PrepAway - Latest Free Exam Questions & Answers

Tag: Exam 70-640 (v.2)

Exam 70-640: TS: Windows Server 2008 Active Directory, Configuring (updated March 29, 2013)

Which command should you run on Computer1?

Your network contains an Active Directory domain.
You have a server named Server1 that runs Windows Server 2008 R2. Server1 is an enterprise root
certification authority (CA).
You have a client computer named Computer1 that runs Windows 7. You enable automatic certificate
enrollment for all client computers that run Windows 7. You need to verify that the Windows 7 client computers
can automatically enroll for certificates.
Which command should you run on Computer1?

What should you configure in the adatum.com domain?

Your network contains two Active Directory forests named contoso.com and adatum.com. The functional level
of both forests is Windows Server 2008 R2. Each forest contains one domain. Active Directory Certificate
Services (AD CS) is configured in the contoso.com forest to allow users from both forests to automatically
enroll user certificates.
You need to ensure that all users in the adatum.comforest have a user certificate from the contoso.com
certification authority (CA).
What should you configure in the adatum.com domain?

You need to ensure that the external users can request certificates by using the new template

You have a server named Server1 that has the following Active Directory Certificate Services (AD CS) role
services installed:
Enterprise root certification authority (CA)
Certificate Enrollment Web Service
Certificate Enrollment Policy Web Service
You create a new certificate template.
External users report that the new template is unavailable when they request a new certificate. You verify that
all other templates are available to the external users. You need to ensure that the external users can request
certificates by using the new template.
What should you do on Server1?

You need to immediately prevent the employee from logging on to the domain

You have an enterprise subordinate certification authority (CA). The CA issues smart card logon certificates.
Users are required to log on to the domain by usinga smart card. Your company’s corporate security policy
states that when an employee resigns, his ability to log on to the network must be immediately revoked. An
employee resigns.
You need to immediately prevent the employee from logging on to the domain.
What should you do?

You need to prevent the external partner from accessing the Web site

Your network contains a server that runs Windows Server 2008 R2. The server is configured as an enterprise
root certification authority (CA).
You have a Web site that uses x.509 certificates for authentication. The Web site is configured to usea many-to-one mapping.
You revoke a certificate issued to an external partner. You need to prevent the external partner from accessing
the Web site.
What should you do?

You need to configure the contoso.com zone to resolve client queries for at least four days in the event that

Your company has a main office and five branch offices that are connected by WAN links. The company has an
Active Directory domain named contoso.com. Each branch office has a member server configured as a DNS
server. All branch office DNS servers host a secondary zone for contoso.com.
You need to configure the contoso.com zone to resolve client queries for at least four days in the event that a
WAN link fails.
What should you do?

What are two possible ways to achieve this goal?

Your company has an Active Directory domain named contoso.com. FS1 is a member server in contoso.com.
You add a second network interface card, NIC2, to FS1 and connect NIC2 to a subnet that contains computers
in a DNS domain named fabrikam.com. Fabrikam.com has a DHCP server and a DNS server.
Users in fabrikam.com are unable to resolve FS1 by using DNS.
You need to ensure that FS1 has an A record in the fabrikam.com DNS zone.
What are two possible ways to achieve this goal? (Each correct answer presents a complete solution. Choose
two.)

Which two actions should you perform?

Your company Datum Corporation, has a single ActiveDirectory domain named intranet.adatum.com. The
domain has two domain controllers that run Windows Server 2008 R2 operating system. The domain
controllers also run DNS servers.
The intranet.adatum.com DNS zone is configured as an Active Directory-integrated zone with the Dynamic
updates setting configured to Secure only.
A new corporate security policy requires that the intranet.adatum.com DNS zone must be updated only by
domain controllers or member servers.
You need to configure the intranet.adatum.com zone to meet the new security policy requirement.
Which two actions should you perform? (Each correctanswer presents part of the solution. Choose two.)


Page 15 of 44« First...10...1314151617...203040...Last »