We provide which are the best for clearing 70-640 test, and to get certified by Microsoft TS: Windows Server 2008 Active Directory. Configuring. The covers all the knowledge points of the real 70-640 exam. Crack your Microsoft 70-640 Exam with latest dumps, guaranteed!

Free demo questions for Microsoft 70-640 Exam Dumps Below:

NEW QUESTION 1
Your network contains a single Active Directory domain. The domain contains an enterprise certification authority (CA).
You need to ensure that the encryption keys for e-mail certificates can be recovered from the CA database.
You modify the e-mail certificate template to support key archival.
What should you do next?

  • A. Issue the key recovery agent certificate templat
  • B. Run certutil.exe -recoverke
  • C. Run certreq.exe-polic
  • D. Modify the location of the Authority Information Access (AIA) distribution poin

Answer: A

Explanation:
http://technet.microsoft.com/en-us/library/cc770588.aspx
Identify a Key Recovery Agent
A key recovery agent is a person who is authorized to recover a certificate on behalf of an end user. Because the role of key recovery agents can involve sensitive data, only highly trusted individuals should be assigned to this role.
To identify a key recovery agent, you must configure the Key Recovery Agent certificate template to allow the person assigned to this role to enroll for a key recovery agent certificate.

NEW QUESTION 2
Your network contains an Active Directory domain. The domain contains two file servers. The file servers are configured as shown in the following table.
70-640 dumps exhibit
You create a Group Policy object (GPO) named GPO1 and you link GPO1 to OU1.
You configure the advanced audit policy.
You discover that the settings are not applied to Server1. The settings are applied to Server2.
You need to ensure that access to the file shares on Server1 is audited.
What should you do?

  • A. From Active Directory Users and Computers, modify the permissions of the computer account for Server1.
  • B. From GPO1, configure the Security Option
  • C. From Active Directory Users and Computers, add Server1 to the Event Log Readers grou
  • D. On Server1, run seceditexe and specify the /configure paramete
  • E. On Server1, run auditpol.exe and specify the /set paramete

Answer: E

Explanation:
http://technet.microsoft.com/en-us/library/cc755264.aspx
Auditpol set
Sets the per-user audit policy, system audit policy, or auditing options.

NEW QUESTION 3
You have an enterprise subordinate certification authority (CA).
You have a custom certificate template that has a key length of 1,024 bits. The template is enabled for autoenrollment.
You increase the template key length to 2,048 bits.
You need to ensure that all current certificate holders automatically enroll for a certificate that uses the new template.
Which console should you use?

  • A. Active Directory Administrative Center
  • B. Certification Authority
  • C. Certificate Templates
  • D. Group Policy Management

Answer: C

Explanation:
http://technet.microsoft.com/en-us/library/cc771246.aspx
Re-Enroll All Certificate Holders
This procedure is used when a critical change is made to the certificate template and you want all subjects that hold a certificate that is based on this template to re-enroll as quickly as possible. The next time the subject verifies the version of the certificate against the version of the template on the certification authority (CA), the subject will re-enroll.
Membership in Domain Admins or Enterprise Admins, or equivalent, is the minimum required to complete this procedure. For more information, see Implement Role-Based Administration.
To re-enroll all certificate holders
1. Open the Certificate Templates snap-in.
2. Right-click the template that you want to use, and then click Reenroll All Certificate Holders.

NEW QUESTION 4
Your network contains an Active Directory domain named contoso.com.
The domain has a branch site that contains a read-only domain controller (RODC) named RODC1.
A user named User1 is a member of the Allowed RODC Password Replication Group. User1 frequently logs on to a computer in the branchsite.
You remove User1 from the Allowed RODC Password Replication Group.
You need to ensure that the password of User1 is no longer cached on RODC1.
What should you do?

  • A. Add User1 to the Denied RODC Password Replication Group, and then force Active Directory replicatio
  • B. Run repadmin /rodcpwdrepl rodc2.contoso.com dc.contoso.com cn=User1,cn-users,dc=contoso,dc-co
  • C. Run repadmin /prp delete rodcl.contoso.com allow cn=User1, cn=users, dc=contoso,dc=co
  • D. Reset the password of User1, and then force Active Directory replicatio

Answer: D

NEW QUESTION 5
Your network consists of a single Active Directory domain. User accounts for engineering department are located in an OU named Engineering.
You need to create a password policy for the engineering department that is different from your domain password policy.
What should you do?

