PrepAway - Latest Free Exam Questions & Answers

Category: 70-640 (v.4)

Exam 70-640: TS: Windows Server 2008 Active Directory, Configuring (updated May 5th, 2015)

You need to ensure that the contoso.com users can access the shared printer on Server1

HOTSPOT
Your network contains two Active Directory forests named contoso.com and fabrikam.com. A
two-way forest trust exists between the forests. Selective authentication is enabled on the
trust. Fabrikam.com contains a server named Server1.
You assign Contoso\Domain Users the Manage documents permission and the Print
permission to a shared printer on Server1.
You discover that users from contoso.com cannot access the shared printer on Server1.
You need to ensure that the contoso.com users can access the shared printer on Server1.
Which permission should you assign to Contoso\Domain Users.
To answer, select the appropriate permission in the answer area.

You need to prevent the external partner from accessing the Web site

Your network contains a server that runs Windows Server 2008 R2. The server is configured
as an enterprise root certification authority (CA).
You have a Web site that uses x.509 certificates for authentication. The Web site is
configured to use a manyto-one mapping.
You revoke a certificate issued to an external partner. You need to prevent the external
partner from accessing the Web site.
What should you do?

You need to configure the contoso.com zone to resolve client queries for at least four days in the event that

Your company has a main office and five branch offices that are connected by WAN links.
The company has an Active Directory domain named contoso.com.
Each branch office has a member server configured as a DNS server. All branch office DNS
servers host a secondary zone for contoso.com.
You need to configure the contoso.com zone to resolve client queries for at least four days in
the event that a WAN link fails.
What should you do?

What are two possible ways to achieve this goal?

Your company has an Active Directory domain named contoso.com. FS1 is a member
server in contoso.com.
You add a second network interface card, NIC2, to FS1 and connect NIC2 to a subnet that
contains computers in a DNS domain named fabrikam.com. Fabrikam.com has a DHCP
server and a DNS server.
Users in fabrikam.com are unable to resolve FS1 by using DNS.
You need to ensure that FS1 has an A record in the fabrikam.com DNS zone.
What are two possible ways to achieve this goal? (Each correct answer presents a complete
solution. Choose two.)

Which two actions should you perform?

Your company Datum Corporation, has a single Active Directory domain named
intranet.adatum.com. The domain has two domain controllers that run Windows Server 2008
R2 operating system. The domain controllers also run DNS servers.
The intranet.adatum.com DNS zone is configured as an Active Directory-integrated zone
with the Dynamic updates setting configured to Secure only.
A new corporate security policy requires that the intranet.adatum.com DNS zone must be
updated only by domain controllers or member servers.
You need to configure the intranet.adatum.com zone to meet the new security policy
requirement.
Which two actions should you perform? (Each correct answer presents part of the solution.
Choose two.)

You need to configure the forest trust to meet the new security policy requirement

Your company has two Active Directory forests as shown in the following table.

The forests are connected by using a two-way forest trust. Each trust direction is configured
with forest-wide authentication. The new security policy of the company prohibits users from
the eng.fabrikam.com domain to access resources in the contoso.com domain.
You need to configure the forest trust to meet the new security policy requirement.
What should you do?

You need to prevent members of the TempWorkers group from accessing the confidential data on the file servers

Your company has an Active Directory domain. All consultants belong to a global group
named TempWorkers.
The TempWorkers group is not nested in any other groups.
You move the computer objects of three file servers to a new organizational unit named
SecureServers. These file servers contain only confidential data in shared folders.
You need to prevent members of the TempWorkers group from accessing the confidential
data on the file servers.
You must achieve this goal without affecting access to other domain resources.

What should you do?


Page 47 of 62« First...102030...4546474849...60...Last »