70-640 Exam Details

  • Exam Code
    :70-640
  • Exam Name
    :TS: Windows Server 2008 Active Directory Configuring
  • Certification
    :Microsoft Certifications
  • Vendor
    :Microsoft
  • Total Questions
    :631 Q&As
  • Last Updated
    :Dec 15, 2021

Microsoft 70-640 Online Questions & Answers

  • Question 521:

    Your network contains an Active Directory domain named contoso.com. The contoso.com domain contains a domain controller named DC1.

    You create an Active Directory-integrated GlobalNames zone. You add an alias (CNAME) resource record named Server1 to the zone. The target host of the record is server2.contoso.com. When you ping Server1, you discover that the name fails to resolve. You are able to successfully ping server2.contoso.com.

    You need to ensure that you can resolve names by using the GlobalNames zone.

    Which command should you run?

    A. Dnscmd DCl.contoso.com /ZoneAdd GlobalNames /DsPrimary /DP /domain
    B. Dnscmd DCl.contoso.com /config /Enableglobalnamessupport forest
    C. Dnscmd DCl.contoso.com /config /Enableglobalnamessupport 1
    D. Dnscmd DCl.contoso.com /ZoneAdd GlobalNames /DsPrimary /DP /forest

  • Question 522:

    Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named DC1. DC1 hosts a standard primary zone for contoso.com. You discover that non-domain member computers register records in the contoso.com zone. You need to prevent the non-domain member computers from registering records in the contoso.com zone.

    All domain member computers must be allowed to register records in the contoso.com zone.

    What should you do first?

    A. Configure a trust anchor.
    B. Run the Security Configuration Wizard (SCW).
    C. Change the contoso.com zone to an Active Directory-integrated zone.
    D. Modify the security settings of the %SystemRoot%\System32\Dns folder.

  • Question 523:

    Your network contains an Active Directory domain named contoso.com. The Active Directory sites are configured as shown in the Sites exhibit. (Click the Exhibit button.)

    You need to ensure that DC1 and DC4 are the only servers that replicate Active Directory changes between the sites.

    What should you do?

    A. Configure DC1 as a preferred bridgehead server for IP transport.
    B. Configure DC4 as a preferred bridgehead server for IP transport.
    C. From the DC4 server object, create a Connection object for DC1.
    D. From the DC1 server object, create a Connection object for DC4.

  • Question 524:

    Your network consists of a single Active Directory domain. You have a domain controller and a member server that run Windows Server 2008 R2. Both servers are configured as DNS servers. Client computers run either Windows XP Service Pack 3 or Windows 7.

    You have a standard primary zone on the domain controller. The member server hosts a secondary copy of the zone.

    You need to ensure that only authenticated users are allowed to update host (A) records in the DNS zone.

    What should you do first?

    A. On the member server, add a conditional forwarder.
    B. On the member server, install Active Directory Domain Services.
    C. Add all computer accounts to the DNS UpdateProxy group.
    D. Convert the standard primary zone to an Active Directory-integrated zone.

  • Question 525:

    Your network contains an Active Directory forest named contoso.com. You need to create an Active Directory Rights Management Services (AD RMS) licensingonly cluster. What should you do? To answer, move the appropriate actions from the Possible Actions list to the Necessary Actions area and arrange them in the correct order.

    Select and Place:

  • Question 526:

    You need to remove the Active Directory Domain Services role from a domain controller named DC1.

    What should you do?

    A. Run the netdom remove DC1 command.
    B. Run the Dcpromo utility. Remove the Active Directory Domain Services role.
    C. Run the nltest /remove_server: DC1 command.
    D. Reset the Domain Controller computer account by using the Active Directory Users and Computers utility.

  • Question 527:

    Your company has an Active Directory domain. All servers run Windows Server.

    You deploy a Certification Authority (CA) server.

    You create a new global security group named CertIssuers.

    You need to ensure that members of the CertIssuers group can issue, approve, and revoke certificates.

    What should you do?

    A. Assign the Certificate Manager role to the CertIssuers group
    B. Place CertIssuers group in the Certificate Publisher group
    C. Run the certsrv -add CertIssuers command promt of the certificate server
    D. Run the add -member-membertype memberset CertIssuers command by using Microsoft Windows Powershell

  • Question 528:

    Your network consists of a single Active Directory domain. All domain controllers run Windows Server 2003.

    You upgrade all domain controllers to Windows Server 2008. You need to configure the Active Directory environment to support the application of multiple password policies.

    What should you do?

    A. Raise the functional level of the domain to Windows Server 2008.
    B. On one domain controller, run dcpromo /adv.
    C. Create multiple Active Directory sites.
    D. On all domain controllers, run dcpromo /adv.

  • Question 529:

    Your company has a main office and three branch offices. The company has an Active Directory forest that has a single domain. Each office has one domain controller. Each office is configured as an Active Directory site.

    All sites are connected with the DEFAULTIPSITELINK object. You need to decrease the replication latency between the domain controllers.

    What should you do?

    A. Decrease the replication schedule for the DEFAULTIPSITELINK object.
    B. Decrease the replication interval for the DEFAULTIPSITELINK object.
    C. Decrease the cost between the connection objects.
    D. Decrease the replication interval for all connection objects.

  • Question 530:

    Your company has an organizational unit named Production. The Production organizational unit has a child organizational unit named RandD. You create a GPO named Software Deployment and link it to the Production organizational unit.

    You create a shadow group for the RandD organizational unit. You need to deploy an application to users in the Production organizational unit.

    You also need to ensure that the application is not deployed to users in the RandD organizational unit.

    What are two possible ways to achieve this goal? (Each correct answer presents a complete solution. Choose two.)

    A. Configure the Block Inheritance setting on the RandD organizational unit.
    B. Configure the Enforce setting on the software deployment GPO.
    C. Configure security filtering on the Software Deployment GPO to Deny Apply group policy for the RandD security group.
    D. Configure the Block Inheritance setting on the Production organizational unit.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Microsoft exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 70-640 exam preparations and Microsoft certification application, do not hesitate to visit our Vcedump.com to find your solutions here.