  • A. Create a new GP
  • B. Link the GPO to the Engineering O
  • C. Create a new GP
  • D. Link the GPO to the domai
  • E. Block policy inheritance on all OUs except for the Engineering O
  • F. Create a global security group and add all the user accounts for the engineering department to the grou
  • G. Create a new Password Policy Object (PSO) and apply it to the grou
  • H. Create a domain local security group and add all the user accounts for the engineering department to the grou
  • I. From the Active Directory Users and Computer console, select the group and run the Delegation of Control Wizar

Answer: C

Explanation:
http://technet.microsoft.com/en-us/library/cc736813(WS.10).aspx
TechNet: Linking GPOs
If you need to modify some of the settings contained in the Default Domain Policy GPO, it is recommended that you create a new GPO for this purpose, link it to the domain, and set the Enforce option.
http://technet.microsoft.com/en-us/library/cc779159(WS.10).aspx
TechNet: Establishing Group Policy Operational Guidelines
Do not modify the default domain policy or default domain controller policy unless necessary. Instead, create a new GPO at the domain level and set it to override the default settings in the default policies.
Step 2
Edit the “Domain Password Policy” GPO and go to Computer Configurations>Policies>Windows
Settings>Security Settings>Account Policy>Password Policy and configured the password policies settings to the configuration you desire.
C:Documents and Settingsusernwz1Desktop1.PNG
Step 3
Once you have configured the password policy settings make the “Domain Password Policy” GPO the highest in the Linked GPO processing order.
TIP: Make sure you inform all your users when you are going to do this as it may trigger them to change their password the next time they logon.
C:Documents and Settingsusernwz1Desktop1.PNG
Done… told you it was easy….
Note: Even if you apply the password policies to the “Domain Controllers” OU it will not modify the domain’s password policy. As far as I know this is the only exception to the rule as to how GPO’s apply to objects. As you can see in the image below the “Minimum password length” in the “Domain Password Policy” GPO is still applied to the domain controller even though I have another GPO linking to the “Domain Controllers” OU configuration the same setting.
C:Documents and Settingsusernwz1Desktop1.PNG
For a better explanation as to why the GPO that is linked to the Domain and not the Domain Controllers is used for the password policy for all users check out Jorge’s Quest for Knowledge! – Why GPOs with Password and Account Lockout Policy Settings must be linked to the AD domain object to be affective on AD domain user accounts (http://blogs.dirteam.com/blogs/jorge/archive/2008/12/16/why-gpos-with-password-and-accountlockout- policy-settings-must-be-linked-to-the-ad-domain-object-to-be-affective-on-ad-domain-useraccounts.aspx)
How to set a Fine Grain Password Policy
Fine Grain Password Policies (FGPP) were introduced as a new feature of Windows Server 2008. Before this the only way to have different password polices for the users in your environment was to have separate domains… OUCH!
Pre-Requisites/Restrictions
You domain must be Windows Server 2008 Native Mode, this means ALL of your domain controllers must be running Windows Server 2008 or later. You can check this by selection the “Raise domain functional level” on the top of the domain in Active Directory Users and Computers.
C:Documents and Settingsusernwz1Desktop1.PNG
Explanation http://technet.microsoft.com/en-us/library/cc770394(WS.10).aspx AD DS: Fine-Grained Password Policies The domain functional level must be Windows Server 2008. The other restriction with this option is that you can only apply FGPP to users object or
