Microsoft Certkiller Exam Bundle

Size: px
Start display at page:

Download "Microsoft Certkiller Exam Bundle"

Transcription

1 Microsoft Certkiller Exam Bundle Number: Passing Score: 700 Time Limit: 145 min File Version: Microsoft Exam Bundle Exam Name: Microsoft TS: Windows Server 2008 Active Directory, Configuring Exam For Full Set of Questions please visit:

2 Exam A QUESTION 1 You have a domain controller named Server1 that runs Windows Server 2008 R2. You need to determine the size of the Active Directory database on Server1. A. Run the Active Directory Sizer tool. B. Run the Active Directory Diagnostics data collector set. C. From Windows Explorer, view the properties of the %systemroot%\ntds\ntds.dit file. D. From Windows Explorer, view the properties of the %systemroot%\sysvol\domain folder. Correct Answer: C /Reference: QUESTION 2 You need to receive an message whenever a domain user account is locked out. Which tool should you use? A. Active Directory Administrative Center B. Event Viewer C. Resource Monitor D. Security Configuration Wizard Correct Answer: B /Reference: QUESTION 3 Your network contains an Active Directory domain named contoso.com. You have a management computer named Computer1 that runs Windows 7. You need to forward the logon events of all the domain controllers in contoso.com to Computer1. All new domain controllers must be dynamically added to the subscription. A. From Computer1, configure source-initiated event subscriptions. From a Group Policy object (GPO) linked to the Domain Controllers organizational unit (OU), configure the Event Forwarding node. B. From Computer1, configure collector-initiated event subscriptions. From a Group Policy object (GPO) linked to the Domain Controllers organizational unit (OU), configure the Event Forwarding node. C. From Computer1, configure source-initiated event subscriptions. Install a server authentication certificate on Computer1. Implement autoenrollment for the Domain Controllers organizational unit (OU). D. From Computer1, configure collector-initiated event subscriptions. Install a server authentication certificate on Computer1. Implement autoenrollment for the Domain Controllers organizational unit (OU).

3 Correct Answer: A /Reference: QUESTION 4 Your network contains an Active Directory domain that has two sites. You need to identify whether logon scripts are replicated to all domain controllers. Which folder should you verify? A. GroupPolicy B. NTDS C. SoftwareDistribution D. SYSVOL Correct Answer: D /Reference: QUESTION 5 You install a standalone root certification authority (CA) on a server named Server1. You need to ensure that every computer in the forest has a copy of the root CA certificate installed in the local computer's Trusted Root Certification Authorities store. Which command should you run on Server1? A. certreq.exe and specify the -accept parameter B. certreq.exe and specify the -retrieve parameter C. certutil.exe and specify the -dspublish parameter D. certutil.exe and specify the -importcert parameter Correct Answer: C /Reference: QUESTION 6 You have an enterprise subordinate certification authority (CA). You have a group named Group1. You need to allow members of Group1 to publish new certificate revocation lists. Members of Group1 must not be allowed to revoke certificates. A. Add Group1 to the local Administrators group.

4 B. Add Group1 to the Certificate Publishers group. C. Assign the Manage CA permission to Group1. D. Assign the Issue and Manage Certificates permission to Group1. Correct Answer: C /Reference: QUESTION 7 You have an enterprise subordinate certification authority (CA) configured for key archival. Three key recovery agent certificates are issued. The CA is configured to use two recovery agents. You need to ensure that all of the recovery agent certificates can be used to recover all new private keys. A. Add a data recovery agent to the Default Domain Policy. B. Modify the value in the Number of recovery agents to use box. C. Revoke the current key recovery agent certificates and issue three new key recovery agent certificates. D. Assign the Issue and Manage Certificates permission to users who have the key recovery agent certificates. Correct Answer: B /Reference: QUESTION 8 You have an enterprise subordinate certification authority (CA). The CA is configured to use a hardware security module. You need to back up Active Directory Certificate Services on the CA. Which command should you run? A. certutil.exe backup B. certutil.exe backupdb C. certutil.exe backupkey D. certutil.exe store Correct Answer: A /Reference:

5 QUESTION 9 You have Active Directory Certificate Services (AD CS) deployed. You create a custom certificate template. You need to ensure that all of the users in the domain automatically enroll for a certificate based on the custom certificate template. Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.) A. In a Group Policy object (GPO), configure the autoenrollment settings. B. In a Group Policy object (GPO), configure the Automatic Certificate Request Settings. C. On the certificate template, assign the Read and Autoenroll permission to the Authenticated Users group. D. On the certificate template, assign the Read, Enroll, and Autoenroll permission to the Domain Users group. Correct Answer: AD /Reference: QUESTION 10 You have an enterprise subordinate certification authority (CA). You have a custom certificate template that has a key length of 1,024 bits. The template is enabled for autoenrollment. You increase the template key length to 2,048 bits. You need to ensure that all current certificate holders automatically enroll for a certificate that uses the new template. Which console should you use? A. Active Directory Administrative Center B. Certification Authority C. Certificate Templates D. Group Policy Management Correct Answer: C /Reference: QUESTION 11 Your network contains an Active Directory forest. All domain controllers run Windows Server 2008 Standard. The functional level of the domain is Windows Server You have a certification authority (CA). The relevant servers in the domain are configured as shown below:

6 You need to ensure that you can install the Active Directory Certificate Services (AD CS) Certificate Enrollment Web Service on the network. A. Upgrade Server1 to Windows Server 2008 R2. B. Upgrade Server2 to Windows Server 2008 R2. C. Raise the functional level of the domain to Windows Server D. Install the Windows Server 2008 R2 Active Directory Schema updates. Correct Answer: D /Reference: QUESTION 12 You have a domain controller that runs the DHCP service. You need to perform an offline defragmentation of the Active Directory database on the domain controller. You must achieve this goal without affecting the availability of the DHCP service. A. Restart the domain controller in Directory Services Restore Mode. Run the Disk Defragmenter utility. B. Restart the domain controller in Directory Services Restore Mode. Run the Ntdsutil utility. C. Stop the Active Directory Domain Services service. Run the Ntdsutil utility. D. Stop the Active Directory Domain Services service. Run the Disk Defragmenter utility. Correct Answer: C /Reference: QUESTION 13 Your network contains an Active Directory forest. You need to add a new user principal name (UPN) suffix to the forest. Which tool should you use? A. Active Directory Administrative Center B. Active Directory Domains and Trusts C. Active Directory Sites and Services D. Active Directory Users and Computers Correct Answer: B /Reference:

7 QUESTION 14 Your network contains an Active Directory domain. The domain contains two sites named Site1 and Site2. Site 1 contains five domain controllers. Site2 contains one read-only domain controller (RODC). Site1 and Site2 connect to each other by using a slow WAN link. You discover that the cached password for a user named User1 is compromised on the RODC. On a domain controller in Site1, you change the password for User1. You need to replicate the new password for User1 to the RODC immediately. The solution must not replicate other objects to the RODC. Which tool should you use? A. Active Directory Sites and Services B. Active Directory Users and Computers C. Repadmin D. Replmon Correct Answer: A /Reference: QUESTION 15 Your network contains an Active Directory domain named contoso.com. The properties of the contoso.com DNS zone are configured as shown in the exhibit. (Click the Exhibit button.)

