70-640 Exam Details

  • Exam Code
    :70-640
  • Exam Name
    :TS: Windows Server 2008 Active Directory Configuring
  • Certification
    :Microsoft Certifications
  • Vendor
    :Microsoft
  • Total Questions
    :631 Q&As
  • Last Updated
    :Dec 15, 2021

Microsoft 70-640 Online Questions & Answers

  • Question 331:

    You need to compact an Active Directory database on a domain controller that runs Windows Server 2008 R2.

    What should you do?

    A. Run defrag.exe /a /c.
    B. Run defrag.exe /c /u.
    C. From Ntdsutil, use the Files option.
    D. From Ntdsutil, use the Metadata cleanup option.

  • Question 332:

    Your network contains an Active Directory forest named contoso.com. The forest contains a single domain. The domain contains 50 domain controllers that run Windows Server 2008 R2.

    The domain contains a group named Computer_Location.

    You plan to create 1,000 computer accounts in the domain in several organizational units (OUs). You need to ensure that the members of the Computer_Location group can modify the description of each computer account as soon as the

    account is created.

    The solution must use permissions that are applied explicitly to the new computer accounts.

    What should you do?

    A. Run the dsadd.exe command
    B. Run the nltest.exe command.
    C. Run the Set-AdDomain cmdlet.
    D. Run the dsmove.exe command.
    E. Run the dcpromo.exe command.
    F. Run the Move-AdDirectoryServer cmdlet.
    G. Use the Active Directory Schema snap-in.
    H. Use the Active Directory Users and Computers console.

  • Question 333:

    A corporate network includes a single Active Directory Domain Services (AD DS) domain.

    The HR department has a dedicated organizational unit (OU) named HR. The HR OU has two sub- OUs: HR Users and HR Computers. User accounts for the HR department reside in the HR Users OU. Computer accounts for the HR department reside in the HR Computers OU. All HR department employees belong to a security group named HR Employees. All HR department computers belong to a security group named HR PCs.

    Company policy requires that passwords are a minimum of 6 characters. You need to ensure that, the next time HR department employees change their passwords, the passwords are required to have at least 8 characters. The password length requirement should not change for employees of any other department.

    What should you do?

    A. Modify the password policy in the GPO that is applied to the domain.
    B. Create a new GPO, with the necessary password policy, and link it to the HR Users OU.
    C. Create a new GPO, with the necessary password policy, and link it to the HR Computers OU.
    D. Modify the password policy in the GPO that is applied to the domain controllers OU.

  • Question 334:

    You are decommissioning domain controllers that hold all forest-wide operations master roles.

    You need to transfer all forest-wide operations master roles to another domain controller.

    Which two roles should you transfer? (Each correct answer presents part of the solution. Choose two.)

    A. Domain naming master
    B. Infrastructure master
    C. RID master
    D. PDC emulator
    E. Schema master

  • Question 335:

    Your network contains an Active Directory domain named contoso.com.

    You create two global groups named Group1 and Group2. The group membership of each group is shown in the following table.

    You create the Password Settings objects (PSOs) shown in the following table.

    In the table below, identify which PSOs will apply to User1 and User2. Make only one selection in each column.

    Hot Area:

  • Question 336:

    Your network contains a single Active Directory domain. The domain contains an enterprise certification authority (CA).

    You need to ensure that the encryption keys for e-mail certificates can be recovered from the CA database.

    You modify the e-mail certificate template to support key archival.

    What should you do next?

    A. Issue the key recovery agent certificate template.
    B. Run certutil.exe -recoverkey.
    C. Run certreq.exe-policy.
    D. Modify the location of the Authority Information Access (AIA) distribution point.

  • Question 337:

    Your network contains a single Active Directory domain. The functional level of the forest is Windows Server 2008 R2.

    You need to enable the Active Directory Recycle Bin.

    What should you use?

    A. the Dsmod tool
    B. the Enable-ADOptionalFeature cmdlet
    C. the Ntdsutil tool
    D. the Set-ADDomainMode cmdlet

  • Question 338:

    Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1. Server1 has the Active Directory Federation Services (AD FS) role installed. You have an application named App1 that is configured to use Server1 for AD FS authentication. You deploy a new server named Server2. Server2 is configured as an AD FS 2.0 server.

    You need to ensure that App1 can use Server2 for authentication.

    What should you do on Server2?

    A. Add an attribute store.
    B. Create a relying party trust.
    C. Create a claims provider trust.
    D. Create a relaying provider trust.

  • Question 339:

    Your network contains an Active Directory domain. The domain contains five sites. One of the sites contains a read-only domain controller (RODC) named RODC1.

    You need to identify which user accounts can have their password cached on RODC1.

    Which tool should you use?

    A. Get-ADFineGrainedPasswordPolicy
    B. Dcdiag
    C. Get-ADDomamControllerPasswordReplicationPolicy
    D. Get-ADAccountResultantPasswordReplicationPolicy

  • Question 340:

    ABC.com has a network that is comprise of a single Active Directory Domain. As an administrator at ABC.com, you install Active Directory Lightweight Directory Services (AD LDS) on a server that runs Windows Server 2008. To enable Secure Sockets Layer (SSL) based connections to the AD LDS server, you install certificates from a trusted Certification Authority (CA) on the AD LDS server and client computers.

    Which tool should you use to test the certificate with AD LDS?

    A. Ldp.exe
    B. Active Directory Domain services
    C. ntdsutil.exe
    D. Lds.exe
    E. wsamain.exe
    F. None of the above

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Microsoft exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 70-640 exam preparations and Microsoft certification application, do not hesitate to visit our Vcedump.com to find your solutions here.