70-640 Exam Details

  • Exam Code
    :70-640
  • Exam Name
    :TS: Windows Server 2008 Active Directory Configuring
  • Certification
    :Microsoft Certifications
  • Vendor
    :Microsoft
  • Total Questions
    :631 Q&As
  • Last Updated
    :Dec 15, 2021

Microsoft 70-640 Online Questions & Answers

  • Question 141:

    Your network contains an Active Directory forest. The forest contains two domain controllers. The domain controllers are configured as shown in the following table.

    All client computers run Windows 7.

    You need to ensure that all client computers in the domain keep the same time as an external time server.

    What should you do?

    A. From DC1, run the time command.
    B. From DC2, run the time command.
    C. From DC1, run the w32tm.exe command.
    D. From DC2, run the w32tm.exe command.

  • Question 142:

    Your company has a single Active Directory forest with a single domain. Consultants in different departments of the company require access to different network resources. The consultants belong to a global group named TempWorkers.

    Three file servers are placed in a new organizational unit named SecureServers. The file servers contain confidential data in shared folders.

    You need to prevent the consultants from accessing the confidential data. What should you do?

    A. Create a new Group Policy Object (GPO) and link it to the SecureServers organizational unit. Assign the Deny access to this computer from the network user right to the TempWorkers global group.
    B. Create a new Group Policy Object (GPO) and link it to the domain. Assign the Deny access to this computer from the network user right to the TempWorkers global group.
    C. On the three file servers, create a share on the root of each hard disk. Configure the Deny Full control permission for the TempWorkers global group on the share.
    D. Create a new Group Policy Object (GPO) and link it to the domain. Assign the Deny log on locally user right to the TempWorkers global group.
    E. Create a new Group Policy Object (GPO) and link it to the SecureServers organizational unit. Assign the Deny log on locally user right to the TempWorkers global group.

  • Question 143:

    Your network contains an Active Directory forest named contoso.com. The functional level of the forest is Windows Server 2008 R2.

    The DNS zone for contoso.com is Active Directory-integrated. You deploy a read-only domain controller (RODC) named RODC1.

    You install the DNS Server server role on RODC1.

    You discover that RODC1 does not have any DNS application directory partitions. You need to ensure that RODC1 has a copy of the DNS application directory partition of contoso.com.

    What should you do?

    A. From DNS Manager, right-click RODC1 and click Create Default Application Directory Partitions.
    B. From DNS Manager, create primary zones.
    C. Run ntdsutil.exe. From the Partition Management context, run the create nc command.
    D. Run dnscmd.exe and specify the /enlistdirectorypartition parameter.

  • Question 144:

    ABC.com has a main office and a branch office. ABC.com's network consists of a single Active Directory forest.

    Some of the servers in the network run Windows Server 2008 and the rest run Windows server 2003.

    You are the administrator at ABC.com. You have installed Active Directory Domain Services (AD DS) on a computer that runs Windows Server 2008. The branch office is located in a physically insecure place. It has no IT personnel onsite and there are no administrators over there. You need to setup a Read-Only Domain Controller (RODC) on the Server Core installation computer in the branch office.

    What should you do to setup RODC on the computer in branch office?

    A. Execute an attended installation of AD DS
    B. Execute an unattended installation of AD DS
    C. Execute RODC through AD DS
    D. Execute AD DS by using deploying the image of AD DS
    E. none of the above

  • Question 145:

    Your company has two offices. The offices are located in Miami and London. The network contains an Active Directory forest named contoso.com. The forest contains two child domains named miami.contoso.com and london.contoso.com.

    Each domain contains 50 domain controllers that run Windows Server 2008 R2.

    Each office is configured as an Active Directory site.

    The office in London recently hired several thousand new employees.

    You need to move 10 domain controllers from miami.contoso.com to london.contoso.com.

    What should you do?

    A. Run the dsadd.exe command
    B. Run the nltest.exe command.
    C. Run the Set-AdDomain cmdlet.
    D. Run the dsmove.exe command.
    E. Run the dcpromo.exe command.
    F. Run the Move-AdDirectoryServer cmdlet.
    G. Use the Active Directory Schema snap-in.
    H. Use the Active Directory Users and Computers console.

  • Question 146:

    Your network contains a domain controller that runs Windows Server 2008 R2. You run the following command on the domain controller:

    dsamain.exe -dbpath c:\$SNAP_201006170326_VOLUMEC$\Windows\NTDS\ntds.dit -ldapport 389 -allowNonAdminAccess

    The command fails.

    You need to ensure that the command completes successfully.

    How should you modify the command?

    A. Include the path to Dsamain.
    B. Change the value of the -dbpath parameter.
    C. Change the value of the -ldapport parameter.
    D. Remove the allowNonAdminAccess

  • Question 147:

    A corporate network contains a Windows Server 2008 R2 Active Directory forest. You need to add a user principal name (UPN) suffix to the forest. Which tool should you use?

    A. Active Directory Users and Computers console
    B. Active Directory Sites and Services console
    C. Ntdsutil
    D. Active Directory module for Windows PowerShell E. Active Directory Domains and Trusts Console

  • Question 148:

    You need to deploy a read-only domain controller (RODC) that runs Windows Server 2008 R2.

    What is the minimal forest functional level that you should use?

    A. Windows Server 2008 R2
    B. Windows Server 2008
    C. Windows Server 2003
    D. Windows 2000

  • Question 149:

    Your company has an Active Directory forest. Not all domain controllers in the forest are configured as Global Catalog Servers. Your domain structure contains one root domain and one child domain.

    You modify the folder permissions on a file server that is in the child domain. You discover that some Access Control entries start with S-1-5-21 and that no account name is listed.

    You need to list the account names.

    What should you do?

    A. Move the RID master role in the child domain to a domain controller that holds the Global Catalog.
    B. Modify the schema to enable replication of the friendlynames attribute to the Global Catalog.
    C. Move the RID master role in the child domain to a domain controller that does not hold the Global Catalog.
    D. Move the infrastructure master role in the child domain to a domain controller that does not hold the Global Catalog.

  • Question 150:

    Your company has an Active Directory domain. All consultants belong to a global group named TempWorkers.

    The TempWorkers group is not nested in any other groups.

    You move the computer objects of three file servers to a new organizational unit named SecureServers. These file servers contain only confidential data in shared folders.

    You need to prevent members of the TempWorkers group from accessing the confidential data on the file servers.

    You must achieve this goal without affecting access to other domain resources.

    What should you do?

    A. Create a new GPO and link it to the SecureServers organizational unit. Assign the Deny access to this computer from the network user right to the TempWorkers global group.
    B. Create a new GPO and link it to the domain. Assign the Deny access to this computer from the network user right to the TempWorkers global group.
    C. Create a new GPO and link it to the domain. Assign the Deny log on locally user right to the TempWorkers global group.
    D. Create a new GPO and link it to the SecureServers organizational unit. Assign the Deny log on locally user right to the TempWorkers global group.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Microsoft exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 70-640 exam preparations and Microsoft certification application, do not hesitate to visit our Vcedump.com to find your solutions here.