2013 Latest 70-640 Braindumps Free Tests 101-110

Ensurepass

 

QUESTION 101

You have a Windows Server 2008 R2 that has the Active Directory Certificate Services server role installed. You need to minimize the amount of time it takes for client computers to download a certificate revocation list (CRL). What should you do?

 

A.       Install and configure an Online Responder.

B.       Import the Issuing CA certificate into the Trusted Root Certification Authorities store on all client workstations.

C.       Install and configure an additional domain controller.

D.      Import the Root CA certificate into the Trusted Root Certification Authorities store on all client workstations.

 

Correct Answer: A

 

QUESTION 102

You want users to log on to Active Directory by using a new Principal Name (UPN). You need to modify the UPN suffix for all user accounts. Which tool should you use?

 

A.       Dsmod

B.       Netdom

C.       Redirusr

D.      Active Directory Domains and Trusts

 

Correct Answer: A

 

 

QUESTION 103

Your network consists of a single Active Directory domain. All domain controllers run Windows Server 2008 R2. Auditing is configured to log changes made to the Managed By attribute on group objects in an organizational unit named OU1. You need to log changes made to the Description attribute on all group objects in OU1 only. What should you do?

 

A.       Run auditpol.exe.

B.       Modify the auditing entry for OU1.

C.       Modify the auditing entry for the domain.

D.      Create a new Group Policy Object (GPO). Enable Audit account management policy setting. Link the GPO to OU1.

 

Correct Answer: D

 

 

QUESTION 104

Your company uses shared folders. Users are granted access to the shared folders by using domain local groups. One of the shared folders contains confidential data. You need to ensure that unauthorized users are not able to access the shared folder that contains confidential data. What should you do?

 

A.       Enable the Do not trust this computer for delegation property on all the computers of unauthorized users by using the Dsmod utility.

B.       Instruct the unauthorized users to log on by using the Guest account. Configure the Deny Full control permission on the shared folders that hold the confidential data for the Guest account.

C.       Create a Global Group named Deny DLG. Place the global group that contains the unauthorized users in to the Deny DLG group. Configure the Allow Full control permission on the shared folder that hold the confidential data for the Deny DLG group.

D.       Create a Domain Local Group named Deny DLG. Place the global group that contains the unauthorized users in to the Deny DLG group. Configure the Deny Full control permission on the shared folder that hold the confidential data for the Deny DLG group.

Correct Answer: D

 

 

QUESTION 105

Your company has an Active Directory domain. You install an Enterprise Root certification authority (CA) on a member server named Server1. You need to ensure that only the Security Manager is authorized to revoke certificates that are supplied by Server1. What should you do?

 

A.       Remove the Request Certificates permission from the Domain Users group.

B.       Remove the Request Certificated permission from the Authenticated Users group.

C.       Assign the Allow – Manage CA permission to only the Security Manager user Account.

D.      Assign the Allow – Issue and Manage Certificates permission to only the Security Manger user account.

 

Correct Answer: D

 

 

QUESTION 106

You need to deploy a read-only domain controller (RODC) that runs Windows Server 2008 R2. What is the minimal forest functional level that you should use?

 

A.       Windows Server 2008 R2

B.       Windows Server 2008

C.       Windows Server 2003

D.      Windows 2000

 

Correct Answer: C

 

 

QUESTION 107

Your company has three Active Directory domains in a single forest. You install a new Active Directory enabled application. The application ads new user attributes to the Active Directory schema. You discover that the Active Directory replication traffic to the Global Catalogs has increased. You need to prevent the new attributes from being replicated to the Global Catalog. You must achieve this goal without affecting application functionality. What should you do?

 

A.       Change the replication interval for the DEFAULTIPSITELINK object to 9990.

B.       Change the cost for the DEFAULTIPSITELINK object to 9990.

C.       Make the new attributes in the Active Directory as defunct.

D.      Modify the properties in the Active Directory schema for the new attributes.

 

Correct Answer: D

 

 

QUESTION 108

You are decommissioning one of the domain controllers in a child domain. You need to transfer all domain operations master roles within the child domain to a newly installed domain controller in the same child domain. Which three domain operations master roles should you transfer? (Each correct answer presents part of the solution. Choose three.)

 

A.       RID master

B.       PDC emulator

C.       Schema master

D.      Infrastructure master

E.       Domain naming master

 

Correct Answer: ABD

 

 

QUESTION 109

There are 100 servers and 2000 computers present at your company’s headquarters. The DHCP service is installed on a two-node Microsoft failover cluster named CKMFO to ensure the high availability of the service. The nodes are named as CKMFON1 and CKMFON2. The cluster on CKMFO has one physical shared disk of 400 GB capacity. A 200GB single volume is configured on the shared disk. Company has decided to host a Windows Internet Naming Service (WINS) on CKMFON1. The DHCP and WINS services will be hosted on other nodes. Using High Availability Wizard, you begin creating the WINS service group on cluster available on CKMFON1 node. The wizard shows an error "no disks are available" during configuration. Which action should you perform to configure storage volumes on CKMFON1 to successfully add the WINS Service group to CKMFON1?

 

A.       Backup all data on the single volume on CKMFON1 and configure the disk with GUID partition table and create two volumes. Restore the backed up data on one of the volumes and use the other for WINS service group.

B.       Add a new physical shared disk to the CKMFON1 cluster and configure a new volume on it. Use this volume to fix the error in the wizard.

C.       Add new physical shared disks to CKMFON1 and EMBFON2. Configure the volumes onthese disk and direct CKMOFONI to use CKMFON2 volume for the WINS service group.

D.       Add and configure a new volume on the existing shared disk which has 400GB of space. Use this volume to fix the error in the wizard.

E.        None of the above.

 

Correct Answer: B

 

 

QUESTION 110

Company servers run Windows Server 2008. It has a single Active Directory domain. A server called S4 has file services role installed. You install some disk for additional storage. The disks are configured as shown in the exhibit.

 

clip_image001

 

To support data stripping with parity, you have to create a new drive volume. What should you do to achieve this objective?

 

A.       Build a new spanned volume by combining Disk0 and Disk1.

B.       Create a new Raid-5 volume by adding another disk.

C.       Create a new virtual volume by combining Disk 1 and Disk 2.

D.      Build a new striped volume by combining Disk0 and Disk 2.

 

Correct Answer: B

Download Ensurepass Latest 2013 70-640 Braindumps Free Tests , help you to pass exam 100%.