users in global security groups (not computers). Explanation http://technet.microsoft.com/en-us/library/cc770394(WS.10).aspx AD DS: Fine-Grained Password Policies Fine-grained password policies apply only to user objects … and global security groups. TIP: If you setup an “Automatic Shadow Group
(http://policelli.com/blog/archive/2008/01/15/manage-shadowgroups-in-windows-server-2008/)” you can apply these password policies to users automatically to
any users located in an OU.
Creating a Password Setting Object (PSO)
Step 1 Under Administrator Tools Open ADSI Edit and connect it to a domain and domain controller you want to setup the new password policy.
C:Documents and Settingsusernwz1Desktop1.PNG
Note: If you do not see this option go to “Turn Windows Features On or Off” and make sure the “AD DS and AD LDS Tools” are installed. (You will need RSAT also installed if you are on Windows 7).
Step 2 Double click on the “CN=DomainName” then double click on “CN=System” and then double click on “CN=Password Settings Container”.
C:Documents and Settingsusernwz1Desktop1.PNG
Step 3
Right click on “CN=Password Settings Container” and then click on “New” then “Object.
C:Documents and Settingsusernwz1Desktop1.PNG
Step 4
Click on “Next”
C:Documents and Settingsusernwz1Desktop1.PNG
Step 5
Type the name of the PSO in the “Value” field and then click “Next”
C:Documents and Settingsusernwz1Desktop1.PNG
Note: With the exception of the password length the following values are all the same as the default values in the “Default Domain Policy”.
Step 6
Type in a number that will be the Precedence for this Password Policy then click “Next”.
Note: This is used if a users has multiple Password Settings Object (PSO) applied to them.
C:Documents and Settingsusernwz1Desktop1.PNG
Step 7
Type “FALSE” in the value field and click “Next”
Note: You should almost never use “TRUE” for this setting.
C:Documents and Settingsusernwz1Desktop1.PNG
Step 8
Type “24” in the “Value” field and click “Next”
C:Documents and Settingsusernwz1Desktop1.PNG
Step 9
Type “TRUE” in the “Value” field and click “Next”
C:Documents and Settingsusernwz1Desktop1.PNG
Step 10
Type “5” in the “Value” field and click “Next”
C:Documents and Settingsusernwz1Desktop1.PNG
Step 11
Type “1:00:00:00” in the “Value” field and click “Next”
C:Documents and Settingsusernwz1Desktop1.PNG
Step 12
Type “42:00:00:00” in the “Value” field and click “Next” C:Documents and Settingsusernwz1Desktop1.PNG Step 13
Type “10” in the “Value” field and click “Next” C:Documents and Settingsusernwz1Desktop1.PNG Step 14
Type “0:00:30:00” field and click “Next” C:Documents and Settingsusernwz1Desktop1.PNG Step 15
Type “0:00:33:00” in the “Value” field and click “Next” C:Documents and Settingsusernwz1Desktop1.PNG Step 16
Click “Finish”
C:Documents and Settingsusernwz1Desktop1.PNG
You have now created the Password Settings Object (PSO) and you can close the
ADSIEdit tool.
Now to apply the PSO to a users or group…
Step 17
Open Active Directory Users and Computers and navigate to “System > Password Settings
Container”
Note: Advanced Mode needs to be enabled.
C:Documents and Settingsusernwz1Desktop1.PNG
Step 18
Double click on the PSO you created then click on the “Attribute Editor” tab and then select the “msDS-PSOAppliedTo” attribute and click “Edit”
C:Documents and Settingsusernwz1Desktop1.PNG
Step 19
Click “Add Windows Accounts….” button.
C:Documents and Settingsusernwz1Desktop1.PNG
Step 20
Select the user or group you want to apply this PSO and click “OK”
C:Documents and Settingsusernwz1Desktop1.PNG
Step 21
Click “OK”
C:Documents and Settingsusernwz1Desktop1.PNG
Step 22
Click “OK”
C:Documents and Settingsusernwz1Desktop1.PNG
And your are done… (told you it was hard).
Fine Grain Password Policies as you can see are very difficult to setup and manage so it is probably best you use them sparingly in your organisation… But if you really have to have a simple password or extra complicated password then at least it give you away to do this without having to spin up another domain.

