Microsoft 83-640 Real Exam Questions

TS: Windows Server 2008 Active Directory, Configuring

1: Your company has a single-domain Active Directory forest. The functional level of the domain is Windows Server 2008. You perform the following activities:
Create a global distribution group.
Add users to the global distribution group.
Create a shared folder on a Windows Server 2008 member server.
Place the global distribution group in a domain local group that has access to the shared folder. You need to ensure that the users have access to the shared folder.
What should you do?
A.Raise the forest functional level to Windows Server 2008.
B.Add the global distribution group to the Domain Administrators group.
C.Change the group type of the global distribution group to a security group.
D.Change the scope of the global distribution group to a Universal distribution group.
Correct Answers: C

2: Your company has an Active Directory domain that runs Windows Server 2008. The Sales OU contains an OU for Computers, an OU for Groups, and an OU for Users,
You perform nightly backups. An administrator deletes the Groups OU.
You need to restore the Groups OU without affecting users and computers in the Sales OU.
What should you do?
A.Perform an authoritative restore of the Sales OU.
B.Perform an authoritative restore of the Groups OU.
C.Perform a non-authoritative restore of the Groups OU.
D.Perform a non-authoritative restore of the Sales OU.
Correct Answers: B

3: Your network consists of a single Active Directory domain. All domain controllers run Windows Server 2008.
You need to identify the Lightweight Directory Access Protocol (LDAP) clients that are using the largest amount of available CPU resources on a domain controller.
What should you do?
A.Review performance data in Resource Monitor.
B.Review the Hardware Events log in the Event Viewer.
C.Run the LAN Diagnostics Data Collector Set. Review the LAN Diagnostics report.
D.Run the Active Directory Diagnostics Data Collector Set. Review the Active Directory Diagnostics report.
Correct Answers: D

4: Your network consists of a single Active Directory domain. All domain controllers run Windows Server 2008. You need to capture all replication errors from all domain controllers to a central location.
What should you do?
A.Configure event log subscriptions.
B.start the System Performance data collector set.
C.start the Active Directory Diagnostics data collector set.
D.Install Network Monitor and create a new a new capture.
Correct Answers: A

5: Your network consists of a single Active Directory domain. All domain controllers run Windows Server 2003.
You upgrade all domain controllers to Windows Server 2008.
You need to configure the Active Directory environment to support the application of multiple password policies.
What should you do?
A.Create multiple Active Directory sites.
B.On all domain controllers, run dcpromo /adv.
C.On one domain controller, run dcpromo /adv.
D.Raise the functional level of the domain to Windows Server 2008.
Correct Answers: D

6: Your company has an Active Directory forest that contains client computers that run Windows Vista and Microsoft Windows XP.
You need to ensure that users are able to install approved application updates on their computers.
Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)
A.Set up Automatic Updates through Control Panel on the client computers.
B.Create a GPO and link it to the Domain Controllers organizational unit. Configure the GPO to automatically search for updates on the Microsoft Update site.
C.Create a GPO and link it to the domain. Configure the GPO to direct the client computers to the Microsoft WSUS server for approved updates.
D.Install the Microsoft WSUS application on a server in the environment. Configure the server to search for new updates on the Internet. Approve all required updates.
Correct Answers: C D

7: Your company purchases a new application to deploy on 200 computers. The application requires that you modify the registry on each target computer before you install the application.
The registry modifications are in a file that has an .adm extension. You need to prepare the target computers for the application. What should you do?
A.Import the .adm file into a new Group Policy Object (GPO). Edit the GPO and link it to an organizational unit that contains the target computers.
B.Create a Microsoft Windows PowerShell script to copy the .adm file to the startup folder of each target computer.
C.Create a Microsoft Windows PowerShell script to copy the .adm file to each computer. Run the REDIRUsr COIMTAINER-DN command on each target computer.
D.Create a Microsoft Windows PowerShell script to copy the .adm file to each computer. Run the REDIRCmp CONTAINER-DN command on each target computer.
Correct Answers: A

8: You need to relocate the existing user and computer objects in your company to different organizational units.
What are two possible ways to achieve this goal? (Each correct answer presents a complete solution. Choose two.)
A.Run the Dsmod utility.
B.Run the Active Directory Migration Tool (ADMT).
C.Run the Active Directory Users and Computers utility.
D.Run the move-item command in the Microsoft Windows PowerShell utility.
Correct Answers: A C

9: Your company has an Active Directory domain that has an organizational unit named Sales. The Sales organizational unit contains two global security groups named sales managers and sales executives.
You need to apply desktop restrictions to the sales executives group. You must not apply these desktop restrictions to the sales managers group. You create a GPO named DesktopLockdown and link it to the Sales organizational unit.
What should you do next?
A.Configure the Deny Apply Group Policy permission for the sales managers on the DesktopLockdown GPO.
B.Configure the Deny Apply Group Policy permission for the sales executives on the DesktopLockdown GPO.
C.Configure the Deny Apply Group Policy permission for Authenticated Users on the DesktopLockdown GPO.
D.Configure the Allow Apply Group Policy permission for Authenticated Users on the DesktopLockdown GPO.
Correct Answers: A

10: Your company has file servers located in an organizational unit named Payroll. The file servers contain payroll files located in a folder named Payroll.
You create a GPO.
You need to track which employees access the Payroll files on the file servers.
What should you do?
A.Enable the Audit object access option. Link the GPO to the Payroll organizational unit. On the file servers, configure Auditing for the Everyone group in the Payroll folder.
B.Enable the Audit object access option. Link the GPO to the domain. On the domain controllers, configure Auditing for the Authenticated Users group in the Payroll folder.
C.Enable the Audit process tracking option. Link the GPO to the Domain Controllers organizational unit. On the file servers, configure Auditing for the Authenticated Users group in the Payroll folder.
D.Enable the Audit process tracking option. Link the GPO to the Payroll organizational unit. On the file servers, configure Auditing for the Everyone group in the Payroll folder.
Correct Answers: A

Download  |  Password: certificatexam.com