8 You need to update all service location (SRV) records for a domain controller in the domain. What should you do? A. Restart the Netlogon service. B. Restart the DNS Client service. C. Run sc.exe and specify the triggerinfo parameter. D. Run ipconfig.exe and specify the /registerdns parameter. Correct Answer: A /Reference: : QUESTION 16 Your network contains an Active Directory domain. The domain contains 1,000 user accounts. You have a list that contains the mobile phone number of each user. You need to add the mobile number of each user to Active Directory. A. Create a file that contains the mobile phone numbers, and then run ldifde.exe. B. Create a file that contains the mobile phone numbers, and then run csvde.exe. C. From Adsiedit, select the CN=Users container, and then modify the properties of the container.

9 D. From Active Directory Users and Computers, select all of the users, and then modify the properties of the users. Correct Answer: A /Reference: QUESTION 17 Your network contains an Active Directory domain named contoso.com. All domain controllers and member servers run Windows Server All client computers run Windows 7. From a client computer, you create an audit policy by using the Advanced Audit Policy Configuration settings in the Default Domain Policy Group Policy object (GPO). You discover that the audit policy is not applied to the member servers. The audit policy is applied to the client computers. You need to ensure that the audit policy is applied to all member servers and all client computers. A. Add a WMI filter to the Default Domain Policy GPO. B. Modify the security settings of the Default Domain Policy GPO. C. Configure a startup script that runs auditpol.exe on the member servers. D. Configure a startup script that runs auditpol.exe on the domain controllers. Correct Answer: C /Reference: QUESTION 18 Your company uses an application that stores data in an Active Directory Lightweight Directory Services (AD LDS) instance named Instance1. You attempt to create a snapshot of Instance1 as shown in the exhibit. (Click the Exhibit button.) You need to ensure that you can take a snapshot of Instance1.

10 A. At the command prompt, run net start VSS. B. At the command prompt, run net start Instance1. C. Set the Startup Type for the Instance1 service to Disabled. D. Set the Startup Type for the Volume Shadow Copy Service (VSS) to Manual. Correct Answer: A /Reference: QUESTION 19 Your network contains 10 domain controllers that run Windows Server 2008 R2. The network contains a member server that is configured to collect all of the events that occur on the domain controllers. You need to ensure that administrators are notified when a specific event occurs on any of the domain controllers. You want to achieve this goal by using the minimum amount of administrative effort. A. From Event Viewer on the member server, create a subscription. B. From Event Viewer on each domain controller, create a subscription. C. From Event Viewer on the member server, run the Create Basic Task Wizard. D. From Event Viewer on each domain controller, run the Create Basic Task Wizard. Correct Answer: C /Reference: QUESTION 20 Your network contains a single Active Directory domain named contoso.com. An administrator accidentally deletes the _msdsc.contoso.com zone. You recreate the _msdsc.contoso.com zone. You need to ensure that the _msdsc.contoso.com zone contains all of the required DNS records. What should you do on each domain controller? A. Restart the Netlogon service. B. Restart the DNS Server service. C. Run dcdiag.exe /fix. D. Run ipconfig.exe /registerdns. Correct Answer: A /Reference: QUESTION 21 Your network contains an Active Directory-integrated zone. All DNS servers that host the zone are domain controllers. You add multiple DNS records to the zone. You need to ensure that the records are replicated to all DNS servers. Which tool should you use? A. Dnslint B. Ldp

11 C. Nslookup D. Repadmin Correct Answer: D /Reference: QUESTION 22 Your network contains an Active Directory forest. The forest contains two domains named contoso.com and eu.contoso.com. All domain controllers are DNS servers. The domain controllers in contoso.com host the zone for contoso.com. The domain controllers in eu.contoso.com host the zone for eu.contoso.com. The DNS zone for contoso.com is configured as shown in the exhibit. (Click the Exhibit button.) You need to ensure that all domain controllers in the forest host a writable copy of _msdsc.contoso.com. Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.) A. Create a zone delegation record in the contoso.com zone. B. Create a zone delegation record in the eu.contoso.com zone. C. Create an Active Directory-integrated zone for _msdsc.contoso.com. D. Create a secondary zone named _msdsc.contoso.com in eu.contoso.com. Correct Answer: AC /Reference: QUESTION 23 You need to compact an Active Directory database on a domain controller that runs Windows Server 2008 R2.

12 A. Run defrag.exe /a /c. B. Run defrag.exe /c /u. C. From Ntdsutil, use the Files option. D. From Ntdsutil, use the Metadata cleanup option. Correct Answer: C /Reference: QUESTION 24 Your network contains an Active Directory domain named contoso.com. Contoso.com contains a member server that runs Windows Server 2008 Standard. You need to install an enterprise subordinate certification authority (CA) that supports private key archival. You must achieve this goal by using the minimum amount of administrative effort. What should you do first? A. Initialize the Trusted Platform Module (TPM). B. Upgrade the member server to Windows Server 2008 R2 Standard. C. Install the Certificate Enrollment Policy Web Service role service on the member server. D. Run the Security Configuration Wizard (SCW) and select the Active Directory Certificate Services - Certification Authority server role template check box. Correct Answer: B /Reference: QUESTION 25 You have an enterprise subordinate certification authority (CA). You have a custom Version 3 certificate template. Users can enroll for certificates based on the custom certificate template by using the Certificates console. The certificate template is unavailable for Web enrollment. You need to ensure that the certificate template is available on the Web enrollment pages. A. Run certutil.exe Cpulse. B. Run certutil.exe Cinstallcert. C. Change the certificate template to a Version 2 certificate template. D. On the certificate template, assign the Autoenroll permission to the users. Correct Answer: C /Reference: QUESTION 26 Your network contains an Active Directory domain. The domain contains a member server named Server1 that runs Windows Server 2008 R2. You need to configure Server1 as a global catalog server. A. Modify the Active Directory schema.

13 B. From Ntdsutil, use the Roles option. C. Run the Active Directory Domain Services Installation Wizard on Server1. D. Move the Server1 computer object to the Domain Controllers organizational unit (OU). Correct Answer: C /Reference: QUESTION 27 Your network contains an Active Directory domain. All domain controller run Windows Server You replace all domain controllers with domain controllers that run Windows Server 2008 R2. You raise the functional level of the domain to Windows Server 2008 R2. You need to minimize the amount of SYSVOL replication traffic on the network. A. Raise the functional level of the forest to Windows Server 2008 R2. B. Modify the path of the SYSVOL folder on all of the domain controllers. C. On a global catalog server, run repadmin.exe and specify the KCC parameter. D. On the domain controller that holds the primary domain controller (PDC) emulator FSMO role, run dfsrmig.exe. Correct Answer: C /Reference: QUESTION 28 Your network contains an Active Directory forest. The forest contains two domain controllers. The domain controllers are configured as shown in the following table. All client computers run Windows 7. You need to ensure that all client computers in the domain keep the same time as an external time server. A. From DC1, run the time command. B. From DC2, run the time command. C. From DC1, run the w32tm.exe command. D. From DC2, run the w32tm.exe command. Correct Answer: D /Reference:

14 QUESTION 29 Your network contains an Active Directory domain named contoso.com. Contoso.com contains two domain controllers. The domain controllers are configured as shown in the following table. All client computers have IP addresses in the to range. You need to minimize the number of client authentication requests sent to DC2. A. Create a new site named Site1. Create a new subnet object that has the /24 prefix and assign the subnet to Site1. Move DC1 to Site1. B. Create a new site named Site1. Create a new subnet object that has the /32 prefix and assign the subnet to Site1. Move DC1 to Site1. C. Create a new site named Site1. Create a new subnet object that has the /32 prefix and assign the subnet to Site1. Move DC2 to Site1. D. Create a new site named Site1. Create a new subnet object that has the /24 prefix and assign the subnet to Site1. Move DC2 to Site1. Correct Answer: C /Reference: QUESTION 30 Active Directory Rights Management Services (AD RMS) is deployed on your network. You need to configure AD RMS to use Kerberos authentication. Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.) A. Register a service principal name (SPN) for AD RMS. B. Register a service connection point (SCP) for AD RMS. C. Configure the identity setting of the _DRMSAppPool1 application pool. D. Configure the useapppoolcredentials attribute in the Internet Information Services (IIS) Correct Answer: AD /Reference: QUESTION 31 Your company has four offices. The network contains a single Active Directory domain. Each office has a domain controller. Each office has an organizational unit (OU) that contains the user accounts for the users in that office. In each office, support technicians perform basic troubleshooting for the users in their respective office. You need to ensure that the support technicians can reset the passwords for the user accounts in their respective office only. The solution must prevent the technicians from creating user accounts. What should you do? A. For each OU, run the Delegation of Control Wizard.

15 B. For the domain, run the Delegation of Control Wizard. C. For each office, create an Active Directory group, and then modify the security settings for each group. D. For each office, create an Active Directory group, and then modify the controlaccessrights attribute for each group. Correct Answer: A /Reference: QUESTION 32 Your network contains a single Active Directory domain. Client computers run either Windows XP Service Pack 3 (SP3) or Windows 7. All of the computer accounts for the client computers are located in an organizational unit (OU) named OU1. You link a new Group Policy object (GPO) named GPO10 to OU1. You need to ensure that GPO10 is applied only to client computers that run Windows 7. A. Create a new OU in OU1. Move the Windows XP computer accounts to the new OU. B. Enable block inheritance on OU1. C. Create a WMI filter and assign the filter to GPO10. D. Modify the permissions of OU1. Correct Answer: C /Reference: QUESTION 33 Your network contains two Active Directory forests named contoso.com and nwtraders.com. Active Directory Rights Management Services (AD RMS) is deployed in each forest. You need to ensure that users from the nwtraders.com forest can access AD RMS protected content in the contoso.com forest. A. Add a trusted user domain to the AD RMS cluster in the nwtraders.com domain. B. Create an external trust from nwtraders.com to contoso.com. C. Add a trusted user domain to the AD RMS cluster in the contoso.com domain. D. Create an external trust from contoso.com to nwtraders.com. Correct Answer: C /Reference: QUESTION 34 You need to purge the list of user accounts that were authenticated on a read-only domain controller (RODC).

16 A. Run the repadmin.exe command and specify the /prp parameter. B. From Active Directory Sites and Services, modify the properties of the RODC computer object. C. From Active Directory Users and Computers, modify the properties of the RODC computer object. D. Run the dsrm.exe command and specify the -u parameter. Correct Answer: A /Reference: QUESTION 35 Your company has a main office and four branch offices. An Active Directory site exists for each office. Each site contains one domain controller. Each branch office site has a site link to the main office site. You discover that the domain controllers in the branch offices sometimes replicate directly to each other. You need to ensure that the domain controllers in the branch offices only replicate to the domain controller in the main office. A. Modify the firewall settings for the main office site. B. Disable the Knowledge Consistency Checker (KCC) for each branch office site. C. Disable site link bridging. D. Modify the security settings for the main office site. Correct Answer: C /Reference: QUESTION 36 Your network contains an Active Directory domain. You create and mount an Active Directory snapshot. You run dsamain.exe as shown in the exhibit. (Click the Exhibit button.)

17 You need to ensure that you can browse the contents of the Active Directory snapshot. What should you? A. Stop Active Directory Domain Services (AD DS), and then rerun dsamain.exe. B. Change the value of the dbpath parameter, and then rerun dsamain.exe. C. Change the value of the ldapport parameter, and then rerun dsamain.exe. D. Restart the Volume Shadow Copy Service (VSS), and then rerun dsamain.exe. Correct Answer: B /Reference:

18 Exam B QUESTION 1 Your network contains an Active Directory domain. You need to back up all of the Group Policy objects (GPOs), Group Policy permissions, and Group Policy links for the domain. A. From Group Policy Management Console (GPMC), back up the GPOs. B. From Windows Explorer, copy the content of the %systemroot%\sysvol folder. C. From Windows Server Backup, perform a system state backup. D. From Windows PowerShell, run the Backup-GPO cmdlet. Correct Answer: A /Reference: QUESTION 2 Your network contains a domain controller that runs Windows Server 2008 R2. You need to reset the Directory Services Restore Mode (DSRM) password on the domain controller. Which tool should you use? A. Ntdsutil B. Dsamain C. Active Directory Users and Computers D. Local Users and Groups Correct Answer: A /Reference: QUESTION 3 Your network contains an Active Directory forest. All client computers run Windows 7. The network contains a high-volume enterprise certification authority (CA). You need to minimize the amount of network bandwidth required to validate a certificate. A. Configure an LDAP publishing point for the certificate revocation list (CRL). B. Configure an Online Certification Status Protocol (OCSP) responder. C. Modify the settings of the delta certificate revocation list (CRL). D. Replicate the certificate revocation list (CRL) by using Distributed File System (DFS). Correct Answer: B

19 /Reference: QUESTION 4 Your network contains an Active Directory domain. The domain contains an organizational unit (OU) named OU1. OU1 contains all managed service accounts in the domain. You need to prevent the managed service accounts from being deleted accidentally from OU1. Which cmdlet should you use? A. Set-ADUser B. Set-ADOrganizationalUnit C. Set-ADServiceAccount D. Set-ADObject Correct Answer: D /Reference: QUESTION 5 Your network contains an Active Directory domain named contoso.com. Contoso.com contains a writable domain controller named DC1 and a read-only domain controller (RODC) named DC2. All domain controllers run Windows Server 2008 R2. You need to install a new writable domain controller named DC3 in a remote site. The solution must minimize the amount of replication traffic that occurs during the installation of Active Directory Domain Services (AD DS) on DC3. What should you do first? A. Run dcpromo.exe /createdcaccount on DC3. B. Run ntdsutil.exe on DC2. C. Run dcpromo.exe /adv on DC3. D. Run ntdsutil.exe on DC1. Correct Answer: C /Reference: QUESTION 6 Your network contains an Active Directory forest. The forest contains 10 domains. All domain controllers are configured as global catalog servers. You remove the global catalog role from a domain controller named DC5. You need to reclaim the hard disk space used by the global catalog on DC5. A. From Active Directory Sites and Services, run the Knowledge Consistency Checker (KCC). B. From Active Directory Sites and Services, modify the general properties of DC5. C. From Ntdsutil, use the Semantic database analysis option. D. From Ntdsutil, use the Files option. Correct Answer: D

