9
Get Success in Passing Your Certification Exam at first attempt! 70-640 www.dumpspdf.com

70-640 Success in Passing Your Certification Exam at first attempt! 70-640

Embed Size (px)

Citation preview

Get Success in Passing Your Certification Exam at first attempt! 

70-640www.dumpspdf.com

Vendor: Microsoft

Exam Code: 70-640

Exam Name: Windows Server 2008 Active Directory. Configuring

Version: Demo

www.dumpspdf.com

196 Get Complete Collection of 70-640 Exam's Question and Answers. http://www.Test4Prep.com

Question: 1 HOTSPOT

Your network contains an Active Directory domain named contoso.com. You need to view which password setting object is applied to a user. Which filter option in Attribute Editor should you enable? To answer, select the appropriate filter option in the answer area.

Answer:

Question: 2

Your company has an Active Directory forest. Each regional office has an organizational unit (OU) named Marketing. The Marketing OU contains all users and computers in the region's Marketing department. You need to install a Microsoft Office 2007 application only on the computers in the Marketing OUs. You create a GPO named MarketingApps. What should you do next?

A. Configure the GPO to assign the application to the computer account. Link the GPO to the domain. B. Configure the GPO to assign the application to the user account. Link the GPO to each Marketing OU.

197 Get Complete Collection of 70-640 Exam's Question and Answers. http://www.Test4Prep.com

C. Configure the GPO to assign the application to the computer account. Link the GPO to each Marketing OU. D. Configure the GPO to publish the application to the user account. Link the GPO to each Marketing OU.

Answer: C

Question: 3

Your network contains an Active Directory domain named contoso.com. The functional level of the forest is Windows Server 2008 R2. The Default Domain Controller Policy Group Policy object (GPO) contains audit policy settings. On a domain controller named DC1, an administrator configures the Advanced Audit Policy Configuration settings by using a local GPO. You need to identify what will be audited on DC1. Which tool should you use?

A. Get-ADObject B. Secedit C. Security Configuration and Analysis D. Auditpol

Answer: D

Question: 4

A network contains an Active Directory forest. The forest schema contains a custom attribute for user objects. You need to view the custom attribute value of 500 user accounts in a Microsoft Excel table. Which tool should you use?

A. Dsmod B. Csvde C. Ldifde D. Dsrm

Answer: B

Question: 5

Your network contains an Active Directory forest named contoso.com. The forest contains two domains named contoso.com and child.contoso.com. All domain controllers run Windows Server 2008. All forest-wide operations master roles are in child.contoso.com. An administrator successfully runs adprep.exe /forestprep from the Windows Server 2008 R2 Service Pack 1 (SP1) installation media. You plan to run adprep.exe /domainprep in each domain. You need to ensure that you have the required user rights to run the command successfully in each domain. Of which groups should you be a member? (Each correct answer presents part of the solution. Choose two.)

198 Get Complete Collection of 70-640 Exam's Question and Answers. http://www.Test4Prep.com

A. Administrators in child.contoso.com B. Enterprise Admins in contoso.com C. Domain Admins in child.contoso.com D. Domain Admins in contoso.com E. Administrators in contoso.com F. Schema Admins in contoso.com

Answer: CD

Question: 6

Your network contains an Active Directory forest named contoso.com. The forest contains a single domain and 10 domain controllers. All of the domain controllers run Windows Server 2008 R2 Service Pack 1 (SP1). The forest contains an application directory partition named dc=app1, dc=contoso,dc=com. A domain controller named DC1 has a copy of the application directory partition. You need to configure a domain controller named DC2 to receive a copy of dc=app1, dc=contoso, dc=corn. Which tool should you use?

A. Active Directory Sites and Services B. Dsmod C. Dcpromo D. Dsmgmt

Answer: B

Question: 7

A corporate environment includes a Windows Server 2008 R2 Active Directory Domain Services (AD DS) domain. You need to enable Universal Group Membership Caching on several domain controllers in the domain. Which tool should you use?

A. Dsmod B. Dscmd C. Ntdsutil D. Active Directory Sites and Services console

Answer: A

Question: 8

Your network contains an Active Directory forest. The forest contains three domains. All domain controllers have the DNS Server server role installed. The forest contains three sites named Site1, Site2, and Site3. Each site contains the users, client computers, and domain controllers of each

199 Get Complete Collection of 70-640 Exam's Question and Answers. http://www.Test4Prep.com

domain. Site1 contains the first domain controller deployed to the forest. The sites connect to each other by using unreliable WAN links. The users in Site2 and Site3 report that is takes a long time to log on to their client computer when they use their user principal name (UPN). The users in Site1 do not experience the same issue. You need to reduce the amount of time it takes for the Site2 users and the Site3 users to log on to their client computer by using their UPN. What should you do?

