Issuu on Google+

Microsoft 70-640

TS: Windows Server 2008 Active Directory, Configuring Version: Demo 32.4


Microsoft 70-640 Exam Topic 1, Exam Set 3

QUESTION NO: 1 Your network contains an Active Directory forest. The forest contains multiple domains. You need to ensure that users in the human resources department can search for employees by using the employeeNumber attribute. What should you do? A. From Active Directory Sites and Services, modify the properties of each global catalog server. B. From the Active Directory Schema snap-in, modify the properties of the user object class. C. From Active Directory Sites and Services, modify the NTDS Settings object of each global catalog server. D. From the Active Directory Schema snap-in, modify the properties of the employeeNumber attribute. Answer: D Explanation:

Topic 2, Exam Set 1

QUESTION NO: 2 Your company has an Active Directory forest that contains only Windows Server 2008 domain controllers. You need to prepare the Active Directory domain to install Windows Server 2008 R2 domain controllers. Which two tasks should you perform? (Each correct answer presents part of the solution. Choose two.) A. Run the adprep /domainprep command. B. Raise the forest functional level to Windows Server 2008. C. Raise the domain functional level to Windows Server 2008. D. Run the adprep /forestprep command. Answer: A,D Explanation:

"A Composite Solution With Just One Click" - Certification Guaranteed

2


Microsoft 70-640 Exam

Topic 1, Exam Set 3

QUESTION NO: 3 Your network contains an Active Directory forest. All client computers run Windows 7. The network contains a high-volume enterprise certification authority (CA). You need to minimize the amount of network bandwidth required to validate a certificate. What should you do? A. Configure an LDAP publishing point for the certificate revocation list (CRL). B. Configure an Online Certification Status Protocol (OCSP) responder. C. Modify the settings of the delta certificate revocation list (CRL). D. Replicate the certificate revocation list (CRL) by using Distributed File System (DFS). Answer: B Explanation:

Topic 2, Exam Set 1

QUESTION NO: 4 You have a domain controller that runs Windows Server 2008 R2 and is configured as a DNS server. You need to record all inbound DNS queries to the server. What should you configure in the DNS Manager console? A. Enable debug logging. B. Enable automatic testing for simple queries. C. Configure event logging to log errors and warnings. D. Enable automatic testing for recursive queries. Answer: A Explanation:

"A Composite Solution With Just One Click" - Certification Guaranteed

3


Microsoft 70-640 Exam

QUESTION NO: 5 Your company has a server that runs an instance of Active Directory Lightweight Directory Service (AD LDS). You need to create new organizational units in the AD LDS application directory partition. What should you do? A. Use the dsmod OU <OrganizationalUnitDN> command to create the organizational units. B. Use the Active Directory Users and Computers snap-in to create the organizational units on the AD LDS application directory partition. C. Use the dsadd OU <OrganizationalUnitDN> command to create the organizational units. D. Use the ADSI Edit snap-in to create the organizational units on the AD LDS application directory partition. Answer: D Explanation: To create new OUs in the AD LDS application directory partition, you should use ADSI Edit snapin. ADSI Edit is a snap-in that runs in a Microsoft Management Console (MMC). The default console containing ADSI Edit is AdsiEdit.msc. If this snap-in is not added in your MMC, you can do it by adding through Add/Remove Snap-in menu option in the MMC or you can open AdsiEdit.msc from a Windows Explorer.

Topic 1, Exam Set 3

QUESTION NO: 6 Your network contains an Active Directory domain named adatum.com. The domain contains a domain controller named DC1. DC1 has an IP address of 192.168.200.100. You need to identify the zone that contains the Pointer (PTR) record for 0C1. Which zone should you identify? A. adatum.com B. _msdcs.adatum.com C. 100.168.192.in-addr.arpa D. 200.168.192.in-addr.arpa "A Composite Solution With Just One Click" - Certification Guaranteed

4


Microsoft 70-640 Exam Answer: D Explanation:

Topic 3, Exam Set 2

QUESTION NO: 7 Your network contains a single Active Directory domain. The functional level of the forest is Windows Server 2008 R2. You need to enable the Active Directory Recycle Bin. What should you use? A. the Dsmod tool B. the Enable-ADOptionalFeature cmdlet C. the Ntdsutil tool D. the Set-ADDomainMode cmdlet Answer: B Explanation:

Topic 1, Exam Set 3

QUESTION NO: 8 A corporate network includes a singe Active Directory Domain Services ( ADDS ) domain. The AD DS infrastructure is shown in the following graphic. (See Exhibit)

"A Composite Solution With Just One Click" - Certification Guaranteed

5


Microsoft 70-640 Exam

When the Montreal Site domain controller is offline, authentication request for Montreal branch office users are sent to the Toronto Site domain controller. You need to ensure that when the Montreal Site domain controller is offline, authentication requests for Montreal branch offices users are sent to Quebec City Site domain controller. What should you do? A. Create a site link bridge between the Montreal Site and the Quebec City Site. B. Enable the global catalog role on the Montreal Site domain controller. C. Modify the Default Domain Policy Group Policy Object D. Delete the Toronto-Montreal Site Link Answer: D Explanation:

QUESTION NO: 9 Your network contains an Active Directory domain named contoso.com. Contoso.com contains a member server that runs Windows Server 2008 Standard. You need to install an enterprise subordinate certification authority (CA) that supports private key archival. You must achieve this goal by using the minimum amount of administrative effort. What should you do first? A. Initialize the Trusted Platform Module (TPM). "A Composite Solution With Just One Click" - Certification Guaranteed

6


Microsoft 70-640 Exam B. Upgrade the member server to Windows Server 2008 R2 Standard. C. Install the Certificate Enrollment Policy Web Service role service on the member server. D. Run the Security Configuration Wizard (SCW) and select the Active Directory Certificate Services - Certification Authority server role template check box. Answer: B Explanation:

QUESTION NO: 10 Your network contains an Active Directory forest. All users have a value set for the Department attribute. From Active Directory Users and Computers, you search a domain for all users who have a Department attribute value of Marketing. The search returns 50 users. From Active Directory Users and Computers, you search the entire directory for all users who have a Department attribute value of Marketing. The search does not return any users. You need to ensure that a search of the entire directory for users in the marketing department returns all of the users who have the Marketing Department attribute. What should you do? A. Install the Windows Search Service role service on a global catalog server. B. From the Active Directory Schema snap-in modify the properties of the Department attribute. C. Install the Indexing Service role service on a global catalog server. D. From the Active Directory Schema snap-in modify the properties of the user class. Answer: B Explanation:

"A Composite Solution With Just One Click" - Certification Guaranteed

7


Free Microsoft 70-640 Brain dumps