New Released Braindump2go Microsoft 70-640 Dumps PDF – Questions and Answers Updated with Microsoft Official Exam Center! Visit Braindump2go and download our 70-640 Exam Questions Now, Pass 70-640 100% at your first time!
Vendor: Microsoft
Exam Code: 70-640
Exam Name: TS: Windows Server 2008 Active Directory, Configuring
Keywords: 70-640 Exam Dumps,70-640 Practice Tests,70-640 Practice Exams,70-640 Exam Questions,70-640 Dumps,70-640 Dumps PDF,70-640 VCE,70-640 Braindump,70-640 TS: Windows Server 2008 Active Directory, Configuring
QUESTION 571
Your network contains a domain controller that has two network connections named Internal and Private.
Internal has an IP address of 192.168.0.20.
Private has an IP address of 10.10.10.5.
You need to prevent the domain controller from registering Host (A) records for the 10.10.10.5 IP address.
What should you do?
A. Modify the netlogon.dns file on the domain controller.
B. Modify the Name Server settings of the DNS zone for the domain.
C. Modify the properties of the Private network connection on the domain controller.
D. Disable netmask ordering on the DNS server that hosts the DNS zone for the domain.
Answer: C
QUESTION 572
Your network contains an Active Directory domain named contoso.com.
The domain contains a file server named Server1 that runs Windows Server 2008 R2.
Server1 has a file share named Share1.
You plan to configure the audit policy settings of Server1 by using a Group Policy object (GPO).
You need to ensure that entries are generated in the Event Log when the users in a group named Group1 successfully access or fail to access the files in Share1.
The event entries must show the specific operation each user attempted.
The solution must minimize the number of audit entries in the Event Log.
Which Object Access audit policy should you configure?
A. Audit File Share
B. Audit Detailed File Share
C. Audit File System
D. Audit Other Object Access Events
Answer: C
QUESTION 573
Your network contains an Active Directory domain.
The domain contains two Active Directory sites named Site1 and Site2.
Site1 contains two domain controllers named DC1 and DC2.
Site2 contains two domain controller named DC3 and DC4,
The functional level of the domain is Windows Server 2008 R2.
The functional level of the forest is Windows Server 2003.
Active Directory replication between Site1 and Site2 occurs from 20:00 to 01:00 every day.
At 07:00, an administrator deletes a user account while he is logged on to DC1.
You need to restore the deleted user account.
You want to achieve this goal by using the minimum amount of administrative effort.
What should you do?
A. On DC3, stop Active Directory Domain Services, perform an authoritative restore, and then
start Active Directory Domain Services.
B. On DC3, run the Restore-ADObject cmdlet.
C. On DC1, run the Restore-ADObject cmdlet.
D. On DC1, stop Active Directory Domain Services, restore the SystemState, and then start
Active Directory Domain Services.
Answer: A
QUESTION 574
You create a standard primary zone for contoso.com.
You need to specify a user named Admin1 as the person responsible for managing the zone.
What should you do? (Each correct answer presents a complete solution. Choose two.)
A. Open the %Systemroot\System32\DNS\Contoso.com.dns file by using Notepad and
change all instances of “hostmaster.contoso.com” to “admin1.contoso.com”.
B. From DNS Manager, open the properties of the Start of Authority (SOA) record
ofcontoso.com, Specify admin1.contoso.com as the responsible person.
C. Open the %Systemroot\System32\DNS\Contoso.com.dns file by using Notepad and
change all instances of “[email protected]” to “[email protected]”.
D. From DNS Manager, open the properties of the Start of Authority (SOA) record
ofcontoso.com. Specify [email protected] as the responsible person.
Answer: BC
QUESTION 575
Your network contains two Active Directory forests named contoso.com and nwtraders.com.
The functional level of both forests is Windows Server 2003.
Contoso.com contains one domain.
Nwtraders.com contains two domains.
You need to ensure that users in contoso.com can access the resources in all domains.
The solution must require the minimum number of trusts.
Which type of trust should you create?
A. external
B. forest
C. realm
D. shortcut
Answer: B
QUESTION 576
You install an Active Directory domain in a test environment.
You need to reset the passwords of all the user accounts in the domain from a domain controller.
Which two Windows PowerShell commands should you run? (Each correct answer presents part of the solution, choose two.)
A. $ newPassword = *
B. Import-Module ActiveDirectory
C. Import-Module WebAdministration
D. Get- AdUser -filter * | Set- ADAccountPossword – NewPassword $
newPassword – Reset
E. Set- ADAccountPossword – NewPassword – Reset
F. $ newPassword = (Read-Host – Prompt “New Password” – AsSecureString )
G. Import-Module ServerManager
Answer: DF
QUESTION 577
Your network contains two forests named adatum.com and litwareinc.com.
The functional level of all the domains is Windows Server 2003.
The functional level of both forests is Windows 2000.
You need to create a forest trust between adatum.com and litwareinc.com.
What should you do first?
A. Create an external trust.
B. Raise the functional level of both forests.
C. Configure SID filtering.
D. Raise the functional level of all the domains.
Answer: B
QUESTION 578
Your network contains an Active Directory forest named contoso.com.
The forest contains a single domain.
The domain contains two domain controllers named DC1 and DC2 that run Windows Server 2008 R2.
DC1 is configured as a global catalog server.
You need to configure DC2 as the only global catalog server in the forest.
The solution must maintain DC1 in the domain.
What should you do?
A. Run the dsadd.exe command
B. Run the nltest.exe command.
C. Run the Set-AdDomain cmdlet.
D. Run the dsmove.exe command.
E. Run the dcpromo.exe command.
F. Run the Move-AdDirectoryServer cmdlet.
G. Use the Active Directory Schema snap-in.
H. Use the Active Directory Users and Computers console.
Answer: H
QUESTION 579
Hotspot Question
Your network contains two Active Directory forests named contoso.com and fabrikam.com.
The contoso.com forest contains a server named Server1l that has the Certification Authority role service installed.
You need to ensure that Windows 7 client computers in the fabrikam.com forest can enroll for certificates from Server1.
The solution must minimize the number of role services installed on Server1.
Which additional role service or role services should you install? To answer, select the appropriate role service or role services in the answer area.
Answer:
QUESTION 580
A corporate network includes a single Active Directory Domain Services (AD D5) domain.
The AD DS infrastructure is shown in the following graphic.
When the Montreal Site domain controller is offline, authentication requests for Montreal branch office users are sent to the Toronto Site domain controller.
You need to ensure that when the Montreal Site domain controller is offline, authentication requests for Montreal branch office users are sent to the Quebec City Site domain controller.
What should you do?
A. Create a site link bridge between the Montreal Site and the Quebec City Site.
B. Create a registry entry on each client computer in the Montreal branch office,
C. Enable the global catalog role on the Montreal Site domain controller
D. Delete the Toronto-Montreal Site Link.
Answer: A
Braindump2go is one of the Leading 70-640 Exam Preparation Material Providers Around the World! We Offer 100% Money Back Guarantee on All Products! Feel Free In Downloading Our New Released 70-640 Real Exam Questions!