Monday, 11 June 2012

short note on Group Policy


GROUP POLICY

In this we can restrict the users, Groups and OU ’s to access the Desktop settings, control panel, etc.
There are four types of group policy, they are:

               1- Local level group policy
               2- Site level policy
               3- Domain level policy

How to apply local level group policy?
To apply local level group policy, type gpedit.msc in the   RUN or CMD.
How to apply site level policy?
Go to active directory sites and services , then right click on the site, click on the property and then click on the group policy.
How to apply Domain level policy?
Go to dsa.msc in CMD -domain name property- group policy.
How to apply an ou?
Select particular ou property- group policy.
Highest priority levels?
OU—Domain—Sites.
what is Block policy inheritance?
Once we check this policy ,no other policy will apply for the particular OU or Domain.
What is No override?
Once we check this option, the block policy inheritance will not work.
Where the group policy stores or presents?
sysvol – gpt.ini.

Note:-
►Group policy Replication happens from sysvol  to  sysvol.
► To check the group policy Replication , we use a tool called “gpotool.exe.
►To take a group policy Backup, we use a tool called “GPMC”

How group policy is not applied for a particular User or Client?
 Need to go to the particular computer, then RUN or CMD prompt type
  “GPUPDATR /FORCE”.

How to test the Group policy in a CMD prompt?
Go to RUN and type “GPRESULT GPO.txt

