Microsoft 70-640 Real Exam Questions
This Technology Specialist (TS) exam, Exam 70-640: TS: Windows Server 2008 Active Directory, Configuring, became available in March 2008. This exam is available in English, Brazilian Portuguese, Chinese [Simplified], French, Japanese, Korean, Russian, and Spanish.
1: You work as a technology specialist in an international company named Wiikigo. Your major job is to configure Windows Server 2008 Active Directory. And you are experienced in configuring the Active Directory infrastructure and maintaining Active Directory objects. There is a single Active Directory domain in the company network. Windows Server 2008 is run by all domain controllers that are configured as DNS servers. A domain controller named DC01 has a standard primary zone for wiikigo.com. A domain controller named DC02 has a standard secondary zone for wiikigo.com. You have to make sure that the replication of the wiikigo.com zone is encrypted. You must not lose any zone data. So what action should you perform?
A.The zone transfer settings of the standard primary zone should be configured. The Master Servers lists on the secondary zone should be modified.
B.The interface that the DNS server listens on should be modified on both servers.
C.The primary zone should be converted into an Active Directory-integrated zone. The secondary zone should be deleted.
D.The primary zone should be converted into an Active Directory-integrated stub zone. The secondary zone should be deleted.
Correct Answers: C
2: You work as a technology specialist in an international company named Wiikigo. Your major job is to configure Windows Server 2008 Active Directory.
And you are experienced in configuring the Active Directory infrastructure and maintaining Active Directory objects. A single Active Directory domain is contained by your network. And there is a domain controller and a member server that run Windows Server 2008 in the company. The company configures the two servers as DNS servers. Either Windows XP Service Pack 2 or Windows Vista is run by client computers. There is a standard primary zone on the domain controller. A secondary copy of the zone is hosted by the member server. According to the company requirements, you should make sure that host (A) records in the DNS zone can only be updated by authenticated users.
Which action should be performed to achieve the goal?
A.The standard primary zone should be converted to an Active Directory-integrated zone.
B.On the member server, a conditional forwarder should be added.
C.On the member server, Active Directory Domain Services should be installed.
D.All computer accounts should be added to the DNSUpdateProxy group.
Correct Answers: A
3: You work as a technology specialist in an international company named Wiikigo. Your major job is to configure Windows Server 2008 Active Directory.
And you are experienced in configuring the Active Directory infrastructure and maintaining Active Directory objects. There is an Active Directory domain in the company. You have the domain controller logged on to. You find that you cannot access the Active Directory Schema snap-in in the Microsoft Management Console (MMC). Since you are the technical support, you are required to make sure that the Active Directory Schema snap-in is available.
Which action should you perform to achieve the goal?
A.To achieve the goal, you should connect to the schema master operations master and open the schema for writing by utilizing the Ntdsutil.exe command.
B.To achieve the goal, you should have the Active Directory Lightweight Directory Services (AD LDS) role added to the domain controller by utilizing Server Manager.
C.To achieve the goal, you should register Schmmgmt.dll.
D.To achieve the goal, you should utilize an account that is a member of the Schema Admins group to log off and log on again.
Correct Answers: C
4: You work as a technology specialist in an international company named Wiikigo. Your major job is to configure Windows Server 2008 Active Directory. And you are experienced in configuring the Active Directory infrastructure and maintaining Active Directory objects. There is a domain controller which runs Windows Server 2008. The domain controller has the Windows Server Backup feature installed. You have to use an existing backup file to perform a non-authoritative restore of the domain controller. So what action should you perform?
A.The domain controller should be restarted in safe mode. Perform a critical volume restore by using the WBADMIN command.
B.The domain controller should be restarted in safe mode. Perform a critical volume restore by using the Windows Server Backup snap-in.
C.The domain controller should be restarted in Directory Services Restore Mode. Perform a critical volume restore by using the WBADMIN command.
D.The domain controller should be restarted in Directory Services Restore Mode. Perform a critical volume restore by using the Windows Server Backup snap-in.
Correct Answers: C
5: You work as a technology specialist in an international company named Wiikigo. Your major job is to configure Windows Server 2008 Active Directory. And you are experienced in configuring the Active Directory infrastructure and maintaining Active Directory objects. There is an Active Directory forest in your company network. One domain is contained in this forest. Windows Server 2008 is run by all domain controllers that are configured as DNS servers. You have an Active Directory-integrated zone and two Active Directory sites. There are five domain controllers in each site. You have a new NS record added to the zone. According to the company requirement, you have to make sure that all domain controllers immediately receive the new NS record. So what action should you perform?
A.Run repadmin /syncall from the command prompt.
B.Increase the version number of the SOA record from the DNS Manager console.
C.Reload the zone from the DNS Manager console.
