70-640 Exam Details

  • Exam Code
    :70-640
  • Exam Name
    :TS: Windows Server 2008 Active Directory Configuring
  • Certification
    :Microsoft Certifications
  • Vendor
    :Microsoft
  • Total Questions
    :631 Q&As
  • Last Updated
    :Dec 15, 2021

Microsoft 70-640 Online Questions & Answers

  • Question 161:

    Your company plans to open a new branch office.

    The new office will have a low-speed connection to the Internet. You plan to deploy a read-only domain controller (RODC) in the branch office.

    You need to create an offline copy of the Active Directory database that can be used to install the Active Directory on the new RODC.

    Which commands should you run from Ntdsutil? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

    Select and Place:

  • Question 162:

    Your network contains an Active Directory domain named contoso.com.

    All domain controllers were upgraded from Windows Server 2003 to Windows Server 2008 R2 Service Pack 1 (SP1). The functional level of the domain is Windows Server 2003.

    You need to configure SYSVOL to use DFS Replication.

    Which tools should you use? (Each correct answer presents part of the solution. Choose two.)

    A. Dfsrmig
    B. Frsdiag
    C. Ntdsutil
    D. Set-ADForest
    E. Repadmin
    F. Set-ADDomainMode
    G. DFS Management

  • Question 163:

    Your company has a main office and a branch office. You deploy a read-only domain controller (RODC) that runs Microsoft Windows Server 2008 to the branch office.

    You need to ensure that users at the branch office are able to log on to the domain by using the RODC.

    What should you do?

    A. Add another RODC to the branch office.
    B. Configure a new bridgehead server in the main office.
    C. Decrease the replication interval for all connection objects by using the Active Directory Sites and Services console.
    D. Configure the Password Replication Policy on the RODC.

  • Question 164:

    Your network contains an Active Directory forest. The forest contains two domains named contoso.com and eu.contoso.com. All domain controllers are DNS servers.

    The domain controllers in contoso.com host the zone for contoso.com. The domain controllers in eu.contoso.com host the zone for eu.contoso.com. The DNS zone for contoso.com is configured as shown in the exhibit. (Click the Exhibit button.)

    You need to ensure that all domain controllers in the forest host a writable copy of _msdsc.contoso.com.

    Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)

    A. Create a zone delegation record in the contoso.com zone.
    B. Create a zone delegation record in the eu.contoso.com zone.
    C. Create an Active Directory-integrated zone for _msdsc.contoso.com.
    D. Create a secondary zone named _msdsc.contoso.com in eu.contoso.com.

  • Question 165:

    Your network contains an Active Directory domain named contoso.com.

    You have a comma separated value (CSV) file named Users.txt. Users.txt contains the information for 500 users and all of the attributes required to create user accounts.

    You plan to automate the creation of user accounts by using the Users.txt file.

    You need to identify which two cmdlets you must run. The solution must pipe the output from the first cmdlet to the second cmdlet.

    What should you run from Windows PowerShell? To answer, configure the appropriate PowerShell command in the answer area.

    Hot Area:

  • Question 166:

    Your network contains an Active Directory forest. The forest contains 10 domains. All domain controllers are configured as global catalog servers.

    You remove the global catalog role from a domain controller named DC5. You need to reclaim the hard disk space used by the global catalog on DC5.

    What should you do?

    A. From Active Directory Sites and Services, run the Knowledge Consistency Checker (KCC).
    B. From Active Directory Sites and Services, modify the general properties of DC5.
    C. From Ntdsutil, use the Semantic database analysis option.
    D. From Ntdsutil, use the Files option.

  • Question 167:

    Your network contains an Active Directory forest named contoso.com. The forest contains three domains named contoso.com, childl.contoso.com, and child2.contoso.com. The childl.contoso.com domain contains five domain controllers. The

    domain controllers are configured as shown in the following table.

    You plan to decommission the child1.contoso.com domain.

    You need to identify which two FSMO roles can be moved from childl.contoso.com to child2.contoso.com.

    Which two FSMO roles should you identify? (Each correct answer presents part of the solution. Choose two.)

    A. Domain naming master
    B. Schema master
    C. Infrastructure master
    D. PDC emulator
    E. RID master

  • Question 168:

    You have an enterprise root certification authority (CA) that runs Windows Server 2008 R2. You need to ensure that you can recover the private key of a certificate issued to a Web server.

    What should you do?

    A. From the CA, run the Get-PfxCertificate cmdlet.
    B. From the Web server, run the Get-PfxCertificate cmdlet.
    C. From the CA, run the certutil.exe tool and specify the -exportpfx parameter.
    D. From the Web server, run the certutil.exe tool and specify the -exportpfx parameter.

  • Question 169:

    Your company has an Active Directory forest.

    You plan to install an Enterprise certification authority (CA) on a dedicated stand-alone server. When you attempt to add the Active Directory Certificate Services (AD CS) role, you find that the Enterprise CA option is not available.

    You need to install the AD CS role as an Enterprise CA.

    What should you do first?

    A. Add the DNS Server role.
    B. Add the Active Directory Lightweight Directory Service (AD LDS) role.
    C. Add the Web server (IIS) role and the AD CS role.
    D. Join the server to the domain.

  • Question 170:

    Your network contains an Active Directory domain.

    The domain contains a certification authority (CA).

    The network contains several Layer 3 switches.

    You need to ensure that the switches can request certificates from the CA.

    Which role service should you deploy?

    A. Network Device Enrollment Service
    B. Windows Token-based Agent
    C. Network Policy Server
    D. Client Certificate Mapping Authentication

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Microsoft exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 70-640 exam preparations and Microsoft certification application, do not hesitate to visit our Vcedump.com to find your solutions here.