Windows Server 2003 interview questions


Windows Server 2003 interview  questions 

  1. How do you double-boot a Win 2003 server box? The Boot.ini file is set as read-only, system, and hidden to prevent unwanted editing. To change the Boot.ini timeout and default settings, use the System option in Control Panel from the Advanced tab and select Startup.
  2. What do you do if earlier application doesn’t run on Windows Server 2003? When an application that ran on an earlier legacy version of Windows cannot be loaded during the setup function or if it later malfunctions, you must run the compatibility mode function. This is accomplished by right-clicking the application or setup program and selecting Properties –> Compatibility –> selecting the previously supported operating system.
  3.  If you uninstall Windows Server 2003, which operating systems can you revert to? Win ME and Win 98.
  4. How do you get to Internet Firewall settings? Start –> Control Panel –> Network and Internet Connections –> Network Connections.
  5. What are the Windows Server 2003 keyboard shortcuts? Winkey opens or closes the Start menu. Winkey + BREAK displays the System Properties dialog box. Winkey + TAB moves the focus to the next application in the taskbar. Winkey + SHIFT + TAB moves the focus to the previous application in the taskbar. Winkey + B moves the focus to the notification area. Winkey + D shows the desktop. Winkey + E opens Windows Explorer showing My Computer. Winkey + F opens the Search panel. Winkey + CTRL + F opens the Search panel with Search for Computers module selected. Winkey + F1 opens Help. Winkey + M minimizes all. Winkey + SHIFT+ M undoes minimization. Winkey + R opens Run dialog. Winkey + U opens the Utility Manager. Winkey + L locks the computer.
  6. What is Active Directory? Active Directory is a network-based object store and service that locates and manages resources, and makes these resources available to authorized users and groups. An underlying principle of the Active Directory is that everything is considered an object—people, servers, workstations, printers, documents, and devices. Each object has certain attributes and its own security access control list (ACL).
  7. Where are the Windows NT Primary Domain Controller (PDC) and its Backup Domain Controller (BDC) in Server 2003? The Active Directory replaces them. Now all domain controllers share a multimaster peer-to-peer read and write relationship that hosts copies of the Active Directory.
  8. How long does it take for security changes to be replicated among the domain controllers? Security-related modifications are replicated within a site immediately. These changes include account and individual user lockout policies, changes to password policies, changes to computer account passwords, and modifications to the Local Security Authority (LSA).
  9. What’s new in Windows Server 2003 regarding the DNS management? When DC promotion occurs with an existing forest, the Active Directory Installation Wizard contacts an existing DC to update the directory and replicate from the DC the required portions of the directory. If the wizard fails to locate a DC, it performs debugging and reports what caused the failure and how to fix the problem. In order to be located on a network, every DC must register in DNS DC locator DNS records. The Active Directory Installation Wizard verifies a proper configuration of the DNS infrastructure. All DNS configuration debugging and reporting activity is done with the Active Directory Installation Wizard.
  10. When should you create a forest? Organizations that operate on radically different bases may require separate trees with distinct namespaces. Unique trade or brand names often give rise to separate DNS identities. Organizations merge or are acquired and naming continuity is desired. Organizations form partnerships and joint ventures. While access to common resources is desired, a separately defined tree can enforce more direct administrative and security restrictions.
  11. How can you authenticate between forests? Four types of authentication are used across forests: (1) Kerberos and NTLM network logon for remote access to a server in another forest; (2) Kerberos and NTLM interactive logon for physical logon outside the user’s home forest; (3) Kerberos delegation to N-tier application in another forest; and (4) user principal name (UPN) credentials.
  12. What snap-in administrative tools are available for Active Directory? Active Directory Domains and Trusts Manager, Active Directory Sites and Services Manager, Active Directory Users and Group Manager, Active Directory Replication (optional, available from the Resource Kit), Active Directory Schema Manager (optional, available from adminpak)
  13. What types of classes exist in Windows Server 2003 Active Directory? 
    1. Structural class. The structural class is important to the system administrator in that it is the only type from which new Active Directory objects are created. Structural classes are developed from either the modification of an existing structural type or the use of one or more abstract classes.
    2. Abstract class. Abstract classes are so named because they take the form of templates that actually create other templates (abstracts) and structural and auxiliary classes. Think of abstract classes as frameworks for the defining objects.
    3. Auxiliary class. The auxiliary class is a list of attributes. Rather than apply numerous attributes when creating a structural class, it provides a streamlined alternative by applying a combination of attributes with a single include action.
    4. 88 class. The 88 class includes object classes defined prior to 1993, when the 1988 X.500 specification was adopted. This type does not use the structural, abstract, and auxiliary definitions, nor is it in common use for the development of objects in Windows Server 2003 environments.
  14. How do you delete a lingering object? Windows Server 2003 provides a command called Repadmin that provides the ability to delete lingering objects in the Active Directory. 
  15. What is Global Catalog? The Global Catalog authenticates network user logons and fields inquiries about objects across a forest or tree. Every domain has at least one GC that is hosted on a domain controller. In Windows 2000, there was typically one GC on every site in order to prevent user logon failures across the network.
  16. How is user account security established in Windows Server 2003? When an account is created, it is given a unique access number known as a security identifier (SID). Every group to which the user belongs has an associated SID. The user and related group SIDs together form the user account’s security token, which determines access levels to objects throughout the system and network. SIDs from the security token are mapped to the access control list (ACL) of any object the user attempts to access.
  17. If I delete a user and then create a new account with the same username and password, would the SID and permissions stay the same? No. If you delete a user account and attempt to recreate it with the same user name and password, the SID will be different. 
  18. What do you do with secure sign-ons in an organization with many roaming users? Credential Management feature of Windows Server 2003 provides a consistent single sign-on experience for users. This can be useful for roaming users who move between computer systems. The Credential Management feature provides a secure store of user credentials that includes passwords and X.509 certificates.
  19. Anything special you should do when adding a user that has a Mac? "Save password as encrypted clear text" must be selected on User Properties Account Tab Options, since the Macs only store their passwords that way.
  20. What remote access options does Windows Server 2003 support? Dial-in, VPN, dial-in with callback.
  21. Where are the documents and settings for the roaming profile stored? All the documents and
    environmental settings for the roaming user are stored locally on the system, and, when the user logs off, all changes to the locally stored profile are copied to the shared server folder. Therefore, the first time a roaming user logs on to a new system the logon process may take some time, depending on how large his profile folder is.
  22. Where are the settings for all the users stored on a given machine? \Document and Settings\All Users
Windows 2000 administration questions