NEW QUESTION 6
You have an Active Directory domain named contoso.com.
You have a domain controller named Server1 that is configured as a DNS server.
Server1 hosts a standard primary zone for contoso.com. The Zone Aging/Scavenging
Properties of the contoso.com zone are shown in the exhibit. (Click the Exhibit button.)
70-640 dumps exhibit
You discover that stale resource records are not automatically removed from the contoso.com zone.
You need to ensure that the stale resource records are automatically removed from the contoso.com zone.
What should you do?

  • A. Convert the contoso.com zone to an Active Directory-integrated zon
  • B. set the scavenging period of Server1 to 0 day
  • C. Configure the aging properties for the contoso.com zon
  • D. Modify the Server Aging/Scavenging propertie

Answer: D

NEW QUESTION 7
You need to validate whether Active Directory successfully replicated between two domain controllers.What should you do?

  • A. Run the DSget comman
  • B. Run the Dsquery comman
  • C. Run the RepAdmin comman
  • D. Run the Windows System Resource Manage

Answer: C

Explanation:
http://technet.microsoft.com/en-us/library/cc794749.aspx You can use the repadmin /showrepl command to verify successful replication to a specific domain controller.

NEW QUESTION 8
Your network contains a single Active Directory domain. All servers run Windows Server 2008 R2.
You deploy a new server that runs Windows Server 2008 R2. The server is not connected to the internal network.
You need to ensure that the new server is already joined to the domain when it first connects to the internal network.
What should you do?

  • A. From a domain controller, run sysprep.exe and specify the /oobe paramete
  • B. From the new server, run sysprep.exe and specify the /generalize paramete
  • C. From a domain controller, run sysprep.exe and specify the /generalize paramete
  • D. From the new server, run sysprep.exe and specify the /oobe paramete
  • E. From a domain-joined computer, run djoin.exe and specify the /provision paramete
  • F. From the new server, run djoin.exe and specify the /requestodj paramete
  • G. From a domain-joined computer, run djoin.exe and specify the /requestodj paramete
  • H. From the new server, run djoin.exe and specify the /provision paramete

Answer: C

Explanation:
Explanation 1: MS Press - Self-Paced Training Kit (Exam 70-640) (2nd Edition, July 2012) pages 217, 218 Offline Domain Join Offline domain join is also useful when a computer is deployed in a lab or other disconnected environment. When the computer is connected to the domain network and started for the first time, it will already be a member of the domain. This also helps to ensure that Group Policy settings are applied at the first startup. Four major steps are required to join a computer to the domain by using offline domain join:
1. Log on to a computer in the domain that is running Windows Server 2008 R2 or Windows 7 with an account that has permissions to join computers to the domain.
2. Use the DJoin command to provision a computer for offline domain join. This step prepopulates Active
Directory with the information that Active Directory needs to join the computer to the domain, and exports the information called a blob to a text file.
3. At the offline computer that you want to join the domain use DJoin to import the blob into
the Windows directory.
4. When you start or restart the computer, it will be a member of the domain.
Explanation 2:
http://technet.microsoft.com/nl-nl/library/offline-domain-join-djoin-step-by-step.aspx
Steps for performing an offline domain join
The offline domain join process includes the following steps:
1. Run the djoin.exe /provision command to create computer account metadata for the
destination computer (the computer that you want to join to the domain). As part of this
command, you must specify the name of the domain that you want the computer to join.
2. Run the djoin.exe /requestODJ command to insert the computer account metadata into
the Windows directory of the destination computer.
3. When you start the destination computer, either as a virtual machine or after a complete
operating system installation, the computer will be joined to the domain that you specify.

NEW QUESTION 9
Your network contains an Active Directory domain named contoso.com. The domain contains two domain controllers named Serverl and Server2.
DNS Manager on Server2 is shown in the exhibit. (Click the Exhibit button.)
70-640 dumps exhibit
To answer, complete each statement according to the information presented in the exhibit. Each correct selection is worth one point.
70-640 dumps exhibit

    Answer:

    Explanation: 70-640 dumps exhibit

    NEW QUESTION 10
    The default domain GPO in your company is configured by using the following account policy settings:
    Minimum password length: 8 characters
    Maximum password age: 30 days
    Enforce password history: 12 passwords remembered
    Account lockout threshold: 3 invalid logon attempts
    Account lockout duration: 30 minutes
    You install Microsoft SQL Server on a computer named Server1 that runs Windows Server 2008 R2. The SQL Server application uses a service account named SQLSrv. The SQLSrv account has domain user rights.
    The SQL Server computer fails after running successfully for several weeks. The SQLSrv user account is not locked out.
    You need to resolve the server failure and prevent recurrence of the failure. Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)

    • A. Reset the password of the SQLSrv user accoun
    • B. Configure the local security policy on Server1 to grant the Logon as a service right on the SQLSrv user accoun
    • C. Configure the properties of the SQLSrv account to Password never expire
    • D. Configure the properties of the SQLSrv account to User cannot change passwor
    • E. Configure the local security policy on Server1 to explicitly grant the SQLSrv user account the Allow logon locally user righ

    Answer: AC

    Explanation:
    Personal comment:
    Maximum password age: 30 days
    The most probable cause for the malfunction is that the password has expired.
    You need to reset the password and set it to never expire.
    70-640 dumps exhibit
    C:Documents and Settingsusernwz1Desktop1.PNG

    NEW QUESTION 11
    Your network contains an Active Directory forest named contoso.com.
    You need to identify whether a fine-grained password policy is applied to a specific group.
    Which tool should you use?

