Configuring Advanced Windows Server Services

    CITY & GUILDS LIMITED
    Vocational

    This topic covers configuring advanced Windows Server services, including network services, file services, directory services, and high availability. Learners will implement features like Dynamic Access Control, certificate services, and failover clustering.

    34
    Learning Outcomes
    36
    Assessment Guidance
    36
    Key Skills
    24
    Key Terms
    50
    Assessment Criteria

    Assessment criteria

    City & Guilds Level 3 Diploma in ICT Systems Support
    City & Guilds Level 4 Diploma For ICT Professionals (Systems and Principles)
    City & Guilds Level 3 Diploma in ICT Professional Competence
    City & Guilds Level 2 Diploma in ICT Systems and Principles for IT Professionals
    City & Guilds Level 2 Award in ICT Systems and Principles
    City & Guilds Level 2 Certificate in ICT Systems Support
    City & Guilds Level 3 Certificate in ICT Systems and Principles
    City & Guilds Level 2 Diploma in ICT Systems Support
    City & Guilds Level 3 Diploma in ICT Systems and Principles for IT Professionals
    City & Guilds Level 2 Diploma in ICT Professional Competence

    Topic Overview

    The City & Guilds Level 2 Diploma in ICT Systems and Principles for IT Professionals is a comprehensive vocational qualification designed to equip you with the practical skills and theoretical knowledge needed for a career in IT. This diploma covers a broad range of topics including computer hardware, software, networking, database systems, and cybersecurity. You'll learn how to build and maintain computer systems, set up networks, and understand the principles behind modern ICT infrastructure. The course is structured around hands-on tasks and real-world scenarios, making it ideal for those who prefer applied learning over purely academic study.

    This qualification is highly valued by employers because it focuses on industry-relevant competencies. You'll develop problem-solving skills, technical proficiency, and an understanding of how ICT systems support business operations. The diploma also prepares you for further study, such as the Level 3 Diploma or specialised certifications like CompTIA A+. By the end of the course, you'll be able to confidently troubleshoot hardware issues, configure operating systems, and implement basic security measures. Whether you're aiming for an apprenticeship, entry-level IT role, or progression to higher education, this diploma provides a solid foundation.

    The course is divided into mandatory and optional units, allowing you to tailor your learning to your interests. Mandatory units cover essential topics like computer systems, software installation, and network fundamentals. Optional units let you explore areas such as web development, database design, or digital marketing. Assessment is through a combination of practical assignments, online tests, and a portfolio of evidence. This structure ensures you not only understand theory but can also apply it in practice, which is exactly what employers look for.

    Key Concepts

    Core ideas you must understand for this topic

    • Computer hardware components: Understand the function of CPUs, RAM, storage devices, motherboards, and power supplies. Know how to select components for a given purpose and assemble a system.
    • Operating systems: Learn the roles of operating systems (e.g., Windows, Linux) in managing hardware, running applications, and providing user interfaces. Be able to install, configure, and troubleshoot common OS issues.
    • Networking fundamentals: Grasp concepts like IP addressing, subnetting, network topologies (star, bus, ring), and protocols (TCP/IP, HTTP, FTP). Understand how devices like routers, switches, and modems enable communication.
    • Data security and backup: Know the principles of protecting data through encryption, access controls, and regular backups. Understand threats like malware, phishing, and social engineering, and how to mitigate them.
    • Database concepts: Understand what a database is, how tables, records, and fields are structured, and how to use SQL for basic queries. Appreciate the importance of data integrity and normalisation.