  1. Explain hidden shares. Hidden or administrative shares are share names with a dollar sign ($) appended to their names. Administrative shares are usually created automatically for the root of each drive letter. They do not display in the network browse list.
  2. How do the permissions work in Windows 2000? What permissions does folder inherit from the parent? When you combine NTFS permissions based on users and their group memberships, the least restrictive permissions take precedence. However, explicit Deny entries always override Allow entries.
  3. Why can’t I encrypt a compressed file on Windows 2000? You can either compress it or encrypt it, but not both.
  4. If I rename an account, what must I do to make sure the renamed account has the same permissions as the original one? Nothing, it’s all maintained automatically.
  5. What’s the most powerful group on a Windows system? Administrators.
  6. What are the accessibility features in Windows 2000? StickyKeys, FilterKeys Narrator, Magnifier, and On-Screen Keyboard.
  7. Why can’t I get to the Fax Service Management console? You can only see it if a fax had been installed.
  8. What do I need to ensure before deploying an application via a Group Policy? Make sure it’s either an MSI file, or contains a ZAP file for Group Policy.
  9. How do you configure mandatory profiles? Rename ntuser.dat to ntuser.man
  10. I can’t get multiple displays to work in Windows 2000. Multiple displays have to use peripheral connection interface (PCI) or Accelerated Graphics Port (AGP) port devices to work properly with Windows 2000.
  11. What’s a maximum number of processors Win2k supports? 2
  12. I had some NTFS volumes under my Windows NT installation. What happened to NTFS after Win 2k installation? It got upgraded to NTFS 5.
  13. How do you convert a drive from FAT/FAT32 to NTFS from the command line? convert c: /fs:ntfs
  14. Explain APIPA. Auto Private IP Addressing (APIPA) takes effect on Windows 2000 Professional computers if no DHCP server can be contacted. APIPA assigns the computer an IP address within the range of 169.254.0.0 through 169.254.255.254 with a subnet mask of 255.255.0.0.
  15. How does Internet Connection Sharing work on Windows 2000? Internet Connection Sharing (ICS) uses the DHCP Allocator service to assign dynamic IP addresses to clients on the LAN within the range of 192.168.0.2 through 192.168.0.254. In addition, the DNS Proxy service becomes enabled when you
    implement ICS.
Windows admin interview questions
1.     Describe how the DHCP lease is obtained. It’s a four-step process consisting of (a) IP request, (b) IP offer, © IP selection and (d) acknowledgement.
2.     I can’t seem to access the Internet, don’t have any access to the corporate network and on ipconfig my address is 169.254.*.*. What happened? The 169.254.*.* netmask is assigned to Windows machines running 98/2000/XP if the DHCP server is not available. The name for the technology is APIPA (Automatic Private Internet Protocol Addressing).
3.     We’ve installed a new Windows-based DHCP server, however, the users do not seem to be getting DHCP leases off of it. The server must be authorized first with the Active Directory.
4.     How can you force the client to give up the dhcp lease if you have access to the client PC? ipconfig /release
5.     What authentication options do Windows 2000 Servers have for remote clients? PAP, SPAP, CHAP, MS-CHAP and EAP.
6.     What are the networking protocol options for the Windows clients if for some reason you do not want to use TCP/IP? NWLink (Novell), NetBEUI, AppleTalk (Apple).
7.     What is data link layer in the OSI reference model responsible for? Data link layer is located above the physical layer, but below the network layer. Taking raw data bits and packaging them into frames. The network layer will be responsible for addressing the frames, while the physical layer is reponsible for retrieving and sending raw data bits.
8.     What is binding order? The order by which the network protocols are used for client-server communications. The most frequently used protocols should be at the top.
9.     How do cryptography-based keys ensure the validity of data transferred across the network?  Each IP packet is assigned a checksum, so if the checksums do not match on both receiving and transmitting ends, the data was modified or corrupted.
10.            Should we deploy IPSEC-based security or certificate-based security? They are really two different technologies. IPSec secures the TCP/IP communication and protects the integrity of the packets. Certificate-based security ensures the validity of authenticated clients and servers.
11.            What is LMHOSTS file? It’s a file stored on a host machine that is used to resolve NetBIOS to specific IP addresses.
12.            What’s the difference between forward lookup and reverse lookup in DNS? Forward lookup is name-to-address, the reverse lookup is address-to-name.
13.            How can you recover a file encrypted using EFS? Use the domain recovery agent.




