70-640 Exam Details

  • Exam Code
    :70-640
  • Exam Name
    :TS: Windows Server 2008 Active Directory Configuring
  • Certification
    :Microsoft Certifications
  • Vendor
    :Microsoft
  • Total Questions
    :631 Q&As
  • Last Updated
    :Dec 15, 2021

Microsoft 70-640 Online Questions & Answers

  • Question 371:

    Your network contains 10 domain controllers that run Windows Server 2008 R2. The network contains a member server that is configured to collect all of the events that occur on the domain controllers.

    You need to ensure that administrators are notified when a specific event occurs on any of the domain controllers. You want to achieve this goal by using the minimum amount of administrative effort.

    What should you do?

    A. From Event Viewer on the member server, create a subscription.
    B. From Event Viewer on each domain controller, create a subscription.
    C. From Event Viewer on the member server, run the Create Basic Task Wizard.
    D. From Event Viewer on each domain controller, run the Create Basic Task Wizard.

  • Question 372:

    Your network contains an enterprise certification authority (CA) that runs Windows Server 2008 R2 Enterprise.

    You need to ensure that all of the members of a group named Group1 can view the event log entries for Certificate Services.

    Which snap-in should you use?

    A. Certificate Templates
    B. Certification Authority
    C. Authorization Manager
    D. Active Directory Users and Computers
    E. TPM Management
    F. Security Templates
    G. Group Policy Management
    H. Enterprise PKI
    I. Certificates

  • Question 373:

    Your network contains an Active Directory forest. The forest contains two domains. The forest contains four domain controllers. The domain controllers are configured as shown in the following table.

    All user accounts are located in the child.contoso.com domain. Users in the child.contoso.com domain are members of several security groups in the contoso.com domain.

    Your company decides to change the naming standard of user accounts. You rename all of the user accounts to comply with the new standard. You discover that the old user names are listed in the members' list of the security groups in the

    contoso.com domain.

    You need to ensure that the members' list of the security groups in the contoso.com domain displays the new user names.

    What should you do?

    A. Transfer the PDC emulator role from DC2 to DC3.
    B. Configure DC5 as a global catalog server.
    C. Configure DC1 as a global catalog server.
    D. Transfer the infrastructure master role from DC3 to DC2.

  • Question 374:

    Your company has an Active Directory domain and an organizational unit. The organizational unit is named Web.

    You configure and test new security settings for Internet Information Service (IIS) Servers on a server named IISServerA.

    You need to deploy the new security settings only on the IIS servers that are members of the Web organizational unit.

    What should you do?

    A. Run secedit /configure /db iis.inf from the command prompt on IISServerA, then run secedit /configure /db webou.inf from the comand prompt.
    B. Export the settings on IISServerA to create a security template. Import the security template into a GPO and link the GPO to the Web organizational unit.
    C. Export the settings on IISServerA to create a security template. Run secedit /configure /db webou.inf from the comand prompt.
    D. Import the hisecws.inf file template into a GPO and link the GPO to the Web organizational unit.

  • Question 375:

    Your network contains an Active Directory domain named adatum.com.

    The password policy of the domain requires that the passwords for all user accounts be changed every 50 days.

    You need to create several user accounts that will be used by services. The passwords for these accounts must be changed automatically every 50 days.

    Which tool should you use to create the accounts?

    A. Active Directory Administrative Center
    B. Active Directory Users and Computers
    C. Active Directory Module for Windows PowerShell
    D. ADSI Edit
    E. Active Directory Domains and Trusts

  • Question 376:

    Your network contains an Active Directory domain. The domain is configured as shown in the exhibit. (Click the Exhibit button.)

    Each organizational unit (OU) contains over 500 user accounts. The Finance OU and the Human Resources OU contain several user accounts that are members of a universal group named Group1.

    You have a Group Policy object (GPO) linked to the domain.

    You need to prevent the GPO from being applied to the members of Group1 only.

    What should you do?

    A. Modify the Group Policy permissions.
    B. Enable block inheritance.
    C. Configure the link order.
    D. Enable loopback processing in merge mode.
    E. Enable loopback processing in replace mode.
    F. Configure WMI filtering.
    G. Configure Restricted Groups.
    H. Configure Group Policy Preferences.
    I. Link the GPO to the Finance OU.
    J. Link the GPO to the Human Resources OU.

  • Question 377:

    Your network contains two Active Directory forests named contoso.com and fabrikam.com. A two-way forest trust exists between the forests. Selective authentication is enabled on the trust.

    Fabrikam.com contains a server named Server1.

    You assign Contoso\Domain Users the Manage documents permission and the Print permission to a shared printer on Server1.

    You discover that users from contoso.com cannot access the shared printer on Server1. You need to ensure that the contoso.com users can access the shared printer on Server1.

    Which permission should you assign to Contoso\Domain Users.

    To answer, select the appropriate permission in the answer area.

    Hot Area:

  • Question 378:

    Your company has an Active Directory forest. The forest includes organizational units corresponding to the following four locations:

    London

    Chicago

    New York

    Madrid

    Each location has a child organizational unit named Sales. The Sales organizational unit contains all the users and computers from the sales department.

    The offices in London, Chicago, and New York are connected by T1 connections. The office in Madrid is connected by a 256-Kbps ISDN connection.

    You need to install an application on all the computers in the sales department. Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)

    A. Create a Group Policy Object (GPO) named OfficeInstall that assigns the application to users. Link the GPO to each Sales organizational unit.
    B. Disable the slow link detection setting in the Group Policy Object (GPO).
    C. Configure the slow link detection threshold setting to 1,544 Kbps (T1) in the Group Policy Object (GPO).
    D. Create a Group Policy Object (GPO) named OfficeInstall that assigns the application to the computers. Link the GPO to each Sales organizational unit.

  • Question 379:

    Your network contains an Active Directory domain. All DNS servers are domain controllers. You view the properties of the DNS zone as shown in the exhibit. (Click the Exhibit button.)

    You need to ensure that DNS records can only be updated by the computer that registered the record. What should you do first?

    A. Modify the Dynamic updates setting.
    B. Create a trust anchor.
    C. Modify the zone type.
    D. Modify the Advanced properties of the DNS server.

  • Question 380:

    Your company has two Active Directory forests named contoso.com and fabrikam.com. The company network has three DNS servers named DNS1, DNS2, and DNS3. The DNS servers are configured as shown in the following table.

    All computers that belong to the fabrikam.com domain have DNS3 configured as the preferred DNS server. All other computers use DNS1 as the preferred DNS server.

    Users from the fabrikam.com domain are unable to connect to the servers that belong to the contoso.com domain.

    You need to ensure users in the fabrikam.com domain are able to resolve all contoso.com queries.

    What should you do?

    A. Configure conditional forwarding on DNS1 and DNS2 to forward fabrikam.com queries to DNS3.
    B. Create a copy of the _msdcs.contoso.com zone on the DNS3 server.
    C. Create a copy of the fabrikam.com zone on the DNS1 server and the DNS2 server.
    D. Configure conditional forwarding on DNS3 to forward contoso.com queries to DNS1.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Microsoft exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 70-640 exam preparations and Microsoft certification application, do not hesitate to visit our Vcedump.com to find your solutions here.