REAL QUESTIONS SUBMIT MATERIAL ADVERTISE
Braindumps

Microsoft

Cisco

Citrix

CIW

CompTia

CWNA

Apple

Adobe

HP

Legato

Exin

Filemaker

Brocade

Ericsson

TIA

Veritas

ISEB

SCP

IISFA

ISM

OMG

Apc

Mile2

Foundry

Huawei

McData

Symantec

TeraData

RedHat

Solar Winds

Blue Coat

Riverbed

 

 
 
Click on name of dumper to view the dump
 
Morkal
 
 

 

Braindumps of 83-640
TS: Windows Server 2008 Active Directory, Configuring

 

Exam Questions, Answers, Braindumps (83-640)

First of all I thank to all the dumpers who all sent their braindumps to this site and helped others. Secondly thanx to www.exams.ws

  

QUESTION NO: 1

You work as the network administrator at PassGuide.com. The PassGuide.com network has a domain named PassGuide.com. All servers on the PassGuide.com network run Windows Server 2008. Only one Active-Directory integrated zone has been configured in the PassGuide.com domain. PassGuide.com has requested that you configure DNS zone to automatically remove DNS records that are outdated. What action should you consider?

A. You should consider running the netsh /Reset DNS command from the Command prompt.

B. You should consider enabling Scavenging in the DNS zone properties page.

C. You should consider reducing the TTL of the SOA record in the DNS zone properties page.

D. You should consider disabling updates in the DNS zone properties page.

Answer: B

Explanation:

In the scenario you should enable scavenging through the zone properties because scavenging removes the outdated DNS records from the DNS zone automatically. You should additionally note that patience would be required when enabling scavenging as there are some safety valves built into scavenging which takes long to pop.

Reference:

http://www.gilham.org/Blog/Lists/Posts/Post.aspx?List=aab85845-88d2-4091-8088-a6bbce0a4304&ID=211

QUESTION NO: 2

You work as the network administrator at PassGuide.com. The PassGuide.com network has a domain named PassGuide.com. All servers on the PassGuide.com network run Windows Server 2008. The PassGuide.com network has a server named PASSGUIDE-SR15. You install the Active Directory Lightweight Directory Services (AD LDS) on PASSGUIDE-SR15. Which of the following options can be used for the creation of new Organizational Units (OUís) in the application directory partition of the AD LDS?

A. You should run the net start command on PASSGUIDE-SR15.

B. You should open the ADSI Edit Microsoft Management Console on PASSGUIDE-SR15.

C. You should run the repadmin /dsaguid command on PASSGUIDE-SR15.

D. You should open the Active Directory Users and Computers Console on PASSGUIDE-SR15.

Answer: B

Explanation:

You need to use the ADSI Edit snap-in to create new OUs in the AD LDS application directory partition. You also need to add the snap-in in the Microsoft Management Console (MMC).

QUESTION NO: 3

You work as the network administrator at PassGuide.com. The PassGuide.com network has a domain named PassGuide.com. All servers on the PassGuide.com network run Windows Server 2008. The PassGuide.com network has two domain controllers PASSGUIDE-DC01 and PASSGUIDEDC02. PASSGUIDE-DC01 suffers a catastrophic failure but it is causing problems because it was configured to have Schema Master Operations role. You log on to the PassGuide.com domain as a domain administrator but your attempts to transfer the Schema Master Operations role to PASSGUIDE-DC02 are unsuccessful. What action should you take to transfer the Schema Master Operations role to PASSGUIDEDC02?

A. Your best option would be to have the dcpromo /adv command executed on PASSGUIDEDC02.

B. Your best option would be to have the Schema Master role seized to PASSGUIDE-DC02.

C. Your best option would be to have Schmmgmt.dll registered on PASSGUIDE-DC02.

D. Your best option would be to add your user account to the Schema Administrators group.

Answer: B

Explanation:

To ensure that PASSGUIDE-DC02 holds the Schema Master role you need to seize the Schema Master role on PASSGUIDE-DC02. Seizing the schema master role is a drastic step that should be considered only if the current operations master will never be available again. So to transfer the schema master operations role, you have to seize it on PASSGUIDE-DC02.

Reference:

http://technet2.microsoft.com/windowsserver/en/library/d4301a14-dd18-4b3c-a3ccec9a773f7ffb1033.mspx?mfr=true

QUESTION NO: 4

You work as the network administrator at PassGuide.com. The PassGuide.com network has a single forest. The forest functional level is set at Windows Server 2008. The PassGuide.com network has a Microsoft SQL Server 2005 database server named PASSGUIDE-DB04 that hosts the Active Directory Rights Management Service (AD RMS). You try to access the Active Directory Rights Management Services administration website but received an error message stating:

"SQL Server does not exist or access is denied."

