PassLeader’s 651q 70-640 vce dumps and pdf dumps help passing 70-640 exam! PassLeader nowadays provide the new version 70-640 exam questions with vce and pdf for free download, the latest 70-640 study guide and practice test tell you all details about exam 70-640, you can acquire the 70-640 certification easily by learning PassLeader’s 651q 70-640 premium vce file and pdf dumps. Now visit passleader.com and download free 70-640 exam dumps and you will pass 70-640 exam the other day.
keywords: 70-640 exam,651q 70-640 exam dumps,651q 70-640 exam questions,70-640 pdf dumps,70-640 practice test,70-640 vce dumps,70-640 study guide,70-640 braindumps,TS: Windows Server 2008 Active Directory, Configuring Exam
QUESTION 461
Your network contains an Active Directory forest. The forest contains domain controllers that run Windows Server 2008 R2. The functional level of the forest is Windows Server 2003. The functional level of the domain is Windows Server 2008. From a domain controller, you need to perform an authoritative restore of an organizational unit (OU). What should you do first?
A. Raise the functional level of the forest.
B. Modify the tombstone lifetime of the forest.
C. Restore the system state.
D. Raise the functional level of the domain.
Answer: C
QUESTION 462
Your network contains an Active Directory forest. The forest contains two domains named contoso.com and woodgrovebank.com. You have a custom attribute named Attribute 1 in Active Directory. Attribute 1 is associated to User objects. You need to ensure that Attribute1 is included in the global catalog. What should you do?
A. From the Active Directory Schema snap-in, modify the properties of the Attribute 1 attributeSchema object.
B. In Active Directory Users and Computers, configure the permissions on the Attribute 1 attribute for User objects.
C. From the Active Directory Schema snap-in, modify the properties of the User classSchema object.
D. In Active Directory Sites and Services, configure the Global Catalog settings for all domain controllers in the forest.
Answer: A
QUESTION 463
Your network contains a server named Server1. Server1 runs Windows Server 2008 R2 and has the Active Directory Lightweight Directory Services (AD LDS) role installed. Server1 hosts two AD LDS instances named Instance1 and Instance2. You need to remove Instance2 from Server1 without affecting Instance1. Which tool should you use?
A. NTDSUtil
B. Dsdbutil
C. Programs and Features in the Control Panel
D. Server Manager
Answer: C
QUESTION 464
Your network contains an Active Directory domain. All domain controllers run Windows Server 2008 R2. You need to compact the Active Directory database. What should you do?
A. Run the Get-ADForest cmdlet.
B. Configure subscriptions from Event Viewer.
C. Run the eventcreate.exe command.
D. Configure the Active Directory Diagnostics Data Collector Set (OCS).
E. Create a Data Collector Set (DCS).
F. Run the repadmin.exe command.
G. Run the ntdsutil.exe command.
H. Run the dsquery.exe command.
I. Run the dsamain.exe command.
J. Create custom views from Event Viewer.
Answer: G
QUESTION 465
Your network contains an Active Directory domain. All domain controllers run Windows Server 2008 R2. You need to collect all of the Directory Services events from all of the domain controllers and store the events in a single central computer. What should you do?
A. Run the ntdsutil.exe command.
B. Run the repodmin.exe command.
C. Run the Get-ADForest cmdlet.
D. Run the dsamain.exe command.
E. Create custom views from Event Viewer.
F. Run the dsquery.exe command.
G. Configure the Active Directory Diagnostics Data Collector Set (DCS),
H. Configure subscriptions from Event Viewer.
I. Run the eventcreate.exe command.
J. Create a Data Collector Set (DCS).
Answer: H
QUESTION 466
Your network contains an Active Directory domain. All domain controllers run Windows Server 2008 R2. You need to receive a notification when more than 100 Active Directory objects are deleted per second. What should you do?
