2013 Latest 70-640 Braindumps Free Tests 411-420

Ensurepass

 

QUESTION 411

A corporate network includes an Active Directory-integrated zone. All DNS servers that host the zone are domain controllers. You add multiple DNS records to the zone. You need to ensure that the new records are available on all DNS servers as soon as possible. Which tool should you use?

 

A.       Repadmin

B.       Active Directory Domains and Trusts console

C.       Ldp

D.      Ntdsutil

 

Correct Answer: A

 

 

QUESTION 412

Your network contains an Active Directory forest named contoso.com. The forest contains two domains named contoso.com and child.contoso.com. The forest contains two sites named Seattle and Denver. Both sites contain users, client computers, and domain controllers from both domains. The Seattle site contains the first domain controller deployed to the forest. The Seattle site also contains the primary domain controller (PDC) emulator for both domains. All of the domain controllers are configured as DNS servers. All DNS zones are replicated to all of the domain controllers in the forest. The users in the Denver site report that is takes a long time to log on to their client computer when they use their user principal name (UPN). The users in the Seattle site do not experience the same issue. You need to reduce the amount of time it takes for the Denver users to log on to their client computer by using their UPN. What should you do?

 

A.       Reduce the cost of the site link between the Denver site and the Seattle site.

B.       Enable the global catalog on a domain controller in the Denver site.

C.       Enable universal group membership caching in the Denver site.

D.      Move a PDC emulator to the Denver site.

E.       Reduce the replication interval of the site link between the Denver site and the Seattle site.

F.        Add an additional domain controller to the Denver site.

 

Correct Answer: B

 

 

QUESTION 413

Your network contains two Active Directory forests named contoso.com and fabrikam.com. Each forest contains a single domain. A two-way forest trust exists between the forests. Selective authentication is enabled on the trust. Contoso.com contains a group named Group 1. Fabrikam.com contains a server named Server1. You need to ensure that users in Group1 can access resources on Server1. What should you modify?

 

A.       the permissions of the Group1 group

B.       the UPN suffixes of the contoso.com forest

C.       the UPN suffixes of the fabrikam.com forest

D.      the permissions of the Server1 computer account

 

Correct Answer: A

 

 

QUESTION 414

Your network contains an Active Directory domain named contoso.com. You have an organizational unit (OU) named Sales and an OU named Engineering. Users in the Sates OU frequently log on to client computers in the Engineering OU. You need to meet the following requirements:

 

Ÿ   All of the user settings in the Group Policy objects (GPOs) linked to both the Sales OU and the Engineering OU must be applied to sales users when they log on to client computers in the Engineering OU.

Ÿ   Only the policy settings in the GPOs linked to the Sales OU must be applied to sales users when they log on to client computers in the Sales OU.

Ÿ   Policy settings in the GPOs linked to the Sales OU must not be applied to users in the Engineering OU.

 

What should you do?

 

A.       Modify the Group Policy permissions.

B.       Enable block inheritance.

C.       Configure the link order.

D.      Enable loopback processing in merge mode.

E.       Enable loopback processing in replace mode.

F.        Configure WMI filtering.

G.      Configure Restricted Groups.

H.      Configure Group Policy Preferences.

I.         Link the GPO to the Sales OU.

J.        Link the GPO to the Engineering OU.

 

Correct Answer: D

 

 

QUESTION 415

You have an Active Directory domain named contoso.com. You need to view the account lockout threshold and duration for the domain. Which tool should you use?

 

A.       Computer Management

B.       Net Config

C.       Active Directory Users and Computers

D.      Gpresult

 

Correct Answer: C

 

 

QUESTION 416

Your network contains an Active Directory forest. The forest contains two domains named contoso.com and east.contoso.com. The contoso.com domain contains a domain controller named DC1. The east.contoso.com domain contains a domain controller named DC2. DC1 and DC2 have the DNS Server role installed. You need to create a DNS zone that is available on DC1 and DC2. The solution must ensure that zone transfers are encrypted. What should you do?

 

A.       Create a primary zone on DC1 and store the zone in a zone file. On DC1 and DC2, configure inbound rules and outbound rules by using Windows Firewall with Advanced Security. Create a secondary zone on DC2 and select DC1 as the master.

B.       Create a primary zone on DC1 and store the zone in a DC=ForestDNSZones, DC=Contoso, DC=com naming context.

C.       Create a primary zone on DC2 and store the zone in a DC= DC=East, DC=Contoso/DC=com naming context. Create a secondary zone on DC1 and select DC2 as the master.

D.       Create a primary zone on DC1 and store the zone in a zone file. Configure DNSSEC for the zone. Create a secondary zone on DC2 and select DC1 as the master.

 

Correct Answer: B

 

 

QUESTION 417

Your network contains an Active Directory domain named adatum.com. All servers run Windows Server 2008 R2. The network contains an enterprise certification authority (CA). You need to ensure that all of the members of a group named Managers can view the event log entries for

Certificate Services. Which snap-in should you use?

 

A.       Active Directory Administrative Center

B.       Authorization Manager

C.       Certificate Templates

D.      Certificates

E.       Certification Authority

F.        Enterprise PKI

G.      Group Policy Management

H.      Security Configuration Wizard

I.         Share and Storage Management

 

Correct Answer: G

 

 

QUESTION 418

Your network contains an Active Directory domain named adatum.com. All servers run Windows Server 2008 R2 Enterprise. All client computers run Windows 7 Professional. The network contains an enterprise certification authority (CA). You need to approve a pending certificate request. Which snap-in should you use?

 

A.       Active Directory Administrative Center

B.       Authorization Manager

C.       Certificate Templates

D.      Certificates

E.       Certification Authority

F.        Enterprise PKI

G.      Group Policy Management

H.      Security Configuration Wizard

I.         Share and Storage Management

 

Correct Answer: E

 

 

QUESTION 419

Your network contains an Active Directory domain named contoso.com. You have an organizational unit (OU) named Sales and an OU named Engineering. You have a Group Policy object (GPO) linked to the domain. You need to ensure that the settings in the GPO are not processed by user accounts or computer accounts in the Sales OU. You must achieve this goal by using the minimum amount of administrative effort. What should you do?

 

A.       Modify the Group Policy permissions.

B.       Enable block inheritance.

C.       Configure the link order.

D.      Enable loopback processing in merge mode.

E.       Enable loopback processing in replace mode.

F.        Configure WMI filtering.

G.      Configure Restricted Groups.

H.      Configure Group Policy Preferences.

I.         Link the GPO to the Sales OU.

J.        Link the GPO to the Engineering OU.

 

Correct Answer: B

 

 

QUESTION 420

A corporate network includes a single Active Directory Domain Services (AD DS) domain. The domain contains 10 domain controllers. The domain controllers run Windows Server 2008 R2 and are configured as DNS servers. You plan to create an Active Directory-integrated zone. You need to ensure that the new zone is replicated to only four of the domain controllers. What should you do first?

 

A.       Use the ntdsutil tool to modify the DS behavior for the domain.

B.       Use the ntdsutil tool to add a naming context.

C.       Create a new delegation in the ForestDnsZones application directory partition.

D.      Use the dnscmd tool with the /zoneadd parameter.

 

Correct Answer: B

 

Download Ensurepass Latest 2013 70-640 Braindumps Free Tests , help you to pass exam 100%.