14. What is a Firewall?
Firewalls are of two types:
-Hardware Firewall
-Software Firewall.
Firewall in simple manner is bascially the utility to provide the security over the network. These are the security measures that prevents the network’s in and out traffic to pass through the specific Security filters so that the unwanted and unsecure data can be stopped from entering into the network..
further… as a security measure it also depends on the network designer and implementer that how to use a Firewall mean to say the security measures like how to present the content filtering and Url filtering which type of firewall should be used and where to put it..
15. What a protocol actually means:
A Protocol is bascially set of rules designed and developed for the internetwork or can say intranetwork Communications. the need of Tcp had been rised in early years when like.. IBM Mainframe were not able to Communicate with the Burroughs mainframe.. means if you wish to connect 2 or more computers they should be same with everything from manufacturer to designer and implementer…then TCP imerged as a solution-for-ever..
EARLIER it was NCP( Network Control Protocal) but later it refined into TCP( Transmission Control Protocol) and IP(Internet Protocol)on jan.1,1983..
Some General roles of TCP/IP are:
1. Independence from particular vendor or network.
2. very low data overhead
3. good failure recovery.
and if the thinghs are taken seprately.. then
TCP is bascially responsible for proper data transmission by assuring data integrity it is a connection oriented protocol that follows the under scenerio
1. Handshaking.
2. Packect Sequencing
3. Flow Control.
4. Error handling.
IP : Since the data to be sent must be put somewhere the IP works here .. the required data is packaged in an IP packet.

  1. Ip Address Ranges:
    Class A: 0-126. 127 is a Broadcast
    Class B: 128-191
    Class C: 192-223
    Class D: 224-239
    Class E: 240-255.
17.  What is the difference between TCP and UDP
TCP is a connection oriented protocol, which means that everytime a packet is sent say from host A to B, we will get an acknowledgement. Whereas UDP on the other hand, is a connection less protocol.
Where will it be used : TCP -> Say you have a file transfer and you need to ensure that the file reaches intact, and time is not a factor, in such a case we can use TCP.
UDP-> Media Streaming, question is say you are watching a movie…would you prefer that your movie comes..perfectly….but u need to wait a long time before you see the next frame ?..or would you prefer the movie to keep streaming…Yes…The second option is definely better….This is when we need UDP

18. Main differences between Exchange 2000 and 2003.

*       Improved security, including all those of IIS v 6.0.
*       HTTP over RPC means you do not need to configure a VPN for OWA.
*       Up to 8 node Active / Passive clustering.
*       Volume Shadow Copy for backup.
*       Super upgrade tools like ExDeploy.
*       pfMigrate utility to move public folders from legacy systems.
*       An attempt to control Junk email both on the client and the server.
  1. FSMO ?
      Flexible Single Master Operations
There are just five operations where the usual multiple master model breaks down, and the Active Directory task must only be carried out on one Domain Controller.
1.      PDC Emulator - Most famous for backwards compatibility with NT 4.0 BDC's.  However, there are two other roles which operate even in Windows 2003 Native Domains, synchronizing the W32Time service and creating group policies.  I admit that it is confusing that these two jobs have little to do with PDCs and BDCs. 
 
2.      RID Master - Each object must have a globally unique number (GUID).  The RID master makes sure each domain controller issues unique numbers when you create objects such as users or computers.  For example DC one is given RIDs 1-4999 and DC two is given RIDs 5000 - 9999.
 
3.      Infrastructure Master - Responsible for checking objects in other other domains.  Universal group membership is the most important example.  To me, it seems as though the operating system is paranoid that, a) You are a member of a Universal Group in another domain and b) that group has been assigned Deny permissions.  So if the Infrastructure master could not check your Universal Groups there could be a security breach.
 
4.      Domain Naming Master - Ensures that each child domain has a unique name.  How often do child domains get added to the forest?  Not very often I suggest, so the fact that this is a FSMO does not impact on normal domain activity.  My point is it's worth the price to confine joining and leaving the domain operations to one machine, and save the tiny risk of getting duplicate names or orphaned domains.
 
5.      Schema Master - Operations that involve expanding user properties e.g. Exchange 2003 / forestprep which adds mailbox properties to users.  Rather like the Domain naming master, changing the schema is a rare event.  However if you have a team of Schema Administrators all experimenting with object properties, you would not want there to be a mistake which crippled your forest.  So its a case of Microsoft know best, the Schema Master should be a Single Master Operation.

