70-640 Exam Details

  • Exam Code
    :70-640
  • Exam Name
    :TS: Windows Server 2008 Active Directory Configuring
  • Certification
    :Microsoft Certifications
  • Vendor
    :Microsoft
  • Total Questions
    :631 Q&As
  • Last Updated
    :Dec 15, 2021

Microsoft 70-640 Online Questions & Answers

  • Question 181:

    Your company has an Active Directory domain. The main office has a DNS server named DNS1 that is configured with Active Directory-integrated DNS. The branch office has a DNS server named DNS2 that contains a secondary copy of the

    zone from DNS1. The two offices are connected with an unreliable WAN link.

    You add a new server to the main office.

    Five minutes after adding the server, a user from the branch office reports that he is unable to connect to the new server.

    You need to ensure that the user is able to connect to the new server.

    What should you do?

    A. Clear the cache on DNS2.
    B. Reload the zone on DNS1.
    C. Refresh the zone on DNS2.
    D. Export the zone from DNS1 and import the zone to DNS2.

  • Question 182:

    Your network contains an enterprise certification authority (CA) that runs Windows Server 2008 R2 Enterprise.

    You have a custom certificate template named Template 1. Template1 is published to the CA. You need to ensure that all of the members of a group named Group1 can enroll for certificates that use Template1.

    Which snap-in should you use?

    A. Security Templates
    B. Enterprise PKI
    C. Certification Authority
    D. Certificate Templates
    E. Certificates
    F. TPM Management
    G. Authorization Manager
    H. Group Policy Management
    I. Active Directory Users and Computers

  • Question 183:

    Your network contains an Active Directory forest named contoso.com. The forest contains a domain controller named DC1 that runs Windows Server 2008 R2 Enterprise and a member server named Server1 that runs Windows Server 2008 R2 Standard. You have a computer named Computer1 that runs Windows 7.

    Computer1 is not connected to the network.

    You need to join Computer1 to the contoso.com domain.

    What should you do? To answer, move the appropriate actions from the Possible Actions list to the Necessary Actions area and arrange them in the correct order.

    Select and Place:

  • Question 184:

    Your network contains an Active Directory domain named adatum.com. All servers run Windows Server 2008 R2 Enterprise. All client computers run Windows 7 Professional.

    The network contains an enterprise certification authority (CA).

    You need to approve a pending certificate request.

    Which snap-in should you use?

    A. Active Directory Administrative Center
    B. Authorization Manager
    C. Certificate Templates
    D. Certificates
    E. Certification Authority
    F. Enterprise PKI
    G. Group Policy Management
    H. Security Configuration Wizard
    I. Share and Storage Management

  • Question 185:

    Your network contains two forests named contoso.com and fabrikam.com. The functional level of all the domains is Windows Server 2003. The functional level of both forests is Windows 2000.

    You need to create a trust between contoso.com and fabrikam.com. The solution must ensure that users from contoso.com can only access the servers in fabrikam.com that have the Allowed to Authenticate permission set.

    What should you do? To answer, move the appropriate actions from the Possible Actions list to the Necessary Actions area and arrange them in the correct order.

    Select and Place:

  • Question 186:

    Your network contains an Active Directory forest. The forest contains two domains. You have a standalone root certification authority (CA).

    On a server in the child domain, you run the Add Roles Wizard and discover that the option to select an enterprise CA is disabled.

    You need to install an enterprise subordinate CA on the server.

    What should you use to log on to the new server?

    A. an account that is a member of the Certificate Publishers group in the child domain
    B. an account that is a member of the Certificate Publishers group in the forest root domain
    C. an account that is a member of the Schema Admins group in the forest root domain
    D. an account that is a member of the Enterprise Admins group in the forest root domain

  • Question 187:

    Your network consists of an Active Directory forest named contoso.com. All servers run Windows Server 2008 R2. All domain controllers are configured as DNS servers. The contoso.com DNS zone is stored in the ForestDnsZones Active Directory application partition.

    You have a member server that contains a standard primary DNS zone for dev.contoso.com.

    You need to ensure that all domain controllers can resolve names for dev.contoso.com.

    What should you do?

    A. Modify the properties of the SOA record in the contoso.com zone.
    B. Create a NS record in the contoso.com zone.
    C. Create a delegation in the contoso.com zone.
    D. Create a standard secondary zone on a Global Catalog server.

  • Question 188:

    Your network contains an Active Directory domain. The domain contains four domain controllers.

    You create a new application directory partition.

    You need to ensure that the new application directory partition replicates to only three of the domain controllers.

    Which tool should you use?

    A. Dsdbutil
    B. Active Directory Administrative Center
    C. Dsmod
    D. Dsmgmt

  • Question 189:

    Your network contains an Active Directory domain named contoso.com. The domain has one Active Directory site.

    The domain contains an organizational unit (OU) named OU1. OU1 contains user accounts for 100 users and their managers.

    You apply a Group Policy object (GPO) named GPO1 to OU1. GPO1 restricts several desktop settings.

    The managers request that the desktop settings not be applied to them. You need to prevent the desktop settings in GPOl from being applied to the managers. All other users in OU1 must have GPO1 applied to them.

    What should you do?

    A. Configure the permissions on OU1.
    B. Configure the permissions on the user accounts of the managers.
    C. Link GPO1 to a WMI filter.
    D. Configure the permissions of GPOl.

  • Question 190:

    Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named DC1. DC1 hosts an Active Directory-integrated zone for contoso.com.

    The research department maintains its own DNS servers and hosts a zone named research.contoso.com on a UNIXbased server named Server1.

    The perimeter network contains a DNS server named Server2. Server2 is a standalone server that runs Windows Server 2008 R2.

    You need to configure the DNS settings of Server2 to meet the following requirements:

    Server2 must maintain a copy of all the records in research.contoso.com.

    DC1 must query Server2 to resolve the names of Internet hosts.

    Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)

    A. Create a secondary zone.
    B. Create a conditional forwarder.
    C. Create a stub zone.
    D. Create a primary zone.
    E. Create a Forwarder.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Microsoft exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 70-640 exam preparations and Microsoft certification application, do not hesitate to visit our Vcedump.com to find your solutions here.