only]
B5.7. Troubleshoot security for data transmission. Tools might include the IP Security Monitor MMC snap-in and the Resultant Set of Policy (RSoP) MMC snap-in. [Exam 70-293 only]
B6. Planning, Implementing, and Maintaining Security Infrastructure [Exams 70-293 and 70-296 only]
B6.1. Configure Active Directory directory service for certificate publication. [Exams 70-293 and 70-296 only]
B6.2. Plan a public key infrastructure (PKI) that uses Certificate Services. [Exams 70-293 and 70-296 only]
B6.2.1. Identify the appropriate type of certificate authority to support certificate issuance requirements. [Exams 70-293 and 70-296 only]
B6.2.2. Plan the enrollment and distribution of certificates. [Exams 70-293 and 70-296 only]
B6.2.3. Plan for the use of smart cards for authentication. [Exams 70-293 and 70-296 only]
B6.3. Plan a framework for planning and implementing security. [Exams 70-293 and 70-296 only]
B6.3.1. Plan for security monitoring. [Exams 70-293 and 70-296 only]
B6.3.2. Plan a change and configuration management framework for security. [Exams 70-293 and 70-296 only]
B6.4. Plan a security update infrastructure. Tools might include Microsoft Baseline Security Analyzer and Microsoft Software Update Services.[Exams 70-293 and 70-296 only]
B7. Planning and Implementing an Active Directory Infrastructure [Exams 70-294 and 70-296 only]
B7.1. Plan a strategy for placing global catalog servers. [Exams 70-294 and 70-296 only]
B7.1.1. Evaluate network traffic considerations when placing global catalog servers. [Exams 70-294 and 70-296 only]
B7.1.2. Evaluate the need to enable universal group caching. [Exams 70-294 and 70-296 only]
B7.2. Plan flexible operations master role placement. [Exam 70-294 only]
B7.2.1. Plan for business continuity of operations master roles. [Exam 70-294 only]
B7.2.2. Identify operations master role dependencies. [Exam 70-294 only]
B7.3. Implement an Active Directory directory service forest and domain structure. [Exams 70-294 and 70-296 only]
B7.3.1. Create the forest root domain. [Exams 70-294 and 70-296 only]
B7.3.2. Create a child domain. [Exams 70-294 and 70-296 only]
B7.3.3. Create and configure Application Data Partitions. [Exams 70-294 and 70-296 only]
B7.3.4. Install and configure an Active Directory domain controller. [Exams 70-294 and 70-296 only]
B7.3.5. Set an Active Directory forest and domain functional level based on requirements. [Exams 70-294 and 70-296 only]
B7.3.6. Establish trust relationships. Types of trust relationships might include external trusts, shortcut trusts, and cross-forest trusts. [Exams 70-294 and 70-296 only]
B7.4. Implement an Active Directory site topology. [Exam 70-294 only]
B7.4.1. Configure site links. [Exam 70-294 only]
B7.4.2. Configure preferred bridgehead servers. [Exam 70-294 only]
B7.5. Plan an administrative delegation strategy. [Exam 70-294 only]
B7.5.1. Plan an organizational unit (OU) structure based on delegation requirements. [Exam 70-294 only]
B7.5.2. Plan a security group hierarchy based on delegation requirements. [Exam 70-294 only]
B8. Managing and Maintaining an Active Directory Infrastructure [Exams 70-294 and 70-296 only]
B8.1. Manage an Active Directory forest and domain structure. [Exams 70-294 and 70-296 only]
B8.1.1. Manage trust relationships. [Exams 70-294 and 70-296 only]
B8.1.2. Manage schema modifications. [Exams 70-294 and 70-296 only]
B8.1.3. Add or remove a UPN suffix. [Exams 70-294 and 70-296 only]
B8.2. Manage an Active Directory site. [Exam 70-294 only]
B8.2.1. Configure replication schedules. [Exam 70-294 only]
B8.2.2. Configure site link costs. [Exam 70-294 only]
B8.2.3. Configure site boundaries [Exam 70-294 only]