20 /Reference: QUESTION 7 A corporate network includes an Active Directory-integrated zone. All DNS servers that host the zone are domain controllers. You add multiple DNS records to the zone. You need to ensure that the new records are available on all DNS servers as soon as possible. Which tool should you use? A. Ldp B. Repadmin C. Ntdsutil D. Nslookup E. Active Directory Sites And Services console F. Active Directory Domains And Trusts console G. Dnslint H. Dnscmd Correct Answer: B /Reference: Repadmin /syncall QUESTION 8 You have a DNS zone that is stored in a custom application partition. You need to add a domain controller to the replication scope of the custom application partition. Which tool should you use? A. DNScmd B. DNS Manager C. Server Manager D. Dsmod Correct Answer: A /Reference: QUESTION 9 Your network contains a server named Server1 that runs Windows Server 2008 R2 Standard. Server1 has the Active Directory Certificate Services (AD CS) role installed. You configure a certificate template named Template1 for autoenrollment. You discover that certificates are not being issued to any client computers. The event logs on the client computers do not contain any autoenrollment errors. You need to ensure that all of the client computers automatically receive certificates based on Template1. A. Modify the Default Domain Policy Group Policy object (GPO). B. Modify the Default Domain Controllers Policy Group Policy object (GPO).

21 C. Upgrade Server1 to Windows Server 2008 R2 Enterprise. D. Restart Certificate Services on Server1. Correct Answer: A /Reference: QUESTION 10 Your network contains an Active Directory domain named contoso.com. A partner company has an Active Directory domain named nwtraders.com. The networks for contoso.com and nwtraders.com connect to each other by using a WAN link. You need to ensure that users in contoso.com can access resources in nwtraders.com and resources on the Internet. What should you do first? A. Modify the Trusted Root Certification Authorities store. B. Modify the Intermediate Certification Authorities store. C. Create conditional forwarders. D. Add a root hint to the DNS server. Correct Answer: C /Reference: QUESTION 11 Your network contains an Active Directory forest. The forest contains multiple domains. You need to ensure that users in the human resources department can search for employees by using the employeenumber attribute. A. From Active Directory Sites and Services, modify the properties of each global catalog server. B. From the Active Directory Schema snap-in, modify the properties of the user object class. C. From Active Directory Sites and Services, modify the NTDS Settings objectof each global catalog server. D. From the Active Directory Schema snap-in, modify the properties of the employeenumber attribute. Correct Answer: D /Reference: QUESTION 12 Your network contains a single Active Directory domain. The domain contains an enterprise certification authority (CA).

22 You need to ensure that the encryption keys for certificates can be recovered from the CA database. You modify the certificate template to support key archival. What should you do next? A. Issue the key recovery agent certificate template. B. Run certutil.exe -recoverkey. C. Run certreq.exe-policy. D. Modify the location of the Authority Information Access (AIA) distribution point. Correct Answer: A /Reference: QUESTION 13 Your network contains a domain controller that runs Windows Server 2008 R2. You run the following command on the domain controller: dsamain.exe C dbpath c:\$snap_ _volumec$\windows\ntds\ntds.dit C ldapport allownonadminaccess The command fails. You need to ensure that the command completes successfully. How should you modify the command? A. Change the value of the -dbpath parameter. B. Include the path to Dsamain. C. Change the value of the -ldapport parameter. D. Remove the CallowNonAdminAccess parameter. Correct Answer: C /Reference: QUESTION 14 Your network contains an Active Directory domain. The domain contains 10 domain controllers that run Windows Server 2008 R2. You need to monitor the following information on the domain controllers during the next five days: Memory usage Processor usage The number of LDAP queries A. Create a User Defined Data Collector Set (DCS) that uses the Active Directory Diagnostics template. B. Use the System Performance Data Collector Set (DCS). C. Create a User Defined Data Collector Set (DCS) that uses the System Performance template.

23 D. Use the Active Directory Diagnostics Data Collector Set (DCS). Correct Answer: A /Reference: QUESTION 15 Your network contains an Active Directory domain named contoso.com. Contoso.com contains a domain controller named DC1 and a read-only domain controller (RODC) named RODC1. You need to view the most recent user accounts authenticated by RODC1. What should you do first? A. From Active Directory Sites and Services, right-click the Connection object for DC1, and then click Replicate Now. B. From Active Directory Sites and Services, right-click the Connection object for DC2, and then click Replicate Now. C. From Active Directory Users and Computers, right-click contoso.com, click Change DomainController, and then connect to DC1. D. From Active Directory Users and Computers, right-click contoso.com, click Change Domain Controller, and then connect to RODC1. Correct Answer: C /Reference: QUESTION 16 Your network contains an Active Directory domain. The domain contains 3,000 client computers. All of the client computers run Windows 7. Users log on to their client computers by using standard user accounts. You plan to deploy a new application named App1. The vendor of App1 provides a Setup.exe file to install App1. Setup.exe requires administrative rights to run. You need to deploy App1 to all client computers. The solution must meet the following requirements: - App1 must automatically detect and replace corrupt application files. - App1 must be available from the Start menu on each client computer. What should you do first? A. Create a logon script that calls Setup.exe for App1. B. Create a.zap file. C. Create a startup script that calls Setup.exe for App1. D. Repackage App1 as a Windows Installer package.

24 Correct Answer: D /Reference: QUESTION 17 Your network contains an Active Directory domain named contoso.com. Contoso.com contains a server named Server2. You open the System properties on Server2 as shown in the exhibit. (Click the Exhibit button.) When you attempt to configure Server2 as an enterprise subordinate certification authority (CA), you discover that the enterprise subordinate CA option is unavailable. You need to configure Server2 as an enterprise subordinate CA. What should you do first? A. Upgrade Server2 to Windows Server 2008 R2 Enterprise. B. Log in as an administrator and run Server Manager. C. Import the root CA certificate. D. Join Server2 to the domain.

25 Correct Answer: D /Reference: QUESTION 18 Your network contains an Active Directory domain. The domain contains an enterprise certification authority (CA). You need to ensure that only members of a group named Admin1 can create certificate templates. Which tool should you use to assign permissions to Admin1? A. the Certification Authority console B. Active Directory Users and Computers C. the Certificates snap-in D. Active Directory Sites and Services Correct Answer: A /Reference: QUESTION 19 Your network contains an Active Directory domain. All DNS servers are domain controllers. You view the properties of the DNS zone as shown in the exhibit. (Click the Exhibit button.)