    Learning Objectives

    What you need to know and understand

    • Be able to implement advanced network services, Be able to implement advanced file services, Be able to implement Dynamic Access control, Be able to implement directory services, Be able to implement certificate services, Be able to implement Rights Management Services (RMS), Be able to implement Federation Services (FS), Be able to implement Network Load Balancing (NLB), Be able to implement failover clustering, Be able to implement disaster recovery
    • Configure and manage DHCP, DNS, and IPAM in a multi-site environment.
    • Deploy and enforce Dynamic Access Control policies using claims-based authentication.
    • Design and implement an Active Directory Domain Services multi-domain forest with trusts.
    • Establish and manage an enterprise Certificate Authority hierarchy with certificate templates.
    • Configure Active Directory Rights Management Services (AD RMS) to protect sensitive documents.
    • Deploy Active Directory Federation Services (AD FS) to enable single sign-on for cloud applications.
    • Create and validate a failover cluster using shared storage and cluster shared volumes (CSV).
    • Develop and test a disaster recovery plan including Windows Server Backup and Hyper-V Replica.
    • Be able to implement advanced network services, Be able to implement advanced file services, Be able to implement Dynamic Access control, Be able to implement directory services, Be able to implement certificate services, Be able to implement Rights Management Services (RMS), Be able to implement Federation Services (FS), Be able to implement Network Load Balancing (NLB), Be able to implement failover clustering, Be able to implement disaster recovery
    • Be able to implement advanced network services, Be able to implement advanced file services, Be able to implement Dynamic Access control, Be able to implement directory services, Be able to implement certificate services, Be able to implement Rights Management Services (RMS), Be able to implement Federation Services (FS), Be able to implement Network Load Balancing (NLB), Be able to implement failover clustering, Be able to implement disaster recovery
    • Be able to implement advanced network services, Be able to implement advanced file services, Be able to implement Dynamic Access control, Be able to implement directory services, Be able to implement certificate services, Be able to implement Rights Management Services (RMS), Be able to implement Federation Services (FS), Be able to implement Network Load Balancing (NLB), Be able to implement failover clustering, Be able to implement disaster recovery
    • Configure DHCP and DNS services to support name resolution and dynamic IP addressing in a domain environment.
    • Deploy and manage Distributed File System (DFS) and File Server Resource Manager for advanced file services.
    • Implement Dynamic Access Control policies using central access policies and claims-based authentication.
    • Install and configure Active Directory Domain Services, including user, group, and computer management.
    • Deploy a public key infrastructure (PKI) comprising Certification Authority and certificate templates.
    • Integrate Active Directory Rights Management Services to protect sensitive documents.
    • Set up Active Directory Federation Services for single sign-on with partner organisations.
    • Build a Network Load Balancing cluster for high availability of web services.
    • Create a failover cluster with shared storage for mission-critical server applications.
    • Develop and test a disaster recovery plan including Windows Server Backup and recovery.
    • Be able to implement advanced network services, Be able to implement advanced file services, Be able to implement Dynamic Access control, Be able to implement directory services, Be able to implement certificate services, Be able to implement Rights Management Services (RMS), Be able to implement Federation Services (FS), Be able to implement Network Load Balancing (NLB), Be able to implement failover clustering, Be able to implement disaster recovery
    • Be able to implement advanced network services, Be able to implement advanced file services, Be able to implement Dynamic Access control, Be able to implement directory services, Be able to implement certificate services, Be able to implement Rights Management Services (RMS), Be able to implement Federation Services (FS), Be able to implement Network Load Balancing (NLB), Be able to implement failover clustering, Be able to implement disaster recovery
    • Implement advanced network services such as DHCP, DNS, and IPAM.
    • Configure advanced file services including DFS, FSRM, and iSCSI.
    • Implement Dynamic Access Control to classify and control access to files.
    • Deploy and manage Active Directory Domain Services and additional directory services.
    • Implement Active Directory Certificate Services for PKI.
    • Implement Active Directory Rights Management Services for information protection.
    • Implement Active Directory Federation Services for single sign-on.
    • Configure Network Load Balancing and failover clustering for high availability.
    • Implement disaster recovery solutions including backup and restore.
    • Be able to implement advanced network services, Be able to implement advanced file services, Be able to implement Dynamic Access control, Be able to implement directory services, Be able to implement certificate services, Be able to implement Rights Management Services (RMS), Be able to implement Federation Services (FS), Be able to implement Network Load Balancing (NLB), Be able to implement failover clustering, Be able to implement disaster recovery

