2013 Latest 70-640 Braindumps Free Tests 321-330

Ensurepass

 

QUESTION 321

You install an Active Directory domain in a test environment. You need to reset the passwords of all the user accounts in the domain from a domain controller. Which two Windows PowerShell commands should you run? (Each correct answer presents part of the solution, choose two.)

 

A.       $ newPassword = *

B.       Import-Module ActiveDirectory

C.       Import-Module WebAdministration

D.      Get- AdUser -filter * | Set- ADAccountPossword – NewPassword $ newPassword – Reset

E.       Set- ADAccountPossword – NewPassword – Reset

F.        $ newPassword = (Read-Host – Prompt "New Password" – AsSecureString )

G.      Import-Module ServerManager

 

Correct Answer: DF

 

 

QUESTION 322

Your network contains two forests named adatum.com and litwareinc.com. The functional level of all the domains is Windows Server 2003. The functional level of both forests is Windows 2000.

You need to create a forest trust between adatum.com and litwareinc.com. What should you do first?

 

A.       Create an external trust.

B.       Raise the functional level of both forests.

C.       Configure SID filtering.

D.      Raise the functional level of all the domains.

 

Correct Answer: B

 

 

QUESTION 323

Your network contains an Active Directory forest named adatum.com. All client computers used by the marketing department are in an organizational unit (OU) named Marketing Computers. All user accounts for the marketing department are in an OU named Marketing Users. You purchase a new application. You need to ensure that every user in the domain who logs on to a marketing department computer can use the application. The application must only be available from the marketing department computers. What should you do?

 

A.       Create and link a Group Policy object (GPO) to the Marketing Users OU. Copy the installation package to a shared folder on the network. Assign the application.

B.       Create and link a Group Policy object (GPO) to the Marketing Computers OU. Copy the installation package to a shared folder on the network. Assign the application.

C.       Create and link a Group Policy object (GPO) to the Marketing Computers OU. Copy the installation package to a local drive on each marketing department computer. Publish the application.

D.       Create and link a Group Policy object (GPO) to the Marketing Users OU. Copy the installation package to a folder on each marketing department computer. Publish the application.

 

Correct Answer: B

 

 

QUESTION 324

Your network contains an Active Directory forest named adatum.com. You need to create an Active Directory Rights Management Services (AD RMS) licensing-only cluster. What should you install before you create the AD RMS root cluster?

 

A.       The Failover Cluster feature

B.       The Active Directory Certificate Services (AD CS) role

C.       Microsoft Exchange Server 2010

D.      Microsoft SharePoint Server 2010

E.       Microsoft SQL Server 2008

 

Correct Answer: E

 

 

QUESTION 325

Your network contains an Active Directory domain named contoso.com. The contoso.com domain contains a domain controller named DC1. You create an Active Directory-integrated GlobalNames zone. You add an alias (CNAME) resource record named Server1 to the zone. The target host of the record is server2.contoso.com. When you ping Server1, you discover that the name fails to resolve. You are able to successfully ping server2.contoso.com. You need to ensure that you can resolve names by using the GlobalNames zone. Which command should you run?

 

A.       Dnscmd DCl.contoso.com /ZoneAdd GlobalNames /DsPrimary /DP /domain

B.       Dnscmd DCl.contoso.com /config /Enableglobalnamessupport forest

C.       Dnscmd DCl.contoso.com /config /Enableglobalnamessupport 1

D.      Dnscmd DCl.contoso.com /ZoneAdd GlobalNames /DsPrimary /DP /forest

 

Correct Answer: C

 

 

QUESTION 326

Your network contains an Active Directory domain named contoso.com. The network has a branch office site that contains a read-only domain controller (RODC) named RODC1. RODC1 runs Windows Server 2008 R2. A user logs on to a computer in the branch office site. You discover that the user’s password is not stored on RODC1. You need to ensure that the user’s password is stored on RODC1 when he logs on to a branch office site computer. What should you do?

 

A.       Modify the RODC s password replication policy by removing the entry for the Allowed RODC Password Replication Group.

B.       Modify the RODC’s password replication policy by adding RODC1’s computer account to the list of allowed users, groups, and computers.

C.       Add the user’s user account to the built-in Allowed RODC Password Replication Group on RODC1.

D.       Add RODC1’s computer account to the built-in Allowed RODC Password Replication Group on RODC1.

 

Correct Answer: C

 

 

QUESTION 327

You deploy an Active Directory Federation Services (AD FS) Federation Service Proxy on a server named Server1. You need to configure the Windows Firewall on Server1 to allow external users to authenticate by using AD FS. Which protocol should you allow on Server1?

 

A.       Kerberos

B.       SSL

C.       SMB

D.      RPC

 

Correct Answer: B

 

 

QUESTION 328

Your network contains an Active Directory domain named contoso.com. Contoso.com contains a member server that runs Windows Server 2008 R2 Standard. You need to create an enterprise subordinate certification authority (CA) that can issue certificates based on version 3 certificate templates. You must achieve this goal by using the minimum amount of administrative effort. What should you do first?

 

A.       Run the certutil.exe – addenrollmentserver command.

B.       Install the Active Directory Certificate Services (AD CS) role on the member server.

C.       Upgrade the member server to Windows Server 2008 R2 Enterprise.

D.      Run the certutil.exe – installdefaulttemplates command.

 

Correct Answer: C

 

 

QUESTION 329

Your network contains a server named Server1. The Active Directory Rights Management Services (AD RMS) server role is installed on Server1. An administrator changes the password of the user account that is used by AD RMS. You need to update AD RMS to use the new password. Which console should you use?

 

A.       Active Directory Rights Management Services

B.       Active Directory Users and Computers

C.       Local Users and Groups

D.      Services

 

Correct Answer: A

 

 

QUESTION 330

Your company, Contoso, Ltd., has a main office and a branch office. The offices are connected by a WAN link. Contoso has an Active Directory forest that contains a single domain named ad.contoso.com. The ad.contoso.com domain contains one domain controller named DC1 that is located in the main office. DC1 is configured as a DNS server for the ad.contoso.com DNS zone. This zone is configured as a standard primary zone. You install a new domain controller named DC2 in the branch office. You install DNS on DC2. You need to ensure that the DNS service can update records and resolve DNS queries in the event that a WAN link fails. What should you do?

 

A.       Create a new secondary zone named ad.contoso.com on DC2.

B.       Create a new stub zone named ad.contoso.com on DC2.

C.       Configure the DNS server on DC2 to forward requests to DC1.

D.      Convert the ad.contoso.com zone on DC1 to an Active Directory-integrated zone.

 

Correct Answer: D

 

Download Ensurepass Latest 2013 70-640 Braindumps Free Tests , help you to pass exam 100%.