2013 Latest 70-640 Braindumps Free Tests 61-70

Ensurepass

 

QUESTION 61

You create 200 new user accounts. The users are located in six different sites. New users report that they receive the following error message when they try to log on: "The username or password is incorrect." You confirm that the user accounts exist and are enabled. You also confirm that the user name and password information supplied are correct. You need to identify the cause of the failure. You also need to ensure that the new users are able to log on. Which utility should you run?

 

A.       Active Directory Domains and Trusts

B.       Repadmin

C.       Rstools

D.      Rsdiag

 

Correct Answer: B

 

 

QUESTION 62

Your network contains an Active Directory forest. All domain controllers run Windows Server 2008 R2 and are configured as DNS servers. You have an Active Directory-integrated zone for contoso.com. You have a Unix-based DNS server. You need to configure your Windows Server 2008 R2 environment to allow zone transfers of the contoso. com zone to the Unix-based DNS server. What should you do in the DNS Manager console?

 

A.       Enable BIND secondaries

B.       Create a stub zone

C.       Disable recursion

D.      Create a secondary zone

 

Correct Answer: A

 

 

QUESTION 63

Your company has an Active Directory domain. You log on to the domain controller. The Active Directory Schema snap-in is not available in the Microsoft Management Console (MMC). You need to access the Active Directory Schema snap-in. What should you do?

 

A.       Add the Active Directory Lightweight Directory Services (AD LDS) role to the domain controller by using Server Manager.

B.       Log off and log on again by using an account that is a member of the Schema Administrators group.

C.       Use the Ntdsutil.exe command to connect to the Schema Master operations master and open the schema for writing.

D.       Register Schmmgmt.dll.

 

Correct Answer: D

 

 

QUESTION 64

Your company has a server that runs Windows Server 2008 R2. Active Directory Certificate Services (AD CS) is configured as a standalone Certification Authority (CA) on the server. You need to audit changes to the CA configuration settings and the CA security settings. Which two tasks should you perform? (Each correct answer presents part of the solution. Choose two.)

A.       Configure auditing in the Certification Authority snap-in.

B.       Enable auditing of successful and failed attempts to change permissions on files in the %SYSTEM32%CertSrv directory.

C.       Enable auditing of successful and failed attempts to write to files in the %SYSTEM32%CertLog directory.

D.      Enable the Audit object access setting in the Local Security Policy for the Active Directory Certificate Services (AD CS) server.

 

Correct Answer: AD

 

 

QUESTION 65

Your company has a single-domain Active Directory forest. The functional level of the domain is Windows Server 2008. You perform the following activities:

 

Ÿ   Create a global distribution group.

Ÿ   Add users to the global distribution group.

Ÿ   Create a shared folder on a Windows Server 2008 member server.

Ÿ   Place the global distribution group in a domain local group that has access to the shared folder.

 

You need to ensure that the users have access to the shared folder. What should you do?

 

A.       Add the global distribution group to the Domain Administrators group.

B.       Change the group type of the global distribution group to a security group.

C.       Change the scope of the global distribution group to a Universal distribution group.

D.      Raise the forest functional level to Windows Server 2008.

 

Correct Answer: B

 

 

QUESTION 66

Your company hires 10 new employees. You want the new employees to connect to the main office through a VPN connection. You create new user accounts and grant the new employees they Allow Read and Allow Execute permissions to shared resources in the main office. The new employees are unable to access shared resources in the main office. You need to ensure that users are able to establish a VPN connection to the main office. What should you do?

 

A.  Grant the new employees the Allow Access Dial-in permission.

B.  Grant the new employees the Allow Full control permission.

C.  Add the new employees to the Remote Desktop Users security group.

D.  Add the new employees to the Windows Authorization Access security group.

 

Correct Answer: A

QUESTION 67

Your network consists of a single Active Directory domain. All domain controllers run Windows Server 2008 R2. You need to identify the Lightweight Directory Access Protocol (LDAP) clients that are using the largest amount of available CPU resources on a domain controller. What should you do?

 

A.       Review performance data in Resource Monitor.

B.       Review the Hardware Events log in the Event Viewer.

C.       Run the Active Directory Diagnostics Data Collector Set. Review the Active Directory Diagnostics report.

D.      Run the LAN Diagnostics Data Collector Set. Review the LAN Diagnostics report.

 

Correct Answer: C

 

 

QUESTION 68

Your company has an Active Directory forest that contains only Windows Server 2008 domain controllers. You need to prepare the Active Directory domain to install Windows Server 2008 R2 domain controllers. Which two tasks should you perform? (Each correct answer presents part of the solution. Choose two.)

 

A.       Run the adprep /domainprep command.

B.       Raise the forest functional level to Windows Server 2008.

C.       Raise the domain functional level to Windows Server 2008.

D.      Run the adprep /forestprep command.

 

Correct Answer: AD

 

 

QUESTION 69

You need to identify all failed logon attempts on the domain controllers. What should you do?

 

A.       View the Netlogon.log file.

B.       View the Security tab on the domain controller computer object.

C.       Run Event Viewer.

D.      Run the Security and Configuration Wizard.

 

Correct Answer: C

 

 

QUESTION 70

Your company has a DNS server that has 10 Active Directory integrated zones. You need to provide copies of the zone files of the DNS server to the security department. What should you do?

A.       Run the dnscmd /ZoneInfo command.

B.       Run the ipconfig /registerdns command.

C.       Run the dnscmd /ZoneExport command.

D.      Run the ntdsutil > Partition Management > List commands.

 

Correct Answer: C

Download Ensurepass Latest 2013 70-640 Braindumps Free Tests , help you to pass exam 100%.