for Microsoft certification, Real Success Guaranteed with Updated . 100% PASS 70-640 TS: Windows Server 2008 Active Directory. Configuring exam Today!

Check 70-640 free dumps before getting the full version:

NEW QUESTION 1
You have an Active Directory domain named contoso.com.
You need to view the account lockout threshold and duration for the domain.
Which tool should you use?

  • A. Net User
  • B. Active Directory Users and Computers
  • C. Group Policy Management Console (GPMC)
  • D. Computer Management

Answer: C

NEW QUESTION 2
Your network contains an Active Directory forest. The forest contains a single domain.
You want to provide users from a domain that is located in another forest access to resources in your domain.
You need to configure a trust between the domain in your forest and the domain in the other forest.
What should you create?

  • A. an incoming realm trust
  • B. an incoming external trust
  • C. an outgoing external trust
  • D. an outgoing realm trust

Answer: C

NEW QUESTION 3
HOTSPOT
Your network contains an Active Directory forest named contoso.com.
The password policy of the forest requires that the passwords for all of the user accounts be changed every 30 days.
You need to create user accounts that will be used by services. The passwords for these
accounts must be changed automatically every 30 days.
Which tool should you use to create these accounts?
To answer, select the appropriate tool in the answer area.
70-640 dumps exhibit

    Answer:

    Explanation: 70-640 dumps exhibit

    NEW QUESTION 4
    Your network contains four domain controllers. The domain controllers are configured as shown in the following table.
    70-640 dumps exhibit
    All of the domain controllers are configured to host an Active Directory-integrated zone for their respective domain.
    A GlobalNames zone is deployed in the fabrikam.com forest.
    You add a canonical (CNAME) record named Server1 to the GlobalNames zone.
    You discover that users in the contoso.com forest cannot resolve the name Server1. The users in fabrikam.com can resolve the name Server1.
    You need to ensure that the contoso.com users can resolve names in the GlobalNames zone.
    What should you do? (Each correct answer presents part of the solution. Choose two.)

    • A. Run dnscmd.exe and specify the globalnamesqueryorder parameter on CONT-DC1 and CONT-DC2.
    • B. Add service location (SRV) records named _globalnames to the _msdcs.contoso.com zon
    • C. Run dnscmd.exe and specify the enableglobalnamessupport parameter on CONT-DC1 and CONT-DC2.
    • D. Run dnscmd.exe and specify the globalnamesqueryorder parameter on FABR-DC1 and FABR-DC2.
    • E. Run dnscmd.exe and specify the enableglobalnamessupport parameter on FABR-DC1 and FABR-DC2.
    • F. Add service location (SRV) records named _globalnames to the _msdcs.fabrikam.com zon

    Answer: BC

    NEW QUESTION 5
    Your network contains an Active Directory forest. All client computers run Windows 7.
    The network contains a high-volume enterprise certification authority (CA).
    You need to minimize the amount of network bandwidth required to validate a certificate.
    What should you do?

    • A. Configure an LDAP publishing point for the certificate revocation list (CRL).
    • B. Configure an Online Certification Status Protocol (OCSP) responde
    • C. Modify the settings of the delta certificate revocation list (CRL).
    • D. Replicate the certificate revocation list (CRL) by using Distributed File System (DFS).

    Answer: B

    Explanation:
    MS Press - Self-Paced Training Kit (Exam 70-640) (2nd Edition, July 2012) page 779
    Online responder
    This service is designed to respond to specific certificate validation requests through the Online Certificate
    Status Protocol (OCSP). Using an online responder (OR), the system relying on PKI does not need to obtain a full CRL and can submit a validation request for a specific certificate. The online responder decodes the validation request and determines whether the certificate is valid. When it determines the status of the requested certificate, it sends back an encrypted response containing the information to the requester. Using online responders is much faster and more efficient than using CRLs. AD CS includes online
    responders as a new feature in Windows Server 2008 R2.