19. DNS (Domain Name System)

Active Directory absolutely relies on DNS, this is why you must become an expert on configuring DNS.  Once DNS is setup, it runs itself thanks to the new dynamic component hence DDNS.  TCP/IP knowledge plus understanding of how DNS works is essential when troubleshooting connectivity problems.
What DNS does is enable client machines to resolve servers IP addresses.  Once the client finds the server, Active Directory uses LDAP to locate services like Kerberos, Global Catalog that clients request.
Your first domain controller can be tricky to setup.  To begin with plan then check the Computer Name found in the System Icon.  Before you run DCPROMO make sure you have the correct Primary DNS Suffix, drill down through the More.. button.
My tactic is to do as little configuring of the forward lookup zone as possible and leave it all to the DCPROMO wizard.  Once Active Directory creates the forward lookup zone, I configure Active Directory integration to to replicate DNS records to the other servers.  Then I manually create the reverse lookup zone, add PTR records and check with NSLOOKUP.
I used to think you needed a DHCP server on every Subnet, but now I recommend just two DHCP servers to share each scope, with a DHCP relay agent on each subnet.  DHCP fits in well with DNS and domain controllers, so I would install DHCP on selected domain controllers.
Once you have installed DHCP, there is much configuration work. But before you do anything else, you must Authorize the DHCP servers in Active Directory.  I believe this authorization is a device to make you stop and think 'do I need another DHCP server?'  Officially the authorization is to prevent rogue techies installing an extra DHCP server when it takes their fancy.  


IIS INTERVIEW QUESTIONS


What is the Role of IIS?


Visual studio having It own ASP.NET Engine which is capable enough to run Asp.net web application from visual studio. So we just click on Run button to start the application. 
Now this is the scenarios of local environment. But If we want to host it on server from where all user can access the sites then IIS comes into the picture. 

IIS provides a redesigned WWW architecture that can help you achieve better performance, reliability, scalability, and security for our Web sites. IIS can support following Protocol HTTP/HTTPS, FTP, FTPS, SMTP Etc. We need to host the site on IIS, when request comes from client it first hits the IIS Server, then the server passed it to ASP.NET worker process to execute. Then the response also passes to client via IIS itself. 
Note only Hosting of Site we can create our FTP Server, SMTP Server using IIS itself. 
There are different version of IIS available like 5.1, 6.0, 7.0 etc.

 

What is the different version on IIS that you have worked on?


Before answering this question you need to know what are the different IIS version is available in different OS. Below is the list of IIS version with different Operating system. 
Windows Server 2008 - Windows Vista - Home Premium/ Ultimate
 - IIS 7.0 
Windows Server 2003
 - IIS 6.0 
Windows XP Professional
 - IIS 5.1 
Now based on your working experience you can say that you have worked on IIS 5.1 and 6.0 or only IIS 7. Etc.
 
Now, the next question that can asked after answering this question is “what is the difference between them ?
 ”

What are the main layers of IIS Architecture ?

IIS having mainly two layer Kernel Mode and User Mode

Below are the subsections of both of them.
Kernel Mode  
         HTTP.SYS
User Mode
Web Admin Service
Virtual Directory
Application Pool


What is Application Pool in IIS ?


Before Giving the Definition: you can say like this, Concept of Application pool has from IIS 6.0.
Application pools are used to separate sets of IIS worker processes that share the same configuration and application boundaries. Application pools used to isolate our web application for better security, reliability, and availability and performance and keep running with out impacting each other . The worker process serves as the process boundary that separates each application pool so that when one worker process or application is having an issue or recycles, other applications or worker processes are not affected. 
One Application Pool can have multiple worker process Also. 

Main Point to Remember: 
1. Isolation of Different Web Application 
2. Individual worker process for different web application 
3. More reliably web application 
4. Better Performance

What is the Name of Default Application Pool in IIS?


Though we can create new application pool IIS with different settings, but IIS having its own default application pool named: DefaultAppPool

What are the different types of Identity available in IIS 6.0 ?


