MICROSOFT NEWS: 70-646 Exam Questions has been Updated Today! Get Latest 70-646 VCE and 70-646 PDF Instantly! Welcome to Download the Newest Braindump2go 70-646 VCE&70-646 PDF Dumps: http://www.braindump2go.com/70-646.html (283 Q&As)
2015 Latest released Microsoft Official 70-646 Practice Exam Question Free Download From Braindump2go Now! All New Updated 283 Questions And Answers are Real Questions from Microsoft Exam Center!
Exam Code: 70-646
Exam Name Windows Server 2008, Server Administrator
Certification Provider: Microsoft
Corresponding Certifications: MCSA, MCSA: Windows Server 2008, MCSE, MCSE: Private Cloud Windows Server 2008
70-646 Dumps,70-646 Study Guide,70-646 Exam Questions,70-646 eBook,70-646 eBook PDF,70-646 Dumps PDF,70-646 Dumps Latest,70-646 Book,70-646 Braindumps,70-646 Braindump PDF,70-646 Braindump Free,70-646 Practice Test,70-646 Practice Questions,70-646 PDF eBook,70-646 PDF,70-646 VCE
Case Study 18 – Tailspin Toys (QUESTION 231 – QUESTION 240)
General Background
You are the Windows Server Administrator for Tailspin Toys.
Tailspin Toys has a main office and a manufacturing office.
Tailspin Toys recently acquired Wingtip Toys and is in the beginning stages of Merging the IT environments.
Wingtip Toys has a main office and a sales office.
Technical Background
The companies use the network subnets indicated in the following table:
The Tailspin Toys network and the Wingtip Toys are connected by a point-to-point dedicated 45 Mbps circuit that terminates in the main offices.
The current Tailspin Toys server topology is shown in the following table:
The Tailspin Toys environment has the following characteristics:
– All servers are joined to the tailspintoys.com domain.
– In the Default Domain Policy, the Retain old events Group Policy setting is enabled.
– An Active Directory security group named “Windows System Administrators” is used to control all files and folders on TT-PRINT01.
– A Tailspin Toys administrator named Marx has been delegated rights to multiple Organizational Units (OUs) and object in the tailspintoys.com domain.
– Tailspin Toys developers use Hyper-V Virtual Machines (VM’s) for development. There are 10 development VM’s named TT-DEV01 to TT-DEV20.
The current Wingtip Toys server topology is shown in the following table:
All servers in the Wingtip Toys environment are joined to the wingtiptoys.com domain.
Infrastructure Services
You must ensure that the following infrastructure services requirements are met:
– All domain zones must be stored as Active Directory-integrated zones.
– Only DNS servers located in the Tailspin Toys main offices may communicate with the DNS servers at Wingtip Toys.
– Only DNS servers located in the Wingtip Toys main offices may communicate with the DNS servers at Tailspin Toys
– All tailspintoys.com resources must be resolved from the Wingtip Toys offices.
– All wingtiptoys.com resources must be resolved from the Tailspin toys offices.
– Certificates must be distributed automatically to all Tailspin Toys and Wingtip Toys computers.
Delegated Administration
You must ensure that the following delegated administration requirements are met:
– Tailspin Toys IT security administrators must be able to create, modify and delete user objects in the wingtip.com domain.
– Members of the Domain Admins Group in the tailspintoys.com domain must have full access to the wingtiptoys.com Active Directory environment.
– A delegation policy must grant minimum access rights and simplify the process of delegating rights.
– Minimum permissions must always be delegated to ensure that the least privilege is granted for a job task.
– Members of the TAILSPINTOYS\Helpdesk group must be able to update drivers and add printer ports on TT-PRINT01.
– Members of the TAILSPINTOYS\Helpdesk group must not be able to cancel a print job on TT-PRINT01.
– Tailspin Toys developers must be able to start, stop and apply snapshots to their development VM’s.
IT Security
You must ensure that the following IT security requirements are met:
– Server security must be automated to ensure that newly deployed servers automatically have the same security configurations as existing servers.
– Auditing must be configured to ensure that the deletion of users objects and OUs is logged.
– Microsoft Word and Microsoft Excel files must be automatically encrypted when uploaded to the Confidential documents library on the Tailspin Toys Microsoft SharePoint site.
– Multi factor authentication must control access to Tailspin Toys domain controllers.
– All file and folder auditing must capture the reason for access.
– All folder auditing must capture all delete actions for all existing folders and newly created folders.
– New events must be written to the Security event log in the tailspintoys.com domain and retained indefinitely.
– Drive X:\ on the TT-FILE01 must be encrypted by using Windows BitLocker Drive Encryption and must be automatically unlock.
QUESTION 231
You need to recommend a solution to migrate shared printers from the print server at Wingtip Toys to the print server at Tailspin Toys.
What should you recommend?
A. On the TT-PRINT01 server, run the printmig.exe command-line tool.
B. On the WT-PRINT01 server, run the printbrm.exe command-line tool.
C. On the WT-PRINT01 server, run the printmig.exe command-line tool.
D. On the TT-PRINT01 server, run the printbrm.exe command-line tool.
Answer: D
QUESTION 232
You are planning for the IT integration of Tailspin Toys and Wingtip Toys.
The company has decided on the following name resolution requirements:
– Name resolution for Internet-based resources must continue to operate by using the same DNS servers as prior to the merger.
– The existing connectivity between Tailspin Toys and Wingtip Toys must be used for all network communication.
– The documented name resolution goals must be met.
You need to provide a name resolution solution that meets the requirements.
What should you recommend? (Choose all that apply.)
A. On TT-DC01, TT-DC02, TT-DC03, and TT-DC04, add forwarders with the IP addresses of
172.16.10.10 and 172.16.10.11.