    • A. Active Directory Users and Computers
    • B. Security Configuration Wizard (SCW)
    • C. Group Policy Management Editor
    • D. Active Directory Sites and Services

    Answer: A

    NEW QUESTION 12
    Your network contains an Active Directory domain. All servers run Windows Server 2008 R2.
    You need to audit the deletion of registry keys on each server.
    What should you do?

    • A. From Audit Policy, modify the Object Access settings and the Process Tracking setting
    • B. From Audit Policy, modify the System Events settings and the Privilege Use setting
    • C. From Advanced Audit Policy Configuration, modify the System settings and the Detailed Tracking setting
    • D. From Advanced Audit Policy Configuration, modify the Object Access settings and the Global Object Access Auditing setting

    Answer: D

    Explanation:
    http://technet.microsoft.com/en-us/library/dd408940.aspx
    Advanced Security Audit Policy Step-by-Step Guide
    A global object access audit policy can be used to enforce object access audit policy for a computer, file share, or registry.

    NEW QUESTION 13
    HOTSPOT
    Your network contains an Active Directory domain.
    You need to create a new site link between two sites named Site1 and Site3. The site link must support the replication of domain objects.
    Under which node in Active Directory Sites and Services should you create the site link? To answer, select the appropriate node in the answer area.
    70-640 dumps exhibit

      Answer:

      Explanation: 70-640 dumps exhibit

      NEW QUESTION 14
      Your network contains an Active Directory domain named contoso.com. The contoso.com domain contains a domain controller named DC1.
      You create an Active Directory-integrated GlobalNames zone. You add an alias (CNAME) resource record named Server1 to the zone. The target host of the record is server2.contoso.com.
      When you ping Server1, you discover that the name fails to resolve. You are able to successfully ping server2.contoso.com.
      You need to ensure that you can resolve names by using the GlobalNames zone.
      Which command should you run?

      • A. Dnscmd DCl.contoso.com /ZoneAdd GlobalNames /DsPrimary /DP /domain
      • B. Dnscmd DCl.contoso.com /config /Enableglobalnamessupport forest
      • C. Dnscmd DCl.contoso.com /config /Enableglobalnamessupport 1
      • D. Dnscmd DCl.contoso.com /ZoneAdd GlobalNames /DsPrimary /DP /forest

      Answer: C

      Explanation:
      http://technet.microsoft.com/en-us/library/cc772069.aspx
      dnscmd /config Changes values in the registry for the DNS server and individual zones.
      Accepts server-level settings and zone-level settings.
      Parameter
      /enableglobalnamessupport {0|1}
      Enables or disables support for the GlobalNames zone. The GlobalNames zone supports
      resolution of singlelabel
      DNS names across a forest.
      0
      Disables support for the GlobalNames zone. When you set the value of this command to 0,
      the DNS Server service does not resolve single-label names in the GlobalNames zone.
      1
      Enables support for the GlobalNames zone. When you set the value of this command to 1,
      the DNS Server service resolves single-label names in the GlobalNames zone.

      NEW QUESTION 15
      Your company has a DNS server that has 10 Active Directory integrated zones.
      You need to provide copies of the zone files of the DNS server to the security department.
      What should you do?

      • A. Run the dnscmd /ZoneInfo comman
      • B. Run the ipconfig /registerdns comman
      • C. Run the dnscmd /ZoneExport comman
      • D. Run the ntdsutil > Partition Management > List command