A. Create custom views from Event Viewer.
B. Run the Get-ADForest cmdlet.
C. Run the ntdsutil.exe command.
D. Configure the Active Directory Diagnostics Data Collector Set (DCS).
E. Create a Data Collector Set (DCS).
F. Run the dsamain.exe command.
G. Run the dsquery.exe command.
H. Run the repadmin.exe command.
I. Configure subscriptions from Event Viewer.
J. Run the eventcreate.exe command.
Answer: E
QUESTION 467
Your network contains an Active Directory domain. All domain controllers run Windows Server 2008 R2. You need to create a snapshot of Active Directory. What should you do?
A. Run the dsquery.exe command.
B. Run the dsamain.exe command.
C. Create custom views from Event Viewer.
D. Configure subscriptions from Event Viewer.
E. Create a Data Collector Set (DCS).
F. Configure the Active Directory Diagnostics Data Collector Set (DCS).
G. Run the repadmin.exe command.
H. Run the ntdsutil.exe command.
I. Run the Get-ADForest cmdlet.
J. Run the eventcreate.exe command.
Answer: H
QUESTION 468
Your network contains an Active Directory domain. All domain controllers run Windows Server 2008 R2. You mount an Active Directory snapshot. You need to ensure that you can query the snapshot by using LDAP. What should you do?
A. Run the dsamain.exe command.
B. Create custom views from Event Viewer.
C. Run the ntdsutil.exe command.
D. Configure subscriptions from Event Viewer.
E. Run the Get-ADForest cmdlet.
F. Create a Data Collector Set (DCS).
G. Run the eventcreate.exe command.
H. Configure the Active Directory Diagnostics Data Collector Set (DCS).
I. Run the repadmin.exe command.
J. Run the dsquery.exe command.
Answer: A
QUESTION 469
Domains provide which of the following functions?
A. Creating logical boundaries
B. Easing the administration of users, groups, computers, and other objects
C. Providing a central database of network objects
D. All of the above
Answer: D
QUESTION 470
You are the administrator for a large organization with multiple remote sites. Your supervisor security. What type of server can you implement to ease their would like to have remote users log in locally to their own site, but he is nervous about concerns?
A. Domain controller
B. Global Catalog
C. Read-only domain controller
D. Universal Group Membership Caching Server
Answer: C
http://www.passleader.com/70-640.html
QUESTION 471
You are the network administrator for the ABC Company. Your network consists of two DNS servers named DNS1 and DNS2. The users who are configured to use DNS2 complain because they are unable to connect to Internetwebsites.
The users connected to DNS2 need to be able to access the Internet. What needs to be done?
A. Build a new Active Directory Integrated zone on DNS2.
B. Delete the .(root) zone from DNS2 and configure Conditional forwarding on DNS2.
C. Delete the current cache.dns file.
D. Update your cache.dns file and root hints.
Answer: B
QUESTION 472
You are the network administrator for a large company that has one main site and one branch office. Your company has a single Active Directory forest, ABC.com. You have a single domain controller named ServerA in the main site that has the DNS role installed. ServerA is configured as a primary DNS zone. You have decided to place a domain controller named ServerB in the remote site and implement theDNS role on that server. You want to configure DNS so that if the WAN link fails, users in both sites can still update recordsand resolve any DNS queries. How should you configure the DNS servers?
A. Configure Server B as a secondary DNS server. Set replication to occur every 5 minutes.
B. Configure Server B as s stub zone.
C. Configure Server B as an Active Directory Integrated zone and convert Server A to an Active Directory Integrated zone.
D. Configure Server A as an Active Directory Integrated zone and configure Server B as a secondary zone.
Answer: C
QUESTION 473
You are the network administrator for an organization that has two locations, New York and London. Each location has multiple domains but all domains fall under the same tree, Stellacon.com. Users in the NY.us.stellacon.com domain need to access resources in the London.uk.stellacon.com domain. You need to reduce the amount of time it takes for authentication when users from NY.us.stellacon.com access resources in London.uk.stellacon.com. What can you do?
