Braindump2go Free Exam Microsoft 70-640 Practice Exam Questions (301-310)

The 70-640 Exam Practice Questions and Answers are ideal for the aspring candiates to grab exceptional grades in Microsoft 70-640 Exam! The 70-640 Questions and Answers are developed using the latest updated course content and all the answers are verified to ensure phenoment preparation for the actual 70-640 Exam!

Vendor: Microsoft
Exam Code: 70-640
Exam Name: TS: Windows Server 2008 Active Directory, Configuring

Keywords: 70-640 Exam Dumps,70-640 Practice Tests,70-640 Practice Exams,70-640 Exam Questions,70-640 Dumps,70-640 Dumps PDF,Microsoft 70-640 Exam Dumps,70-640 Questions and Answers,TS: Windows Server 2008 Active Directory, Configuring

QUESTION 301
Your network contains two Active Directory forests named contoso.com and nwtraders.com. Active Directory Rights Management Services (AD RMS) is deployed in each forest.
You need to ensure that users from the nwtraders.com forest can access AD RMS protected content in the contoso.com forest.
What should you do?

A.    Add a trusted user domain to the AD RMS cluster in the nwtraders.com domain.
B.    Add a trusted user domain to the AD RMS cluster in the contoso.com domain.
C.    Create an external trust from nwtraders.com to contoso.com.
D.    Create an external trust from contoso.com to nwtraders.corn.

Answer: B
Explanation:
http://technet.microsoft.com/en-us/library/hh311036.aspx

QUESTION 302
Drag and Drop Question
Your company plans to open a new branch office.
The new office will have a Iow-speed connection to the Internet.
You plan to deploy a read-only domain controller (RODC) in the branch office.
You need to create an offline copy of the Active Directory database that can be used to install Active Directory on the new RODC.
Which commands should you run from Ntdsutil? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
 
Answer: 
 

QUESTION 303
Your network contains an Active Directory forest.
All users have a value set for the Department attribute.
From Active Directory Users and computers, you search a domain for all users who have a Department attribute value of Marketing.
The search returns 50 users.
From Active Directory Users and Computers, you search the entire directory for all users who have a Department attribute value of Marketing.
The search does not return any users.
You need to ensure that a search of the entire directory for users in the marketing department returns all of the users who have the Marketing Department attribute.
What should you do?

A.    Install the Windows Search Service role service on a global catalog server.
B.    From the Active Directory Schema snap-in, modify the properties of the Department attribute.
C.    Install the Indexing Service role service on a global catalog server.
D.    From the Active Directory Schema snap-in, modify the properties of the user class.

Answer: B
Explanation:
http://technet.microsoft.com/en-us/library/how-global-catalog-servers-work.aspx

QUESTION 304
A corporate network includes a single Active Directory Domain Services (AD DS) domain.
The AD DS infrastructure is shown in the following graphic.
When the Montreal site domain controller is offline, authentication requests for Montreal branch office users are sent to the Toronto site domain controller.
You need to ensure that when the Montreal Site domain controller is offline, authentication requests for Montreal branch office users are sent to the Quebec City site domain controller.
What should you do?
 

A.    Create a site link bndge between the Montreal site and the Quebec City site.
B.    Enable the global catalog role on the Montreal site domain controller.
C.    Modify the Default Domain Policy Group Policy Object.
D.    Delete the Toronto-Montreal Site Link

Answer: C

QUESTION 305
A corporate environment includes two Active Directory Domain Services (AD DS) forests, as shown in the following table.
You need to ensure that users in the contoso.com domain can access resources in the eng.fabrikam.com domain.
What should you do?
 

A.    Enable selective authentication.
B.    Enable forest-wide authentication.
C.    Create an external trust between contoso.com and eng.fabrikam.com.
D.    Enable domain-wide authentication.

Answer: C
Explanation:
http://technet.microsoft.com/en-us/library/cc816837.aspx
Creating External Trusts
You can create an external trust to form a one-way or two-way, nontransitive trust with domains that are outside your forest. External trusts are sometimes necessary when users need access to resources that are located in a Windows NT 4.0 domain or in a domain that is in a separate Active Directory Domain Services (AD DS) forest that is not joined by a forest trust.

QUESTION 306
Your network contains an Active Directory domain.
You need to activate the Active Directory Recycle Bin in the domain.
Which tool should you use?

A.    Dsamain
B.    Set-ADDomain
C.    Add-WindowsFeature
D.    Ldp

Answer: D
Explanation:
http://technet.microsoft.com/en-us/library/dd379481.aspx

QUESTION 307
Your network contains an Active Directory domain named contoso.com.
You need to create a script that runs the Best Practices Analyzer (BPA) each week for all of the server roles that BPA supports on each domain controller.
You must achieve this goal by using the minimum amount of administrative effort.
Which tools should you use? (Each correct answer presents part of the solution. Choose three.)

A.    Get-Troubleshooting Pack / Invoke-Troubleshooting Pack.
B.    Import-Module Best Practices.
C.    Get-BPA Model / Invoke-BPA Model.
D.    Import-Module Troubleshooting Pack.
E.    Get- BPA Result.

Answer: BCE

QUESTION 308
A corporate network includes a single Active Directory Domain Services (AD DS) domain.
All regular user accounts reside in an organizational unit (OU) named Employees.
All administrator accounts reside in an OU named Admins.
You need to ensure that any time an administrator modifies an employee’s name in AD DS, the change is audited.
What should you do first?

A.    Enable the Audit directory service access setting in the Default Domain Controllers Policy
Group Policy Object.
B.    Create a Group Policy Object with the Audit directory service access setting enabled and
link it to the Employees OU.
C.    Enable the Audit directory service access setting in the Default Domain Policy Group Policy
Object.
D.    Modify the searchFlags property for the User class in the schema.

Answer: A
Explanation:
http://technet.microsoft.com/en-us/library/cc731607.aspx

QUESTION 309
Your network contains an Active Directory domain.
You need to back up all of the Group Policy objects (GPOs), Group Policy permissions, and Group Policy links for the domain.
What should you do?

A.    From Group Policy Management Console (GPMC), back up the GPOs.
B.    From Windows Explorer, copy the content of the %systemroot%\SYSVOL folder.
C.    From Windows Server Backup, perform a system state backup.
D.    From Windows PowerShell, run the Backup-GPO cmdlet.

Answer: C
Explanation:
http://www.microsoft.com/en-us/download/details.aspx?id=22478

QUESTION 310
Your network contains a domain controller that runs Windows Server 2008 R2.
You need to reset the Directory Services Restore Mode (DSRM) password on the domain controller.
Which tool should you use?

A.    Ntdsutil
B.    Dsamain
C.    Active Directory Users and Computers
D.    Local Users and Groups

Answer: A
Explanation:
http://blogs.technet.com/b/meamcs/archive/2012/05/29/reset-the-dsrm-administrator-password.aspx


Braindump2go New Published Exam Dumps: Microsoft 70-640 Practice Tests Questions, 651 Latest Questions and Answers from Official Exam Centre Guarantee You a 100% Pass! Free Download Instantly!

 

http://www.braindump2go.com/70-640.html