[Pass Ensure VCE Dumps] Free 70-640 651q Exam Dumps With New Update Exam Questions And Answers (301-320)

How to pass the newest 70-640 exam? What new questions are on the latest 70-640 exam? PassLeader’s best 70-640 VCE and PDF exam dumps/70-640 sample questions will tell you all about the 70-640 exam. For all PassLeader’s 651q 70-640 exam questions are the newest and covered all new added questions and answers, which will help you 100% passing exam. And we PassLeader will continue update 70-640 exam questions and answers, you will never fail the 70-640 exam. Hurry up and get the free VCE Player with your premium 70-640 VCE dumps from passleader.com now!

keywords: 70-640 exam,651q 70-640 exam dumps,651q 70-640 exam questions,70-640 pdf dumps,70-640 practice test,70-640 vce dumps,70-640 study guide,70-640 braindumps,TS: Windows Server 2008 Active Directory, Configuring Exam

QUESTION 301
Your network contains two Active Directory forests named contoso.com and nwtraders.com. Active Directory Rights Management Services (AD RMS) is deployed in each forest. You need to ensure that users from the nwtraders.com forest can access AD RMS protected content in the contoso.com forest. What should you do?

A.    Add a trusted user domain to the AD RMS cluster in the nwtraders.com domain.
B.    Add a trusted user domain to the AD RMS cluster in the contoso.com domain.
C.    Create an external trust from nwtraders.com to contoso.com.
D.    Create an external trust from contoso.com to nwtraders.corn.

Answer: B

QUESTION 302
Your company plans to open a new branch of?ce. The new of?ce will have a Iow-speed connection to the Internet. You plan to deploy a read-only domain controller (RODC) in the branch of?ce. You need to create an offline copy of the Active Directory database that can be used to install Active Directory on the new RODC. Which commands should you run from Ntdsutil? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Answer:

QUESTION 303
Your network contains an Active Directory forest. All users have a value set for the Department attribute. From Active Directory Users and computers, you search a domain for all users who have a Department attribute value of Marketing. The search returns 50 users. From Active Directory Users and Computers, you search the entire directory for all users who have a Department attribute value of Marketing. The search does not return any users. You need to ensure that a search of the entire directory for users in the marketing department returns all of the users who have the Marketing Department attribute. What should you do?

A.    Install the Windows Search Service role service on a global catalog server.
B.    From the Active Directory Schema snap-in, modify the properties of the Department attribute.
C.    Install the Indexing Service role service on a global catalog server.
D.    From the Active Directory Schema snap-in, modify the properties of the user class.

Answer: B

QUESTION 304
A corporate network includes a single Active Directory Domain Services (AD DS) domain. The AD DS infrastructure is shown in the following graphic.

When the Montreal site domain controller is offline, authentication requests for Montreal branch office users are sent to the Toronto site domain controller. You need to ensure that when the Montreal Site domain controller is offline, authentication requests for Montreal branch of?ce users are sent to the Quebec City site domain controller. What should you do?

A.    Create a site link bndge between the Montreal site and the Quebec City site.
B.    Enable the global catalog role on the Montreal site domain controller.
C.    Modify the Default Domain Policy Group Policy Object.
D.    Delete the Toronto-Montreal Site Link

Answer: C

QUESTION 305
A corporate environment includes two Active Directory Domain Services (AD DS) forests, as shown in the following table.

You need to ensure that users in the contoso.com domain can access resources in the eng.fabrikam.com domain. What should you do?

A.    Enable selective authentication.
B.    Enable forest-wide authentication.
C.    Create an external trust between contoso.com and eng.fabrikam.com.
D.    Enable domain-wide authentication.

Answer: C

QUESTION 306
Your network contains an Active Directory domain. You need to activate the Active Directory Recycle Bin in the domain. Which tool should you use?

A.    Dsamain
B.    Set-ADDomain
C.    Add-WindowsFeature
D.    Ldp

Answer: D

QUESTION 307
Your network contains an Active Directory domain named contoso.com. You need to create a script that runs the Best Practices Analyzer (BPA) each week for all of the server roles that BPA supports on each domain controller. You must achieve this goal by using the minimum amount of administrative effort. Which tools should you use? (Each correct answer presents part of the solution. Choose three.)

A.    Get-Troubleshooting Pack / Invoke-Troubleshooting Pack.
B.    Import-Module Best Practices.
C.    Get-BPA Model / Invoke-BPA Model.
D.    Import-Module Troubleshooting Pack.
E.    Get- BPA Result.

Answer: BCE

QUESTION 308
A corporate network includes a single Active Directory Domain Services (AD DS) domain. All regular user accounts reside in an organizational unit (OU) named Employees. All administrator accounts reside in an OU named Admins. You need to ensure that any time an administrator modifies an employee’s name in AD DS, the change is audited. What should you do first?

A.    Enable the Audit directory service access setting in the Default Domain Controllers Policy Group Policy Object.
B.    Create a Group Policy Object with the Audit directory service access setting enabled and link it to the Employees OU.
C.    Enable the Audit directory service access setting in the Default Domain Policy Group Policy Object.
D.    Modify the searchFlags property for the User class in the schema.

Answer: C

QUESTION 309
Your network contains an Active Directory domain. You need to back up all of the Group Policy objects (GPOs), Group Policy permissions, and Group Policy links for the domain. What should you do?

A.    From Group Policy Management Console (GPMC), back up the GPOs.
B.    From Windows Explorer, copy the content of the %systemroot%\SYSVOL folder.
C.    From Windows Server Backup, perform a system state backup.
D.    From Windows PowerShell, run the Backup-GPO cmdlet.