    Assessment Criteria

    Key criteria assessors look for in your portfolio

    • Implement advanced network services such as DHCP and DNS.
    • Configure Dynamic Access Control to manage file permissions.
    • Deploy and manage Active Directory certificate services.
    • Set up Network Load Balancing for high availability.
    • Implement failover clustering and disaster recovery solutions.
    • Award credit for correctly configuring a DHCP scope with superscope and failover options.
    • Expect demonstration of creating and linking Group Policy Objects (GPOs) for Dynamic Access Control rules.
    • Learner must show ability to issue certificates from a subordinate CA to clients for authentication.
    • Look for successful establishment of a failover cluster with validated storage and network settings.
    • Assess planning documentation and execution of a backup and restore operation using Windows Server Backup.
    • Implement advanced network services like DHCP and DNS.
    • Configure advanced file services and Dynamic Access Control.
    • Manage directory services and certificate services.
    • Implement RMS, FS, NLB, and failover clustering.
    • Plan and implement disaster recovery.
    • Configure DNS, DHCP, and IPAM correctly.
    • Implement file server resource manager and quotas.
    • Set up failover clustering and Network Load Balancing.
    • Implements advanced network services correctly.
    • Configures file services and Dynamic Access Control.
    • Sets up directory services and certificate services.
    • Deploys RMS, FS, NLB, failover clustering, and disaster recovery.
    • Learner must evidence successful configuration of a DHCP scope with options and demonstrate client lease acquisition.
    • Evidence of deploying DFS Namespace and Replication with access-based enumeration enabled.
    • Correct creation and application of central access policies with user/device claims in a test environment.
    • Demonstration of an operational failover cluster with at least two nodes and a file server role.
    • Documented disaster recovery procedure with successful restoration from backup.
    • Implement advanced network services like DHCP, DNS, and IPAM.
    • Configure file services including DFS and quotas.
    • Deploy Active Directory, certificates, and federation services.
    • Set up Network Load Balancing and failover clustering.
    • Implements advanced network services like DHCP and DNS.
    • Configures advanced file services including DFS.
    • Sets up Dynamic Access Control policies.
    • Deploys and manages certificate services.
    • Implements failover clustering and disaster recovery solutions.
    • Award credit for demonstrating correct configuration of DHCP scopes and DNS zones.
    • Award credit for implementing DFS namespaces and replication groups.
    • Award credit for creating and applying DAC policies with classification rules.
    • Award credit for deploying AD CS with appropriate certificate templates.
    • Award credit for configuring AD RMS templates and exclusion policies.
    • Award credit for setting up AD FS with claims-based authentication.
    • Award credit for configuring NLB with appropriate affinity settings.
    • Award credit for creating a failover cluster and validating its configuration.
    • Award credit for implementing backup and restore procedures using Windows Server Backup.
    • Implement advanced network services (e.g., DHCP, DNS).
    • Configure advanced file services (e.g., DFS, FSRM).
    • Implement Dynamic Access Control and certificate services.
    • Configure Rights Management Services and Federation Services.
    • Implement Network Load Balancing, failover clustering, and disaster recovery.

    Assessment Guidance

    Guidance for achieving higher grades

    • 💡Use PowerShell scripts to automate repetitive tasks.
    • 💡Understand the difference between NLB and failover clustering.
    • 💡Practice setting up a lab environment to simulate configurations.
    • 💡Always test failover scenarios in a lab to anticipate real-world recovery procedures and document each step.
    • 💡Use PowerShell commands alongside GUI to demonstrate deep understanding and efficiency in configuration tasks.
    • 💡For Dynamic Access Control, clearly map business requirements to claims types and resource properties.
    • 💡When implementing certificate services, ensure certificate revocation list (CRL) distribution points are highly available.
    • 💡Practice integrating AD FS with Azure AD to showcase hybrid identity management skills.
    • 💡Use PowerShell for automation.
    • 💡Understand high availability concepts.
    • 💡Practice in a lab environment.
    • 💡Practice in a virtual lab environment.
    • 💡Understand the role of each service in an enterprise.
    • 💡Learn common PowerShell commands for configuration.
    • 💡Use PowerShell scripts for repeatable configurations.
    • 💡Document each step for troubleshooting.
    • 💡Verify services after configuration using appropriate tools.
    • 💡Always maintain a detailed log of configuration steps with screenshots to use as evidence in your portfolio.
    • 💡Test every service configuration in a sandbox environment before rolling out to production-like scenarios.
    • 💡Ensure you understand the interdependencies between services, e.g., DNS is critical for AD and DFS.
    • 💡Be prepared to explain the reasoning behind your configuration choices during observed assessments.
    • 💡Use virtual labs for hands-on practice.
    • 💡Understand dependencies between services.
    • 💡Know common troubleshooting commands.
    • 💡Use virtual labs to practice configurations.
    • 💡Understand the dependencies between services.
    • 💡Document configurations for troubleshooting.
    • 💡Ensure you understand the prerequisites for each service, such as DNS for AD DS.
    • 💡Practice configuring services in a virtual lab environment to gain hands-on experience.
    • 💡Focus on the configuration steps and troubleshooting common issues.
    • 💡Use the official Microsoft documentation as a reference for best practices.
    • 💡In assignments, clearly document your configuration steps and provide screenshots as evidence.
    • 💡Understand the differences between NLB and failover clustering and when to use each.
    • 💡Use PowerShell for automation where possible.
    • 💡Understand the purpose of each service.
    • 💡Practice in a lab environment before implementation.
    • 💡When answering questions about hardware, always use the correct technical terms (e.g., 'solid-state drive' instead of 'hard drive' if it's an SSD). Examiners look for precise vocabulary. Also, mention specific examples like 'SATA III' or 'NVMe' to show deeper knowledge.
    • 💡For networking questions, draw diagrams if allowed. A clear sketch of a star topology with labelled devices (switch, router, PCs) can earn you marks even if your written explanation is brief. Practice common network configurations so you can quickly sketch them.
    • 💡In practical assessments, follow safety procedures explicitly. Mentioning that you've anti-static wrist straps or turned off power before opening a case demonstrates professionalism. Examiners award marks for methodical, safe working practices, not just the final result.