B. On TT-DC01, add a conditional forwarder for wingtiptoys.com, use 172.16.10.10 and
172.16.10.11 as the IP addresses, and then configure it to replicate to all DNS servers in the
tailspintoys.com domain.
C. On TT-DC01, TT-DC02, TT-DC03, and TT-DC04, add a secondary DNS zone for
wingtiptoys.com and specify 172.16.10.10 and 172.16.10.11 as the master DNS servers.
D. On WT-DC01 and WT-DC02, add a secondary DNS zone for tailspintoys.com and specify
10.10.10.10 and 10.10.10.11 as the master DNS servers.
E. On WT-DC01, WT-DC02, WT-DC03, and WT-DC04, add forwarders with the IP addresses of
10.10.10.10 and 10.10.10.11.
F. On WT-DC01, add a conditional forwarder for tailspintoys.com, use 10.10.10.10 and
10.10.10.11 as the IP addresses, and configure it to replicate to all DNS servers in the
wingtiptoys.com domain.
Answer: BF
QUESTION 233
You need to recommend a solution to meet the IT security requirements and data encryption requirements for TT-FILE01 with the minimum administrative effort.
What should you recommend? (Choose all that apply.)
A. Turn on BitLocker on drive X:\ and select the Automatically unlock this drive on this computer
option.
B. Migrate TT-FILE01 to Windows Server 2008 R2 Enterprise.
C. Store BitLocker recovery information in the tailspintoys.com domain.
D. Turn on BitLocker on the system drive.
Answer: AC
Explanation:
Backing up recovery passwords for a BitLocker-protected disk volume allows administrators to recover the volume if it is locked. This ensures that encrypted data belonging to the enterprise can always be accessed by authorized users.
Storage of BitLocker recovery information in Active Directory
Backed up BitLocker recovery information is stored in a child object of the Computer object.
That is, the Computer object is the container for a BitLocker recovery object.
Each BitLocker recovery object includes the recovery password and other recovery information.
More than one BitLocker recovery object can exist under each Computer object, because there can be more than one recovery password associated with a BitLocker-enabled volume.
The name of the BitLocker recovery object incorporates a globally unique identifier (GUID) and date and time information, for a fixed length of 63 characters.
The form is:
<Object Creation Date and Time><Recovery GUID>
For example:
2005-09-30T17:08:23-08:00{063EA4E1-220C-4293-BA01-4754620A96E7}
QUESTION 234
You need to recommend a solution that meets the following requirements:
– Log access to all shared folders on TT-FILE02.
– Minimize administrative effort.
– Ensure that further administrative action is not required when new shared folders are added to TT-FILE02.
What should you recommend?
A. Upgrade TT-FILE02 to Windows Server 2008 Enterprise and use application control policies
in Group Policy.
B. Add the Connection Manager Administration Kit feature on TT-FILE02.
C. Upgrade TT-FILE02 to Windows Server 2008 R2 Standard and use Advanced Audit Policy
Configuration settings in Group Policy.
D. Add the Network Policy and Access Services role to TT-FILE02.
Answer: C
QUESTION 235
You need to delegate print administration to meet the company requirements.
What should you do? To answer, select the appropriate check boxes in the dialog box.
Answer:
QUESTION 236
You need to recommend a solution to meet the certificate distribution requirements.
What should you recommend?
A. Upgrade the Wingtip Toys client computers that run Windows XP to Windows 7.
B. Create a one-way trust from wingtiptoys.com to tailspintoys.com.
C. Create a two-way trust between tailspintoys.com and wingtiptoys.com.
D. Upgrade the Wingtip Toys servers that run Windows Server 2003 to Windows Server 2008
R2.
E. Create a one-way trust from tailspintoys.com to wingtiptoys.com.
Answer: C
QUESTION 237
You need to remove Marc’s delegated rights.
What would you recommend?
A. Use the Delegation of Control Wizard.
B. Run the Resultant Set of Policy (RSoP) tool.
C. Run the dsacls command-line utility.
D. Run the xcalcs command-line utility.
Answer: C
QUESTION 238
You need to recommend a solution to meet the following requirements:
– Meet the company auditing requirements.
– Ensure that further administrative action is not required when new folders are added to the file server.
What should you recommend? (Choose all that apply.)
A. Enable the Audit File System Group Policy setting for Success.
B. Enable the Audit object access Group Policy setting for Success.
C. Enable the Audit File System Group Policy setting for Failure.
D. Enable the Audit Handle Manipulation Group Policy setting for Success.
E. Enable the File system option of the Global Object Access Auditing Group Policy setting.
F. Enable the Audit Handle Manipulation Group Policy setting for Failure.
Answer: BDE
QUESTION 239
You need to recommend a solution that meets the following requirements:
– Log access to all shared folders on TT-FILE02.
– Minimize administrative effort.
– Ensure that further administrative action is not required when new shared folders are added to TT-FILE02.
Which actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order. (Use only actions that apply.)
Answer:
QUESTION 240
New security events are not being written to the current Security event log in the tailspintoys.com domain.
However, old security events are still being maintained in the log.
You need to meet the security event log requirements for the tailspintoys.com domain.
Which Group Policy setting or settings should you select? To answer, select the appropriate setting or settings in the Group Policy Management Editor.
Answer:
Instant Download Braindump2go New Released Microsoft 70-646 Exam Dumps PDF & VCE! Enjoy 1 year Free Updation! 100% Exam Pass Guaranteed Or Full Money Back!
FREE DOWNLOAD: NEW UPDATED 70-646 PDF Dumps & 70-646 VCE Dumps from Braindump2go: http://www.braindump2go.com/70-646.html (283 Q&As)