    NEW QUESTION 6
    A network contains an Active Directory Domain Services (AD DS) domain. Active Directory is configured as shown in the following table.
    70-640 dumps exhibit
    The functional level of the domain is Windows Server 2008 R2. The functional level of the forest is Windows Server 2003.
    Active Directory replication between the Seattle site and the Chicago site occurs from 8:00

    • A. P.
    • B. to 1:00 A.
    • C. every da
    • D. At 7:00 A.
    • E. an administrator deletes a user account while he is logged on to DC001. You need to restore the deleted user accoun
    • F. You must achieve this goal by using the minimum administrative effor
    • G. What should you do?
    • H. On DC006, stop AD DS, perform an authoritative restore, and then start AD D
    • I. On DC001, run the Restore-ADObject cmdle
    • J. On DC006, run the Restore-ADObject cmdle
    • K. On DC001, stop AD DS, restore the system state, and then start AD D

    Answer: A

    Explanation:
    We cannot use Restore-ADObject, because Restore-ADObject is a part of the Recycle Bin
    feature, and you can only use Recycle Bin when the forest functional level is set to
    Windows Server 2008 R2. In the question text it says "The functional level of the forest is
    Windows Server 2003."
    Seehttp://technet.microsoft.com/nl-nl/library/dd379481.aspx
    Performing an authoritative restore on DC006 updates the Update Sequence Number
    (USN) on that DC, which causes it to replicate the restored user account to other DC's.
    Explanation 1:
    MS Press - Self-Paced Training Kit (Exam 70-640) (2nd Edition, July 2012) page 692
    "An authoritative restore restores data that was lost and updates the Update Sequence
    Number (USN) for the data to make it authoritative and ensure that it is replicated to all
    other servers."
    Explanation 2:
    http://technet.microsoft.com/en-us/library/cc755296.aspx
    Authoritative restore of AD DS has the following requirements:
    (...)
    You must stop the Active Directory Domain Services service before you run the ntdsutil
    authoritative restore command and restart the service after the command is complete.

    NEW QUESTION 7
    Your company asks you to implement Windows Cardspace in the domain.
    You want to use Windows Cardspace at your home.
    Your home and office computers run Windows Vista Ultimate.
    What should you do to create a backup copy of Windows Cardspace cards to be used at home?

    • A. Log on with your administrator account and copy WindowsServiceProfiles folder to your USB drive
    • B. Backup WindowsGlobalization folder by using backup status and save the folder on your USB drive
    • C. Back up the system state data by using backup status tool on your USB drive
    • D. Employ Windows Cardspace application to backup the data on your USB driv
    • E. Reformat the C: Drive
    • F. None of the above

    Answer: D

    Explanation:
    http://windows.microsoft.com/en-us/windows7/windows-cardspace-for-itpros#
    BKMK_HowdoIbackupmycardsortransferthemtoanothercomputer
    Windows CardSpace for IT pros
    Microsoft Windows CardSpace. is a system for creating relationships with websites and
    online services.
    Windows CardSpace provides a consistent way for:
    Sites to request information from you.
    You to review the identity of a site.
    You to manage your information by using Information Cards.
    You to review card information before you send it.
    Windows CardSpace can replace the user names and passwords that you use to register
    with and log on to websites and online services.
    15. How do I back up my cards or transfer them to another computer?
    Cards are stored on your computer in an encrypted format. To save a backup file
    containing some or all of your cards or to use a card on a different computer, you can save
    cards to a backup card file.
    To back up your cards:
    1. Start Windows CardSpace.
    2. View all your cards.
    3. In the pane on the right of your screen, click Back up cards.
    4. Select the cards that you want to back up.
    5. Browse to the folder where you want to save the backup card file, and then give it a
    name.
    When you complete these steps, you save a file containing some or all of your cards. You
    can copy the backup card file to media such as a Universal Serial Bus (USB) storage
    device, CD, or other digital media. You can restore the backup card file on this computer or
    on another computer.
    To restore your cards
    1. Save the backup card file to the computer.
    2. Browse to the location of the file on the computer.
    3. Double-click the file, and then follow the instructions to restore the cards.

    NEW QUESTION 8
    Your network contains an Active Directory domain named litwareinc.com. The domain contains two sites named Sitel and Site2. Site2 contains a read-only domain controller (RODC).
    You need to identify which user accounts attempted to authenticate to the RODC.
    Which tool should you use?

