70-640 Exam Details

  • Exam Code
    :70-640
  • Exam Name
    :TS: Windows Server 2008 Active Directory Configuring
  • Certification
    :Microsoft Certifications
  • Vendor
    :Microsoft
  • Total Questions
    :631 Q&As
  • Last Updated
    :Dec 15, 2021

Microsoft 70-640 Online Questions & Answers

  • Question 541:

    Your network contains an Active Directory domain. The domain is configured as shown in the exhibit.

    You have a Group Policy Object (GPO) linked to the domain.

    You need to ensure that the settings in the GPO are not processed by user accounts or computer accounts in the Finance organizational unit (OU). You must achieve this goal by using the minimum amount of administrative effort.

    What should you do?

    A. Modify the Group Policy permissions.
    B. Configure WMI filtering.
    C. Enable block inheritance.
    D. Enable loopback processing in replace mode.
    E. Configure the link order.
    F. Configure Group Policy Preferences.
    G. Link the GPO to the Human Resources OU.
    H. Configure Restricted Groups.
    I. Enable loopback processing in merge mode.
    J. Link the GPO to the Finance OU.

  • Question 542:

    Your network contains an Active Directory forest named contoso.com. The forest contains a single domain. The domain contains two domain controllers named DC1 and DC2 that run Windows Server 2008 R2. DC1 is configured as the infrastructure master for contoso.com.

    You need to move the infrastructure master role from DC1 to DC2.

    What should you do?

    A. Run the dsadd.exe command
    B. Run the nltest.exe command
    C. Run the Set-AdDomain cmdlet.
    D. Run the dsmove.exe command.
    E. Run the dcpromo.exe command.
    F. Run the Move-AdDirectoryServer cmdlet.
    G. Use the Active Directory Schema snap-in.
    H. Use the Active Directory Users and Computers console.

  • Question 543:

    Your network consists of a single Active Directory domain. The domain contains 10 domain controllers. The domain controllers run Windows Server 2008 R2 and are configured as DNS servers.

    You plan to create a new Active Directory-integrated zone.

    You need to ensure that the new zone is only replicated to four of your domain controllers.

    What should you do first?

    A. From the command prompt, run dnscmd and specify the /createdirectorypartition parameter.
    B. Create a new delegation in the ForestDnsZones application directory partition.
    C. From the command prompt, run dnscmd and specify the /enlistdirectorypartition parameter.
    D. Create a new delegation in the DomainDnsZones application directory partition.

  • Question 544:

    Your network contains an Active Directory domain named contoso.com.

    The Zone Transfers settings of contoso.com are configured as shown in the Zone Transfers exhibit. (Click the Exhibit button.)

    The Name Servers settings of contoso.com are configured as shown in the Name Servers exhibit. (Click the Exhibit button.)

    To answer, complete each statement according to the information presented in the exhibits.

    Hot Area:

  • Question 545:

    Your network contains four domain controllers. The domain controllers are configured as shown in the following table.

    All of the domain controllers are configured to host an Active Directory-integrated zone for their respective domain.

    A GlobalNames zone is deployed in the fabrikam.com forest.

    You add a canonical (CNAME) record named Server1 to the GlobalNames zone.

    You discover that users in the contoso.com forest cannot resolve the name Server1. The users in fabrikam.com can resolve the name Server1.

    You need to ensure that the contoso.com users can resolve names in the GlobalNames zone.

    What should you do? (Each correct answer presents part of the solution. Choose two.)

    A. Run dnscmd.exe and specify the globalnamesqueryorder parameter on CONT-DC1 and CONT-DC2.
    B. Add service location (SRV) records named _globalnames to the _msdcs.contoso.com zone.
    C. Run dnscmd.exe and specify the enableglobalnamessupport parameter on CONT-DC1 and CONT- DC2.
    D. Run dnscmd.exe and specify the globalnamesqueryorder parameter on FABR-DC1 and FABR-DC2.
    E. Run dnscmd.exe and specify the enableglobalnamessupport parameter on FABR-DC1 and FABR- DC2.
    F. Add service location (SRV) records named _globalnames to the _msdcs.fabrikam.com zone.

  • Question 546:

    A corporate network contains a Windows Server 2008 R2 Active Directory forest. You need to add a user principal name (UPN) suffix to the forest. Which tool should you use?

    A. Active Directory module for Windows PowerShell
    B. Active Directory Administrative Center console
    C. Active Directory Sites and Services console
    D. Active Directory Users and Computers console

  • Question 547:

    Your network contains a server named Server1 that runs Windows Server 2008 R2. Server1 is configured as an Active Directory Federation Services (AD FS) 2.0 standalone server.

    You plan to add a new token-signing certificate to Server1.

    You import the certificate to the server as shown in the exhibit. (Click the Exhibit button.)

    When you run the Add Token-Signing Certificate wizard, you discover that the new certificate is unavailable.

    You need to ensure that you can use the new certificate for AD FS.

    What should you do?

    A. From the properties of the certificate, modify the Certificate Policy OIDs setting.
    B. Import the certificate to the AD FS 2.0 Windows Service personal certificate store.
    C. From the properties of the certificate, modify the Certificate purposes setting.
    D. Import the certificate to the local computer personal certificate store.

  • Question 548:

    Your network contains an Active Directory domain named contoso.com. Contoso.com contains three servers. The servers are configured as shown in the following table.

    You need to ensure that users can manually enroll and renew their certificates by using the Certificate Enrollment Web Service. Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)

    A. Configure the policy module settings.
    B. Configure the issuance requirements for the certificate templates.
    C. Configure the Certificate Services Client - Certificate Enrollment Policy Group Policy setting.
    D. Configure the delegation settings for the Certificate Enrollment Web Service application pool account.

  • Question 549:

    Your company has a main office and a branch office. All servers are located in the main office. The network contains an Active Directory forest named adatum.com. The forest contains a domain controller named MainDC that runs Windows Server 2008 R2 Enterprise and a member server named FileServer that runs Windows Server 2008 R2 Standard.

    You have a kiosk computer named Public_Computer that runs Windows 7. Public_Computer is not connected to the network.

    You need to join Public_Computer to the adatum.com domain.

    What should you do? To answer, move the appropriate actions from the Possible Actions list to the Necessary Actions area and arrange them in the correct order.

    Select and Place:

  • Question 550:

    You are the network administrator for a large company that has one main site and one branch office.

    Your company has a single Active Directory forest, ABC.com.

    You have a single domain controller named ServerA in the main site that has the DNS role installed.

    ServerA is configured as a primary DNS zone.

    You have decided to place a domain controller named ServerB in the remote site and implement the DNS role on that server.

    You want to configure DNS so that if the WAN link fails, users in both sites can still update records and resolve any DNS queries.

    How should you configure the DNS servers?

    A. Configure Server B as a secondary DNS server. Set replication to occur every 5 minutes.
    B. Configure Server B as s stub zone.
    C. Configure Server B as an Active Directory Integrated zone and convert Server A to an Active Directory Integrated zone.
    D. Configure Server A as an Active Directory Integrated zone and configure Server B as a secondary zone.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Microsoft exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 70-640 exam preparations and Microsoft certification application, do not hesitate to visit our Vcedump.com to find your solutions here.