A. Configure a global catalog server in Site2 and a global catalog server in Site3. B. Reduce the replication interval of the site links. C. Move a primary domain controller (PDC) emulator to Site2 and to Site3. D. Add additional domain controllers to Site2 and to Site3. E. Reduce the cost of the site links. F. Enable universal group membership caching in Site2 and in Site3.

Answer: A

Question: 9

You have a client computer named Computer1 that runs Windows 7. On Computer1, you configure a source-initiated subscription. You configure the subscription to retrieve all events from the Windows logs of a domain controller named DC1. The subscription is configured to use the HTTP protocol. You discover that events from the Security log of DC1 are not collected on Computer1. Events from the Application log of DC1 and the System log of DC1 are collected on Computer1. You need to ensure that events from the Security log of DC1 are collected on Computer1. What should you do?

A. Add the computer account of Computer1 to the Event Log Readers group on the domain controller. B. Add the Network Service security principal to the Event Log Readers group on the domain controller. C. Configure the subscription to use custom Event Delivery Optimization settings. D. Configure the subscription to use the HTTPS protocol.

Answer: B

Question: 10

Your network contains an Active Directory forest named contoso.com. The forest contains six domains. You need to ensure that the administrators of any of the domains can specify a user principal name (UPN) suffix oflitwareinc.com when they create user accounts by using Active Directory Users and Computers. Which tool should you use?

A. Active Directory Administrative Center B. Set-ADDomain C. Active Directory Sites and Services D. Set-ADForest

Answer: C

200 Get Complete Collection of 70-640 Exam's Question and Answers. http://www.Test4Prep.com

Question: 11

Your network contains an Active Directory domain named litwareinc.com. The domain contains two sites named Sitel and Site2. Site2 contains a read-only domain controller (RODC). You need to identify which user accounts attempted to authenticate to the RODC. Which tool should you use?

A. Active Directory Users and Computers B. Ntdsutil C. Get-ADAccountResultantPasswordReplicationPolicy D. Adtest

Answer: A

Question: 12

Your network contains an Active Directory forest. The forest schema contains a custom attribute for user objects. You need to generate a file that contains the last logon time and the custom attribute values for each user in the forest. What should you use?

A. the Get-ADUser cmdlet B. the Export-CSV cmdlet A. the Net User command D. the Dsquery User tool

Answer: A

Question: 13

You have an Active Directory domain named contoso.com. You need to view the account lockout threshold and duration for the domain. Which tool should you use?

A. Net User B. Active Directory Users and Computers C. Group Policy Management Console (GPMC) D. Computer Management

Answer: C

Question: 14

A domain controller named DC4 runs Windows Server 2008 R2. DC4 is configured as a DNS server for fabrikam.com. You install the DNS Server server role on a member server named DNS1 and then you

201 Get Complete Collection of 70-640 Exam's Question and Answers. http://www.Test4Prep.com

create a standard secondary zone for fabrikam.com. You configure DC4 as the master server for the zone. You need to ensure that DNS1 receives zone updates from DC4. What should you do?

A. Add the DNS1 computer account to the DNSUpdateProxy group. B. On DC4, modify the permissions offabrikam.com zone. C. On DNS1, add a conditional forwarder. D. On DC4, modify the zone transfer settings for the fabrikam.com zone.

Answer: D

Question: 15

A company has an Active Directory forest. You plan to install an offline Enterprise root certification authority (CA) on a server named CA1. CA1 is a member of the PerimeterNetwork workgroup and is attached to a hardware security module for private key storage. You attempt to add the Active Directory Certificate Services (AD CS) server role to CA1. The Enterprise CA option is not available. You need to install the AD CS server role as an Enterprise CA on CA1. What should you do first?

A. Add the DNS Server server role to CA1. B. Add the Web Server (IIS) server role and the AD CS server role to CA1. C. Add the Active Directory Lightweight Directory Services (AD LDS) server role to CA1. D. Join CA1 to the domain.

Answer: D

www.dumpspdf.com