    • A. Active Directory Users and Computers
    • B. Ntdsutil
    • C. Get-ADAccountResultantPasswordReplicationPolicy
    • D. Adtest

    Answer: A

    Explanation:
    Original answer was C ("Get-ADAccountResultantPasswordReplicationPolicy").
    Ntdsutil cannot be used for this.
    http://technet.microsoft.com/en-us/library/cc753343.aspx
    Get-ADAccountResultantPasswordReplicationPolicy is used to get the members of the
    allowed list or denied list of a read-only domain controller's password replication policy.
    Get-
    ADDomainControllerPasswordReplicationPolicyUsage could be used, but is not listed.
    http://technet.microsoft.com/en-us/library/ee617207.aspx
    Adtest is used for perfomance testing.
    Explanation 1:
    http://technet.microsoft.com/en-us/library/cc755310.aspx
    Review whose accounts have been authenticated to an RODC
    Periodically, you should review whose accounts have been authenticated to an RODC. (...)
    You can use Active Directory Users and Computers or repadmin /prp to review whose
    accounts have been authenticated to an RODC.
    Explanation 2:
    http://technet.microsoft.com/en-us/library/83a6daba-cdde-4606-97a3-ebb9d7fa6bf(v=ws.10)#BKMK_Aut2
    Gives a step by step explanation on using Active Directory Users and Computers.
    Old explanation:
    Get-ADDomainControllerPasswordReplicationPolicyUsage o get accounts that are
    authenticated by the RODC, use the AuthenticatedAccounts parameter. To get the
    accounts that have passwords stored on the RODC, use the RevealedAccounts parameter.
    http://technet.microsoft.com/en-us/library/ee617194.aspx

    NEW QUESTION 9
    A corporate network includes a single Active Directory Domain Services (AD D5) domain.
    The HR department has a dedicated organization unit (OU) named HR. The HR OU has two sub-OUs: HR Users and HR Computers. User accounts for the HR department reside in the HR Users OU. Computer accounts for the HR department reside in the HR Computers OU. All HR department employees belong to a security group named HR Employees. All HR department computers belong to a security group named HR PCs.
    Company policy requires that passwords are a minimum of six characters.
    You need to ensure that, the next time HR department employees change their passwords, the passwords are required to have at least eight characters. The password length requirement should not change for employees of any other department.
    What should you do?

    • A. Create a fine-grained password policy and apply it to the HR Computers O
    • B. Modify the password policy in the GPO that is applied to the domain controllers O
    • C. Create a fine-grained password policy and apply it to the HR Employees grou
    • D. Modify the password policy in the GPO that is applied to the domai

    Answer: C

    NEW QUESTION 10
    You have a domain controller named Server1 that runs Windows Server 2008 R2.
    You need to determine the size of the Active Directory database on Server1.
    What should you do?

    • A. Run the Active Directory Sizer too
    • B. Run the Active Directory Diagnostics data collector se
    • C. From Windows Explorer, view the properties of the %systemroot%ntdsntds.dit fil
    • D. From Windows Explorer, view the properties of the %systemroot%sysvoldomain folde

    Answer: C

    Explanation:
    http://technet.microsoft.com/en-us/library/cc961761.aspx Directory Data Store Active Directory data is stored in the Ntds.dit ESE database file. Two copies of Ntds.dit are present in separate locations on a given domain controller: %SystemRoot%NTDSNtds.dit This file stores the database that is in use on the domain controller. It contains the values for the domain and a replica of the values for the forest (the Configuration container data). %SystemRoot%System32Ntds.dit This file is the distribution copy of the default directory that is used when you promote a Windows 2000 – based computer to a domain controller. The availability of this file allows you to run the Active Directory Installation Wizard (Dcpromo.exe) without your having to use the Windows 2000 Server operating system CD. During the promotion process, Ntds.dit is copied from the %SystemRoot% System32 directory into the %SystemRoot%NTDS directory. Active Directory is then started from this new copy of the file, and replication updates the file from other domain controllers.

    NEW QUESTION 11
    You are the network administrator for your organization.
    Your company uses a Windows Server 2008 R2 Enterprise Root CA.
    The company has issued a new policy that prevents port 443 and port 80 from being opened on domain controllers and on issuing CAs.
    Your users need to request certificates from a web interface.
    You have already installed the AD CS role.
    What do you need to do next?

    • A. Configure the Certificate Authority Web Enrollment Service on a member serve
    • B. Configure the Certificate Authority Web Enrollment Service on a domain serve
    • C. Configure AD FS on member server to allow secure web-based acces
    • D. Configure AD FS on domain controller to allow secure web-based acces

    Answer: A

    Explanation:
    http://technet.microsoft.com/en-us/library/dd759209.aspx Certificate Enrollment Web Service Overview The Certificate Enrollment Web Service is an Active Directory Certificate Services (AD CS) role service that enables users and computers to perform certificate enrollment by using the HTTPS protocol. Together with the Certificate Enrollment Policy Web Service, this enables policy-based certificate enrollment when the client computer is not a member of a domain or when a domain member is not connected to the domain. Personal note: Since domain controllers are off-limits (regarding open ports), you are left to install the Certificate Enrollment Web Service role service on a plain member server

    NEW QUESTION 12
    A corporate network includes an Active Directory-integrated zone. All DNS servers that host the zone are domain controllers.
    You add multiple DNS records to the zone.
    You need to ensure that the new records are available on all DNS servers as soon as possible.
    Which tool should you use?

