70-640 Exam Details

  • Exam Code
    :70-640
  • Exam Name
    :TS: Windows Server 2008 Active Directory Configuring
  • Certification
    :Microsoft Certifications
  • Vendor
    :Microsoft
  • Total Questions
    :631 Q&As
  • Last Updated
    :Dec 15, 2021

Microsoft 70-640 Online Questions & Answers

  • Question 211:

    Your network contains an Active Directory forest named contoso.com. The forest contains two domains. All domain controllers are configured as global catalog servers.

    The forest root domain contains five domain controllers. The domain controllers are configured as shown in the following table.

    You plan to create a custom attribute in Active Directory that will replicate to all of the global catalog servers.

    You need to identify which domain controller must be online to perform the planned action.

    Which domain controller should you identify?

    A. DC1
    B. DC2
    C. DC3
    D. DC4
    E. DC5

  • Question 212:

    Your company has two offices. The offices are located in Miami and London. The network contains an Active Directory forest named contoso.com. The forest contains two child domains named miami.contoso.com and london.contoso.com. The domain contains 50 domain controllers that run Windows Server 2008 R2.

    Each office is configured as an Active Directory site.

    You plan to deploy several read-only domain controllers (RODCs) to the Miami site.

    You need to pre-create the computer accounts of the RODCs.

    What should you do?

    A. Run the dsadd.exe command
    B. Run the nltest.exe command.
    C. Run the Set-AdDomain cmdlet.
    D. Run the dsmove.exe command.
    E. Run the dcpromo.exe command.
    F. Run the Move-AdDirectoryServer cmdlet.
    G. Use the Active Directory Schema snap-in.
    H. Use the Active Directory Users and Computers console.

  • Question 213:

    Your network contains an Active Directory forest. The forest schema contains a custom attribute for user objects.

    You need to modify the custom attribute value of 500 user accounts.

    Which tool should you use?

    A. Csvde
    B. Dsmod
    C. Dsrm
    D. Ldifde

  • Question 214:

    You have an Active Directory domain named contoso.com.

    You need to view the account lockout threshold and duration for the domain.

    Which tool should you use?

    A. Net User
    B. Active Directory Users and Computers
    C. Group Policy Management Console (GPMC)
    D. Computer Management

  • Question 215:

    Your network contains two Active Directory forests named contoso.com and nwtraders.com. The functional level of both forests is Windows Server 2003.

    Contoso.com contains one domain.

    Nwtraders.com contains two domains.

    You need to ensure that users in contoso.com can access the resources in all domains. The solution must require the minimum number of trusts.

    Which type of trust should you create?

    A. external
    B. forest
    C. realm
    D. shortcut

  • Question 216:

    You have a domain controller that runs Windows Server 2008 R2. The Windows Server Backup feature is installed on the domain controller.

    You need to perform a non-authoritative restore of the domain controller by using an existing backup file.

    What should you do?

    A. Restart the domain controller in Directory Services Restore Mode. Use the WBADMIN command to perform a critical volume restore.
    B. Restart the domain controller in Directory Services Restore Mode. Use the Windows Server Backup snap-in to perform a critical volume restore.
    C. Restart the domain controller in safe mode. Use the Windows Server Backup snap-in to perform a critical volume restore.
    D. Restart the domain controller in safe mode. Use the WBADMIN command to perform a critical volume restore.

  • Question 217:

    Your company has an Active Directory domain. A user attempts to log on to the domain from a client computer and receives the following message: "This user account has expired. Ask your administrator to reactivate the account."

    You need to ensure that the user is able to log on to the domain.

    What should you do?

    A. Modify the properties of the user account to set the account to never expire.
    B. Modify the properties of the user account to extend the Logon Hours setting.
    C. Modify the default domain policy to decrease the account lockout duration.
    D. Modify the properties of the user account to set the password to never expire.

  • Question 218:

    A corporate network includes a single Active Directory Domain Services (AD D5) domain.

    The HR department has a dedicated organization unit (OU) named HR. The HR OU has two sub-OUs:

    HR Users and HR Computers. User accounts for the HR department reside in the HR Users OU. Computer accounts for the HR department reside in the HR Computers OU. All HR department employees belong to a security group named

    HR Employees. All HR department computers belong to a security group named HR PCs.

    Company policy requires that passwords are a minimum of six characters.

    You need to ensure that, the next time HR department employees change their passwords, the passwords are required to have at least eight characters. The password length requirement should not change for employees of any other

    department.

    What should you do?

    A. Create a fine-grained password policy and apply it to the HR Computers OU.
    B. Modify the password policy in the GPO that is applied to the domain controllers OU.
    C. Create a fine-grained password policy and apply it to the HR Employees group.
    D. Modify the password policy in the GPO that is applied to the domain.

  • Question 219:

    Your network contains an Active Directory forest named contoso.com. The forest contains two domains named contoso.com and child.contoso.com. All domain controllers run Windows Server 2008. All forest-wide operations master roles are

    in child.contoso.com.

    An administrator successfully runs adprep.exe /forestprep from the Windows Server 2008 R2 Service Pack 1 (SP1) installation media.

    You plan to run adprep.exe /domainprep in each domain.

    You need to ensure that you have the required user rights to run the command successfully in each domain.

    Of which groups should you be a member? (Each correct answer presents part of the solution. Choose two.)

    A. Administrators in child.contoso.com
    B. Enterprise Admins in contoso.com
    C. Domain Admins in child.contoso.com
    D. Domain Admins in contoso.com
    E. Administrators in contoso.com
    F. Schema Admins in contoso.com

  • Question 220:

    Your network contains an Active Directory forest named contoso.com. The functional level of the forest is Windows Server 2008 R2.

    You have four Active Directory sites. Each site has multiple Active Directory subnets. You need to identify all of the authentication requests that originate from client computers that are not associated to an Active Directory subnet.

    What should you use?

    A. The %Systemroot%\System32\Network_llu.log log file
    B. The %Systemroot%\Debug\Netsetup.log log file
    C. The Authentication User Interface operational log
    D. The %Systemroot%\Debug\Netlogon.log log file

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Microsoft exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 70-640 exam preparations and Microsoft certification application, do not hesitate to visit our Vcedump.com to find your solutions here.