IIS having three different Identities. 
1. Local System
 
2. Local Services 
3. Network Services

Name of default Identity of IIS6.0


Default Identity of IIS 6.0 is NetworkServices .Which is having very minimum rights on your system. The user can only have the read access of the site.

What is Recycling of Application Pool ?

Recycling Application pool means recycle the Worker process (w3wp.exe ) and the memory used for the web application. 
There are two types of recycling related with Application pool 

1. Recycling Worker Process - Predefined Settings 
2. Recycling Worker Process - Based on Memory

What is the Role of Http.Sys in IIS ?


HTTP.SYS is the kernel level components of IIS. All client request comes from client hit the HTTP.Sys of Kernel level. HTTP.SYS then makes a queue for each and every request for each and individual application pool based on the request. 
Whenever we create any application pool IIS automatically registers the pool with HTTP.SYS to identify the particular during request processing.

What are the different security settings available in IIS ?


Below are the commonly used IIS Security settings 

1 Anonymous 
2 Integrated Windows Authentication 
3. Basic Authentication 
4. Digest Authentication 
5. Passport Authentication 

For Set security permission you need to go to Virtul Directory > Right Click > Properties > Directory Security 
Click on Edit Button 

What is the default authentication settings for IIS ?



Anonymous authentication is the default authentication mode for any site that is hosted on IIS, and it runs under the "IUSR_[ServerName]" account.

 

What is web garden ?



By default Each Application Pool runs with a Single Worker Process (W3Wp.exe). We can assign multiple Worker Process With a Single Application Pool. An Application Poll with multiple Worker process called Web Gardens. Each Worker Process Should have there own Thread and Own Memory space.

Generally its not recommended to use InProc Session mode while we are using Web Garden.

Where session data stores in case of "In-Proc" Session mode ?


Session data store inside process memory of worker process [ w3wp.exe ] .

 

How we can create an web garden ?


For creating web graden we need to go to Application Pool, then Right Click on Application Pool > Properties > Goto Performance Tab

In Web Garden Section, increase the number of worker process. By default it is 1.

How we can debug a web application which is hosted on IIS ?


We can easily debug any web application that is hosted on IIS by using Attaching of Worker Process.
From Visual Studio IDE > Tools > Attach To Process
Select the particular Process, then start debugging.

For more information Read this article:

How we can open IIS Configuration manager ?


Just simply Run >inetmgr
Or we can open it from control panel > Administrative tools.

 

How we can create a Virtual Directory on IIS ?

Open IIS Configuration Manager
First of all Right Click on Default web sites > New > Virtual Directory .
Browse the Physical Path. Set the properites. Click on OK

What are the permission settings are available for Virtual Directory ?

Below are the list of permission that can be set during virtaul directory creation
1. Read
2. Run Scripts
3. Execute:
4. Write:
5. Browse

 

What is the folder location for Virtual Directory ?


:\inetpub\wwwroot

What is the use of Enable Pinging Properties for Application Pool ?


IIS should periodically monitor the health of a worker process [ Idle or not , Time for recycle or not, All Worker process are running properly or not ] .
Pining means, Activation Process monitor Worker process performance, health, idle time etc.
By default it sets to 30s .

Does One Web Application can have multiple Application Pool ?


No. Every Web Application should have one Application Pool. Bydefault it is "DefaultAppPool ".

Which version of IIS is available in Windows Server 2008 ?


IIS 7.0 .

Even Vista Home Premium and Ultimate edition is also having IIS 7.0


How we can save an Application Pool Settings?


Application Pool Settings can be save as "XML" Format.

Right Click on Application Pool > All Task > Save Configuration to a File .

This will save all the settings of Application Pool as an XML file.We can make it password protected also.

Which Tool is used for Remote IIS Debugging ?



Tools is : msvsmon.exe

This is located at : Install path\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86

What are the different authentication mode available for IIS Remote Debugging ?


For IIS Remote Debugging msvsmon supported two authentication mode

1. Windows Authentication
2. No-Authentication

How can we get the list of worker process running in IIS along with the Application pool name ?



By running iisapp.vbs script from command Prompt.