B8.3. Monitor Active Directory replication failures. Tools might include Replication Monitor, Event Viewer, and support tools. [Exam 70-294 only]
B8.3.1. Monitor Active Directory replication. [Exam 70-294 only]
B8.3.2. Monitor File Replication service (FRS) replication. [Exam 70-294 only]
B8.4. Restore Active Directory directory services. [Exams 70-294 and 70-296 only]
B8.4.1. Perform an authoritative restore operation. [Exams 70-294 and 70-296 only]
B8.4.2. Perform a nonauthoritative restore operation. [Exams 70-294 and 70-296 only]
B8.5. Troubleshoot Active Directory. [Exam 70-294 only]
B8.5.1. Diagnose and resolve issues related to Active Directory replication. [Exam 70-294 only]
B8.5.2. Diagnose and resolve issues related to operations master role failure. [Exam 70-294 only]
B8.5.3. Diagnose and resolve issues related to the Active Directory database. [Exam 70-294 only]
B9. Planning and Implementing User, Computer, and Group Strategies [Exams 70-294 and 70-296 only]
B9.1. Plan a security group strategy. [Exam 70-294 only]
B9.2. Plan a user authentication strategy. [Exams 70-294 and 70-296 only]
B9.2.1. Plan a smart card authentication strategy. [Exams 70-294 and 70-296 only]
B9.2.2. Create a password policy for domain users. [Exams 70-294 and 70-296 only]
B9.3. Plan an OU structure. [Exam 70-294 only]
B9.3.1. Analyze the administrative requirements for an OU. [Exam 70-294 only]
B9.3.2. Analyze the Group Policy requirements for an OU structure. [Exam 70-294 only]
B9.4. Implement an OU structure. [Exam 70-294 only]
B9.4.1. Create an OU. [Exam 70-294 only]
B9.4.2. Delegate permissions for an OU to a user or to a security group. [Exam 70-294 only]
B9.4.3. Move objects within an OU hierarchy. [Exam 70-294 only]
B10. Planning and Implementing Group Policy [Exams 70-294 and 70-296 only]
B10.1. Plan Group Policy strategy. [Exams 70-294 and 70-296 only]
B10.1.1. Plan a Group Policy strategy by using Resultant Set of Policy (RSoP) Planning mode. [Exams 70-294 and 70-296 only]
B10.1.2. Plan a strategy for configuring the user environment by using Group Policy. [Exams 70-294 and 70-296 only]
B10.1.3. Plan a strategy for configuring the computer environment by using Group Policy. [Exams 70-294 and 70-296 only]
B10.2. Configure the user environment by using Group Policy. [Exams 70-294 and 70-296 only]
B10.2.1. Distribute software by using Group Policy. [Exams 70-294 and 70-296 only]
B10.2.2. Automatically enroll user certificates by using Group Policy. [Exams 70-294 and 70-296 only]
B10.2.3. Redirect folders by using Group Policy. [Exams 70-294 and 70-296 only]
B10.2.4. Configure user security settings by using Group Policy. [Exams 70-294 and 70-296 only]
B10.3. Deploy a computer environment by using Group Policy. [Exam 70-294 only]
B10.3.1. Distribute software by using Group Policy. [Exam 70-294 only]
B10.3.2. Automatically enroll computer certificates by using Group Policy. [Exam 70-294 only]
B10.3.3. Configure computer security settings by using Group Policy. [Exam 70-294 only]
B11. Managing and Maintaining Group Policy [Exams 70-294 and 70-296 only]
B11.1. Troubleshoot issues related to Group Policy application deployment. Tools might include RSoP and the gpresult command.[Exams 70-294 and 70-296 only]
B11.2. Maintain installed software by using Group Policy. [Exam 70-294 only]
B11.2.1. Distribute updates to software distributed by Group Policy. [Exam 70-294 only]
B11.2.2. Configure automatic updates for network clients by using Group Policy. [Exam 70-294 only]
B11.3. Troubleshoot the application of Group Policy security settings. Tools might include RSoP and the gpresult command. [Exams 70-294 and 70-296 only]