70-640 Exam Details

  • Exam Code
    :70-640
  • Exam Name
    :TS: Windows Server 2008 Active Directory Configuring
  • Certification
    :Microsoft Certifications
  • Vendor
    :Microsoft
  • Total Questions
    :631 Q&As
  • Last Updated
    :Dec 15, 2021

Microsoft 70-640 Online Questions & Answers

  • Question 451:

    Your network contains an enterprise root certification authority (CA). You need to ensure that a certificate issued by the CA is valid. What should you do?

    A. Run syskey.exe and use the Update option.
    B. Run sigverif.exe and use the Advanced option.
    C. Run certutil.exe and specify the -verify parameter.
    D. Run certreq.exe and specify the -retrieve parameter.

  • Question 452:

    Your network contains an Active Directory domain. All domain controllers run Windows Server 2008. The functional level of the domain is Windows Server 2003.

    All client computers run Windows 7. You install Windows Server 2008 R2 on a server named Server1.

    You need to perform an offline domain join of Server1.

    Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)

    A. From Server1, run djoin.exe.
    B. From Server1, run netdom.exe.
    C. From a Windows 7 computer, run djoin.exe.
    D. Upgrade one domain controller to Windows Server 2008 R2.
    E. Raise the functional level of the domain to Windows Server 2008.

  • Question 453:

    Your network contains two Active Directory forests named contoso.com and fabrikam.com. Each forest contains a single domain.

    A two-way forest trust exists between the forests. Selective authentication is enabled on the trust.

    Contoso.com contains a group named Group 1.

    Fabrikam.com contains a server named Server1.

    You need to ensure that users in Group1 can access resources on Server1.

    What should you modify?

    A. the permissions of the Group1 group
    B. the UPN suffixes of the contoso.com forest
    C. the UPN suffixes of the fabrikam.com forest
    D. the permissions of the Server1 computer account

  • Question 454:

    ABC.com has a network that consists of a single Active Directory domain.Windows Server 2008 is installed on all domain controllers in the network.

    You are instructed to capture all replication errors from all domain controllers to a central location.

    What should you do to achieve this task?

    A. Initiate the Active Directory Diagnostics data collector set
    B. Set event log subscriptions and configure it
    C. Initiate the System Performance data collector set
    D. Create a new capture in the Network Monitor

  • Question 455:

    Your company has an Active Directory forest. You plan to install an Enterprise certification authority (CA) on a dedicated stand-alone server.

    When you attempt to add the Active Directory Certificate Services (AD CS) server role, you find that the EnterpriseCA option is not available.

    You need to install the AD CS server role as an EnterpriseCA.

    What should you do first?

    A. Add the DNS Server server role.
    B. Add the Active Directory Lightweight Directory Services (AD LDS) server role.
    C. Join the server to the domain.
    D. Add the Web Server (IIS) server role and the AD CS server role.

  • Question 456:

    Your network contains an Active Directory forest. The forest contains two domains named contoso.com and east.contoso.com.

    The contoso.com domain contains a domain controller named DC1. The east.contoso.com domain contains a domain controller namedDC2. DC1 and DC2 have the DNS Server server role installed.

    You need to create a DNS zone that is available on DC1 and DC2. The solution must ensure that zone transfers are encrypted. What should you do?

    A. Create a primary zone on DC1 and store the zone in a zone file. Configure IPSec on DC1 and DC2. Create a secondary zone on DC2 and select DC1 as the master.
    B. Create a primary zone on DC1 and store the zone in the DC=DomainDNSZones,DC=Contoso,DC=com naming context. Create a secondary zone on DC2 and select DC1 as the master.
    C. Create a primary zone on DC1 and store the zone in a zone file. Configure Encrypting File System (EFS) encryption. Create a secondary zone on DC2 and select DC1 as the master.
    D. Create a primary zone on DC1 and store the zone in the DC=Contoso,DC=com naming context. Create a secondary zone on DC2 and select DC1 as the master.

  • Question 457:

    You create a new Active Directory domain. The functional level of the domain is Windows Server 2008 R2. The domain contains five domain controllers.

    You need to monitor the replication of the group policy template files.

    Which tool should you use?

    A. Dfsrdiag
    B. Fsutil
    C. Ntdsutil
    D. Ntfrsutl

  • Question 458:

    Your network contains 50 domain controllers that runs Windows Server 2008 R2. You need to create a script that resets the Directory Services Restore Mode (DSRM) password on all of the domain controllers. The solution must NOT maintain passwords in the script.

    Which two tools should you use? (Each correct answer presents part of the solution. Choose two.)

    A. Active Directory Users and Computers
    B. Ntdsutil
    C. Dsamain
    D. Local Users and Groups

  • Question 459:

    Your network contains an Active Directory domain named contoso.com. The domain contains a file server named Server1. Server1 has a shared folder named Profiles.

    You plan to create a new user template named User_Template. You need to ensure that when you copy User_Temptate, the new user account has a unique profile folder created in the Profiles share.

    Which value should you specify for the profile path?

    A. %Userprofile%\Server1\profiles
    B. \\Server1\profiles\%username%
    C. \\Server1\%userprofile%\
    D. \\Server1\profiles\username

  • Question 460:

    Your company has an Active Directory domain.

    You plan to install the Active Directory Certificate Services (AD CS) server role on a member server that runs Windows Server 2008 R2.

    You need to ensure that members of the Account Operators group are able to issue smartcard credentials.They should not be able to revoke certificates.

    Which three actions should you perform? (Each correct answer presents part of the solution. Choose three.)

    A. Create an Enrollment Agent certificate.
    B. Create a Smartcard logon certificate.
    C. Restrict enrollment agents for the Smartcard logon certificate to the Account Operator group.
    D. Install the AD CS role and configure it as an Enterprise Root CA.
    E. Install the AD CS role and configure it as a Standalone CA.
    F. Restrict certificate managers for the Smartcard logon certificate to the Account Operator group.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Microsoft exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 70-640 exam preparations and Microsoft certification application, do not hesitate to visit our Vcedump.com to find your solutions here.