100% Pass Microsoft 70-640 Exam Questions and Answers Instant Download in Braindump2go (321-330)

Are You Interested in Successfully Completing the Microsoft 70-640 Certification Then Start to Earning Salary? Braindump2go has Leading Edge Developed Microsoft Exam Questions that will Ensure You Pass this 70-640 Certification! Braindump2go Delivers you the Most Accurate, Current and Latest Updated 70-640 Certification Exam Questions Availabe with a 100% Money Back Guarantee Promise!

Vendor: Microsoft
Exam Code: 70-640
Exam Name: TS: Windows Server 2008 Active Directory, Configuring

Keywords: 70-640 Exam Dumps,70-640 Practice Tests,70-640 Practice Exams,70-640 Exam Questions,70-640 Dumps,70-640 Dumps PDF,Microsoft 70-640 Exam Dumps,70-640 Questions and Answers,TS: Windows Server 2008 Active Directory, Configuring

QUESTION 321
Your network contains an Active Directory forest.
The forest contains multiple domains.
You need to ensure that users in the human resources department can search for employees by using the employeeNumber attribute.
What should you do?

A.    From Active Directory Sites and Services, modify the properties of each global catalog server.
B.    From the Active Directory Schema snap-in, modify the properties of the user object class.
C.    From Active Directory Sites and Services, modify the NTDS Settings objectof each global
catalog server.
D.    From the Active Directory Schema snap-in, modify the properties of the employeeNumber
attribute.

Answer: D
Explanation:
http://technet.microsoft.com/en-us/library/how-global-catalog-servers-work.aspx

QUESTION 322
Your network contains a single Active Directory domain.
The domain contains an enterprise certification authority (CA).
You need to ensure that the encryption keys for e-mail certificates can be recovered from the CA database.
You modify the e-mail certificate template to support key archival.
What should you do next?

A.    Issue the key recovery agent certificate template.
B.    Run certutil.exe -recoverkey.
C.    Run certreq.exe-policy.
D.    Modify the location of the Authority Information Access (AIA) distribution point.

Answer: A
Explanation:
http://technet.microsoft.com/en-us/library/cc770588.aspx

QUESTION 323
Your network contains an Active Directory-integrated DNS zone named contoso.com.
You discover that the zone includes DNS records for computers that were removed from the network.
You need to ensure that the DNS records are deleted automatically from the zone.
What should you do?

A.    From DNS Manager, set the aging properties.
B.    Create a scheduled task that runs dnslint.exe /v /d contoso.com.
C.    From DNS Manager, modify the refresh interval of the start of authority (SOA) record.
D.    Create a scheduled task that runs ipconfig.exe /flushdns.

Answer: A
Explanation:
http://technet.microsoft.com/en-us/library/cc753217.aspx

QUESTION 324
Your network contains a domain controller that runs Windows Server 2008 R2.
You run the following command on the domain controller:
dsamain.exe C dbpath c:\$SNAP_201006170326_VOLUMEC$\Windows\NTDS\ntds.dit C ldapport 389 – allowNonAdminAccess
The command fails.
You need to ensure that the command completes successfully.
How should you modify the command?

A.    Change the value of the -dbpath parameter.
B.    Include the path to Dsamain.
C.    Change the value of the -ldapport parameter.
D.    Remove the CallowNonAdminAccess parameter.

Answer: C

QUESTION 325
Your network contains an Active Directory domain.
The domain contains 10 domain controllers that run Windows Server 2008 R2.
You need to monitor the following information on the domain controllers during the next five days:
– Memory usage
– Processor usage
– The number of LDAP queries
What should you do?

A.    Create a User Defined Data Collector Set (DCS) that uses the Active Directory Diagnostics
template.
B.    Use the System Performance Data Collector Set (DCS).
C.    Create a User Defined Data Collector Set (DCS) that uses the System Performance template.
D.    Use the Active Directory Diagnostics Data Collector Set (DCS).

Answer: A

QUESTION 326
Your network contains an Active Directory domain named contoso.com.
Contoso.com contains a domain controller named DC1 and a read-only domain controller (RODC) named RODC1.
You need to view the most recent user accounts authenticated by RODC1.
What should you do first?

