70-640 Exam Details

  • Exam Code
    :70-640
  • Exam Name
    :TS: Windows Server 2008 Active Directory Configuring
  • Certification
    :Microsoft Certifications
  • Vendor
    :Microsoft
  • Total Questions
    :631 Q&As
  • Last Updated
    :Dec 15, 2021

Microsoft 70-640 Online Questions & Answers

  • Question 551:

    You create a user account template for the marketing department. When you copy the user account template, you discover that the Web page attribute is not copied.

    You need to preserve the Web page attribute when you copy the user account template.

    What should you do?

    A. From Active Directory Administrative Center, modify the value of the wWWHomePage attribute for the user account template.
    B. From the Active Directory Schema snap-in, modify the properties of the user class.
    C. From Active Directory Users and Computers, modify the value of the wWWHomePage attribute for the user account template.
    D. From ADSI Edit, modify the properties of the wWWHomePage attribute.

  • Question 552:

    Your company has two Active Directory forests named Forest1 and Forest2, The forest functional level and the domain functional level of Forest1 are set to Windows Server 2008.

    The forest functional level of Forest2 is set to Windows 2000, and the domain functional levels in Forest2 are set to Windows Server 2003.

    You need to set up a transitive forest trust between Forest1 and Forest2.

    What should you do first?

    A. Raise the forest functional level of Forest2 to Windows Server 2003 Interim mode.
    B. Raise the forest functional level of Forest2 to Windows Server 2003.
    C. Upgrade the domain controllers in Forest2 to Windows Server 2008.
    D. Upgrade the domain controllers in Forest2 to Windows Server 2003.

  • Question 553:

    You have a standard primary zone named contoso.com.

    You need to configure how often the zone will be transferred to servers that host a secondary copy of the zone.

    Which tab should you use? To answer, select the appropriate tab in the answer area.

    Hot Area:

  • Question 554:

    Your network contains an Active Directory domain. The domain contains eight domain controllers.

    You need to verify that all the domain controllers can connect to the time server.

    Which command should you run?

    A. netdom.exe query fsmo
    B. dcdiag.exe /e /test:Topology
    C. repadmin.exe /showrepl *
    D. dcdiag.exe /a

  • Question 555:

    Your network contains an Active Directory forest. All domain controllers run Windows Server 2008 Standard.

    The functional level of the domain is Windows Server 2003.

    You have a certification authority (CA).

    The relevant servers in the domain are configured as shown below:

    You need to ensure that you can install the Active Directory Certificate Services (AD CS) Certificate Enrollment Web Service on the network.

    What should you do?

    A. Upgrade Server1 to Windows Server 2008 R2.
    B. Upgrade Server2 to Windows Server 2008 R2.
    C. Raise the functional level of the domain to Windows Server 2008.
    D. Install the Windows Server 2008 R2 Active Directory Schema updates.

  • Question 556:

    Active Directory Rights Management Services (AD RMS) is deployed on your network. You need to configure AD RMS to use Kerberos authentication. Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)

    A. Register a service principal name (SPN) for AD RMS.
    B. Register a service connection point (SCP) for AD RMS.
    C. Configure the identity setting of the _DRMSAppPool1 application pool.
    D. Configure the useAppPoolCredentials attribute in the Internet Information Services (IIS) metabase.

  • Question 557:

    Your network contains three servers named ADFS1, ADFS2, and ADFS3 that run Windows Server 2008 R2. ADFS1 has the Active Directory Federation Services (AD FS) Federation Service role service installed.

    You plan to deploy AD FS 2.0 on ADFS2 and ADFS3.

    You need to export the token-signing certificate from ADFS1, and then import the certificate to ADFS2 and ADFS3.

    In which format should you export the certificate?

    A. Personal Information Exchange PKCS #12 (.pfx)
    B. DER encoded binary X.509 (.cer)
    C. Cryptographic Message Syntax Standard PKCS #7 (.p7b)
    D. Base-64 encoded X.S09 (.cer)

  • Question 558:

    Your network contains an Active Directory forest named contoso.com. The functional level of the forest is Windows Server 2008 R2.

    The DNS zone for contoso.com is Active Directory-integrated. You deploy a read-only domain controller (RODC) named RODC1. You install the DNS Server server role on RODC1.

    You discover that RODC1 does not have any DNS application directory partitions.

    You need to ensure that RODC1 has a copy of the DNS application directory partition of contoso.com.

    What should you do? (Each correct answer presents a complete solution. Choose two.)

    A. From DNS Manager, right-click RODC1 and click Create Default Application Directory Partitions.
    B. Run ntdsutil.exe. From the Partition Management context, run the create nc command.
    C. Run dnscmd.exe and specify the /createbuiltindirectorypartitions parameter.
    D. Run ntdsutil.exe. From the Partition Management context, run the add nc replica command.
    E. Run dnscmd.exe and specify the /enlistdirectorypartition parameter.

  • Question 559:

    Your company has a server that runs Windows Server 2008 R2. The server runs an instance of ActiveDirectory Lightweight Directory Services (AD LDS).

    You need to replicate the AD LDS instance on a test computer that is located on the network.

    What should you do?

    A. Run the repadmin /kcc command on the test computer.
    B. Create a naming context by running the Dsmgmt command on the test computer.
    C. Create a new directory partition by running the Dsmgmt command on the test computer.
    D. Create and install a replica by running the AD LDS Setup wizard on the test computer.

  • Question 560:

    You install a standalone root certification authority (CA) on a server named Server1. You need to ensure that every computer in the forest has a copy of the root CA certificate installed in the local computer's Trusted Root Certification Authorities store.

    Which command should you run on Server1?

    A. certreq.exe and specify the -accept parameter
    B. certreq.exe and specify the -retrieve parameter
    C. certutil.exe and specify the -dspublish parameter
    D. certutil.exe and specify the -importcert parameter

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Microsoft exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 70-640 exam preparations and Microsoft certification application, do not hesitate to visit our Vcedump.com to find your solutions here.