26 You need to ensure that only domain members can register DNS records in the zone. What should you do first? A. Modify the zone type. B. Create a trust anchor. C. Modify the Advanced properties of the DNS server. D. Modify the Dynamic updates setting. Correct Answer: A /Reference: QUESTION 20 Your network contains two Active Directory forests named contoso.com and nwtraders.com. The functional level of both forests is Windows Server Contoso.com contains one domain. Nwtraders.com contains two domains. You need to ensure that users in contoso.com can access the resources in all domains. The solution must require the minimum number of trusts. Which type of trust should you create? A. external B. forest C. realm D. shortcut

27 Correct Answer: B /Reference: QUESTION 21 You install an Active Directory domain in a test environment. You need to reset the passwords of all the user accounts in the domain from a domain controller. Which two Windows PowerShell commands should you run? (Each correct answer presents part of the solution, choose two.) A. $ newpassword = * B. Import-Module ActiveDirectory C. Import-Module WebAdministration D. Get- AdUser -filter * Set- ADAccountPossword - NewPassword $ newpassword - Reset E. Set- ADAccountPossword - NewPassword - Reset F. $ newpassword = (Read-Host - Prompt "New Password" - AsSecureString ) G. Import-Module ServerManager Correct Answer: DF /Reference: QUESTION 22 Your network contains two forests named adatum.com and litwareinc.com. The functional level of all the domains is Windows Server The functional level of both forests is Windows You need to create a forest trust between adatum.com and litwareinc.com. What should you do first? A. Create an external trust. B. Raise the functional level of both forests. C. Configure SID filtering. D. Raise the functional level of all the domains. Correct Answer: B /Reference: QUESTION 23 Your network contains an Active Directory forest named adatum.com. You need to create an Active Directory Rights Management Services (AD RMS) licensing-only cluster. What should you install before you create the AD RMS root cluster?

28 A. The Failover Cluster feature B. The Active Directory Certificate Services (AD CS) role C. Microsoft Exchange Server 2010 D. Microsoft SharePoint Server 2010 E. Microsoft SQL Server 2008 Correct Answer: E /Reference: QUESTION 24 Your network contains an Active Directory domain named contoso.com. The contoso.com domain contains a domain controller named DC1. You create an Active Directory-integrated GlobalNames zone. You add an alias (CNAME) resource record named Server1 to the zone. The target host of the record is server2.contoso.com. When you ping Server1, you discover that the name fails to resolve. You are able to successfully ping server2.contoso.com. You need to ensure that you can resolve names by using the GlobalNames zone. Which command should you run? A. Dnscmd DCl.contoso.com /ZoneAdd GlobalNames /DsPrimary /DP /domain B. Dnscmd DCl.contoso.com /config /Enableglobalnamessupport forest C. DnscmdDCl.contoso.com/config/Enableglobalnamessupport 1 D. Dnscmd DCl.contoso.com /ZoneAdd GlobalNames /DsPrimary /DP /forest Correct Answer: C /Reference: QUESTION 25 You deploy an Active Directory Federation Services (AD FS) Federation Service Proxy on a server named Server1. You need to configure the Windows Firewall on Server1 to allow external users to authenticate by using AD FS. Which protocol should you allow on Server1? A. Kerberos B. SSL C. SMB D. RPC Correct Answer: B

29 /Reference: QUESTION 26 Your network contains a server named Server1. The Active Directory Rights Management Services (AD RMS) server role is installed on Server1. An administrator changes the password of the user account that is used by AD RMS. You need to update AD RMS to use the new password. Which console should you use? A. Active Directory Rights Management Services B. Active Directory Users and Computers C. Local Users and Groups D. Services Correct Answer: A /Reference: QUESTION 27 Your network contains an enterprise certification authority (CA) that runs Windows Server 2008 R2 Enterprise. You enable key archival on the CA. The CA is configured to use custom certificate templates for Encrypted File System (EFS) certificates. You need to archive the private key for all new EFS certificates. Which snap-in should you use? A. Active Directory Users and Computers B. Authorization Manager C. Group Policy Management D. Enterprise PKI E. Security Templates F. TPM Management G. Certificates H. Certification Authority I. Certificate Templates Correct Answer: H /Reference: QUESTION 28 Your network contains an enterprise certification authority (CA) that runs Windows Server 2008 R2 Enterprise. You need to ensure that users can enroll for certificates that use the IPSEC (Offline request) certificate

30 template Which snap-in should you use? A. Enterprise PKI B. TPM Management C. Certificates D. Active Directory Users and Computers E. Authorization Manager F. Certification Authority G. Group Policy Management H. Security Templates I. Certificate Templates Correct Answer: I /Reference: QUESTION 29 Your network contains an enterprise certification authority (CA) that runs Windows Server 2008 R2 Enterprise. You need to approve a pending certificate request. Which snap-in should you use? A. Active Directory Users and Computers B. Authorization Manager C. Certification Authority D. Group Policy Management E. Certificate Templates F. TPM Management G. Certificates H. Enterprise PKI I. Security Templates Correct Answer: C /Reference:

31 Exam C QUESTION 1 Your network contains an Active Directory domain named adatum.com. You need to ensure that IP addresses can be resolved to fully qualified domain names (FQDNs). Under which node in the DNS snap-in should you add a zone? A. Reverse Lookup Zones B. adatum.com C. Forward Lookup Zones D. Conditional Forwarders E. _msdcs.adatum.com Correct Answer: A /Reference: QUESTION 2 Your network contains an Active Directory domain named adatum.com. The domain contains a domain controller named DC1. DC1 has an IP address of You need to identify the zone that contains the Pointer (PTR) record for 0C1. Which zone should you identify? A. adatum.com B. _msdcs.adatum.com C in-addr.arpa D in-addr.arpa Correct Answer: D /Reference: QUESTION 3 Your network contains an Active Directory domain named adatum.com. The password policy of the domain requires that the passwords for all user accounts be changed every 50 days. You need to create several user accounts that will be used by services. The passwords for these accounts must be changed automatically every 50 days. Which tool should you use to create the accounts? A. Active Directory Administrative Center B. Active Directory Users and Computers C. Active Directory Module for Windows PowerShell

32 D. ADSI Edit E. Active Directory Domains and Trusts Correct Answer: C /Reference: QUESTION 4 Your network contains an Active Directory domain. The domain contains several domain controllers. You need to modify the Password Replication Policy on a read-only domain controller (RODC). Which tool should you use? A. Group Policy Management B. Active Directory Domains and Trusts C. Active Directory Users and Computers D. Computer Management E. Security Configuration Wizard Correct Answer: C /Reference: QUESTION 5 Your network contains an Active Directory forest. The forest contains two domains named contoso.com and woodgrovebank.com. You have a custom attribute named Attribute 1 in Active Directory. Attribute 1 is associated to User objects. You need to ensure that Attribute1 is included in the global catalog. A. From the Active Directory Schema snap-in, modify the properties of the Attribute 1 attributeschema object. B. In Active Directory Users and Computers, configure the permissions on the Attribute 1 attribute for User objects. C. From the Active Directory Schema snap-in, modify the properties of the User classschema object. D. In Active Directory Sites and Services, configure the Global Catalog settings for all domain controllers in the forest. Correct Answer: A /Reference: QUESTION 6 Your network contains a server named Server1. Server1 runs Windows Server 2008 R2 and has the Active Directory Lightweight Directory Services (AD LDS) role installed. Server1 hosts two AD LDS instances named

33 Instance1 and Instance2. You need to remove Instance2 from Server1 without affecting Instance1. Which tool should you use? A. NTDSUtil B. Dsdbutil C. Programs and Features in the Control Panel D. Server Manager Correct Answer: C /Reference: QUESTION 7 Your network contains an Active Directory domain. All domain controllers run Windows Server 2008 R2. You need to collect all of the Directory Services events from all of the domain controllers and store the events in a single central computer. A. Run the ntdsutil.exe command. B. Run the repodmin.exe command. C. Run the Get-ADForest cmdlet. D. Run the dsamain.exe command. E. Create custom views from Event Viewer. F. Run the dsquery.exe command. G. Configure the Active Directory Diagnostics Data Collector Set (DCS), H. Configure subscriptions from Event Viewer. I. Run the eventcreate.exe command. J. Create a Data Collector Set (DCS). Correct Answer: H /Reference: QUESTION 8 Your network contains an Active Directory domain. All domain controllers run Windows Server 2008 R2. You need to create a snapshot of Active Directory. A. Run the dsquery.exe command. B. Run the dsamain.exe command. C. Create custom views from Event Viewer. D. Configure subscriptions from Event Viewer.

