Microsoft 70-640 Online Practice
Questions and Exam Preparation
70-640 Exam Details
Exam Code
:70-640
Exam Name
:TS: Windows Server 2008 Active Directory Configuring
Certification
:Microsoft Certifications
Vendor
:Microsoft
Total Questions
:631 Q&As
Last Updated
:Dec 15, 2021
Microsoft 70-640 Online Questions &
Answers
Question 501:
Your network contains a single Active Directory domain. Active Directory Rights Management Services (AD RMS) is deployed on the network.
A user named User1 is a member of only the AD RMS Enterprise Administrators group. You need to ensure that User1 can change the service connection point (SCP) for the AD RMS installation.The solution must minimize the administrative rights of User1.
To which group should you add User1?
A. AD RMS Auditors B. AD RMS Service Group C. Domain Admins D. Schema Admins
C. Domain Admins
http://social.technet.microsoft.com/wiki/contents/articles/710.the-ad-rms-service-connection-point.aspx The AD RMS Service Connection Point
The Active Directory Rights Management Services (AD RMS) Service Connection Point (SCP) is an object in Active Directory that holds the web address of the AD RMS certification cluster. AD RMS- enabled applications use the SCP to
discover the AD RMS service; it is the first connection point for users to discover the AD RMS web services.
The AD RMS SCP can be registered automatically during AD RMS installation, or it can be registered after installation has completed. To register the SCP you must be a member of the local AD RMS Enterprise Administrators group and the
Active Directory Domain Services (AD DS) Enterprise Admins group, or you must have been given the appropriate authority.
Question 502:
Your network contains an Active Directory forest named contoso.com. The forest contains two Active Directory sites named Seattle and Montreal. The Montreal site is a branch office that contains only a single read-only domain controller
(RODC).
You accidentally delete the site link between the two sites.
You recreate the site link while you are connected to a domain controller in Seattle.
You need to replicate the change to the RODC in Montreal.
Which node in Active Directory Sites and Services should you use?To answer, select the appropriate node in the answer area.
Hot Area:
Reference 1: http://blogs.technet.com/b/ashleymcglone/archive/2011/06/29/report-and-edit-ad-site-links-frompowershellturboyour-ad-replication.aspx Site links are stored in the Configuration partition of the AD database.
To use Active Directory Sites and Services to force replication of the configuration partition to an RODC
1. Open the Active Directory Sites and Services snap-in (Dssite.msc).
2. Double-click Sites, double-click the name of the site that has the RODC, double-click Servers, double-click the name of the RODC, right-click NTDS Settings, and then click Replicate configuration to the selected DC.
3. Click OK to close the message indicating that AD DS has replicated the connections.
Question 503:
You have a domain controller named DC1 that runs Windows Server 2008 R2. DC1 is configured as a DNS server for contoso.com.
You install the DNS server server role on a member server named server1 and then you create a standard secondary zone for contoso.com. You configure DC1 as the master server for the zone. You need to ensure that Server1 receives zone updates from DC1.
What should you do?
A. On DC1, modify the permissions of contoso.com zone. B. On Server1, add a conditional forwarder. C. Add the Server1 computer account to the DNsUpdateProxy group. D. On DC1, modify the zone transfer settings for the contoso.com zone.
D. On DC1, modify the zone transfer settings for the contoso.com zone.
Modify Zone Transfer Settings You can use the following procedure to control whether a zone will be transferred to other servers and which servers can receive the zone transfer. To modify zone transfer settings using the Windows interface
1.
Open DNS Manager.
2.
Right-click a DNS zone, and then click Properties.
3.
On the Zone Transfers tab, do one of the following:
To disable zone transfers, clear the Allow zone transfers check box. To allow zone transfers, select the Allow zone transfers check box.
4.
If you allowed zone transfers, do one of the following:
To allow zone transfers to any server, click To any server. To allow zone transfers only to the DNS servers that are listed on the Name Servers tab, click Only to servers listed on the Name Servers tab.
To allow zone transfers only to specific DNS servers, click Only to the following servers, and then add the IP address of one or more DNS servers.
Question 504:
Your company, Contoso, Ltd., has a main office and a branch office. The offices are connected by a WAN link. Contoso has an Active Directory forest that contains a single domain named ad.contoso.com.
The ad.contoso.com domain contains one domain controller named DC1 that is located in the main office. DC1 is configured as a DNS server for the ad.contoso.com DNS zone. This zone is configured as a standard primary zone.
You install a new domain controller named DC2 in the branch office. You install DNS on DC2. You need to ensure that DC2 can resolve DNS queries for ad.contoso.com in the event that a WAN link fails. The solution must prevent DC2 from
updating records in ad.contoso.com.
What should you do?
A. Configure the DNS server on DC2 to forward requests to DC1. B. Convert the ad.contoso.com zone on DC1 to an Active Directory-integrated zone. C. Create a new secondary zone named ad.contoso.com on DC2. D. Create a new stub zone named ad.contoso.com on DC2.
B. Convert the ad.contoso.com zone on DC1 to an Active Directory-integrated zone.
Question 505:
Your company has four offices. The network contains a single Active Directory domain. Each office has a domain controller. Each office has an organizational unit (OU) that contains the user accounts for the users in that office. In each office, support technicians perform basic troubleshooting for the users in their respective office.
You need to ensure that the support technicians can reset the passwords for the user accounts in their respective office only. The solution must prevent the technicians from creating user accounts.
