70-640 Exam Details

  • Exam Code
    :70-640
  • Exam Name
    :TS: Windows Server 2008 Active Directory Configuring
  • Certification
    :Microsoft Certifications
  • Vendor
    :Microsoft
  • Total Questions
    :631 Q&As
  • Last Updated
    :Dec 15, 2021

Microsoft 70-640 Online Questions & Answers

  • Question 411:

    Your network contains an Active Directory domain named contoso.com. The domain contains an enterprise certification authority (CA). You need to deploy certificates based on Version 1 templates to all of the computers in the domain. The

    solution must minimize administrative effort.

    You create a Group Policy object (GPO) named GPOl and link the GPO to the domain.

    What should you do next?

    A. In GPOl, configure Certificate Services Client - Certificate Enrollment Policy.
    B. Duplicate the templates. In GPOl, configure Certificate Services Client - Auto-Enrollment.
    C. Duplicate the templates. In GPOl, configure Automatic Certificate Request Settings.
    D. In GPOl, configure Certificate Services Client - Auto-Enrollment.

  • Question 412:

    Your network contains an Active Directory domain. The domain contains 20 domain controllers. You need to identify which domain controllers are global catalog servers. Which tool should you use?

    A. Netsh
    B. Dsquery
    C. Nltest
    D. Get-ADRootDSE

  • Question 413:

    Your network contains two Active Directory forests named contoso.com and adatum.com. Active Directory Rights Management Services (AD RMS) is deployed in contoso.com. An AD RMS trusted user domain (TUD) exists between contoso.com and adatum.com.

    From the AD RMS logs, you discover that some clients that have IP addresses in the adatum.com forest are authenticating as users from contoso.com.

    You need to prevent users from impersonating contoso.com users.

    What should you do?

    A. Configure trusted e-mail domains.
    B. Enable lockbox exclusion in AD RMS.
    C. Create a forest trust between adatum.com and contoso.com.
    D. Add a certificate from a third-party trusted certification authority (CA).

  • Question 414:

    Your network contains an Active Directory forest. The forest contains one domain named contoso.com.

    You discover the following event in the Event log of domain controllers: "The request for a new accountidentifier pool failed. The operation will be retried until the request succeeds. The error is " %1 ""

    You need to ensure that the domain controllers can acquire new account-identifier pools successfully.

    What should you do?

    A. Move the domain naming master role.
    B. Move the global catalog server.
    C. Restart the Active Directory Domain Services (AD DS) service.
    D. Deploy an additional global catalog server.
    E. Move the infrastructure master role.
    F. Move the PDC emulator role.
    G. Install a read-only domain controller (RODC).
    H. Move the RID master role.
    I. Move the bridgehead server.
    J. Move the schema master role.

  • Question 415:

    Your company has a main office and a branch office. The main office contains two domain controllers. You create an Active Directory site named BranchOfficeSite. You deploy a domain controller in the branch office, and then add the domain controller to the BranchOfficeSite site.

    You discover that users in the branch office are randomly authenticated by either the domain controller in the branch office or the domain controllers in the main office.

    You need to ensure that the users in the branch office always attempt to authenticate to the domain controller in the branch office first.

    What should you do?

    A. Create organizational units (OUs).
    B. Create Active Directory subnet objects.
    C. Modify the slow link detection threshold.
    D. Modify the Location attribute of the computer objects.

  • Question 416:

    Your network contains an Active Directory forest. The forest contains a single domain. You want to provide users from a domain that is located in another forest access to resources in your domain.

    You need to configure a trust between the domain in your forest and the domain in the other forest.

    What should you create?

    A. an incoming realm trust
    B. an incoming external trust
    C. an outgoing external trust
    D. an outgoing realm trust

  • Question 417:

    Your company has an Active Directory domain. The company has two domain controllers named DC1 and DC2. DC1 holds the Schema Master role.

    DC1 fails. You log on to Active Directory by using the administrator account. You are not able to transfer the Schema Master operations role.

    You need to ensure that DC2 holds the Schema Master role.

    What should you do?

    A. Configure DC2 as a bridgehead server.
    B. On DC2, seize the Schema Master role.
    C. Log off and log on again to Active Directory by using an account that is a member of the Schema Administrators group. Start the Active Directory Schema snap-in.
    D. Register the Schmmgmt.dll. Start the Active Directory Schema snap-in.

  • Question 418:

    Your network contains a single Active Directory domain. All servers run Windows Server 2008 R2.

    You deploy a new server that runs Windows Server 2008 R2. The server is not connected to the internal network.

    You need to ensure that the new server is already joined to the domain when it first connects to the internal network.

    What should you do?

    A. From a domain controller, run sysprep.exe and specify the /oobe parameter. From the new server, run sysprep.exe and specify the /generalize parameter.
    B. From a domain controller, run sysprep.exe and specify the /generalize parameter. From the new server, run sysprep.exe and specify the /oobe parameter.
    C. From a domain-joined computer, run djoin.exe and specify the /provision parameter. From the new server, run djoin.exe and specify the /requestodj parameter.
    D. From a domain-joined computer, run djoin.exe and specify the /requestodj parameter. From the new server, run djoin.exe and specify the /provision parameter.

  • Question 419:

    Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named DC1. DC1 has the DNS Server server role installed and hosts an Active Directory- integrated zone for contoso.com. The no-refresh interval is set to three days and the refresh interval is set to 10 days.

    The Advanced DNS settings of DC1 are shown in the Advanced DNS Settings exhibit. (Click the Exhibit button.)

    You open the properties of a static record named Server1 as shown in the Server1 Record exhibit. (Click the Exhibit button.)

    You discover that the scavenging process ran today, but the record for Server1 was not deleted. You run dnscmd.exe and specify the ageallrecords parameter.

    You need to identify when the record for Server1 will be deleted from the zone.

    In how many days will the record be deleted?

    A. 7
    B. 10
    C. 17
    D. 20

  • Question 420:

    A corporate network includes a single Active Directory Domain Services (AD D5) domain and two AD DS sites. The AD DS sites are named Toronto and Montreal.

    Each site has multiple domain controllers.

    You need to determine which domain controller holds the Inter-Site Topology Generator role for the Toronto site.

    What should you do?

    A. Use the Ntdsutil tool with the roles parameter.
    B. Use the Ntdsutil tool with the local roles parameter.
    C. Use the LDP tool to view the NTDS Site Settings for the Toronto site.
    D. Use the LDP tool to view the properties of each domain controller in the Toronto site

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Microsoft exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 70-640 exam preparations and Microsoft certification application, do not hesitate to visit our Vcedump.com to find your solutions here.