    Common Mistakes

    Common errors to avoid in your coursework

    • Misconfiguring DNS forwarders or root hints.
    • Forgetting to back up certificate authority keys.
    • Failing to test failover clustering in a non-production environment.
    • Misconfiguring DNS forwarders leading to name resolution failures across forests.
    • Neglecting to back up the Certificate Authority private key before migration or disaster.
    • Forgetting to set correct permissions on AD RMS service connection point.
    • Assuming NLB automatically provides session persistence without sticky sessions configuration.
    • Omitting the validation of cluster configuration, resulting in undetected hardware or driver issues.
    • Misconfiguring certificate templates.
    • Overlooking dependencies in clustering.
    • Inadequate testing of disaster recovery plans.
    • Misconfiguring permissions leading to access issues.
    • Not testing failover after clustering setup.
    • Overlooking certificate services requirements.
    • Misconfiguring certificate services leading to trust issues.
    • Overlooking dependencies between services.
    • Failing to test failover or recovery procedures.
    • Neglecting to authorise DHCP servers in Active Directory, leading to clients not receiving IP addresses.
    • Misconfiguring DNS zones or forwarders, causing name resolution failures.
    • Forgetting to back up the CA private key, risking PKI recovery issues.
    • Incorrectly configuring cluster networks, resulting in failover not triggering as expected.
    • Misconfiguring DNS forwarders or zones.
    • Overlooking certificate revocation checks.
    • Incorrect cluster quorum settings.
    • Misconfiguring DNS settings causing resolution failures.
    • Not testing failover configurations thoroughly.
    • Overlooking security permissions in file services.
    • Misconfiguring DNS forwarders or failing to set correct permissions on DNS zones.
    • Overlooking the need for a shared storage solution when configuring failover clustering.
    • Not properly securing certificate services, leaving private keys accessible.
    • Confusing AD RMS with IRM and failing to configure the RMS service account correctly.
    • Incorrectly setting up AD FS proxies, leading to authentication failures.
    • Neglecting to test failover and disaster recovery procedures, assuming they will work.
    • Misconfiguring DNS or DHCP scopes.
    • Overlooking certificate revocation and renewal.
    • Failing to test failover and recovery procedures.
    • Misconception: 'All RAM is the same, so any stick will work in any computer.' Correction: RAM comes in different types (DDR3, DDR4, DDR5), speeds, and form factors (DIMM, SO-DIMM). Using incompatible RAM can cause system instability or failure to boot. Always check your motherboard's specifications.
    • Misconception: 'If I delete a file, it's gone forever.' Correction: Deleting a file usually removes the reference to it, but the data remains on the storage device until overwritten. This is why data recovery tools can often retrieve 'deleted' files. Secure deletion methods (e.g., overwriting with zeros) are needed to truly erase data.
    • Misconception: 'A higher IP address means a better connection.' Correction: IP addresses are just logical identifiers; they don't indicate speed or quality. A device with 192.168.1.100 is not 'better' than one with 192.168.1.1. Performance depends on factors like bandwidth, latency, and network congestion.

