70-640 Exam Details

  • Exam Code
    :70-640
  • Exam Name
    :TS: Windows Server 2008 Active Directory Configuring
  • Certification
    :Microsoft Certifications
  • Vendor
    :Microsoft
  • Total Questions
    :631 Q&As
  • Last Updated
    :Dec 15, 2021

Microsoft 70-640 Online Questions & Answers

  • Question 271:

    Your network contains an Active Directory domain named contoso.com. The domain contains two member servers named Server1 and Server2. You configure Server1 as a standalone root certification authority (CA). You identify the following requirements for the public key infrastructure (PKI):

    The root CA must be offline once the PKI is deployed.

    Users must be able to enroll for certificates automatically.

    You need to configure Server2 to meet the PKI requirements. What should you configure on Server2?

    A. A standalone subordinate CA
    B. A standalone root CA
    C. An enterprise subordinate CA
    D. An enterprise root CA

  • Question 272:

    Your network contains an Active Directory domain. The domain contains a member server named Server1 that runs Windows Server 2008 R2.

    You need to configure Server1 as a global catalog server.

    What should you do?

    A. Modify the Active Directory schema.
    B. From Ntdsutil, use the Roles option.
    C. Run the Active Directory Domain Services Installation Wizard on Server1.
    D. Move the Server1 computer object to the Domain Controllers organizational unit (OU).

  • Question 273:

    Your network contains a domain controller that is configured as a DNS server. The server hosts an Active Directory-integrated zone for the domain. You need to reduce how long it takes until stale records are deleted from the zone.

    What should you do?

    A. From the configuration directory partition of the forest, modify the tombstone lifetime.
    B. From the configuration directory partition of the forest, modify the garbage collection interval.
    C. From the aging properties of the zone, modify the no-refresh interval and the refresh interval.
    D. From the start of authority (SOA) record of the zone, modify the refresh interval and the expire interval.

  • Question 274:

    Your network contains an Active Directory forest. The forest contains multiple sites.

    You need to enable universal group membership caching for a site.

    What should you do?

    A. From Active Directory Sites and Services, modify the NTDS Settings.
    B. From Active Directory Sites and Services, modify the NTDS Site Settings.
    C. From Active Directory Users and Computers, modify the properties of all universal groups used in the site.
    D. From Active Directory Users and Computers, modify the computer objects for the domain controllers in the site.

  • Question 275:

    Your network contains two Active Directory forests named contoso.com and fabrikam.com. The contoso.com forest contains a server named Server1l that has the Certification Authority role service installed.

    You need to ensure that Windows 7 client computers in the fabrikam.com forest can enroll for certificates from Server1. The solution must minimize the number of role services installed on Server1.

    Which additional role service or role services should you install? To answer, select the appropriate role service or role services in the answer area.

    Hot Area:

  • Question 276:

    A corporate network includes an Active Directory Domain Services (AD DS) forest that contains two domains. All servers run Windows Server 2008 R2. All domain controllers are configured as DNS servers.

    A standard primary zone for dev.contoso.com is stored on a member server. You need to ensure that all domain controllers can resolve names from the dev.contoso.com zone.

    What should you do?

    A. On one domain controller, create a secondary zone.
    B. On the member server, create a secondary zone.
    C. On each domain controller, create a secondary zone.
    D. On one domain controller, create a conditional forwarder. Configure the conditional forwarder to replicate to all DNS servers in the domain.

  • Question 277:

    ABC.com has an Active Directory forest on a single domain. The domain operates Windows Server 2008. A new administrator accidentally deletes the entire organizational unit in the Active Directory database that hosts 6000 objects.

    You have backed up the system state data using third-party backup software. To restore backup, you start the domain controller in the Directory Services Restore Mode (DSRM). You need to perform an authoritative restore of the organizational unit and restore the domain controller to its original state.

    Which three actions should you perform?

    Select and Place:

  • Question 278:

    Your network contains an Active Directory forest named fabrikam.com. The forest contains the following domains:

    Fabrikam.com

    Eu.fabrikam.com

    Na.fabrikam.com

    Eu.contoso.com

    Na.contoso.com

    You need to configure the forest to ensure that the administrators of any of the domains can specify a user principal name (UPN) suffix of contoso.com when they create user accounts from Active Directory users and Computers.

    Which tool should you use?

    A. Active Directory Users and Computers
    B. Set-ADAccountControl
    C. Set-ADForest
    D. New-ADObject

  • Question 279:

    Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2008 R2. The functional level of the domain is Windows Server 2008 R2. The functional level of the forest is Windows Server 2008.

    You have a member server named Server1 that runs Windows Server 2008.

    You need to ensure that you can add Server1 to contoso.com as a domain controller.

    What should you run before you promote Server1?

    A. dcpromo.exe /CreateDCAccount
    B. dcpromo.exe /ReplicaOrNewDomain:replica
    C. Set-ADDomainMode -Identity contoso.com -DomainMode Windows2008Domain
    D. Set-ADForestMode -Identity contoso.com -ForestMode Windows2008R2Forest

  • Question 280:

    Your network contains an Active Directory domain named contoso.com. The domain has one Active Directory site.

    The domain contains an organizational unit (OU) named 0U1. OU1 contains user accounts for 100 users and their managers.

    You apply a Group Policy object (GPO) named GPO1 to OU1. GPO1 restricts several desktop settings.

    The managers request that the desktop settings not be applied to them. You need to prevent the desktop settings in GPO1 from being applied to the managers. All other users in OU1 must have GPO1 applied to them.

    What should you do?

    A. Link GPO1 to the site and remove the link for GPO1 from OU1.
    B. Move the managers to a child OU of OU1 and block inheritance on the child OU.
    C. Configure the permissions on OU1.
    D. Disable the computer configurations of GPO1.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Microsoft exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 70-640 exam preparations and Microsoft certification application, do not hesitate to visit our Vcedump.com to find your solutions here.