Below are the steps :
1. Start > Run > Cmd
2. Go To Windows > System32
3. Run cscript iisapp.vbs

If there are multiple worker process running on IIS, then how can you attach a particular worker process for application ?


Well, If there are multiple worker process running in IIS, it means I have to know the name of my application pool. Then I can run cscript iisapi.vbs script to find out the process ID and Application Pool name . Based on the process Id for particular application I have to attache the process from Visual studio IDE.

Why do we need to IIS Remote Debugging ?


There are following reasons where we can use remote debugging
1. Your development server does not have IIS installed.
2. Development server and Build/Released/Hosting Server is different
3. Multiple user want to debug simultaneously.

Does IIS allows multiple user to Remote debug simultaneously ?


Yes. This is one of the great features of msvsmon.exe . Each instance of the remote debugger has a unique server name.we can give an instance of the remote debugger any server name. Now multiple user can able to access the server instance.

What is the use of aspnet_regiis -i command ?



This is used automatically register the .NET Framework with your IIS.

For more information :

 

Can we have multiple web sites on IIS ?


Yes. IIS Can have multiple web sites and Each and every web sites can have multiple virtual Directory.

Note : Here web sites means the Root Node.

Where is the default location for IIS Log files ?



Its
C:\WINDOWS\system32\LogFiles\W3SVC1

What is ISAPI Filter ?



This is one of the more important question for experienced guys.

Please read this in details.
http://msdn.microsoft.com/en-us/library/ms524610.aspx

What are the major innovation in IIS 7.0 ?



Below are the Major Innovation in IIS 7.0
Components are designed as module and there are major change in administration settings.
FYI : You can find out many of them, just go thorugh Microsoft IIS web site.

What is the Role of Windows Activation Process in IIS ?


WAP is the Controller of Worker process under a Application Pool. Windows Activation Process which is managed by the worker process by starting, stopping and recycling the application pool. When to start, stop and Recycle should be defined on Application Pool Settings. Activation Process is also responsible for Health Monitor of Application Pool during runtime.

FYI : Health monitoring setting can be easily found in Properties of Application Pool.

What are the different type of application pool available in IIS 7.0 ?


IIS 7.0 having two types of application pool.

1. DefaultAppPool (Integrated)
2. ClassicAppPool

Which is not an Identity of Application Pool ?

NOTE: This is objective type question, Please click question title for correct answer.


Which application pool having maximum privilege on the server ?


NOTE: This is objective type question, Please click question title for correct answer.

What is name of default application pool in IIS ?


NOTE: This is objective type question, Please click question title for correct answer.

 

What are the worker process for IIS 5.1 and IIS 6.0 ?


For IIS 5.1 > aspnet_wp.exe
For IIS 6.0 > w3wp.exe

Name of the tool which is used for remote debugging of IIS


NOTE: This is objective type question, Please click question title for correct answer.

What is Web Farm ?


This is one of the most questions in IIS. And along with that interviewer can as

what is the different between Web farm and Web Garden ?


When we hosted our web Application on multiple web server under a load balancer call the Web Farm. This is generally used for heavy load web application where there are many user request at a time. So When Web Application is hosted on Different IIS Server over a load balancer, Load balancer is responsible for distribute the load on different server.

Please have a look into this :


What is the default Identity of an Application Pool ?


NetworkServices

How can we set the default page for any web application ?



We can set the default page for a web site from the Virtual Directory Setting.
How To :
IIS Manager > Virtual Directory > Right Click > Properties > GoTo Document Tab.

How we can set the Idle Time out of an worker process ?


We can set the Idle time out for an worker process from Application Pool Properties.

In Performance Tab of Application pool, we can set the Idle Time out of the worker process. This means worker process will shut down after that given time period if it stay idle. And will again wake up again if a new request comes.

Is there any alternative way to host site on IIS rather than opening IIS Manager ?



Yes, We can directly host any site from the physical location of directory itself.

Right Click on Physical Folder > Properties > Web Sharing

There you need to select > "Share This Folder" Option Button. Then it will ask for alias name and other setting. Then Click on OK.

To Validate : Run > Inetmgr > Check there should an virtual directory with the same "Alias" name that you have given.

If there are already one Virtual directory exist it will showing you the error message while you providing the "Alias" name.

