PrepAway - Latest Free Exam Questions & Answers

Author: seenagape

You have a custom certi?cate template named Sales_Temp

Your network contains an Active Directory domain named adatum.com. All servers run Windows Server 2008 R2 Enterprise. All client computers run Windows 7 Professional.

The network contains an enterprise certification authority (CA).

You have a custom certi?cate template named Sales_Temp. Sales_Temp is published to the CA.

You need to ensure that all of the members of a group named Sales can enroll for certi?cates that use Sales_Temp.

Which snap-in should you use?

The network contains an enterprise certi?cation authority (CA)

Your network contains an Active Directory domain named adatum.com. All servers run Windows Server 2008 R2 Enterprise. All client computers run Windows 7 Professional.

The network contains an enterprise certi?cation authority (CA).

You enable key archival on the CA. The CA is con?gured to use custom certi?cate templates for Encrypted File System (EFS) certi?cates.

All users plan to encrypt files by using EFS.

You need to ensure that the private keys for all new EFS certi?cates are archived.

Which snap-in should you use?

You discover the following event in the Event log of domain controllers: The request for a new account-identi?

Your network contains an Active Directory forest. The forest contains one domain named contoso.com.

You discover the following event in the Event log of domain controllers: The request for a new account-identi?er pool failed. The operation will be retried until the request succeeds. The error is ” %1 “”

You need to ensure that the domain controllers can acquire new account-identi?er pools successfully.

What should you do?

DC1 and DC2 are con?gured as DNS servers and host the Active Directory-integrated zone for contoso

Your network contains an Active Directory domain named contoso.com. Contoso.com contains two domain controllers named DC1 and DC2. DC1 and DC2 are con?gured as DNS servers and host the Active Directory-integrated zone for contoso.com.

From DNS Manager on DC1, you enable scavenging for the contoso.com zone.

You discover stale DNS records in the zone.

You need to ensure that the stale DNS records are deleted from contoso.com.

What should you do?

DC1 is con?gured as a DNS server for contoso

You have a domain controller named DC1 that runs Windows Server 2008 R2. DC1 is con?gured as a DNS server for contoso.com.

You install the DNS server server role on a member server named server1 and then you create a standard secondary zone for contoso.com. You con?gure DC1 as the master server for the zone.

You need to ensure that Server1 receives zone updates from DC1.

What should you do

You discover that GPO2 has a setting that con?icts with a setting in GPO1

Your network contains an Active Directory domain.

You have two Group Policy objects (GPOS) named GPO1 and GPO2. GPO1 and GPO2 are linked to the Finance organizational unit (OU) and contain multiple settings.

You discover that GPO2 has a setting that con?icts with a setting in GPO1. When the policies are applied, the setting in GPO2 takes effect.

You need to ensure that the settings in GPO1 supersede the settings in GPO2. The solution must ensure that all non-con?icting settings in both GPOs are applied.

What should you do?

You need to prevent the GPO from being applied to the members of Group1 only

Your network contains an Active Directory domain named contoso.com.

You have an organizational unit (OU) named Sales and an OU named Engineering. Each OU contains over 200 user accounts.

The Sales OU and the Engineering OU contain several user accounts that are members of a universal group named Group1.

You have a Group Policy object (GPO) linked to the domain.

You need to prevent the GPO from being applied to the members of Group1 only.

What should you do?

The domain contains two ?le servers

Your network contains an Active Directory domain. The domain contains two ?le servers. The ?le servers are con?gured as shown in the following table.

You create a Group Policy object (GPO) named GPO1 and you link GPO1 to OU1.

You con?gure the advanced audit policy.

You discover that the settings are not applied to Server1. The settings are applied to Server2.

You need to ensure that access to the ?le shares on Server1 is audited.

What should you do?

Which tools should you use? (Each correct answer presents part of the solution

Your network contains an Active Directory domain. The domain contains 5,000 user accounts.

You need to disable all of the user accounts that have a description of Temp.

You must achieve this goal by using the minimum amount of administrative effort.

Which tools should you use? (Each correct answer presents part of the solution. Choose two.)