70-640 Exam Details

  • Exam Code
    :70-640
  • Exam Name
    :TS: Windows Server 2008 Active Directory Configuring
  • Certification
    :Microsoft Certifications
  • Vendor
    :Microsoft
  • Total Questions
    :631 Q&As
  • Last Updated
    :Dec 15, 2021

Microsoft 70-640 Online Questions & Answers

  • Question 431:

    You deploy an Active Directory Federation Services (AD FS) Federation Service Proxy on a server namedServer1. You need to configure the Windows Firewall on Server1 to allow external users to authenticate by using AD FS. Which protocol should you allow on Server1?

    A. Kerberos
    B. SSL
    C. SMB
    D. RPC

  • Question 432:

    Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named Server1. Server1 has an IP address of 192.168.200.100.

    You need to view the Pointer (PTR) record for Server1.

    Which zone should you open in the DNS snap-in to view the record? To answer, select the appropriate zone in the answer area.

    Hot Area:

  • Question 433:

    You configure and deploy a Group Policy object (GPO) that contains AppLocker settings.

    You need to identify whether a specific application file is allowed to run on a computer.

    Which Windows PowerShell cmdlet should you use?

    A. Get-AppLockerFileInformation
    B. Get-GPOReport
    C. Get-GPPermissions
    D. Test-AppLockerPolicy

  • Question 434:

    Your network contains an Active Directory domain named contoso.com. You need to create a Group Policy object (GPO) that contains all of the settings included in the Windows Server 2008 R2 Security Baseline. The solution must minimize administrative effort.

    Which three actions should you perform in sequence? (To answer, move the appropriate three actions from the list of actions to the answer area and arrange them in the correct order.)

    Select and Place:

  • Question 435:

    A corporate network includes a single Active Directory Domain Services (AD D5) domain. All regular user accounts reside in an organizational unit (OU) named Employees. All administrator accounts reside in an OU named Admins.

    You need to ensure that any time an administrator modifies an employee's name in AD DS, the change is audited.

    What should you do first?

    A. Use the Auditpol.exe command-line tool to enable the directory services access auditing subcategory.
    B. Enable the Audit directory service access setting in the Default Domain Controllers Policy Group Policy Object.
    C. Create a Group Policy Object with the Audit directory service access setting enabled and link it to the Employees OU.
    D. Enable the Audit directory service access setting in the Default Domain Policy Group Policy Object.

  • Question 436:

    Your company has an Active Directory Rights Management Services (AD RMS) server. Users have Windows Vista computers. An Active Directory domain is configured at the Windows Server 2003 functional level.

    You need to configure AD RMS so that users are able to protect their documents.

    What should you do?

    A. Install the AD RMS client 2.0 on each client computer.
    B. Add the RMS service account to the local administrators group on the AD RMS server.
    C. Establish an e-mail account in Active Directory Domain Services (AD DS) for each RMS user.
    D. Upgrade the Active Directory domain to the functional level of Windows Server 2008.

  • Question 437:

    Your company has a main office and 50 branch offices. Each office contains multiple subnets. You need to automate the creation of Active Directory subnet objects.

    What should you use?

    A. the Dsadd tool
    B. the Netsh tool
    C. the New-ADObject cmdlet
    D. the New-Object cmdlet

  • Question 438:

    Your company has an Active Directory forest that contains multiple domain controllers. The domain controllers run Windows Server 2008.

    You need to perform an authoritative restore of a deleted organizational unit and its child objects.

    Which four actions should you perform in sequence? (To answer, move the appropriate four actions from the list of actions to the answer area, and arrange them in the correct order.)

    Select and Place:

  • Question 439:

    Contoso, Ltd. has an Active Directory domain named ad.contoso.com. Fabrikam, Inc. has an Active Directory domain named intranet.fabrikam.com. Fabrikam's security policy prohibits the transfer of internal DNS zone data outside the Fabrikam network.

    You need to ensure that the Contoso users are able to resolve names from the intranet.fabrikam.com domain.

    What should you do?

    A. Create a new stub zone for the intranet.fabrikam.com domain.
    B. Configure conditional forwarding for the intranet.fabrikam.com domain.
    C. Create a standard secondary zone for the intranet.fabrikam.com domain.
    D. Create an Active DirectoryCintegrated zone for the intranet.fabrikam.com domain.

  • Question 440:

    You need to force a domain controller to register all service location (SRV) resource records in DNS.

    Which command should you run?

    A. ipconfig.exe /registerdns
    B. net.exe stop dnscache and net.exe start dnscache
    C. net.exe stop netlogon and net.exe start netlogon
    D. regsvr32.exe dnsrslvr.dll

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Microsoft exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 70-640 exam preparations and Microsoft certification application, do not hesitate to visit our Vcedump.com to find your solutions here.