70-640 Exam Details

  • Exam Code
    :70-640
  • Exam Name
    :TS: Windows Server 2008 Active Directory Configuring
  • Certification
    :Microsoft Certifications
  • Vendor
    :Microsoft
  • Total Questions
    :631 Q&As
  • Last Updated
    :Dec 15, 2021

Microsoft 70-640 Online Questions & Answers

  • Question 301:

    You need to relocate the existing user and computer objects in your company to different organizational units.

    What are two possible ways to achieve this goal? (Each correct answer presents a complete solution. Choose two.)

    A. Run the move-item command in the Microsoft Windows PowerShell utility.
    B. Run the Active Directory Users and Computers utility.
    C. Run the Dsmove utility.
    D. Run the Active Directory Migration Tool (ADMT).

  • Question 302:

    Company has servers on the main network that run Windows Server 2008. It also has two domain controllers.

    Active Directory services are running on a domain controller named CKDC1. You have to perform critical updates of Windows Server 2008 on CKDC1 without rebooting the server.

    What should you do to perform offline critical updates on CKDC1 without rebooting the server?

    A. Start the Active Directory Domain Services on CKDC1
    B. Disconnect from the network and start the Windows update feature
    C. Stop the Active Directory domain services and install the updates. Start the Active Directory domain services after installing the updates.
    D. Stop Active Directory domain services and install updates. Disconnect from the network and then connect again.
    E. None of the above

  • Question 303:

    You are the network administrator for the ABC Company.

    The ABC Company has all Windows Server 2008 R2 Active Directory domains and uses an Enterprise Root certificate server.

    You need to verify that revoked certificate data is highly available.

    What should you do?

    A. Implement a Group Policy Object(GPO) that has the Certificate Verification Enabled option.
    B. Using Network Load Balancing, implement an Online Certificate Status Protocol(OCSP) responder.
    C. Implement a Group Policy object(GPO) that enables the Online Certificate Status Protocol(OCSP) responder.
    D. Using Network Load Balancing, implement the Certificate Verification Enabled option.

  • Question 304:

    Your network contains two servers named Server1 and Server2 that run Windows Server 2008 R2. Server1 has the Active Directory Federation Services (AD FS) Federation Service role service installed.

    You plan to deploy AD FS 2.0 on Server2.

    You need to export the token-signing certificate from Server1, and then import the certificate to Server2.

    Which format should you use to export the certificate?

    A. Base-64 encoded X.509 (.cer)
    B. Cryptographic Message Syntax Standard PKCS #7 (.p7b)
    C. DER encoded binary X.509 (.cer)
    D. Personal Information Exchange PKCS #12 (.pfx)

  • Question 305:

    Your network contains an Active Directory domain. The domain contains two domain controllers named DC1 and DC2. DC1 hosts a standard primary DNS zone for the domain. Dynamic updates are enabled on the zone. DC2 hosts a standard secondary DNS zone for the domain.

    You need to configure DNS to allow only secure dynamic updates.

    What should you do first?

    A. On DC1 and DC2, configure a trust anchor.
    B. On DC1 and DC2, configure a connection security rule.
    C. On DC1, configure the zone transfer settings.
    D. On DC1, configure the zone to be stored in Active Directory.

  • Question 306:

    Your network contains an Active Directory domain named contoso.com. You have an organizational unit (OU) named Sales and an OU named Engineering.

    You have a Group Policy object (GPO) linked to the domain.

    You need to ensure that the settings in the GPO are not processed by user accounts or computer accounts in the Sales OU. You must achieve this goal by using the minimum amount of administrative effort.

    What should you do?

    A. Modify the Group Policy permissions.
    B. Enable block inheritance.
    C. Configure the link order.
    D. Enable loopback processing in merge mode.
    E. Enable loopback processing in replace mode.
    F. Configure WMI filtering.
    G. Configure Restricted Groups.
    H. Configure Group Policy Preferences.
    I. Link the GPO to the Sales OU.
    J. Link the GPO to the Engineering OU.

  • Question 307:

    You have an enterprise subordinate certification authority (CA).

    You have a custom Version 3 certificate template.

    Users can enroll for certificates based on the custom certificate template by using the Certificates console. The certificate template is unavailable for Web enrollment.

    You need to ensure that the certificate template is available on the Web enrollment pages.

    What should you do?

    A. Run certutil.exe pulse.
    B. Run certutil.exe installcert.
    C. Change the certificate template to a Version 2 certificate template.
    D. On the certificate template, assign the Autoenroll permission to the users.

  • Question 308:

    Your company, Contoso Ltd, has offices in North America and Europe. Contoso has an Active Directory forest that has three domains.

    You need to reduce the time required to authenticate users from the labs.eu.contoso.com domain when they access resources in the eng.na.contoso.com domain.

    What should you do?

    A. Decrease the replication interval for all Connection objects.
    B. Decrease the replication interval for the DEFAULTIPSITELINK site link.
    C. Set up a one-way shortcut trust from eng.na.contoso.com to labs.eu.contoso.com.
    D. Set up a one-way shortcut trust from labs.eu.contoso.com to eng.na.contoso.com.

  • Question 309:

    Your network contains an Active Directory domain named contoso.com.

    You need to create one password policy for administrators and another password policy for all other users.

    Which tool should you use?

    A. Ntdsutil
    B. Active Directory Users and Computers
    C. ADSI Edit
    D. Group Policy Management Console (GPMC)

  • Question 310:

    Your network contains an Active Directory domain named contoso.com. Contoso.com contains two domain controllers. The domain controllers are configured as shown in the following table.

    All client computers have IP addresses in the 10.1.2.1 to 10.1.2.240 range. You need to minimize the number of client authentication requests sent to DC2. What should you do?

    A. Create a new site named Site1. Create a new subnet object that has the 10.1.1.0/24 prefix and assign the subnet to Site1. Move DC1 to Site1.
    B. Create a new site named Site1. Create a new subnet object that has the 10.1.1.1/32 prefix and assign the subnet to Site1. Move DC1 to Site1.
    C. Create a new site named Site1. Create a new subnet object that has the 10.1.1.2/32 prefix and assign the subnet to Site1. Move DC2 to Site1.
    D. Create a new site named Site1. Create a new subnet object that has the 10.1.2.0/24 prefix and assign the subnet to Site1. Move DC2 to Site1.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Microsoft exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 70-640 exam preparations and Microsoft certification application, do not hesitate to visit our Vcedump.com to find your solutions here.