Can we create one Application Pool From Another Application Pool ?



Yes. We can.
While creating Application Application Pool From IIS, there should have two option available first one is for Default Setting and Another is for Existing Setting as template.
We can select the second one and from the drop down listed below we can select any on the Application Pool as Template,.

What are the main components of SVCHost.exe ?


Main components for SVCHost.exe are WWW Publishing Service (W3SVC) and Windows Activation Porcess (WAP) .

W3SVC is the mediator of HTTP.SYS and Windows Activation Process. Windows Activation Process maintain the worker processes.

What are the different way that we can hosted site on IIS ?


We can hosted site on IIS either creating Virtual Directory through IIS manager or Using Folder Web Sharing .
Apart from that Visual studio provide some inbuilt features to host the site on IIS like using Publishing the web site , Using Copy web Tool or Creating Virtual directory during the creating the project by choosing Location as HTTP

How does IIS process an ASP.net request ?


When client request for an aspx pages, request comes to kernel level off IIS means to HTTP.SYS . HTTP.SYS receives the request and based on the application pool name [ Which is already registred with the HTTP.SYS ] it send the request to worker process. Windows Activation process works as mediator of them. w3wp.exe loads "aspnet_isapi.dll" files to start the HTTPRuntime . HTTPRuntime creates HTTPApplication objects and all request are passed through HTTPModule and finally reached to HttpHandler . This is the request pipeline. After end of Request pipeline ASP.NET Page lifecycle starts.

For more Information :
http://www.codeproject.com/KB/aspnet/aspnetrequestarchitecture.aspx

From where we can set the Session Time Out in IIS ?



We can set the Session time out settings from the Virtual Directory for that site.

Right Click on Virtual Directory > Properties > Click on "Configuration" Button
Goto the "Option" Tab. There in Enable Session State Section you can configure the Session Timeout .

What are the different "Execution Permission" available for IIS for an virtual directory ?



There are three Execution Permission available.
1. None
2. Scripts Only
3. Scripts and Executable


From where you can change the ASP.NET Version in IIS ?



This can be change from Virtual Directory properties. First open Properties of Virtual Directory > GoTo ASP.NET Version Tab.

There we can have change the ASP.NET Version.

What is the latest version of IIS released with Windows 7



IIS 7.5

What is the default user name of an anonymous login in IIS?

In IIS, an anonymous user will be given with a user name of "IUSR_MachineName "

How can we take back-ups in IIS Server?



Step 1 : In the IIS (inetmgr), right click on the "Computer" icon under "Internet Information Services" . Click "All Tasks" and select "Backup/Restore Configuration".

Step 2 : Click on button "Create backup". Give Name for your backup file. If you want encryption enable encryption option and give UserName and Password and then click OK.

What is IIS metabase? And In which format IIS stors configurations?



IIS metabase is a special databse which is used to maintain the settings and configurations data for IIS. In simple term, it is a configuration base for IIS (Metabase.xml).

IIS 5.0 --> Metabse is in Binary.
IIS 6.0 & 7.5 --> Metabase is in XML.

List of Error & Status codes in IIS 6.0?


Status Code Type of Code
100 Series - Informational
200 Series - Success
300 Series - Redirection
400 Series - Client Error
500 Series - Server Error

 

How to recycle application pool from the command prompt in IIS7?


1. Use appcmd.exe to recycle the application pool from the command prompt.

2. appcmd.exe is the command line tool for IIS7, you will find this tool at following location :

%systemroot%\system32\inetsrv\appcmd

3. To recycle your application pool use the following command:
appcmd recycle apppool /apppool.name:

What are the Different steps to be followed to get SSL(Secure Sockets Layer) for our Web Application ?



  1. Intially we have to Generate a certificate request from our IIS

  1. Now we have to request a certificate from the certificate authority(CA)

  1. This CA is an entity which issues Digital Certificates.

  1. After receiving the certificate we have to install that particular certificate on our Web Server using IIS

  1. We have to use Secure Hyper Text Transfer Protocol(HTTPS) when accessing secure pages in our application.

By this way we could make our web page as SSL protected. !!!
Browser Name:
Browser Version:
Browser Code Name:
User-Agent: