PrepAway - Latest Free Exam Questions & Answers

Author: admin

What should you do to be able to create the new child domain?

You are the network administrator for Contoso, Ltd. The network consists of a single Active Directory forest that contains a single domain named contoso.com. You have a user account named CONTOSOadmin that is a member of the Domain Admins global group. You need to create a new child domain named NA.contoso.com in the forest. You install a stand-alone Windows Server 2003 computer named DC3. You use the Active Directory Installation Wizard to promote DC3 to a domain controller in the new domain. You choose to create a domain controller for a new child domain in an existing domain tree.
You enter the user name and password for CONTOSOadmin. You choose contoso.com as the parent domain, and you type NA as the name of the child domain. You receive the error message shown in the exhibit. (Click the Exhibit button.) You need to be able to create the new child domain. What should you do?

What should you do to improve the response time of the application?

You are the network administrator for your company. All servers run Windows Server 2003. The network contains two Web servers named Server1 and Server2 and three application servers named Server3, Server4, and Server5. All five servers have similar hardware. The servers are configured as Network Load Balancing clusters, as shown in the exhibit. (Click the Exhibit button.)
A Web services application hosted on Server1 and Server2 communicates to application components hosted on Server3, Server4, and Server5 by using the IP address 10.1.20.11. The application is designed to be stateless. The Network Load Balancing settings for each server are listed in the following table.
Users report that response time to the Web services application is slow. You investigate the performance of each server and observe the information listed in the following table.
You need to improve the response time of the application. What should you do?

What should you do to configure Active Directory to support autoenrollment of certificates?

You are a network administrator for your company. The network consists of a single Windows 2000 Active Directory forest that has four domains. All client computers run Windows XP Professional. The company’s written security policy states that all e-mail messages must be electronically signed when sent to other employees.
You decide to deploy Certificate Services and automatically enroll users for e-mail authentication certificates. You install Windows Server 2003 on two member servers and install Certificate Services. You configure one Windows Server 2003 computer as a root certification authority (CA). You configure the other Windows Server 2003 server as an enterprise subordinate CA. You open Certificate Templates on the enterprise subordinate CA, but you are unable to configure certificates templates for autoenrollment.
The Certificate Templates administration tool is shown in the exhibit. (Click the Exhibit button.)
You need to configure Active Directory to support autoenrollment of certificates.
What should you do?

What should you do to restore Internet connectivity on the affected client computers?

Your company has an Active Directory directory service domain. All servers in your environment run Windows Server 2003. You use dynamically assigned IP addresses. You set Internet proxy settings by using Web Proxy Automatic Discovery (WPAD). After a new Group Policy is applied, multiple client computers cannot access the Internet. You verify that physical network connectivity for the client computers is functional and that the client computers can communicate with the DHCP server, the WPAD server, and the default gateway. On each affected client computer, the Internet options are configured as shown in the following graphic. You need to restore Internet connectivity on the affected client computers.
exhibit What should you do?

What should you do to minimize the amount of administrative effort required when changes are requested?

You are the network administrator for your company. All servers run Windows Server 2003. You configure a baseline security template named Baseline.inf. Several operations groups are responsible for creating templates containing settings that satisfy operational requirements. You receive the templates shown in the following table.
The operations groups agree that in the case of conflicting settings, the priority order listed in the following table establishes the resultant setting.
You need to create one or more Group Policy objects (GPOs) to implement the security settings. You want to minimize the amount of administrative effort required when changes are requested by the various operations groups. What should you do?

Which two actions should you take to report the results of your observations to management?

You are the network administrator for your company. The network consists of a single Active Directory domain. All servers run Windows Server 2003. When the network was designed, the design team set design specifications. After the network was implemented, the deployment team set baseline specifications. The specifications for broadcast traffic are. The design specification requires that broadcast traffic must be 5 percent or less of total network traffic. The baseline specification showed that the broadcast traffic is always 1 percent or less of total network traffic during normal operation.You need to monitor the network traffic and find out if the level of broadcast traffic is within design and baseline specifications.
You decide to use Network Monitor. After monitoring for 1 hour, you observe the results shown in the exhibit. (Click the Exhibit button.)
You need to report the results of your observations to management.
Which two actions should you take? (Each correct answer presents part of the solution. Choose two.)

Which two actions should you perform to ensure that support technicians have the appropriate remote administra

All servers in your environment run Windows Server 2003. You are planning security policies for remote network administration for your companys Tier 1, Tier 2, and Tier 3 support technicians. Your security policies must support the requirements shown in the following table.
You enable Terminal Services for Tier 3 support technicians. You need to ensure that support technicians have the appropriate remote administration access to all servers. Which two actions should you perform?
(Each correct answer presents part of the solution. Choose two.)

What should you do to ensure that Windows NT Workstation 4.0 client computers can connect to servers ?

You are a network administrator for your company. The network consists of a single Active Directory domain. All servers run Windows Server 2003. Client computers run Windows 2000 Professional, Windows XP Professional, or Windows NT Workstation 4.0.The company wants to increase the security of the communication on the network by using IPSec as much as possible. The company does not want to upgrade the Windows NT Workstation 4.0 client computers to another operating system. The servers use a custom IPSec policy named Domain Servers.
The rules of the Domain Servers IPSec policy are shown in the exhibit. (Click the Exhibit button.)
You create a new Group Policy object (GPO) and link it to the domain. You configure the GPO to assign the predefined IPSec policy named Client (Respond Only).
After these configuration changes, users of the Windows NT Workstation 4.0 computers report that they cannot connect to the servers in the domain.You want to ensure that Windows NT Workstation 4.0 client computers can connect to servers in the domain.What should you do?

What should you do to ensure that all client computers can connect to server-based resources on all subnets?

You are the network administrator for your company. The relevant portion of the network is shown in the exhibit. (Click the Exhibit button.)
All servers run Windows Server 2003. Each subnet of the network contains 100 Windows XP Professional computers. Each subnet also contains a DHCP server, which provides TCP/IP configuration information to all computers on its local subnet. You create and configure Subnet3 for a new department at your company. Users in Subnet3 report that they cannot connect to resources located on servers in Subnet1 and Subnet2. When they attempt to connect to these resources, they receive the following error message. "Server not found." The users can successfully connect to resources located on servers in Subnet3. Users in Subnet1 and Subnet2 report that they cannot connect
to resources located on servers in Subnet3. When they attempt to connect to these resources, they receive the following error message. "Server did not respond in a timely manner." The users can successfully connect to resources in both Subnet1 and Subnet2.
You need to ensure that all client computers can connect to server-based resources on all subnets. What should you do?

Which two actions should you take to make only the changes that are required to meet the requirements?

You are the network administrator for your company. The network consists of a single Active Directory domain. The company’s written security policy requires that computers in a file server role must have a minimum file size for event log settings. In the past, logged events were lost because the size of the event log files was too small. You want to ensure that the event log files are large enough to hold history. You also want the security event log to be cleared manually to ensure that no security information is lost. The application log must clear events as needed. You create a security template named Fileserver.inf to meet the requirements. You need to test each file server and take the appropriate corrective action if needed.
You audit a file server by using Fileserver.inf and receive the results shown in the exhibit. (Click the Exhibit button.)
You want to make only the changes that are required to meet the requirements.
Which two actions should you take? (Each correct answer presents part of the solution. Choose two.)