How can you access the AD RMS administration website?

A. You need to restart the Internet Information Server (IIS) service and the MSSQLSVC service on PASSGUIDE-DB04.

B. You need to install the Active Directory Lightweight Directory Services (AD LDS) on PASSGUIDE-DB04.

C. You need to reinstall the AD RMS instance on PASSGUIDE-DB04.

D. You need to reinstall the SQL Server 2005 instance on PASSGUIDE-DB04.

E. You need to run the DCPRO command on PASSGUIDE-SR04

Answer: A

Explanation:

You need to restart the internet information server (IIS) to correct the problem. The starting of the MSSQULSVC service will allow you to access the database from AD RMS administration website.

QUESTION NO: 5

You work as an enterprise administrator at PassGuide.com. The PassGuide.com network has a domain named PassGuide.com. The PassGuide.com network has a Windows Server 2008 computer named PASSGUIDE-SR03 that functions as an Enterprise Root certificate authority (CA). A new PassGuide.com security policy requires that revoked certificate information should be available for examination at all times. What action should you take adhere to the new policy?

A. This can be accomplished by having a list of trusted certificate authorities published to the PassGuide.com domain.

B. This can be accomplished by having the Online Certificate Status Protocol (OCSP) responder implemented.

C. This can be accomplished by having the OCSP Response Signing certificate imported.

D. This can be accomplished by having the Startup Type of the Certificate Propagation service set to Automatic.

E. This can be accomplished by having the computer account of PASSGUIDE-SR03 added to the PGCertificates group.

Answer: B

Explanation:

You should use the network load balancing and publish an OCSP responder. This will ensure that the revoked certificate information will be available at all times. You do not need to download the entire CRL to check for revocation of a certificate; the OCSP is an online responder that can receive a request to check for revocation of a certificate. This will also speed up certificate revocation checking as well as reducing network bandwidth tremendously.

QUESTION NO: 6

You work as the network administrator at PassGuide.com. The PassGuide.com network has a domain named PassGuide.com. All servers on the PassGuide.com network run Windows Server 2008. You are responsible for managing two servers PASSGUIDE-SR01 and PASSGUIDE-SR02. They are setup with the following configuration.

PASSGUIDE-SR01 running Enterprise Root certificate authority (CA)

PASSGUIDE-SR02 running Online Responder role service

Which of the steps must you perform for configuring the Online Responder to be supported on PASSGUIDE-SR01?

A. You should enable the Dual Certificate List extension on PASSGUIDE-SR01.

B. You should ensure that PASSGUIDE-SR01 is a member of the CertPublishers group.

C. You should import the OCSP Response Signing certificate to PASSGUIDE-SR01.

D. You should enable the Authority Information Access (AIA) extension on PASSGUIDE-SR01.

E. You should run the CERTSRV command on PASSGUIDE-SR01.

Answer: D

Explanation:

In order to configure the online responder role service on PASSGUIDE-SR01 you need to configure the AIA extension. The authority information access extension will indicate how to access CA information and services for the issuer of the certificate in which the extension appears. Information and services may include on-line validation services and CA policy data. This extension may be included in subject or CA certificates, and it MUST be non-critical

QUESTION NO: 7

You work as the network administrator at PassGuide.com. The PassGuide.com network has a domain named PassGuide.com. All servers on the PassGuide.com network run Windows Server 2008 and all client computers run Windows Vista. The PassGuide.com network has a client computer named PASSGUIDE-WS640 that was last used six months ago. During the course of the day you attempt to log on to PASSGUIDE-WS640 but you are unable to authenticate during the logon process. What action should you consider in order to log on to PASSGUIDE-WS640?

A. You should consider opening the command prompt on PASSGUIDE-WS640 and running the netsh set machine command.

B. You should consider opening the command prompt on PASSGUIDE-WS640 and running the repadmin command.

C. You should consider removing PASSGUIDE-WS640 from the domain and then rejoining it.

D. You should consider deleting the computer account for PASSGUIDE-WS640 in Active Directory Users and Computers, and then recreate the computer account.

Answer: C

Explanation:

In the scenario you should have the computer disjoined from the domain and rejoined to the domain whilst having the computer account reset as well. You should additionally note that the long inactivity caused the computer to stop responding to the authentication query using the Active Directory records. You should note by disjoining and rejoining with the account being reset would refresh the computer account passwords.