A.    From Active Directory Sites and Services, right-click the Connection object for DC1, and then
click Replicate Now.
B.    From Active Directory Sites and Services, right-click the Connection object for DC2, and then
click Replicate Now.
C.    From Active Directory Users and Computers, right-click contoso.com, click Change
DomainController, and then connect to DC1.
D.    From Active Directory Users and Computers, right-click contoso.com, click Change
Domain Controller, and then connect to RODC1.

Answer: C

QUESTION 327
Your network contains an Active Directory domain.
The domain contains 3,000 client computers.
All of the client computers run Windows 7.
Users log on to their client computers by using standard user accounts.
You plan to deploy a new application named App1.
The vendor of App1 provides a Setup.exe file to install App1.
Setup.exe requires administrative rights to run.
You need to deploy App1 to all client computers.
The solution must meet the following requirements:
– App1 must automatically detect and replace corrupt application files.
– App1 must be available from the Start menu on each client computer.
What should you do first?

A.    Create a logon script that calls Setup.exe for App1.
B.    Create a .zap file.
C.    Create a startup script that calls Setup.exe for App1.
D.    Repackage App1 as a Windows Installer package.

Answer: D
Explanation:
http://technet.microsoft.com/en-us/library/cc739578.aspx
Windows Installer features Diagnoses and repairs corrupted applications–An application can query Windows Installer to determine whether an installed application has missing or corrupted files. If any are detected, Windows Installer repairs the application by recopying only those files found to be missing or corrupted.

QUESTION 328
Your network contains an Active Directory domain named contoso.com.
Contoso.com contains two sites named Site1 and Site2.
Site1 contains a domain controller named DC1.
In Site1, you install a new domain controller named DC2.
You ship DC2 to Site2.
You discover that certain users in Site2 authenticate to DC1.
You need to ensure that the users in Site2 always attempt to authenticate to DC2 first.
What should you do?

A.    From Active Directory Users and Computers, modify the Location settings of the DC2
computer object.
B.    From Active Directory Sites and Services, modify the Location attribute for Site2.
C.    From Active Directory Sites and Services, move the DC2 server object.
D.    From Active Directory Users and Computers, move the DC2 computer object.

Answer: C
Explanation:
DC2 may be shipped to Site2, but it’s not yet associated properly with Site2 in Active Directory.
http://technet.microsoft.com/en-us/library/cc816674.aspx
http://technet.microsoft.com/en-us/library/cc754697.aspx
Using sites

QUESTION 329
Your network contains an Active Directory domain.
The domain contains an enterprise certification authority (CA).
You need to ensure that only members of a group named Admin1 can create certificate templates.
Which tool should you use to assign permissions to Admin1?

A.    the Certification Authority console
B.    Active Directory Users and Computers
C.    the Certificates snap-in
D.    Active Directory Sites and Services

Answer: D

QUESTION 330
Your network contains an Active Directory domain named contoso.com.
Contoso.com contains a server named Server2.
You open the System properties on Server2 as shown in the exhibit. (Click the Exhibit button.)
When you attempt to configure Server2 as an enterprise subordinate certification authority (CA), you discover that the enterprise subordinate CA option is unavailable.
You need to configure Server2 as an enterprise subordinate CA.
What should you do first?
 

A.    Upgrade Server2 to Windows Server 2008 R2 Enterprise.
B.    Log in as an administrator and run Server Manager.
C.    Import the root CA certificate.
D.    Join Server2 to the domain.

Answer: D
Explanation:
http://social.technet.microsoft.com/Forums/nl-BE/winserversecurity/thread/1a1172c6-abdb-4c5a-8a7cea254de5dada


Braindump2go Regular Updates of Microsoft 70-640 Preparation Materials Exam Dumps, with Accurate Answers, Keeps the Members One Step Ahead in the Real 70-640 Exam. Field Experts with more than 10 Years Experience in Certification Field work with us.

 

http://www.braindump2go.com/70-640.html

         

Comments are closed.