PrepAway - Latest Free Exam Questions & Answers

Category: 70-640 (v.4)

Exam 70-640: TS: Windows Server 2008 Active Directory, Configuring (updated May 5th, 2015)

You need to ensure that only authenticated users are allowed to update host (A) records in the DNS zone

Your network consists of a single Active Directory domain. You have a domain controller and
a member server that run Windows Server 2008 R2. Both servers are configured as DNS
servers. Client computers run either Windows XP Service Pack 3 or Windows 7.
You have a standard primary zone on the domain controller. The member server hosts a
secondary copy of the zone.
You need to ensure that only authenticated users are allowed to update host (A) records in
the DNS zone.
What should you do first?

You need to configure the contoso.com zone to automatically remove expired records

Your company has two domain controllers that are configured as internal DNS servers. All
zones on the DNS servers are Active Directory-integrated zones. The zones allow all
dynamic updates.
You discover that the contoso.com zone has multiple entries for the host names of
computers that do not exist.
You need to configure the contoso.com zone to automatically remove expired records.
What should you do?

You need to implement a certification authority (CA) server that meets the following requirements…?

You have an Active Directory domain that runs Windows Server 2008 R2.
You need to implement a certification authority (CA) server that meets the following
requirements:
Allows the certification authority to automatically issue certificates
Integrates with Active Directory Domain Services
What should you do?

You need to grant members of the Account Operators group the ability to only manage Basic EFS certificates

You have a Windows Server 2008 R2 Enterprise Root certification authority (CA).
You need to grant members of the Account Operators group the ability to only manage Basic
EFS certificates.
You grant the Account Operators group the Issue and Manage Certificates permission on
the CA.

Which three tasks should you perform next? (Each correct answer presents part of the
solution.
Choose three.)

Your company uses an Enterprise Root certification authority (CA) and an Enterprise Intermediate C

Your company has an Active Directory domain. All servers run Windows Server 2008 R2.
Your company uses an Enterprise Root certification authority (CA) and an Enterprise
Intermediate CA.
The Enterprise Intermediate CA certificate expires.
You need to deploy a new Enterprise Intermediate CA certificate to all computers in the
domain.
What should you do?

You need to ensure that the French-language version of the templates is available

Your company has recently acquired a new subsidiary company in Quebec. The Active
Directory administrators of the subsidiary company must use the French-language version of
the administrative templates.
You create a folder on the PDC emulator for the subsidiary domain in the path
%systemroot%\SYSVOL\domain\Policies\PolicyDefinitions\FR.
You need to ensure that the French-language version of the templates is available.
What should you do?

Which two actions should you perform?

The default domain GPO in your company is configured by using the following account
policy settings:
Minimum password length: 8 characters
Maximum password age: 30 days
Enforce password history: 12 passwords remembered
Account lockout threshold: 3 invalid logon attempts
Account lockout duration: 30 minutes
You install Microsoft SQL Server on a computer named Server1 that runs Windows Server
2008 R2. The SQL Server application uses a service account named SQLSrv. The SQLSrv
account has domain user rights.
The SQL Server computer fails after running successfully for several weeks. The SQLSrv
user account is not locked out.

You need to resolve the server failure and prevent recurrence of the failure. Which two
actions should you perform? (Each correct answer presents part of the solution. Choose
two.)

You need to set up a transitive forest trust between Forest1 and Forest2

Your company has two Active Directory forests named Forest1 and Forest2, The forest
functional level and the domain functional level of Forest1 are set to Windows Server 2008.
The forest functional level of Forest2 is set to Windows 2000, and the domain functional
levels in Forest2 are set to Windows Server 2003.
You need to set up a transitive forest trust between Forest1 and Forest2.
What should you do first?


Page 40 of 62« First...102030...3839404142...5060...Last »