      Answer: C

      Explanation:
      http://servergeeks.wordpress.com/2012/12/31/dns-zone-export/ DNS Zone Export In Non-AD Integrated DNS Zones DNS zone file information is stored by default in the %systemroot%windowssystem32dns folder. When the DNS Server service starts it loads zones from these files. This behavior is limited to any primary and secondary zones that are not AD integrated. The files will be named as <ZoneFQDN>.dns.
      70-640 dumps exhibit
      C:Documents and Settingsusernwz1Desktop1.PNG
      In AD Integrated DNS Zones AD-integrated zones are stored in the directory they do not have corresponding zone files
      i.e. they are not stored as .dns files. This makes sense because the zones are stored in, and loaded from, the directory. Now it is important task for us to take a backup of these AD integrated zones before making any changes to DNS infrastructure. Dnscmd.exe can be used to export the zone to a file. The syntax of the command is: DnsCmd <ServerName> /ZoneExport <ZoneName> <ZoneExportFile> <ZoneName> — FQDN of zone to export /Cache to export cache As an example, let’s say we have an AD integrated zone named habib.local, our DC is server1. The command to export the file would be: Dnscmd server1 /ZoneExport habib.local habib.local.bak
      70-640 dumps exhibit
      C:Documents and Settingsusernwz1Desktop1.PNG
      70-640 dumps exhibit
      C:Documents and Settingsusernwz1Desktop1.PNG
      You can refer to a complete article on DNSCMD in Microsoft TechNet website
      http://technet.microsoft.com/en-us/library/cc772069(v=ws.10).aspx

      NEW QUESTION 16
      You have Active Directory Certificate Services (AD CS) deployed. You create a custom certificate template.
      You need to ensure that all of the users in the domain automatically enroll for a certificate based on the custom certificate template.
      Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)

      • A. In a Group Policy object (GPO), configure the autoenrollment setting
      • B. In a Group Policy object (GPO), configure the Automatic Certificate Request Setting
      • C. On the certificate template, assign the Read and Autoenroll permission to the Authenticated Users grou
      • D. On the certificate template, assign the Read, Enroll, and Autoenroll permission to the Domain Users grou

      Answer: AD

      Explanation:
      http://technet.microsoft.com/en-us/library/dd379539.aspx
      To automatically enroll client computers for certificates in a domain environment, you must:
      Configure an autoenrollment policy for the domain.
      (...)
      In Configuration Model, select Enabled to enable autoenrollment.
      Configure certificate templates for autoenrollment.
      (...)
      In the Permissions for Authenticated Users list, select Read, Enroll, and Autoenroll in the
      Allow column, and then click OK and Close to finish
      Configure an enterprise CA.

      NEW QUESTION 17
      Your network contains an Active Directory forest. The forest contains one domain named contoso.com.
      You attempt to run adprep /domainprep and the operation fails.
      You discover that the first domain controller deployed to the forest failed.
      You need to run adprep /domainprep successfully.
      What should you do?

      • A. Move the domain naming master rol
      • B. Install a read-only domain controller (RODC).
      • C. Move the PDC emulator rol
      • D. Move the RID master rol
      • E. Move the infrastructure master rol
      • F. Deploy an additional global catalog serve
      • G. Move the bridgehead serve
      • H. Move the schema master rol
      • I. Restart the Active Directory Domain Services (AD DS) servic
      • J. Move the global catalog serve

      Answer: E

      Explanation:
      Adprep /domainprep must be run on the server holding the Infrastructure Master role. The
      role was originally installed on the first domain controller in the forest. Now it's down and
      another domain controller must get the Infrastructure Master role.
      Explanation 1:
      http://technet.microsoft.com/en-us/library/cc754889.aspx
      Planning Operations Master Role Placement
      Operations master role holders are assigned automatically when the first domain controller
      in a given domain is created. The two forest-level roles (schema master and domain
      naming master) are assigned to the first domain controller created in a forest. In addition,
      the three domain-level roles (RID master, infrastructure master, and PDC emulator) are
      assigned to the first domain controller created in a domain.
      Explanation 2:
      http://technet.microsoft.com/en-us/library/dd464018.aspx
      Adprep /domainprep Must be run on the infrastructure operations master for the domain.

      NEW QUESTION 18
      Your network contains an Active Directory domain. The domain contains a group named Group1. The minimum password length for the domain is set to six characters.
      You need to ensure that the passwords for all users in Group1 are at least 10 characters
      long. All other users must be able to use passwords that are six characters long.
      You create an Active Directory Fine Grained Password Policy.
      What should you do next?

      • A. From the Default Domain Policy, modify the password polic
      • B. Run the Add-ADFineGrainedPasswordPolicySubject cmdle
      • C. Run the Set-ADDomain cmdle
      • D. From the Default Domain Controller Policy, modify the password polic

      Answer: B

      P.S. Surepassexam now are offering 100% pass ensure 70-640 dumps! All 70-640 exam questions have been updated with correct answers: https://www.surepassexam.com/70-640-exam-dumps.html (631 New Questions)