    Frequently Asked Questions

    Common questions students ask about this topic

    Pass / Merit / Distinction Evidence Checklist

    How your portfolio evidence is graded for CITY & GUILDS LIMITED Configuring Advanced Windows Server Services

    Every vocational unit is marked against named criteria rather than an exam percentage. Your tutor's brief lists the exact codes for this unit — here is what each band is asking you to do.

    Pass (P)

    Demonstrate baseline knowledge, accurate terminology, and core practical application.

    Merit (M)

    Provide detailed analysis, structured explanations, and clear workplace reasoning.

    Distinction (D)

    Deliver thorough evaluation, original problem solving, and fully justified recommendations.

    Before You Start

    Prior knowledge that will help with this topic

    • Basic computer literacy: You should be comfortable using a computer, navigating the internet, and managing files. This course builds on everyday skills, so no advanced knowledge is required.
    • Maths and English at Level 1 or equivalent: You'll need to interpret technical data, calculate storage capacities, and write clear reports. A GCSE grade D/3 or above in both subjects is typically recommended.
    • Interest in technology: A genuine curiosity about how computers work and a willingness to troubleshoot problems will help you succeed. No prior IT qualification is necessary, but enthusiasm goes a long way.

    Coursework AI Review

    Paste your assignment brief and check your draft against its P/M/D criteria

    Key Terminology

    Essential terms to know

    • Be able to implement advanced network services, Be able to implement advanced file services, Be able to implement Dynamic Access control, Be able to implement directory services, Be able to implement certificate services, Be able to implement Rights Management Services (RMS), Be able to implement Federation Services (FS), Be able to implement Network Load Balancing (NLB), Be able to implement failover clustering, Be able to implement disaster recovery
    • Advanced network services
    • Dynamic file access
    • Identity and federation
    • Public key infrastructure
    • Load balancing and clustering
    • Disaster recovery strategies
    • Be able to implement advanced network services, Be able to implement advanced file services, Be able to implement Dynamic Access control, Be able to implement directory services, Be able to implement certificate services, Be able to implement Rights Management Services (RMS), Be able to implement Federation Services (FS), Be able to implement Network Load Balancing (NLB), Be able to implement failover clustering, Be able to implement disaster recovery
    • Be able to implement advanced network services, Be able to implement advanced file services, Be able to implement Dynamic Access control, Be able to implement directory services, Be able to implement certificate services, Be able to implement Rights Management Services (RMS), Be able to implement Federation Services (FS), Be able to implement Network Load Balancing (NLB), Be able to implement failover clustering, Be able to implement disaster recovery
    • Be able to implement advanced network services, Be able to implement advanced file services, Be able to implement Dynamic Access control, Be able to implement directory services, Be able to implement certificate services, Be able to implement Rights Management Services (RMS), Be able to implement Federation Services (FS), Be able to implement Network Load Balancing (NLB), Be able to implement failover clustering, Be able to implement disaster recovery
    • Windows Server Infrastructure Services
    • Identity and Access Management
    • High Availability and Clustering
    • Disaster Recovery and Business Continuity
    • Enterprise Network Services
    • Be able to implement advanced network services, Be able to implement advanced file services, Be able to implement Dynamic Access control, Be able to implement directory services, Be able to implement certificate services, Be able to implement Rights Management Services (RMS), Be able to implement Federation Services (FS), Be able to implement Network Load Balancing (NLB), Be able to implement failover clustering, Be able to implement disaster recovery
    • Be able to implement advanced network services, Be able to implement advanced file services, Be able to implement Dynamic Access control, Be able to implement directory services, Be able to implement certificate services, Be able to implement Rights Management Services (RMS), Be able to implement Federation Services (FS), Be able to implement Network Load Balancing (NLB), Be able to implement failover clustering, Be able to implement disaster recovery
    • Advanced network services configuration
    • File services and Dynamic Access Control
    • Directory services and identity management
    • Certificate services and PKI
    • Rights Management and Federation Services
    • High availability and disaster recovery
    • Be able to implement advanced network services, Be able to implement advanced file services, Be able to implement Dynamic Access control, Be able to implement directory services, Be able to implement certificate services, Be able to implement Rights Management Services (RMS), Be able to implement Federation Services (FS), Be able to implement Network Load Balancing (NLB), Be able to implement failover clustering, Be able to implement disaster recovery

    Ready to learn?

    AI-powered learning tailored to this unit