D.Restart the DNS Server service from the Services snap-in.
Correct Answers: A
6: You work as a technology specialist in an international company named Wiikigo. Your major job is to configure Windows Server 2008 Active Directory. And you are experienced in configuring the Active Directory infrastructure and maintaining Active Directory objects. There are file servers in your company, and they are located in an organizational unit named PRoll. PRoll files are included by file servers which are in a folder named PRoll. A GPO is created. Since you are the technical support, you are required to have the employees who access the PRoll files on the file servers tracked. Which action should be performed?
A.The Audit process tracking option should be enabled. And then, the GPO should be linked to the PRoll organizational unit. At last, Auditing for the Everyone group in the PRoll folder should be configured on the file servers.
B.The Audit object access option should be enabled. And then, the GPO should be linked to the PRoll organizational unit. At last, Auditing for the Everyone group in the PRoll folder should be configured on the file servers.
C.The Audit object access option should be enabled. And then, the GPO should be linked to the domain. At last, Auditing for the Authenticated Users group in the PRoll folder should be configured on the domain controllers.
D.The Audit process tracking option should be enabled. And then, the GPO should be linked to the Domain Controllers organizational unit. At last, Auditing for the Authenticated Users group in the PRoll folder should be configured on the file servers.
Correct Answers: B
7: You work as a technology specialist in an international company named Wiikigo. Your major job is to configure Windows Server 2008 Active Directory. And you are experienced in configuring the Active Directory infrastructure and maintaining Active Directory objects. There is a head office and 9 branch offices in your company. An Active Directory site is contained by each branch office, and one domain controller is included by the Active Directory site. The company configures only domain controllers in the head office as Global Catalog servers. Since you are the technical support, you are required to disable the Universal Group Membership Caching option on the domain controllers in the branch offices. As you should disable the disable the Universal Group Membership Caching option, which level should you choose?
A.You should disable the Universal Group Membership Caching option at Connection object level.
B.You should disable the Universal Group Membership Caching option at Site level.
C.You should disable the Universal Group Membership Caching option at Server level.
D.You should disable the Universal Group Membership Caching option at Domain level.
Correct Answers: B
8: You work as a technology specialist in an international company named Wiikigo. Your major job is to configure Windows Server 2008 Active Directory. And you are experienced in configuring the Active Directory infrastructure and maintaining Active Directory objects. There is an Active Directory forest in your company network. Windows Server 2008 is run by all domain controllers that are configured as DNS servers. You have an Active Directory-integrated zone for wiikigo.com. You have a UNIX-based DNS server. Your Windows Server 2008 environment needs to be configured to allow zone transfers of the wiikigo.com zone to the UNIX-based DNS server. What action should you perform in the DNS Manager console?
A.A secondary zone should be created.
B.BIND secondaries should be enabled.
C.You should disable recursion.
D.A stub zone should be created.
Correct Answers: B
9: You work as a technology specialist in an international company named Wiikigo. Your major job is to configure Windows Server 2008 Active Directory. And you are experienced in configuring the Active Directory infrastructure and maintaining Active Directory objects. There is a single-domain Active Directory forest in your company. The functional level of the domain plays at the functional level of Windows Server 2008. You perform the following activities:
Create a global distribution group.
Have users added to the global distribution group.
Create a shared folder on a Windows Server 2008 member server.
Place the global distribution group in a domain local group that has access to the shared folder.
According to the company requirement, you have to make sure that the users have access to the shared folder. So what action should you perform to make sure of this?
A.The group type of the global distribution group should be changed to a security group.
B.The scope of the global distribution group should be changed to a Universal distribution group.
C.Raise the forest functional level should be raised to Windows Server 2008.
D.Add the global distribution group should be added to the Domain Administrators group.
Correct Answers: A
10: You work as a technology specialist in an international company named Wiikigo. Your major job is to configure Windows Server 2008 Active Directory. And you are experienced in configuring the Active Directory infrastructure and maintaining Active Directory objects. There is an organizational unit named Production in your company. The Production organizational unit has a child organizational unit named R&D. After a GPO named Software Deployment is created by you, you link it to the Production organizational unit. You create a shadow group for the R&D organizational unit. You have to deploy an application to users in the Production organizational unit. You also need to make sure that the application is not deployed to users in the R&D organizational unit. What are two possible ways to achieve this goal?
A.In order to achieve this goal, security filtering on the Software Deployment GPO should be configured to Deny Apply group policy for the R&D security group.
B.In order to achieve this goal, the Enforce setting should be configured on the software deployment GPO.
C.In order to achieve this goal, the Block Inheritance setting should be configured on the R&D organizational unit.
D.In order to achieve this goal, the Block Inheritance setting should be configured on the Production organizational unit.
Correct Answers: A C
Download | Password: ciscobibles.com