    • A. Ldp
    • B. Repadmin
    • C. Ntdsutil
    • D. Nslookup
    • E. Active Directory Sites And Services console
    • F. Active Directory Domains And Trusts console
    • G. Dnslint
    • H. Dnscmd

    Answer: B

    Explanation:
    http://technet.microsoft.com/en-us/library/cc811569.aspx
    Forcing Replication
    Sometimes it becomes necessary to forcefully replicate objects and entire partitions
    between domain controllers that may or may not have replication agreements.
    Force a replication event with all partners
    The repadmin /syncall command synchronizes a specified domain controller with all
    replication partners.
    Syntax
    repadmin /syncall <DC> [<NamingContext>] [<Flags>]
    Parameters
    <DC>
    Specifies the host name of the domain controller to synchronize with all replication
    partners.
    <NamingContext>
    Specifies the distinguished name of the directory partition.
    <Flags>
    Performs specific actions during the replication.

    NEW QUESTION 13
    Your company has a main office and a branch office. The branch office has an Active Directory site that contains a read-only domain controller (RODC).
    A user from the branch office reports that his account is locked out.
    From a writable domain controller in the main office, you discover that the user's account is not locked out. You need to ensure that the user can log on to the domain.
    What should you do?

    • A. Modify the Password Replication Polic
    • B. Reset the password of the user accoun
    • C. Run the Knowledge Consistency Checker (KCC) on the ROD
    • D. Restore network communication between the branch office and the main offic

    Answer: D

    Explanation:
    Not sure if:
    Run the Knowledge Consistency Checker (KCC) on the RODC.
    or
    Restore network communication between the branch office and the main office.

    NEW QUESTION 14
    Your network contains a single Active Directory domain named contoso.com.
    An administrator accidentally deletes the _msdsc.contoso.com zone. You recreate the _msdsc.contoso.com zone.
    You need to ensure that the _msdsc.contoso.com zone contains all of the required DNS records.
    What should you do on each domain controller?

    • A. Restart the Netlogon servic
    • B. Restart the DNS Server servic
    • C. Run dcdiag.exe /fi
    • D. Run ipconfig.exe /registerdn

    Answer: A

    Explanation:
    Explanation 1: http://support.microsoft.com/kb/817470 To register the required records to the single root domain controller, restart the Net Logon service on all the domain controllers. The replication works correctly if the replication window is not less than the default DNS Time to Live (TTL) entry. To restart the Net Logon service, follow these steps:
    1. Click Start, click Run, type cmd in the Open box, and then press ENTER.
    2. At the command prompt, type the following command, and then press ENTER: net stop netlogon
    3. Type net start netlogon, and then press ENTER.
    Explanation 2:
    http://serverfault.com/questions/383915/how-do-i-manually-create-the-msdcs-dns-zone-for-a-domain-that-wascreated-pre-s
    Be sure to restart the Netlogon services on all DC's when the zone has been replicated to them. This forces the DC's to register their SRV records in the _msdcs zone.

    NEW QUESTION 15
    Your network contains two Active Directory forests named contoso.com and adatum.com.
    The functional level of both forests is Windows Server 2008 R2. Each forest contains one
    domain. Active Directory Certificate Services (AD CS) is configured in the contoso.com forest to allow users from both forests to automatically enroll user certificates.
    You need to ensure that all users in the adatum.com forest have a user certificate from the contoso.com certification authority (CA).
    What should you configure in the adatum.com domain?