34 E. Create a Data Collector Set (DCS). F. Configure the Active Directory Diagnostics Data Collector Set (DCS). G. Run the repadmin.exe command. H. Run the ntdsutil.exe command. I. Run the Get-ADForest cmdlet. J. Run the eventcreate.exe command. Correct Answer: H /Reference: QUESTION 9 Your network contains an Active Directory domain. All domain controllers run Windows Server 2008 R2. You mount an Active Directory snapshot. You need to ensure that you can query the snapshot by using LDAP. A. Run the dsamain.exe command. B. Create custom views from Event Viewer. C. Run the ntdsutil.exe command. D. Configure subscriptions from Event Viewer. E. Run the Get-ADForest cmdlet. F. Create a Data Collector Set (DCS). G. Run the eventcreate.exe command. H. Configure the Active Directory Diagnostics Data Collector Set (DCS). I. Run the repadmin.exe command. J. Run the dsquery.exe command. Correct Answer: A /Reference:

35 Exam D QUESTION 1 Your network contains an Active Directory forest named adatum.com. The forest contains four child domains named europe.adatum.com, northamerica.adatum.com, asia.adatum.com, and africa.adatum.com. You need to create four new groups in the forest root domain. The groups must be configured as shown in the following table. To answer, drag the appropriate group type to the correct group name in the answer area. Select and Place: Correct Answer:

36 /Reference: QUESTION 2 Your network contains an Active Directory domain named adatum.com. You need to use Group Policies to deploy the line-of-business applications shown in the following table. To answer, drag the appropriate deployment method to the correct application in the answer area. Select and Place:

37 Correct Answer: /Reference: You can use Group Policy to distribute computer programs by using the following methods: Assigning Software You can assign a program distribution to users or computers. If you assign the program to a user, it is installed when the user logs on to the computer. When the user first runs the program, the installation is finalized. If you assign the program to a computer, it is installed when the computer starts, and it is available to all users who log on to the computer. When a user first runs the program, the installation is finalized. Publishing Software You can publish a program distribution to users. When the user logs on to the computer, the published program is displayed in the Add or Remove Programs dialog box, and it can be installed from there.

38 QUESTION 3 Your network contains an Active Directory forest. The DNS infrastructure fails. You rebuild the DNS infrastructure. You need to force the registration of the Active Directory Service Locator (SRV) records in DNS. Which service should you restart on the domain controllers? To answer, select the appropriate service in the answer area. Point and Shoot: Correct Answer:

39 /Reference: The Netlogon service would be involved with this. QUESTION 4 Your network contains an Active Directory forest named contoso.com. The password policy of the forest requires that the passwords for all of the user accounts be changed every 30 days. You need to create user accounts that will be used by services. The passwords for these accounts must be changed automatically every 30 days. Which tool should you use to create these accounts? To answer, select the appropriate tool in the answer area. Point and Shoot:

40 Correct Answer: /Reference: Creating a Managed Service Account Applies To: Windows Server 2008 R2 This topic explains how to use the Active Directory module for Windows PowerShell to create a managed service account. Managed service accounts are used to run various services for applications that are operating in your domain environment. Example 1 The following example demonstrates how to create a service account, SQL-SRV1, in the container Managed Service Accounts in the Fabrikam.com domain: New-ADServiceAccount -Name SQL-SRV1 -Path "CN=Managed Service Accounts,DC=FABRIKAM,DC=COM"

41 QUESTION 5 Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named Server1. Server1 has an IP address of You need to view the Pointer (PTR) record for Server1. Which zone should you open in the DNS snap-in to view the record? To answer, select the appropriate zone in the answer area. Point and Shoot: Correct Answer: /Reference: the corresponding in-addr.arpa zone would be , assuming a default subnet of /24s QUESTION 6 Your network contains an Active Directory domain. You need to create a new site link between two sites named Site1 and Site3. The site link must support the

42 replication of domain objects. Under which node in Active Directory Sites and Services should you create the site link? To answer, select the appropriate node in the answer area Point and Shoot: Correct Answer:

43 /Reference: To create a site link Open Active Directory Sites and Services. To open Active Directory Sites and Services, click Start, click Administrative Tools, and then click Active Directory Sites and Services. In the console tree, right-click the intersite transport protocol that you want the site link to use. Where? Active Directory Sites and Services\Sites\Inter-Site Transports\IP or SMTP Click New Site Link. In Name, type the name for the site link. In Sites not in this site link, click a site to add to the site link, and then click Add. Repeat to add more sites to the site link. To remove a site from the site link, in Sites in this link, click the site, and then click Remove. When you have added the sites that you want to be connected by this site link, click OK. QUESTION 7 Your network contains two forests named contoso.com and fabrikam.com. The functional level of all the domains is Windows Server The functional level of both forests is Windows You need to create a trust between contoso.com and fabrikam.com. The solution must ensure that users from contoso.com can only access the servers in fabrikam.com that have the Allowed to Authenticate permission set. To answer, move the appropriate actions from the Possible Actions list to the Necessary Actions area and arrange them in the correct order. Build List and Reorder: Correct Answer: /Reference:

44 QUESTION 8 Your network contains an Active Directory forest named contoso.com. You need to create an Active Directory Rights Management Services (AD RMS) licensing-only cluster. To answer, move the appropriate actions from the Possible Actions list to the Necessary Actions area and arrange them in the correct order. Build List and Reorder: Correct Answer: /Reference: QUESTION 9 Your network contains an Active Directory forest named contoso.com. The forest contains a domain controller named DC1 that runs Windows Server 2008 R2 Enterprise and a member server named Server1 that runs Windows Server 2008 R2 Standard. You have a computer named Computer1 that runs Windows 7. Computer1 is not connected to the network. You need to join Computer1 to the contoso.com domain. To answer, move the appropriate actions from the Possible Actions list to the Necessary Actions area and arrange them in the correct order. Build List and Reorder:

45 Correct Answer: /Reference: QUESTION 10 Your network contains an Active Directory domain named contoso.com. You need to ensure that IP addresses can be resolved to fully qualified domain names (FQDNs). Under which node in the DNS snap-in should you add a zone? To answer, select the appropriate node in the answer area. Point and Shoot:

46 Correct Answer: /Reference: QUESTION 11 Your company has two domain controllers named DC1 and DC2. DC1 hosts all domain and forest operations master roles. DC1 fails. You need to rebuild DC1 by reinstalling the operating system. You also need to rollback all operations master roles to their original state. You perform a metadata cleanup and remove all references of DC1. Which three actions should you perform next? (To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.) Build List and Reorder: Correct Answer:

47 /Reference: QUESTION 12 You need to perform an offline defragmentation of an Active Directory database. Which four actions should you perform in sequence? (To answer, move the appropriate four actions from the list of actions to the answer area and arrange them in the correct order.) Build List and Reorder: Correct Answer: /Reference: QUESTION 13 ABC.com has an Active Directory forest on a single domain. The domain operates Windows Server A new administrator accidentally deletes the entire organizational unit in the Active Directory database that hosts 6000 objects. You have backed up the system state data using third-party backup software. To restore backup, you start the domain controller in the Directory Services Restore Mode (DSRM). You need to perform an authoritative restore of the organizational unit and restore the domain controller to its original state. Which three actions should you perform?