A. Set up a one-way shortcut trust from London.uk.stellacon.com to NY.us.stellacon.com.
B. Set up a one-way shortcut trust from NY.us.stellacon.com to London.uk.stellacon.com.
C. Enable Universal Group Membership Caching in NY.us.stellacon.com.
D. Enable Universal Group Membership Caching in London.uk.stellacon.com.
Answer: A
QUESTION 474
You need to deactivate the UGMC option on some of your domain controllers. At which level in Active Directory would you deactivate UGMC?
A. Server
B. Site
C. Domain
D. Forest
Answer: B
QUESTION 475
You work for an organization with a single domain forest. Your company has one main location and two branch locations. All locations are configured as Active Directory sites and all sites are connected with the DEFAULTIPSITELINK object. Your connections are running slower than the company policy allows. You want to decrease the replication latency between all domain controllers in the various sites. What should you do?
A. Decrease the Replication interval for the DEFAULTIPSITELINK object.
B. Decrease the Replication interval for the site.
C. Decrease the Replication schedule for the site.
D. Decrease the Replication schedule for all domain controllers.
Answer: A
QUESTION 476
You are the network administrator for the ABC Company. The ABC Company has all Windows Server 2008 R2 Active Directory domains and uses an EnterpriseRoot certificate server. You need to verify that revoked certificate data is highly available. What should you do?
A. Implement a Group Policy Object(GPO) that has the Certificate Verification Enabled option.
B. Using Network Load Balancing, implement an Online Certificate Status Protocol(OCSP) responder.
C. Implement a Group Policy object(GPO) that enables the Online Certificate Status Protocol(OCSP) responder.
D. Using Network Load Balancing, implement the Certificate Verification Enabled option.
Answer: B
QUESTION 476
You deploy a new Active Directory Federation Services (AD FS) federation server. You request new certificates for the AD FS federation server. You need to ensure that the AD FS federation server can use the new certificates. To which certificate store should you import the certificates?
A. Computer
B. IIS Admin Service service account
C. Local Administrator
D. World Wide Web Publishing Service service account
Answer: A
QUESTION 478
You are the administrator of an organization with a single Active Directory domain. A user who left the company returns after 16 weeks. The user tries to log onto their old computer and receives an error stating that authentication hasfailed. The user’s account has been enabled. You need to ensure that the user is able to log onto the domain using that computer. What do you do?
A. Reset the computer account in Active Directory. Disjoin the computer from the domain and then rejoin the computer to the domain.
B. Run the ADadd command to rejoin the computer account.
C. Run the MMC utility on the user’s computer and add the Domain Computers snap-in.
D. Re-create the user account and reconnect the user account to the computer account.
Answer: A
QUESTION 479
You are the administrator of an organization with a single Active Directory domain. One of your senior executives tries to log onto a machine and receives the error “This user account has expired. Ask your administrator to reactivate your account”. You need to make sure this doesn’t happen again to this user. What do you do?
A. Configure the domain policy to disable account lockouts.
B. Configure the password policy to extend the maximum password age to 0.
C. Modify the user’s properties to set the Account Never Expires setting.
D. Modify the user’s properties to extend the maximum password age to 0.
Answer: C
QUESTION 480
You work for an organization with a single Windows Server 2008 R2 Active Directory domain. The domain has OUs for Sales, Marketing, Admin, R&D and Finance. You need only the users in the Finance OU to get Windows Office 2010 installed automatically ontotheir computers. You create a GPO named OfficeApp. What is the next step in getting all the Finance users Office 2010?
A. Edit the GPO and assign the Office application to the users account. Link the GPO to the Finance OU.
B. Edit the GPO and assign the Office application to the users account. Link the GPO to the domain.
C. Edit the GPO and assign the Office application to the computer account. Link the GPO to the domain.
D. Edit the GPO and assign the Office application to the computer account. Link the GPO to the Finance OU.
Answer: D
http://www.passleader.com/70-640.html