Latest MCSA 70-642 Real Exam Download 31-40

Ensurepass

QUESTION 31

Your company has an Active Directory forest. All domain controllers run the DNS Server server role. The company plans to decommission the WINS service. You need to enable forest-wide single name resolution. What should you do?

 

A.      Enable WINS-R lookup in DNS

B.      Create Service Location (SRV) records for the single name resources

C.      Create an Active Directory-integrated zone named LegacyWINS. Create host (A) records for the single name resources

D.      Create an Active Directory-integrated zone named GlobalNames. Create an alias host (CNAME) records for the single name resources

 

Correct Answer: D

 

 

QUESTION 32

You manage a domain controller that runs Windows Server 2008 R2 and the DNS Server server role. The DNS server hosts an Active Directory-integrated zone for your domain. You need to provide a user with the ability to manage records in the zone. The user must not be able to modify the DNS server settings. What should you do?

 

A.      Add the user to the DNSUpdateProxy Global security group.

B.      Add the user to the DNSAdmins Domain Local security group.

C.      Grant the user permissions on the zone.

D.      Grant the user permissions on the DNS server.

 

Correct Answer: C

 

 

QUESTION 33

Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2008 R2 and are configured as DNS servers. All client computers run Windows 7. You create a new zone named secure.contoso.com and configure the zone to use DNSSEC. You need to ensure that all client computers verify whether the name and address information of secure.contoso.com is validated by the DNS servers. What should you configure from Group Policy?

 

A.      an IPSec Security policy

B.      the DNS Client settings

C.      the Public Key policies

D.      a Name Resolution Policy rule

 

Correct Answer: D

 

 

QUESTION 34

Your company has a main office and two branch offices that are connected by WAN links. The main office runs the DNS Server service on three domain controllers. The zone for your domain is configured as an Active Directory-integrated zone. Each branch office has a single member server that hosts a secondary zone for the domain. The DNS servers in the branch offices use the main office DNS server as the DNS Master server for the zone. You need to minimize DNS zone transfer traffic over the WAN links. What should you do?

 

A.      Decrease the Retry Interval setting in the Start of Authority (SOA) record for the zone.

B.      Decrease the Refresh Interval setting in the Start of Authority (SOA) record for the zone.

C.      Increase the Refresh Interval setting in the Start of Authority (SOA) record for the zone.

D.      Disable the netmask ordering option in the properties of the DNS Master server for the zone.

 

Correct Answer: C

 

 

QUESTION 35

Your network contains an Active Directory domain. The domain contains an enterprise certification authority (CA) named Server1 and a server named Server2. On Server2, you deploy Network Policy Server (NPS) and you configure a Network Access Protection (NAP) enforcement policy for IPSec. From the Health Registration Authority snap-in on Server2, you set the lifetime of health certificates to four hours. You discover that the validity period of the health certificates issued to client computers is one year. You need to ensure that the health certificates are only valid for four hours. What should you do?

 

A.      Modify the Request Handling settings of the certificate template used for the health certificates.

B.      Modify the Issuance Requirements settings of the certificate template used for the health certificates.

C.      On Server1, run certutil.exe -setreg policyeditflags +editf_attributeenddate.

D.      On Server1, run certutil.exe Csetregdbflags +dbflags_enablevolatilerequests.

 

Correct Answer: C

 

 

QUESTION 36

Your company has a single Active Directory domain. All servers run Windows Server 2008 R2. You install an additional DNS server that runs Windows Server 2008 R2. You need to delete the pointer record for the IP address 10.3.2.127. What should you do?

 

A.      Use DNS manager to delete the 127.in-addr.arpa zone.

B.      Run the dnscmd /RecordDelete 10.3.2.127 command at the command prompt.

C.      Run the dnscmd /ZoneDelete 127.in-addr.arpa command at the command prompt.

D.      Run the dnscmd /RecordDelete 10.in-addr.arpa. 127.2.3 PTR command at the command prompt.

 

Correct Answer: D

 

 

QUESTION 37

Your company has a server that runs Windows Server 2008 R2. You have a new application that locates remote resources by name. The new application requires IPv6. You need to ensure that the application can locate remote resources by using IPv6. What should you do?

 

A.      Create a new Pointer (PTR) DNS record.

B.      Create a new Quad-A (AAAA) DNS record.

C.      Create a new Signature (SIG) DNS record.

D.      Create a new Route Through (RT) DNS record.

 

Correct Answer: B

 

 

QUESTION 38

You are building a test environment to evaluate DNS Security Extensions (DNSSEC). You have a domain controller named Server1 that runs Windows Server 2008 R2 in your test environment. Server1 has the DNS Server server role installed. You need to configure Server1 to support the DNSSEC evaluation. Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)

 

A.      Create a new Quad-A (AAAA) DNS record.

B.      Create a new Signature (SIG) DNS record.

C.      Create a new Public key (KEY) DNS record.

D.      Create a new Well-known service (WKS) DNS record.

 

Correct Answer: BC

 

 

 

 

QUESTION 39

Your company has a domain controller that runs Windows Server 2008 R2 and the DNS role. The DNS domain is named contoso.com. You need to ensure that inquiries about contoso.com are sent to dnsadmin@contoso.com. What should you do?

 

A.      Create a Signature (SIG) record for the domain controller.

B.      Modify the Name Server (NS) record for the domain controller.

C.      Modify the Service Location (SRV) record for the domain controller.

D.      Modify the Start of Authority (SOA) record on the domain controller.

 

Correct Answer: D

 

 

QUESTION 40

Your company has a domain controller named Server1 that runs Windows Server 2008 R2 and the DNS server role. A server named Server2 runs Windows Server 2003 and Microsoft Exchange Server 2007. The company wants to deploy a new Exchange server named Server3 to receive all inbound e- mail traffic. You need to configure DNS to direct incoming e-mail traffic to the Exchange servers. You also need to ensure that higher priority is given to Server3. What should you do?

 

A.      Set the priority value of the Server2 Mail Exchanger (MX) record to 20. Create a new Mail Exchanger (MX) record for Server3. Set the priority value to 5.

B.      Set the priority value of the Server2 Mail Exchanger (MX) record to 5. Create a new Mail Exchanger (MX) record for Server3. Set the priority value to 20.

C.      Create a new Service Location (SRV) record in the domain for Server3. Set the port number value to 25. Configure the priority setting to 20.

D.      Create a new Service Location (SRV) record in the domain for Server3. Set the port number value to 110. Configure the priority setting to 5.

 

Correct Answer: A

 

Download Latest 70-642 Real Free Tests , help you to pass exam 100%.