PrepAway - Latest Free Exam Questions & Answers

Author: seenagape

You need to configure the Active Directory environment to support the application of multiple password policie

Your network consists of a single Active Directory domain. All domain controllers run Windows Server 2003. You upgrade all domain controllers to Windows Server 2008. You need to configure the Active Directory environment to support the application of multiple password policies. What should you do?

Which node should you use to achieve this task? To answer, select the appropriate node in the answer area

Your network contains a server named Server1 that runs Windows Server 2008 R2. You configure IPSec on Server1. You need to identify the total number of encrypted bytes sent and received by Server1. Which node should you use to achieve this task? To answer, select the appropriate node in the answer area.

You need to ensure that users from the domain can successfully establish a VPN connection to Server3

You are a security administrator for your company. The network consists of a single Active Directory domain. All servers run Windows Server 2003. The network contains three member servers named Server1, Server2, and Server3.

The three member servers are connected to the Internet. You plan to implement remote access to the company network for users that work from home. You configure and enable Routing and Remote Access on Server1 and Server2. An assistant, who is an administrator on all member servers, configures and enables Routing and Remote Access on Server3. Users from the domain can successfully establish VPN connections from the lnternet to Server1 and Server2. However, users cannot establish a VPN connection to Server3. You discover that Server3 can only authenticate Internet VPN connections from local user accounts.

You need to ensure that users from the domain can successfully establish a VPN connection to Server3. What should you do?

You need to enable Internet name resolution for all client computers

Your company has an Active Directory domain named contoso.com. The company network has two DNS servers named DNS1 and DNS2.

The DNS servers are configured as shown in the following table.

Domain users, who are configured to use DNS2 as the preferred DNS server, are unable to connect to Internet Web sites.

You need to enable Internet name resolution for all client computers.

What should you do?

You need to configure DNS to provide zone data to the DNS server in the new branch office

Your company has a main office and two branch offices. Domain controllers in the main office host an Active Directory-integrated zone.

The DNS servers in the branch offices host a secondary zone for the domain and use the main office DNS servers as their DNS Master servers for the zone.

The company adds a new branch office. You add a member server named Branch3 and install the DNS Server server role on the server. You configure a secondary zone for the domain. The zone transfer fails.

You need to configure DNS to provide zone data to the DNS server in the new branch office.

What should you do?

You need to ensure that all computers in Segment B automatically install security patches

You are the security administrator for your company. The network consists of two segments named Segment A and Segment B. The client computers on the network run Windows XP Professional. The servers run Windows Server 2003.

Segment A contains a single server named Server1. Segment B contains all other computers, including a server named Server2. The company’s written security policy states that Segment B must not be connected to the lnternet. Segment A is allowed to connect to the lnternet. There is no network connection between Segment A and Segment B. You can copy files from Segment A to Segment B only by using a CD-ROM to transport the files between the two segments. The network topology is displayed in the exhibit. (Refer to the Exhibit.)

You are planning a patch management infrastructure. On Segment B, you install Software Update Services (SUS) on Server2. You configure Automatic Updates on all computers in Segment B to use http://Server2 and to install security patches.

You need to ensure that all computers in Segment B automatically install security patches. What should you do?

You need to install the AD CS role as an Enterprise CA

Your company has an Active Directory forest. You plan to install an Enterprise certification authority (CA) on a dedicated stand-alone server. When you attempt to add the Active Directory Certificate Services (AD CS) role, you find that the Enterprise CA option is not available. You need to install the AD CS role as an Enterprise CA. What should you do first?

Which two actions should you perform on the DNS servers? (Each correct answer presents a complete solution

Your network contains an Active Directory domain. The domain contains DNS servers that run Windows Server 2008 R2. The network has two external links. One link connects to the Internet.

The other link directly connects to the network of a partner company. The partner companys network is not connected to the Internet. You need to ensure that users on your network can access resources on the partner companys network. The solution must ensure that the users on your network can continue to access resources on the Internet. Which two actions should you perform on the DNS servers? (Each correct answer presents a complete solution. Choose two.)

You need to prevent users from running VBS files regardless of how they arrive on client computers

You are a security administrator for your company. The network consists of a single Active Directory domain. All servers run Windows Server 2003. All client computers run Windows XP Professional.

The company occasionally experiences downtime because of malicious lnternet worms that arrive as Microsoft Visual Basic Scripting Edition (VBS) files. You examine several client computers and discover that VBS files are downloaded by using Microsoft Outlook, instant messaging, or peer-to-peer file sharing programs.

You need to prevent users from running VBS files regardless of how they arrive on client computers. What should you do?

Which two tasks should you perform? (Each correct answer presents part of the solution

Your company has an Active Directory domain. All servers run Windows Server 2008 R2. Your company runs an Enterprise Root certification authority (CA).

You need to ensure that only administrators can sign code.

Which two tasks should you perform? (Each correct answer presents part of the solution. Choose two.)