    • A. From the Default Domain Controllers Policy, modify the Enterprise Trust setting
    • B. From the Default Domain Controllers Policy, modify the Trusted Publishers setting
    • C. From the Default Domain Policy, modify the Certificate Enrollment polic
    • D. From the Default Domain Policy, modify the Trusted Root Certification Authority setting

    Answer: C

    Explanation:
    http://technet.microsoft.com/en-us/library/dd851772.aspx Manage Certificate Enrollment Policy by Using Group Policy Configuring certificate enrollment policy settings by using Group Policy

    NEW QUESTION 16
    Your company has an Active Directory domain and an organizational unit. The organizational unit is named Web.
    You configure and test new security settings for Internet Information Service (IIS) Servers on a server named IISServerA.
    You need to deploy the new security settings only on the IIS servers that are members of the Web organizational unit.
    What should you do?

    • A. Run secedit /configure /db iis.inf from the command prompt on IISServerA, then run secedit /configure /db webou.inf from the comand promp
    • B. Export the settings on IISServerA to create a security templat
    • C. Import the security template into a GPO and link the GPO to the Web organizational uni
    • D. Export the settings on IISServerA to create a security templat
    • E. Run secedit /configure /db webou.inf from the comand promp
    • F. Import the hisecws.inf file template into a GPO and link the GPO to the Web organizational uni

    Answer: B

    Explanation:
    http://www.itninja.com/blog/view/using-secedit-to-apply-security-templates Using Secedit To Apply Security Templates Secedit /configure /db secedit.sdb /cfg"c:tempcustom.inf" /silent >nul This command imports a security template file, “custom.inf” into the workstation’s or server’s local security database. /db must be specified. When specifying the default secuirty database (secedit.sdb,) I found that providing no path worked best. The /cfg option informs Secedit that it is to import the .inf file into the specified database, appending it to any existing .inf files that have already been imported to this system. You can optionally include an /overwrite switch to overwrite all previous configurations for this machine. The /silent option supresses any pop-ups and the >nul hides the command line output stating success or failure of the action.

    NEW QUESTION 17
    Your company has an Active Directory forest. Each regional office has an organizational unit (OU) named Marketing. The Marketing OU contains all users and computers in the region's Marketing department.
    You need to install a Microsoft Office 2007 application only on the computers in the Marketing OUs.
    You create a GPO named MarketingApps.
    What should you do next?

    • A. Configure the GPO to assign the application to the computer accoun
    • B. Link the GPO to the domai
    • C. Configure the GPO to assign the application to the user accoun
    • D. Link the GPO to each Marketing O
    • E. Configure the GPO to assign the application to the computer accoun
    • F. Link the GPO to each Marketing O
    • G. Configure the GPO to publish the application to the user accoun
    • H. Link the GPO to each Marketing O

    Answer: C

    Explanation:
    http://support.microsoft.com/kb/816102
    You can use Group Policy to distribute computer programs by using the following methods:
    Assigning Software You can assign a program distribution to users or computers. If you assign the program to a user, it is installed when the user logs on to the computer. When the user first runs the program, the installation is completed. If you assign the program to a computer, it is installed when the computer starts, and it is available to all users who log on to the computer. When a user first runs the program, the installation is completed.
    Publishing Software
    You can publish a program distribution to users. When the user logs on to the computer, the published program is displayed in the Add or Remove Programs dialog box, and it can be installed from there.

    NEW QUESTION 18
    A corporate environment includes a Windows Server 2008 R2 Active Directory Domain Services (AD DS) domain.
    You need to enable Universal Group Membership Caching on several domain controllers in the domain.
    Which tool should you use?

    • A. Dsmod
    • B. Dscmd
    • C. Ntdsutil
    • D. Active Directory Sites and Services console

    Answer: D

    Explanation: http://technet.microsoft.com/en-us/library/cc816928.aspx
    Enable Universal Group Membership Caching in a Site
    In a branch site that has no global catalog server and in a forest that has multiple domains, you can use this procedure to enable Universal Group Membership Caching on a domain controller in the site so that a global catalog server does not have to be contacted across a wide area network (WAN) link for every initial user logon.
    To enable Universal Group Membership Caching in a site
    1. Open Active Directory Sites and Services.
    2. In the console tree, expand Sites, and then click the site in which you want to enable Universal Group Membership Caching.
    3. In the details pane, right-click the NTDS Site Settings object, and then click Properties.
    4. Under Universal Group Membership Caching, select Enable Universal Group Membership Caching.
    5. In the Refresh cache from list, click the site that you want the domain controller to contact when the
    Universal Group membership cache must be updated, and then click OK.

    Recommend!! Get the Full 70-640 dumps in VCE and PDF From Certleader, Welcome to Download: https://www.certleader.com/70-640-dumps.html (New 631 Q&As Version)