70-640 Exam Details

  • Exam Code
    :70-640
  • Exam Name
    :TS: Windows Server 2008 Active Directory Configuring
  • Certification
    :Microsoft Certifications
  • Vendor
    :Microsoft
  • Total Questions
    :631 Q&As
  • Last Updated
    :Dec 15, 2021

Microsoft 70-640 Online Questions & Answers

  • Question 501:

    Your network contains a single Active Directory domain. Active Directory Rights Management Services (AD RMS) is deployed on the network.

    A user named User1 is a member of only the AD RMS Enterprise Administrators group. You need to ensure that User1 can change the service connection point (SCP) for the AD RMS installation.The solution must minimize the administrative rights of User1.

    To which group should you add User1?

    A. AD RMS Auditors
    B. AD RMS Service Group
    C. Domain Admins
    D. Schema Admins

  • Question 502:

    Your network contains an Active Directory forest named contoso.com. The forest contains two Active Directory sites named Seattle and Montreal. The Montreal site is a branch office that contains only a single read-only domain controller

    (RODC).

    You accidentally delete the site link between the two sites.

    You recreate the site link while you are connected to a domain controller in Seattle.

    You need to replicate the change to the RODC in Montreal.

    Which node in Active Directory Sites and Services should you use?To answer, select the appropriate node in the answer area.

    Hot Area:

  • Question 503:

    You have a domain controller named DC1 that runs Windows Server 2008 R2. DC1 is configured as a DNS server for contoso.com.

    You install the DNS server server role on a member server named server1 and then you create a standard secondary zone for contoso.com. You configure DC1 as the master server for the zone. You need to ensure that Server1 receives zone updates from DC1.

    What should you do?

    A. On DC1, modify the permissions of contoso.com zone.
    B. On Server1, add a conditional forwarder.
    C. Add the Server1 computer account to the DNsUpdateProxy group.
    D. On DC1, modify the zone transfer settings for the contoso.com zone.

  • Question 504:

    Your company, Contoso, Ltd., has a main office and a branch office. The offices are connected by a WAN link. Contoso has an Active Directory forest that contains a single domain named ad.contoso.com.

    The ad.contoso.com domain contains one domain controller named DC1 that is located in the main office. DC1 is configured as a DNS server for the ad.contoso.com DNS zone. This zone is configured as a standard primary zone.

    You install a new domain controller named DC2 in the branch office. You install DNS on DC2. You need to ensure that DC2 can resolve DNS queries for ad.contoso.com in the event that a WAN link fails. The solution must prevent DC2 from

    updating records in ad.contoso.com.

    What should you do?

    A. Configure the DNS server on DC2 to forward requests to DC1.
    B. Convert the ad.contoso.com zone on DC1 to an Active Directory-integrated zone.
    C. Create a new secondary zone named ad.contoso.com on DC2.
    D. Create a new stub zone named ad.contoso.com on DC2.

  • Question 505:

    Your company has four offices. The network contains a single Active Directory domain. Each office has a domain controller. Each office has an organizational unit (OU) that contains the user accounts for the users in that office. In each office, support technicians perform basic troubleshooting for the users in their respective office.

    You need to ensure that the support technicians can reset the passwords for the user accounts in their respective office only. The solution must prevent the technicians from creating user accounts.

    What should you do?

    A. For each OU, run the Delegation of Control Wizard.
    B. For the domain, run the Delegation of Control Wizard.
    C. For each office, create an Active Directory group, and then modify the security settings for each group.
    D. For each office, create an Active Directory group, and then modify the controlAccessRights attribute for each group.

  • Question 506:

    Your network contains an Active Directory domain named adatum.com. The domain contains an enterprise certification authority (CA). When submitting a request for a certificate based on the EnrollmentAgent template, you receive the error message shown in the exhibit. (Click the Exhibit button.)

    You need to ensure that you can enroll for the certificate successfully. What should you modify?

    A. the Security settings of the issuing CA
    B. the Cryptography settings of the certificate template
    C. the Security settings of the certificate template
    D. the Enrollment Agents settings of the issuing CA

  • Question 507:

    Your network contains an Active Directory forest. The forest contains two domains named contoso.com and woodgrovebank.com. You have a custom attribute named Attributel in Active Directory. Attributel is associated to User objects. You need to ensure that Attributel is included in the global catalog.

    What should you do?

    A. From the Active Directory Schema snap-in, modify the properties of the Attributel attributeSchema object.
    B. In Active Directory Sites and Services, configure the Global Catalog settings for all domain controllers in the forest.
    C. In Active Directory Users and Computers, configure the permissions on the Attributel attribute for User objects.
    D. From the Active Directory Schema snap-in, modify the properties of the User classSchema object.

  • Question 508:

    Your network contains an Active Directory domain named adatum.com. The domain contains a domain controller named DC1. DC1 has an IP address of 192.168.200.100.

    You need to identify the zone that contains the Pointer (PTR) record for DC1.

    Which zone should you identify?

    A. adatum.com
    B. _msdcs.adatum.com
    C. 100.168.192.in-addr.arpa
    D. 200.168.192.in-addr.arpa

  • Question 509:

    Your network contains an Active Directory forest named contoso.com. The forest contains four child domains named east.contoso.com, west.contoso.com, south.contoso.com, and north.contoso.com.

    You need to create four new groups in the forest root domain. The groups must be configured as shown in the following table.

    What should you do? To answer, drag the appropriate group type to the correct group name in the answer area.

    Select and Place:

  • Question 510:

    You need to ensure that users who enter three successive invalid passwords within 5 minutes are locked out for 5 minutes.

    Which three actions should you perform? (Each correct answer presents part of the solution. Choose three.)

    A. Set the Minimum password age setting to one day.
    B. Set the Maximum password age setting to one day.
    C. Set the Account lockout duration setting to 5 minutes.
    D. Set the Reset account lockout counter after setting to 5 minutes.
    E. Set the Account lockout threshold setting to 3 invalid logon attempts.
    F. Set the Enforce password history setting to 3 passswords remembered.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Microsoft exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 70-640 exam preparations and Microsoft certification application, do not hesitate to visit our Vcedump.com to find your solutions here.