48 Build List and Reorder: Correct Answer: /Reference:

49 Exam E QUESTION 1 Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 and a domain controller named DC1. On Server1, you configure a collector-initiated subscription for the Application log of DC1. The subscription is configured to collect all events. After several days, you discover that Server1 failed to collect any events from DC1, although there are more than 100 new events in the Application log of DC1. You need to ensure that Server1 collects events from DC1. A. On Server1, run wecutil quick-config. B. On Server1, run winrm quickconfig. C. On DC1, run wecutil quick-config. D. On DC1, run winrm quickconfig. Correct Answer: D /Reference: QUESTION 2 A network contains an Active Directory Domain Services (AD DS) domain. Active Directory is configured as shown in the following table. The functional level of the domain is Windows Server 2008 R2. The functional level of the forest is Windows Server Active Directory replication between the Seattle site and the Chicago site occurs from 8:00 P.M. to 1:00 A.M. every day. At 7:00 A.M. an administrator deletes a user account while he is logged on to DC001. You need to restore the deleted user account. You must achieve this goal by using the minimum administrative effort. A. On DC006, stop AD DS, perform an authoritative restore, and then start AD DS. B. On DC001, run the Restore-ADObject cmdlet. C. On DC006, run the Restore-ADObject cmdlet. D. On DC001, stop AD DS, restore the system state, and then start AD DS. Correct Answer: A

50 /Reference: QUESTION 3 Your network contains an Active Directory domain. The domain is configured as shown in the exhibit. You have a Group Policy Object (GPO) linked to the domain. You need to ensure that the settings in the GPO are not processed by user accounts or computer accounts in the Finance organizational unit (OU). You must achieve this goal by using the minimum amount of administrative effort. A. Modify the Group Policy permissions. B. Configure WMI filtering. C. Enable block inheritance. D. Enable loopback processing in replace mode. E. Configure the link order. F. Configure Group Policy Preferences. G. Link the GPO to the Human Resources OU. H. Configure Restricted Groups. I. Enable loopback processing in merge mode. J. Link the GPO to the Finance OU. Correct Answer: C /Reference:

51 QUESTION 4 Your network contains an Active Directory domain named contoso.com. You have an organizational unit (OU) named Sales and an OU named Engineering. You have two Group Policy Objects (GPOs) named GPO1 and GPO2. GPO1 and GPO2 are linked to the Sales OU and contain multiple settings. You discover that GPO2 has a setting that conflicts with a setting in GPO1. When the policies are applied, the setting in GPO2 takes effect. You need to ensure that the settings in GPO1 supersede the settings in GPO2. The solution must ensure that all non-conflicting settings in both GPOs are applied. A. Configure Restricted Groups. B. Configure the link order. C. Link the GPO to the Sales OU. D. Link the GPO to the Engineer OU. E. Enable loopback processing in merge mode. F. Modify the Group Policy permissions. G. Configure WMI filtering. H. Configure Group Policy Permissions. I. Enable loopback processing in replace mode. J. Enable block inheritance. Correct Answer: B /Reference: QUESTION 5 A corporate network includes a single Active Directory Domain Services (AD DS) domain. The HR department has a dedicated organizational unit (OU) named HR. The HR OU has two sub-ous: HR Users and HR Computers. User accounts for the HR department reside in the HR Users OU. Computer accounts for the HR department reside in the HR Computers OU. All HR department employees belong to a security group named HR Employees. All HR department computers belong to a security group named HR PCs. Company policy requires that passwords are a minimum of 6 characters. You need to ensure that, the next time HR department employees change their passwords, the passwords are required to have at least 8 characters. The password length requirement should not change for employees of any other department.

52 A. Modify the password policy in the GPO that is applied to the domain. B. Create a new GPO, with the necessary password policy, and link it to the HR Users OU. C. Create a fine-grained password policy and apply it to the HR Users OU. D. Modify the password policy in the GPO that is applied to the domain controllers OU. Correct Answer: C /Reference: QUESTION 6 A corporate network includes a single Active Directory Domain Services (AD DS) domain. All regular user accounts reside in an organisational unit (OU) named Employees. All administrator accounts reside in an OU named Admins. You need to ensure that any time an administrator modifies an employee's name in AD DS, the change is audited. What should you do first? A. Create a Group Policy Object with the Audit directory service access setting enabled and link it to the Employees OU. B. Modify the searchflags property for the Name attribute in the Schema. C. Create a Group Policy Object with the Audit directory service access setting enabled and link it to the Admins OU. D. Use the Auditpol.exe command-line tool to enable the directoryservicechanges auditing subcategory. Correct Answer: D /Reference: QUESTION 7 Your network contains an Active Directory forest named contoso.com. You need to provide a user named User1 with the ability to create and manage subnet objects. The solution must minimize the number of permissions assigned to User1. A. From Active Directory Users and Computers, run the Delegation of Control wizard. B. From Active Directory Administrative Centre, add User1 to the Schema Admins group. C. From Active Directory Sites and Services, run the Delegation of Control wizard. D. From Active Directory Administrative Centre, add User1 to the Network Configuration Operators group. Correct Answer: C

53 /Reference: QUESTION 8 A corporate network contains a Windows Server 2008 R2 Active Directory forest. You need to add a User Principle Name (UPN) suffix to the forest. What tool should you use? A. Dsmgmt. B. Active Directory Domains and Trusts console. C. Active Directory Users and Computers console. D. Active Directory Sites and Services console. Correct Answer: B /Reference: QUESTION 9 Your network contains an Active Directory domain named contoso.com. All domain controllers were upgraded from Windows Server 2003 to Windows Server 2008 R2 Service Pack 1 (SP1). The functional level of the domain is Windows Server You need to configure SYSVOL to use DFS Replication. Which tools should you use? (Each correct answer presents part of the solution. Choose two.) A. Dfsrmig B. Frsdiag C. Ntdsutil D. Set-ADForest E. Repadmin F. Set-ADDomainMode G. DFS Management Correct Answer: AF /Reference: QUESTION 10 You manage an Active Directory forest named contoso.com. The forest contains an empty root domain named contoso.com and a child domain named child.contoso.com. All domain controllers run Windows Server The functional level of the forest is Windows Server You need to raise the functional level of the forest to Windows Server 2008 R2. You must achieve this goal by using the minimum amount of administrative effort.

54 To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order. Build List and Reorder: Correct Answer: /Reference: QUESTION 11 Your network contains an Active Directory forest. The forest contains one domain named contoso.com. You attempt to run adprep /domainprep and the operation fails. You discover that the first domain controller deployed to the forest failed. You need to run adprep /domainprep successfully.