QUESTION NO: 8

You work as an enterprise administrator at PassGuide.com. The PassGuide.com network has a forest with a domain named PassGuide.com. The PassGuide.com network has a Windows Server 2008 domain controller named PASSGUIDEDC01 that hosts the Directory Services Recovery Mode (DSRM) role. What would be the best option to take to have the DSRM password reset?

A. The best option is to open the Active Directory Security for Computers snap-in.

B. The best option is to run the ntdsutil command.

C. The best option is to run the Netsh command.

D. The best option is to open the Domain Controller security snap-in.

Answer: B

Explanation:

You should use the ntdsutil utility to reset the DSRM password. You can use Ntdsutil.exe to reset this password for the server on which you are working, or for another domain controller in the domain. Type ntdsutil and at the ntdsutil command prompt, type set dsrm password.

Reference:

http://support.microsoft.com/kb/322672

QUESTION NO: 9

You work as an enterprise administrator at PassGuide.com. The PassGuide.com network has a domain named PassGuide.com. All servers on the PassGuide.com network run Windows Server 2008. PassGuide.com has two offices Chicago and Dallas.

The network has the following setup.

Chicago Office - Domain Controller named PASSGUIDE-DC01

Dallas Office - Read-Only Domain Controller named PASSGUIDE-DC02

How can you make sure that Dallas Office users use only PASSGUIDE-DC02 for authentication?

A. You should consider having PASSGUIDE-DC02 configured as a bridehead server in the Dallas office.

B. You should consider installing and configuring the Password Replication Policy on PASSGUIDE-DC02.

C. You should consider having PASSGUIDE-DC01 configured as a bridehead server in the Chicago office.

D. You should consider installing and configuring the Password Replication Policy on PASSGUIDE-DC01.

E. You should consider having the Global Catalog installed on PASSGUIDE-DC01.

Answer: B

Explanation:

You should use the Password Replication Policy on the RODC. This will allow the users at the Dallas office to log on to the domain with RODC. RODCs donít cache any user or machine passwords.

QUESTION NO: 10

You work as the network administrator at PassGuide.com. The PassGuide.com network has a domain named intl.PassGuide.com. All servers on the PassGuide.com network run Windows Server 2008. The domain controllers on the PassGuide.com domain are configured to function as DNS servers. What action should you take to ensure that computers that are not part of the intl.PassGuide.com domain are not able to dynamically register their DNS registration information in the intl.PassGuide.com zone?

A. You should consider removing the .(root) zone from the intl.PassGuide.com zone.

B. You should consider running the dnscmd /AgeAllRecords command.

C. You should consider configuring Secure Only dynamic updates.

D. You should consider configuring the intl.PassGuide.com zone as an Active Directory integrated zone.

Answer: C

Explanation:

In order to ensure that only domain members are able to register their DNS records dynamically you need to set the option Secure only for Dynamic updates. This will only allow the domain members to register their DNS records dynamically.

Reference:

www.microsoft.com/technet/prodtechnol/windows2000serv/reskit/cnet/cncf_imp_afpf.mspx

QUESTION NO: 11

You work as a network administrator at PassGuide.com. The PassGuide.com network has a domain named PassGuide.com. All servers on the PassGuide.com network run Windows Server 2008. The PassGuide.com network has two servers named PASSGUIDE-SR01 and PASSGUIDE-SR02 that are configured as domain controllers and as DNS servers. Both servers have the following setup for the PassGuide.com domain.

PASSGUIDE-SR01 - Standard Primary zone

PASSGUIDE-SR02 - Standard Secondary zone.

You have to perform the following tasks

- Perform the replication of PassGuide.com Zone Data

- Make sure that Zone Data maintains encryption

- Prevent the loss of Zone Data

How can you accomplish the goals. (Each correct answer presents part of the solution. (Choose TWO.)

A. You should consider having the zone transfer settings configured on PASSGUIDE-SR01 and PASSGUIDE-SR02.

B. You should consider having the primary zone on PASSGUIDE-SR02 converted to an Active Directory-integrated stub zone.

C. You should consider having the primary zone on PASSGUIDE-SR01 converted to an Active Directory-integrated zone.

D. You should consider having the secondary zone on PASSGUIDE-SR02 deleted.

E. You should consider having the primary zone on PASSGUIDE-SR01 deleted.

Answer: C,D

Explanation:

In the scenario you should have the PassGuide.com primary zone converted to an active directory-integrated zone and delete the secondary zone as this would ensure replication of the PassGuide.com zone is encrypted whilst preventing data loss.

