2013 Latest 70-640 Braindumps Free Tests 391-400

Ensurepass

 

 

QUESTION 391

Your network contains an Active Directory domain named contoso.com. Contoso.com contains two domain controllers named DC1 and DC2. DC1 and DC2 are configured as DNS servers and host the Active Directory-integrated zone for contoso.com. From DNS Manager on DC1, you enable scavenging for the contoso.com zone. You discover stale DNS records in the zone. You need to ensure that the stale DNS records are deleted from contoso.com. What should you do?

 

A.       From DNS Manager, enable scavenging on DC1.

B.       From DNS Manager, reload the zone.

C.       Run dnscmd.exe and specify the ageallrecords parameter.

D.      Run dnscmd.exe and specify the startscavenging parameter.

 

Correct Answer: A

 

 

QUESTION 392

Your network contains an Active Directory forest. The forest contains one domain named contoso.com. You discover the following event in the Event log of domain controllers: ‘The request for a new account- identifier pool failed. The operation will be retried until the request succeeds. The error is " %1 "". You need to ensure that the domain controllers can acquire new account-identifier pools successfully. What should you do?

 

A.       Move the domain naming master role.

B.       Move the global catalog server.

C.       Restart the Active Directory Domain Services (AD DS) service.

D.      Deploy an additional global catalog server.

E.       Move the infrastructure master role.

F.        Move the PDC emulator role.

G.      Install a read-only domain controller (RODC).

H.      Move the RID master role.

I.         Move the bridgehead server.

J.        Move the schema master role.

 

Correct Answer: H

 

 

QUESTION 393

Your network contains an Active Directory domain named adatum.com. All servers run Windows Server 2008 R2 Enterprise. All client computers run Windows 7 Professional. The network contains an enterprise certification authority (CA). You enable key archival on the CA. The CA is configured to use custom certificate templates for Encrypted File System (EFS) certificates. All users plan to encrypt files by using EFS. You need to ensure that the private keys for all new EFS certificates are archived. Which snap-in should you use?

 

A.       Share and Storage Management

B.       Security Configuration wizard

C.       Enterprise PKI

D.      Active Directory Administrative Center

E.       Certification Authority

F.        Group Policy Management

G.      Certificate Templates

H.      Authorization Manager

I.         Certificates

 

Correct Answer: G

 

 

QUESTION 394

Your network contains an Active Directory domain named adatum.com. All servers run Windows Server 2008 R2 Enterprise. All client computers run Windows 7 Professional. The network contains an enterprise certification authority (CA). You have a custom certificate template named Sales_Temp. Sales_Temp is published to the CA. You need to ensure that all of the members of a group named Sales can enroll for certificates that use Sales_Temp. Which snap-in should you use?

 

A.       Enterprise PKI

B.       Certification Authority

C.       Share and storage Management

D.      Certificate Templates

E.       Security Configuration Wizard

F.        Authorization Manager

G.      Group Policy Management

H.      Certificates

I.         Active Directory Administrative Center

 

Correct Answer: D

 

 

QUESTION 395

Your network contains an Active Directory forest named adatum.com. All domain controllers currently run Windows Server 2003 Service Pack 2 (SP2). The functional level of the forest and the domain is Windows Server 2003. You need to deploy a read-only domain controller (RODC) that runs Windows Server 2008 R2. What should you do first?

 

A.       Deploy a writable domain controller that runs Windows Server 2008 R2.

B.       Raise the functional level of the forest to Windows Server 2008.

C.       Run adprep.exe.

D.      Raise the functional level of the domain to Windows Server 2003.

 

Correct Answer: C

 

 

QUESTION 396

Your network contains two Active Directory forests named contoso.com and nwtraders.com. Active Directory Rights Management Services (AD RMS) is deployed in each forest. You need to ensure that users from the nwtraders.com forest can access AD RMS protected content in the contoso.com forest. What should you do?

 

A.       Add a trusted user domain to the AD RMS cluster in the nwtraders.com domain.

B.       Add a trusted user domain to the AD RMS cluster in the contoso.com domain.

C.       Create an external trust from nwtraders.com to contoso.com.

D.      Create an external trust from contoso.com to nwtraders.corn.

 

Correct Answer: B

 

 

QUESTION 397

Your company plans to open a new branch office. The new office will have a Iow-speed connection to the Internet. You plan to deploy a read-only domain controller (RODC) in the branch office. You need to create an offline copy of the Active Directory database that can be used to install Active Directory on the new RODC. Which commands should you run from Ntdsutil?

 

To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

 

Build List and Reorder:

clip_image002

 

Correct Answer:

clip_image003

 

 

 

QUESTION 398

Your network contains an Active Directory forest. All users have a value set for the Department attribute. From Active Directory Users and computers, you search a domain for all users who have a Department attribute value of Marketing. The search returns 50 users. From Active Directory Users and Computers, you search the entire directory for all users who have a Department attribute value of Marketing. The search does not return any users. You need to ensure that a search of the entire directory for users in the marketing department returns all of the users who have the Marketing Department attribute. What should you do?

 

A.       Install the Windows Search Service role service on a global catalog server.

B.       From the Active Directory Schema snap-in, modify the properties of the Department attribute.

C.       Install the Indexing Service role service on a global catalog server.

D.      From the Active Directory Schema snap-in, modify the properties of the user class.

 

Correct Answer: B

 

 

QUESTION 399

A corporate network includes a single Active Directory Domain Services (AD DS) domain. The AD DS infrastructure is shown in the following graphic.

 

clip_image005

 

When the Montreal site domain controller is offline, authentication requests for Montreal branch office users are sent to the Toronto site domain controller. You need to ensure that when the Montreal Site domain controller is offline, authentication requests for Montreal branch office users are sent to the Quebec City site domain controller. What should you do?

 

A.       Create a site link bndge between the Montreal site and the Quebec City site.

B.       Enable the global catalog role on the Montreal site domain controller.

C.       Modify the Default Domain Policy Group Policy Object.

D.      Delete the Toronto-Montreal Site Link

 

Correct Answer: C

 

 

 

QUESTION 400

A corporate environment includes two Active Directory Domain Services (AD DS) forests, as shown in the following table.

 

clip_image007

You need to ensure that users in the contoso.com domain can access resources in the eng.fabrikam.com domain. What should you do?

 

A.       Enable selective authentication.

B.       Enable forest-wide authentication.

C.       Create an external trust between contoso.com and eng.fabrikam.com.

D.      Enable domain-wide authentication.

 

Correct Answer: C

Download Ensurepass Latest 2013 70-640 Braindumps Free Tests , help you to pass exam 100%.