2013 Latest 70-640 Braindumps Free Tests 371-380

Ensurepass

 

QUESTION 371

All vendors belong to a global group named vendors. You place three file servers in a new organizational unit (OU) named ConfidentialFileServers. The three file servers contain confidential data located in shared folders. You need to record any failed attempts made by the vendors to access the confidential data. Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)

 

A.       Create a new Group Policy Object (GPO) and link it to the CONFIDENTIALFILESERVERS OU. Configure the Audit object access failure audit policy setting.

B.       Create a new Group Policy Object (GPO) and link it to the CONFIDENTIALFILESERVERS OU. Configure the Audit privilege use Failure audit policy setting.

C.       On each shared folder on the three file servers, add the Vendors global group to the Auditing tab. Configure Failed Full control setting in the AuditingEntry dialog box.

D.       On each shared folder on the three file servers, add the three servers to the Auditing tab. Configure Failed Full control setting in the AuditingEntry dialog box.

E.        Create a new Group Policy Object (GPO) and link it to the CONFIDENTIALFILESERVERS OU. Configure the Deny access to this computer from the network user rights setting for the Vendors global group.

 

Correct Answer: AC

 

 

QUESTION 372

A corporate network includes a single Active Directory Domain Services (AD DS) domain. The HR department has a dedicated organizational unit (OU) named HR. The HR OU has two sub-OUs: HR Users and HR Computers. User accounts for the HR department reside in the HR Users OU. Computer accounts for the HR department reside in the HR Computers OU. All HR department employees belong to a security group named HR Employees. All HR department computers belong to a security group named HR PCs. Company policy requires that passwords are a minimum of 6 characters. You need to ensure that, the next time HR department employees change their passwords, the passwords are required to have at least 8 characters. The password length requirement should not change for employees of any other department. What should you do?

 

A.       Modify the password policy in the GPO that is applied to the domain.

B.       Create a new GPO, with the necessary password policy, and link it to the HR Users OU.

C.       Create a fine-grained password policy and apply it to the HR Users OU.

D.      Modify the password policy in the GPO that is applied to the domain controllers OU.

 

Correct Answer: C

 

 

QUESTION 373

A corporate network includes a single Active Directory Domain Services (AD DS) domain. All regular user accounts reside in an organisational unit (OU) named Employees. All administrator accounts reside in an OU named Admins. You need to ensure that any time an administrator modifies an employee’s name in AD DS, the change is audited. What should you do first?

 

A.       Create a Group Policy Object with the Audit directory service access setting enabled and link it to the Employees OU.

B.       Modify the searchFlags property for the Name attribute in the Schema.

C.       Create a Group Policy Object with the Audit directory service access setting enabled and link it to the Admins OU.

D.       Use the Auditpol.exe command-line tool to enable the directory service changes auditing subcategory.

 

Correct Answer: D

 

 

QUESTION 374

Your network contains an Active Directory forest named contoso.com. You need to provide a user named User1 with the ability to create and manage subnet objects. The solution must minimize the number of permissions assigned to User1. What should you do?

 

A.       From Active Directory Users and Computers, run the Delegation of Control wizard.

B.       From Active Directory Administrative Centre, add User1 to the Schema Admins group.

C.       From Active Directory Sites and Services, run the Delegation of Control wizard.

D.      From Active Directory Administrative Centre, add User1 to the Network Configuration Operators group.

 

Correct Answer: C

 

 

QUESTION 375

A corporate network contains a Windows Server 2008 R2 Active Directory forest. You need to add a User Principle Name (UPN) suffix to the forest. What tool should you use?

 

A.       Dsmgmt.

B.       Active Directory Domains and Trusts console.

C.       Active Directory Users and Computers console.

D.      Active Directory Sites and Services console.

 

Correct Answer: B

 

 

QUESTION 376

Your network contains a single Active Directory domain that has two sites named Site1 and Site2. Site1 has two domain controllers named DC1 and DC2. Site2 has two domain controllers named DC3 and DC4. DC3 fails. You discover that replication no longer occurs between the sites. You verify the connectivity between DC4 and the domain controllers in Site1. On DC4, you run repadmin.exe /kcc. Replication between the sites continues to fail. You need to ensure that Active Directory data replicates between the sites. What should you do?

 

A.       From Active Directory Sites and Services, configure the NTDS Site Settings of Site2.

B.       From Active Directory Sites and Services, configure DC3 so it is not a preferred bridgehead server.

C.       From Active Directory Users and Computers, configure the NTDS settings of DC4.

D.      From Active Directory Users and Computers, configure the location settings of DC4.

 

Correct Answer: B

 

 

QUESTION 377

Your network contains an Active Directory domain named contoso.com. All domain controllers were upgraded from Windows Server 2003 to Windows Server 2008 R2 Service Pack 1 (SP1). The functional level of the domain is Windows Server 2003. You need to configure SYSVOL to use DFS Replication. Which tools should you use? (Each correct answer presents part of the solution. Choose two.)

 

A.       Dfsrmig

B.       Frsdiag

C.       Ntdsutil

D.      Set-ADForest

E.       Repadmin

F.        Set-ADDomainMode

G.      DFS Management

 

Correct Answer: AF

 

 

QUESTION 378

Your network contains an Active Directory forest named contoso.com. The functional level of the forest is Windows Server 2008 R2. The DNS zone for contoso.com is Active Directory-integrated. You deploy a read-only domain controller (RODC) named RODC1. You install the DNS Server role on RODC1. You discover that RODC1 does not have any application directory partitions. You need to ensure that RODC1 has a directory partition of contoso.com. What should you do?

 

A.       From DNS Manager, create secondary zones.

B.       Run Dnscmd.exe, and specify the /enlistdirectorypartition parameter.

C.       From DNS Manager, right-click RODC1 and click Update Server Data Files.

D.      Run Dnscmd.exe and specify the /createbuiltindirectorypartitions parameter.

 

Correct Answer: B

 

 

QUESTION 379

You manage an Active Directory forest named contoso.com. The forest contains an empty root domain named contoso.com and a child domain named child.contoso.com. All domain controllers run Windows Server 2008. The functional level of the forest is Windows Server 2008. You need to raise the functional level of the forest to Windows Server 2008 R2. You must achieve this goal by using the minimum amount of administrative effort. What should you do?

 

To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

 

Build List and Reorder:

clip_image002

 

 

Correct Answer:

clip_image003

 

 

 

QUESTION 380

Your network contains an Active Directory forest. The forest contains one domain named contoso.com. You attempt to run adprep /domainprep and the operation fails. You discover that the first domain controller deployed to the forest failed. You need to run adprep /domainprep successfully. What should you do?

 

A.       Move the domain naming master role.

B.       Install a read-only domain controller (RODC).

C.       Move the PDC emulator role.

D.      Move the RID master role.

E.       Move the infrastructure master role.

F.        Deploy an additional global catalog server.

G.      Move the bridgehead server.

H.      Move the schema master role.

I.         Restart the Active Directory Domain Services (AD DS) service.

J.        Move the global catalog server.

 

Correct Answer: E

Download Ensurepass Latest 2013 70-640 Braindumps Free Tests , help you to pass exam 100%.