QUESTION NO: 12

You work as the network administrator at PassGuide.com. The PassGuide.com network has a domain named PassGuide.com. All servers on the PassGuide.com network run Windows Server 2008. All master roles in the forest are maintained at a domain controller PASSGUIDE-DC01. You have another domain controller in the network named PASSGUIDE-DC02 which contains better hardware and can improve performance. PASSGUIDE-DC01 is to be removed from the network. Which option can you select in order to ensure that proper roles are transferred to PASSGUIDEDC02 without disrupting the forest wide operations?

A. You should consider transferring the RID Master role and the Schema master role.

B. You should consider transferring the Schema master role and the Domain naming master role.

C. You should consider transferring the Infrastructure master role and the PDC emulator role.

D. You should consider transferring the Infrastructure master role and the Domain naming master role.

E. You should consider transferring the RID Master role and the PDC emulator role.

Answer: C

Explanation:

In order to transfer all forest-wide operation master roles to another domain you need to transfer Domain naming master as well as the Schema master. Schema Master: The schema master domain controller controls all updates and modifications to the schema. To update the schema of a forest, you must have access to the schema master. There can be only one schema master in the whole forest. Domain naming master: The domain naming master domain controller controls the addition or removal of domains in the forest. There can be only one domain naming master in the whole forest.

Reference:

http://support.microsoft.com/kb/324801

QUESTION NO: 13

You work as the enterprise administrator at PassGuide.com. The PassGuide.com network has a domain named PassGuide.com. All servers on the PassGuide.com network run Windows Server 2008. The PassGuide.com network has a domain controller named PASSGUIDE-DC01 that has a single hard drive named Drive C. Drive C hosts the ntds.dit database. You have installed an additional hard drive named Drive D on PASSGUIDE-DC01. What would be the best option to take to transfer the ntds.dit database to Drive D?

A. The best option is to run the Ntdsutil command with the Files option.

B. The best option is to open the Windows Power Shell and use the Copy and Paste functions.

C. The best option is to run the xcopy command.

D. The best option is to open the Windows Explorer and use the Cut and Paste functions.

Answer: A

Explanation:

The way you move the Active Directory database to a new volume, is to move the ntds.dit file to the new volume by opening the Files option in the ntdsutil utility. Use Ntdsutil.exe to move the database file, the log files, or both to a larger existing partition.

Reference:

http://technet2.microsoft.com/windowsserver/en/library/af6646aa-2360-46e4-81cad51707bf01eb1033.mspx?mfr=true

QUESTION NO: 14

You work as the network administrator at PassGuide.com. All servers on the PassGuide.com network run Windows Server 2008. The PassGuide.com network has a server named PASSGUIDE-SR01 that functions as an Enterprise Root certificate authority (CA). What action should you take to configure PASSGUIDE-SR01 to support key archival?

A. The Hisecdc security template should be applied to PASSGUIDE-SR01.

B. The OCSP Response Signing certificate should be imported to PASSGUIDE-SR01.

C. The private key on PASSGUIDE-SR01 should be archived.

D. The Startup Type of the Certificate Propagation service on PASSGUIDE-SR01 should be set to Automatic.

Answer: C

 

 

83-640


 

 

Braindumps Real exam questions and verified answers - 100% passing guarantee - cheap prices.

 

Free brain dumps Braindumps, notes, books for free

 

Braindumps and Exams - Instant download real exam questions - Passing guarantee.

Follow us on FaceBook
Braindumps on Facebook
 
 
 
 
 

CheckPoint

Linux

Novell

DB/2

Network Appliance

EC-Council

Nortel

McAfee

Juniper

ISACA

PMI

Sybase

EMC

HDI

SNIA

ISC

Sair

IBM

Lotus

Exam Express

3COM

BICSI

DeLL

Enterasys

Extreme Networks

Guidance Software

Computer Associates

Network General

SAS Institute

Alcatel Lucent

SeeBeyond

TruSecure

Polycom

Hyperion

Hitachi

Nokia

Fortinet

Vmware

Fujitsu

Tibco

Intel

PostgreSQLCE

BusinessObjects

RESSoftware

BlackBerry

AccessData

ICDL

Isilon

SAP

The Open Group

ACSM

Altiris

Avaya

Cognos

F5

Genesys

SDI

ACI

ASQ

Google

H3C

HIPAA

HRCI

SOA

IIBA

Zend