Answer: A

QUESTION 310
Your network contains a domain controller that runs Windows Server 2008 R2. You need to reset the Directory Services Restore Mode (DSRM) password on the domain controller. Which tool should you use?

A.    Ntdsutil
B.    Dsamain
C.    Active Directory Users and Computers
D.    Local Users and Groups

Answer: A


http://www.passleader.com/70-640.html

QUESTION 311
Your network contains an Active Directory forest. All client computers run Windows 7. The network contains a high-volume enterprise certification authority (CA). You need to minimize the amount of network bandwidth required to validate a certificate. What should you do?

A.    Configure an LDAP publishing point for the certificate revocation list (CRL).
B.    Configure an Online Certification Status Protocol (OCSP) responder.
C.    Modify the settings of the delta certificate revocation list (CRL).
D.    Replicate the certificate revocation list (CRL) by using Distributed File System (DFS).

Answer: B

QUESTION 312
Your network contains an Active Directory domain. You have five organizational units (OUs) named Finance, HR, Marketing, Sales, and Dev. You link a Group Policy object named GPO1 to the domain as shown in the exhibit. (Click the Exhibit button.)

You need to ensure that GPO1 is applied to users in the Finance, HR, Marketing, and Sales OUs. The solution must prevent GPO1 from being applied to users in the Dev OU. What should you do?

A.    Enforce GPO1.
B.    Modify the security settings of the Dev OU.
C.    Link GPO1 to the Finance OU.
D.    Modify the security settings of the Finance OU.

Answer: C

QUESTION 313
Your network contains an Active Directory domain. The domain contains an organizational unit (OU) named OU1. OU1 contains all managed service accounts in the domain. You need to prevent the managed service accounts from being deleted accidentally from OU1. Which cmdlet should you use?

A.    Set-ADUser
B.    Set-ADOrganizationalUnit
C.    Set-ADServiceAccount
D.    Set-ADObject

Answer: D

QUESTION 314
Your network contains an Active Directory domain named contoso.com. Contoso.com contains a writable domain controller named DC1 and a read-only domain controller (RODC) named DC2. All domain controllers run Windows Server 2008 R2. You need to install a new writable domain controller named DC3 in a remote site. The solution must minimize the amount of replication traffic that occurs during the installation of Active Directory Domain Services (AD DS) on DC3. What should you do first?

A.    Run dcpromo.exe /createdcaccount on DC3.
B.    Run ntdsutil.exe on DC2.
C.    Run dcpromo.exe /adv on DC3.
D.    Run ntdsutil.exe on DC1.

Answer: C

QUESTION 315
Your network contains an Active Directory forest. The forest contains 10 domains. All domain controllers are configured as global catalog servers. You remove the global catalog role from a domain controller named DC5. You need to reclaim the hard disk space used by the global catalog on DC5. What should you do?

A.    From Active Directory Sites and Services, run the Knowledge Consistency Checker (KCC).
B.    From Active Directory Sites and Services, modify the general properties of DC5.
C.    From Ntdsutil, use the Semantic database analysis option.
D.    From Ntdsutil, use the Files option.

Answer: D

QUESTION 316
A corporate network includes an Active Directory-integrated zone. All DNS servers that host the zone are domain controllers. You add multiple DNS records to the zone. You need to ensure that the new records are available on all DNS servers as soon as possible. Which tool should you use?

A.    Ldp
B.    Repadmin
C.    Ntdsutil
D.    Nslookup
E.    Active Directory Sites And Services console
F.    Active Directory Domains And Trusts console
G.    Dnslint
H.    Dnscmd

Answer: B

QUESTION 317
You have a DNS zone that is stored in a custom application partition. You need to add a domain controller to the replication scope of the custom application partition. Which tool should you use?

A.    DNScmd
B.    DNS Manager
C.    Server Manager
D.    Dsmod

Answer: A

QUESTION 318
Your network contains a server named Server1 that runs Windows Server 2008 R2 Standard. Server1 has the Active Directory Certificate Services (AD CS) role installed. You configure a certificate template named Template1 for autoenrollment. You discover that certificates are not being issued to any client computers. The event logs on the client computers do not contain any autoenrollment errors. You need to ensure that all of the client computers automatically receive certificates based on Template1. What should you do?

A.    Modify the Default Domain Policy Group Policy object (GPO).
B.    Modify the Default Domain Controllers Policy Group Policy object (GPO).
C.    Upgrade Server1 to Windows Server 2008 R2 Enterprise.
D.    Restart Certificate Services on Server1.

Answer: A

QUESTION 319
Your network contains a server that has the Active Directory Lightweight Directory Services (AD LDS) role installed. You need to perform an automated installation of an AD LDS instance. Which tool should you use?

A.    Dism.exe
B.    Servermanagercmd.exe
C.    Adaminstall.exe
D.    Ocsetup.exe

Answer: C

QUESTION 320
Your network contains an Active Directory domain named contoso.com. A partner company has an Active Directory domain named nwtraders.com. The networks for contoso.com and nwtraders.com connect to each other by using a WAN link. You need to ensure that users in contoso.com can access resources in nwtraders.com and resources on the Internet. What should you do first?

A.    Modify the Trusted Root Certification Authorities store.
B.    Modify the Intermediate Certification Authorities store.
C.    Create conditional forwarders.
D.    Add a root hint to the DNS server.

Answer: C


http://www.passleader.com/70-640.html