What should you do?
A. For each OU, run the Delegation of Control Wizard. B. For the domain, run the Delegation of Control Wizard. C. For each office, create an Active Directory group, and then modify the security settings for each group. D. For each office, create an Active Directory group, and then modify the controlAccessRights attribute for each group.
A. For each OU, run the Delegation of Control Wizard.
Reference 1: http://technet.microsoft.com/en-us/library/cc732524.aspx To delegate control of an organizational unit
1.
To open Active Directory Users and Computers, click Start, click Control Panel, double-click Administrative Tools, and then double-click Active Directory Users and Computers.
2.
To open Active Directory Users and Computers in Windows Server?2012, click Start, type dsa.msc.
3.
In the console tree, right-click the organizational unit (OU) for which you want to delegate control.
4.
Click Delegate Control to start the Delegation of Control Wizard, and then follow the instructions in the wizard.
Reference 2: http://technet.microsoft.com/en-us/library/dd145442.aspx Delegate the following common tasks The following are common tasks that you can select to delegate control of them: Reset user passwords and force password change at next logon
Question 506:
Your network contains an Active Directory domain named adatum.com. The domain contains an enterprise certification authority (CA). When submitting a request for a certificate based on the EnrollmentAgent template, you receive the error message shown in the exhibit. (Click the Exhibit button.)
You need to ensure that you can enroll for the certificate successfully. What should you modify?
A. the Security settings of the issuing CA B. the Cryptography settings of the certificate template C. the Security settings of the certificate template D. the Enrollment Agents settings of the issuing CA
B. the Cryptography settings of the certificate template
Question 507:
Your network contains an Active Directory forest. The forest contains two domains named contoso.com and woodgrovebank.com. You have a custom attribute named Attributel in Active Directory. Attributel is associated to User objects. You need to ensure that Attributel is included in the global catalog.
What should you do?
A. From the Active Directory Schema snap-in, modify the properties of the Attributel attributeSchema object. B. In Active Directory Sites and Services, configure the Global Catalog settings for all domain controllers in the forest. C. In Active Directory Users and Computers, configure the permissions on the Attributel attribute for User objects. D. From the Active Directory Schema snap-in, modify the properties of the User classSchema object.
A. From the Active Directory Schema snap-in, modify the properties of the Attributel attributeSchema object.
Question 508:
Your network contains an Active Directory domain named adatum.com. The domain contains a domain controller named DC1. DC1 has an IP address of 192.168.200.100.
You need to identify the zone that contains the Pointer (PTR) record for DC1.
Which zone should you identify?
A. adatum.com B. _msdcs.adatum.com C. 100.168.192.in-addr.arpa D. 200.168.192.in-addr.arpa
D. 200.168.192.in-addr.arpa
Reference 1:
MCTS 70-640 Cert Guide: Windows Server 2008 Active Directory, Configuring (Pearson IT Certification, 2010) page 57
Reverse lookup: This occurs when a client computer knows the IP address of another computer and requires its hostname, which can be found in the DNS server's PTR (pointer) resource record.
Reference 2:
MCTS 70-640 Cert Guide: Windows Server 2008 Active Directory, Configuring (Pearson IT Certification, 2010) page 45/730
You are configuring a reverse lookup zone for your network, which uses the Class C network address range of 192.168.5.0/24. Which of the following addresses should you use for the reverse lookup zone? a. 5.168.192.in-addr.arpa
b.
0.5.168.192.in-addr.arpa
c.
192.168.5.in-addr.arpa
d.
192.168.5.0.in-addr.arpa
The reverse lookup zone contains octets of the network portion of the IP address in reverse sequence and uses a special domain name ending in in-addr.arpa.
Thus the correct address is 5.168.192.in- addr.arpa. You do not use the host portion of the IP address, so 0.5.168.192.in-addr.arpa is incorrect. The octets must be specified in reverse sequence, so the other two choices are both incorrect.
Question 509:
Your network contains an Active Directory forest named contoso.com. The forest contains four child domains named east.contoso.com, west.contoso.com, south.contoso.com, and north.contoso.com.
You need to create four new groups in the forest root domain. The groups must be configured as shown in the following table.
What should you do? To answer, drag the appropriate group type to the correct group name in the answer area.
Select and Place:
Question 510:
You need to ensure that users who enter three successive invalid passwords within 5 minutes are locked out for 5 minutes.
Which three actions should you perform? (Each correct answer presents part of the solution. Choose three.)
A. Set the Minimum password age setting to one day. B. Set the Maximum password age setting to one day. C. Set the Account lockout duration setting to 5 minutes. D. Set the Reset account lockout counter after setting to 5 minutes. E. Set the Account lockout threshold setting to 3 invalid logon attempts. F. Set the Enforce password history setting to 3 passswords remembered.
C. Set the Account lockout duration setting to 5 minutes. D. Set the Reset account lockout counter after setting to 5 minutes. E. Set the Account lockout threshold setting to 3 invalid logon attempts.
Nowadays, the certification exams become more and more important and required by more and more
enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare
for the exam in a short time with less efforts? How to get a ideal result and how to find the
most reliable resources? Here on Vcedump.com, you will find all the answers.
Vcedump.com provide not only Microsoft exam questions,
answers and explanations but also complete assistance on your exam preparation and certification
application. If you are confused on your 70-640 exam preparations
and Microsoft certification application, do not hesitate to visit our
Vcedump.com to find your solutions here.