2013 Latest 70-640 Braindumps Free Tests 311-320

Ensurepass

 

QUESTION 311

Your network contains a domain controller that runs Windows Server 2008 R2. You run the following command on the domain controller:

dsamain.exe C dbpath c:$SNAP_201006170326_VOLUMEC$WindowsNTDSntds.dit C ldapport 389 – allowNonAdminAccess

The command fails. You need to ensure that the command completes successfully. How should you modify the command?

 

A.       Change the value of the -dbpath parameter.

B.       Include the path to Dsamain.

C.       Change the value of the -ldapport parameter.

D.      Remove the CallowNonAdminAccess parameter.

 

Correct Answer: C

 

 

QUESTION 312

Your network contains an Active Directory domain. The domain contains 10 domain controllers that run Windows Server 2008 R2. You need to monitor the following information on the domain controllers during the next five days:

 

Ÿ   Memory usage

Ÿ   Processor usage

Ÿ   The number of LDAP queries

 

What should you do?

 

A.       Create a User Defined Data Collector Set (DCS) that uses the Active Directory Diagnostics template.

B.       Use the System Performance Data Collector Set (DCS).

C.       Create a User Defined Data Collector Set (DCS) that uses the System Performance template.

D.       Use the Active Directory Diagnostics Data Collector Set (DCS).

 

Correct Answer: A

 

 

QUESTION 313

Your network contains an Active Directory domain named contoso.com. Contoso.com contains a domain controller named DC1 and a read-only domain controller (RODC) named RODC1. You need to view the most recent user accounts authenticated by RODC1. What should you do first?

 

A.       From Active Directory Sites and Services, right-click the Connection object for DC1, and then click Replicate Now.

B.       From Active Directory Sites and Services, right-click the Connection object for DC2, and then click Replicate Now.

C.       From Active Directory Users and Computers, right-click contoso.com, click Change DomainController, and then connect to DC1.

D.       From Active Directory Users and Computers, right-click contoso.com, click Change Domain Controller, and then connect to RODC1.

 

Correct Answer: C

 

 

QUESTION 314

Your network contains an Active Directory domain. The domain contains 3,000 client computers. All of the client computers run Windows 7. Users log on to their client computers by using standard user accounts. You plan to deploy a new application named App1. The vendor of App1 provides a Setup.exe file to install App1. Setup.exe requires administrative rights to run. You need to deploy App1 to all client computers. The solution must meet the following requirements:

 

Ÿ   App1 must automatically detect and replace corrupt application files.

Ÿ   App1 must be available from the Start menu on each client computer.

 

What should you do first?

 

A.       Create a logon script that calls Setup.exe for App1.

B.       Create a .zap file.

C.       Create a startup script that calls Setup.exe for App1.

D.      Repackage App1 as a Windows Installer package.

 

Correct Answer: D

 

 

 

QUESTION 315

Your network contains an Active Directory domain named contoso.com. Contoso.com contains two sites named Site1 and Site2. Site1 contains a domain controller named DC1. In Site1, you install a new domain controller named DC2. You ship DC2 to Site2. You discover that certain users in Site2 authenticate to DC1. You need to ensure that the users in Site2 always attempt to authenticate to DC2 first. What should you do?

 

A.       From Active Directory Users and Computers, modify the Location settings of the DC2 computer object.

B.       From Active Directory Sites and Services, modify the Location attribute for Site2.

C.       From Active Directory Sites and Services, move the DC2 server object.

D.       From Active Directory Users and Computers, move the DC2 computer object.

 

Correct Answer: C

 

 

QUESTION 316

Your network contains an Active Directory domain named contoso.com. Contoso.com contains a server named Server2. You open the System properties on Server2 as shown in the exhibit.

 

clip_image002

 

When you attempt to configure Server2 as an enterprise subordinate certification authority (CA), you discover that the enterprise subordinate CA option is unavailable. You need to configure Server2 as an enterprise subordinate CA. What should you do first?

 

A.       Upgrade Server2 to Windows Server 2008 R2 Enterprise.

B.       Log in as an administrator and run Server Manager.

C.       Import the root CA certificate.

D.      Join Server2 to the domain.

 

Correct Answer: D

 

 

QUESTION 317

Your network contains an Active Directory domain. The domain contains an enterprise certification authority (CA). You need to ensure that only members of a group named Admin1 can create certificate templates. Which tool should you use to assign permissions to Admin1?

 

A.       the Certification Authority console

B.       Active Directory Users and Computers

C.       the Certificates snap-in

D.      Active Directory Sites and Services

 

Correct Answer: D

 

 

QUESTION 318

Your company has a single Active Directory forest with a single domain. Consultants in different departments of the company require access to different network resources. The consultants belong to a global group named TempWorkers. Three file servers are placed in a new organizational unit named SecureServers. The file servers contain confidential data in shared folders. You need to prevent the consultants from accessing the confidential data. What should you do?

 

A.       Create a new Group Policy Object (GPO) and link it to the SecureServers organizational unit. Assign the Deny access to this computer from the network user right to the TempWorkers global group.

B.       Create a new Group Policy Object (GPO) and link it to the domain. Assign the Deny access to this computer from the network user right to the TempWorkers global group.

C.       On the three file servers, create a share on the root of each hard disk. Configure the Deny Full control permission for the TempWorkers global group on the share.

D.       Create a new Group Policy Object (GPO) and link it to the domain. Assign the Deny log on locally user right to the TempWorkers global group.

E.        Create a new Group Policy Object (GPO) and link it to the SecureServers organizational unit. Assign the Deny log on locally user right to the TempWorkers global group.

 

Correct Answer: A

 

 

QUESTION 319

Your network contains an Active Directory domain. All DNS servers are domain controllers. You view the properties of the DNS zone as shown in the exhibit.

 

clip_image003

 

You need to ensure that only domain members can register DNS records in the zone. What should you do first?

 

A.       Modify the zone type.

B.       Create a trust anchor.

C.       Modify the Advanced properties of the DNS server.

D.      Modify the Dynamic updates setting.

 

Correct Answer: A

 

 

QUESTION 320

Your network contains two Active Directory forests named contoso.com and nwtraders.com. The functional level of both forests is Windows Server 2003. Contoso.com contains one domain. Nwtraders.com contains two domains. You need to ensure that users in contoso.com can access the resources in all domains. The solution must require the minimum number of trusts. Which type of trust should you create?

 

A.       external

B.       forest

C.       realm

D.      shortcut

 

Correct Answer: B

Download Ensurepass Latest 2013 70-640 Braindumps Free Tests , help you to pass exam 100%.