70-640 Exam Details

  • Exam Code
    :70-640
  • Exam Name
    :TS: Windows Server 2008 Active Directory Configuring
  • Certification
    :Microsoft Certifications
  • Vendor
    :Microsoft
  • Total Questions
    :631 Q&As
  • Last Updated
    :Dec 15, 2021

Microsoft 70-640 Online Questions & Answers

  • Question 311:

    Your network contains an Active Directory domain named contoso.com. The domain contains the servers shown in the following table.

    The functional level of the forest is Windows Server 2003. The functional level of the domain is Windows Server 2003.

    DNS1 and DNS2 host the contoso.com zone. All client computers run Windows 7 Enterprise.

    You need to ensure that all of the names in the contoso.com zone are secured by using DNSSEC.

    What should you do first?

    A. Change the functional level of the forest.
    B. Change the functional level of the domain.
    C. Upgrade DC1 to Windows Server 2008 R2.
    D. Upgrade DNS1 to Windows Server 2008 R2.

  • Question 312:

    Your network contains a server named Server1 that runs Windows Server 2008 R2 Standard. Server1 has the Active Directory Certificate Services (AD CS) role installed. You configure a certificate template named Template1 for autoenrollment. You discover that certificates are not being issued to any client computers.

    The event logs on the client computers do not contain any autoenrollment errors.

    You need to ensure that all of the client computers automatically receive certificates based on Template1.

    What should you do?

    A. Modify the Default Domain Policy Group Policy object (GPO).
    B. Modify the Default Domain Controllers Policy Group Policy object (GPO).
    C. Upgrade Server1 to Windows Server 2008 R2 Enterprise.
    D. Restart Certificate Services on Server1.

  • Question 313:

    Your network contains an Active Directory domain. The domain contains 5,000 user accounts. You need to disable all of the user accounts that have a description of Temp. You must achieve this goal by using the minimum amount of administrative effort.

    Which tools should you use? (Each correct answer presents part of the solution. Choose two.)

    A. Find
    B. Dsget
    C. Dsmod
    D. Dsadd
    E. Net accounts
    F. Dsquery

  • Question 314:

    Your network contains an Active Directory domain. All domain controller run Windows Server 2003.

    You replace all domain controllers with domain controllers that run Windows Server 2008 R2. You raise the functional level of the domain to Windows Server 2008 R2. You need to minimize the amount of SYSVOL replication traffic on the network.

    What should you do?

    A. Raise the functional level of the forest to Windows Server 2008 R2.
    B. Modify the path of the SYSVOL folder on all of the domain controllers.
    C. On a global catalog server, run repadmin.exe and specify the KCC parameter.
    D. On the domain controller that holds the primary domain controller (PDC) emulator FSMO role, run dfsrmig.exe.

  • Question 315:

    Your network contains a domain controller that runs Windows Server 2008 R2.

    You run the following command on the domain controller:

    dsamain.exe C dbpath c:\$SNAP_201006170326_VOLUMEC$\Windows\NTDS\ntds.dit C ldapport 389 -allowNonAdminAccess

    The command fails.

    You need to ensure that the command completes successfully.

    How should you modify the command?

    A. Change the value of the -dbpath parameter.
    B. Include the path to Dsamain.
    C. Change the value of the -ldapport parameter.
    D. Remove the CallowNonAdminAccess parameter.

  • Question 316:

    Your network contains an Active Directory forest. All client computers run Windows 7. The network contains a high-volume enterprise certification authority (CA).

    You need to minimize the amount of network bandwidth required to validate a certificate.

    What should you do?

    A. Configure an LDAP publishing point for the certificate revocation list (CRL).
    B. Configure an Online Certification Status Protocol (OCSP) responder.
    C. Modify the settings of the delta certificate revocation list (CRL).
    D. Replicate the certificate revocation list (CRL) by using Distributed File System (DFS).

  • Question 317:

    A corporate network includes an Active Directory-integrated zone. All DNS servers that host the zone are domain controllers.

    You add multiple DNS records to the zone.

    You need to ensure that the new records are available on all DNS servers as soon as possible.

    Which tool should you use?

    A. Ntdsutil
    B. Dnscmd
    C. Repadmin
    D. Nslookup

  • Question 318:

    Your network contains an enterprise certification authority (CA) that runs Windows Server 2008 R2 Enterprise.

    You enable key archival on the CA. The CA is configured to use custom certificate templates for Encrypted File System (EFS) certificates.

    You need to archive the private key for all new EFS certificates.

    Which snap-in should you use?

    A. Active Directory Users and Computers
    B. Authorization Manager
    C. Group Policy Management
    D. Enterprise PKI
    E. Security Templates
    F. TPM Management
    G. Certificates
    H. Certification Authority
    I. Certificate Templates

  • Question 319:

    A domain controller named DC4 runs Windows Server 2008 R2. DC4 is configured as a DNS server for fabrikam.com.

    You install the DNS Server server role on a member server named DNS1 and then you create a standard secondary zone for fabrikam.com. You configure DC4 as the master server for the zone.

    You need to ensure that DNS1 receives zone updates from DC4.

    What should you do?

    A. Add the DNS1 computer account to the DNSUpdateProxy group.
    B. On DC4, modify the permissions offabrikam.com zone.
    C. On DNS1, add a conditional forwarder.
    D. On DC4, modify the zone transfer settings for the fabrikam.com zone.

  • Question 320:

    Your network contains a server that has the Active Directory Lightweight Directory Services (AD LDS) role installed.

    You need to perform an automated installation of an AD LDS instance.

    Which tool should you use?

    A. Dism.exe
    B. Servermanagercmd.exe
    C. Adaminstall.exe
    D. Ocsetup.exe

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Microsoft exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 70-640 exam preparations and Microsoft certification application, do not hesitate to visit our Vcedump.com to find your solutions here.