55 A. Move the domain naming master role. B. Install a read-only domain controller (RODC). C. Move the PDC emulator role. D. Move the RID master role. E. Move the infrastructure master role. F. Deploy an additional global catalog server. G. Move the bridgehead server. H. Move the schema master role. I. Restart the Active Directory Domain Services (AD DS) service. J. Move the global catalog server. Correct Answer: E /Reference: QUESTION 12 Your network contains an Active Directory forest named contoso.com. The functional level of the forest is Windows Server 2008 R2. The DNS zone for contoso.com is Active Directory-integrated. You deploy a read-only domain controller (RODC) named RODC1. You install the DNS Server server role on RODC1. You discover that RODC1 does not have any application directory partitions. You need to ensure that RODC1 has a copy of the DNS application directory partition of contoso.com. A. From DNS Manager, create secondary zones. B. Run Dnscmd.exe, and specify the /enlistdirectorypartition parameter. C. From DNS Manager, right-click RODC1 and click Update Server Data Files. D. Run Dnscmd.exe and specify the /createbuiltindirectorypartitions parameter. Correct Answer: B /Reference: QUESTION 13 Your network contains an Active Directory forest named contoso.com. You need to identify whether a fine-grained password policy is applied to a specific group. Which tool should you use? A. Credential Manager B. Group Policy Management Editor

56 C. Active Directory Users and Computers D. Active Directory Sites and Services Correct Answer: C /Reference: QUESTION 14 Your network contains two Active Directory forests named contoso.com and fabrikam.com. Each forest contains one domain. A two-way forest trust exists between the forests. You plan to add users from fabrikam.com to groups in contoso.com. You need to identify which group you must use to assign users in fabrikam.com access to the shared folders in contoso.com. To which group should you add the users? A. Group 1: Security Group - Domain Local. B. Group 2: Distribution Group - Domain Local. C. Group 3: Security Group - Global. D. Group 4: Distribution Group - Global. E. Group 5: Security Group - Universal. F. Group 6: Distribution Group - Univeral. Correct Answer: A /Reference: I think A is wrong here. You would need to use Universal groups to assign users across forests. Domain local groups Groups that are used to grant permissions within a single domain. Members of domain local groups can include only accounts (both user and computer accounts) and groups from the domain in which they are defined. Global groups Groups that are used to grant permissions to objects in any domain in the domain tree or forest. Members of global groups can include only accounts and groups from the domain in which they are defined. Universal groups Groups that are used to grant permissions on a wide scale throughout a domain tree or forest. Members of global groups include accounts and groups from any domain in the domain tree or forest. Security groups Groups that can have security descriptors associated with them. You define security groups in domains using Active Directory Users And Computers. Distribution groups Groups that are used as distribution lists. They can't have security descriptors associated with them. You define distribution groups in domains using Active Directory Users And Computers. QUESTION 15 Your network contains an Active Directory domain. The domain contains two file servers. The file servers are configured as shown in the following table.

57 You create a Group Policy object (GPO) named GPO1 and you link GPO1 to OU1. You configure the advanced audit policy. You discover that the settings are not applied to Server1. The settings are applied to Server2. You need to ensure that access to the file shares on Server1 is audited. A. From Active Directory Users and Computers, modify the permissions of the computer account for Server1. B. From GPO1, configure the Security Options. C. From Active Directory Users and Computers, add Server1 to the Event Log Readers group. D. On Server1, run seceditexe and specify the /configure parameter. E. On Server1, run auditpol.exe and specify the /set parameter. Correct Answer: E /Reference: QUESTION 16 Your network contains an Active Directory domain named contoso.com. You have an organizational unit (OU) named Sales and an OU named Engineering. Each OU contains over 200 user accounts. The Sales OU and the Engineering OU contain several user accounts that are members of a universal group named Group1. You have a Group Policy object (GPO) linked to the domain. You need to prevent the GPO from being applied to the members of Group1 only. A. Modify the Group Policy permissions. B. Configure Restricted Groups. C. Configure WMI filtering. D. Configure the link order. E. Enable loopback processing in merge mode. F. Link the GPO to the Sales OU. G. Configure Group Policy Preferences. H. Link the GPO to the Engineering OU. I. Enable block inheritance. J. Enable loopback processing in replace mode.

58 Correct Answer: A /Reference: QUESTION 17 Your network contains an Active Directory domain. You have two Group Policy objects (GPOS) named GPO1 and GPO2. GPO1 and GPO2 are linked to the Finance organizational unit (OU) and contain multiple settings. You discover that GPO2 has a setting that conflicts with a setting in GPO1. When the policies are applied, the setting in GPO2 takes effect. You need to ensure that the settings in GPO1 supersede the settings in GPO2. The solution must ensure that all non-conflicting settings in both GPOs are applied. A. Configure the link order. B. Configure Restricted Groups. C. Enable block inheritance. D. Link the GPO to the Finance OU. E. Enable Ioopback processing in merge mode. F. Enable Ioopback processing in replace mode. G. Link the GPO to the Human Resources OU. H. Configure Group Policy Preferences. I. Configure WMI filtering. J. Modify the Group Policy permissions. Correct Answer: A /Reference: QUESTION 18 A corporate network includes an Active Directory-integrated zone. AIl DNS servers that host the zone are domain controllers. You add multiple DNS records to the zone. You need to ensure that the new records are available on all DNS servers as soon as possible. Which tool should you use? A. Active Directory Sites And Services console B. Ntdsutil C. Dnslint D. Nslookup Correct Answer: A

59 /Reference: ssniyer -- In the case where (Exam J, Q24) Repadmin is not an answer option, I will go with AD Sites and Services because it allows to force AD replication across connection objects. Both DNSLint and nslookup are diagnostic tools. DNSLint is useful to make sure RRs are associated with the right services and nslookup for domain namespace resolution issues. There is no diagnostic need in this question. Dnscmd is useful to administer/maintain a DNS server or zone using a command line tool. It is also the right tool to create Application Directory Partition. However, I don't see literature to suggest it as a good replication tool for AD integrated zones. QUESTION 19 Your network contains an Active Directory domain named contoso.com. Contoso.com contains two domain controllers named DC1 and DC2. DC1 and DC2 are configured as DNS servers and host the Active Directoryintegrated zone for contoso.com. From DNS Manager on DC1, you enable scavenging for the contoso.com zone. You discover stale DNS records in the zone. You need to ensure that the stale DNS records are deleted from contoso.com. A. From DNS Manager, enable scavenging on DC1. B. From DNS Manager, reload the zone. C. Run dnscmd.exe and specify the ageallrecords parameter. D. Run dnscmd.exe and specify the startscavenging parameter. Correct Answer: A /Reference: QUESTION 20 Your network contains an Active Directory domain named adatum.com. All servers run Windows Server 2008 R2 Enterprise. All client computers run Windows 7 Professional. The network contains an enterprise certification authority (CA). You enable key archival on the CA. The CA is configured to use custom certificate templates for Encrypted File System (EFS) certificates. All users plan to encrypt files by using EFS. You need to ensure that the private keys for all new EFS certificates are archived. Which snap-in should you use? A. Share and Storage Management B. Security Configuration wizard C. Enterprise PKI

60 D. Active Directory Administrative Center E. Certification Authority F. Group Policy Management G. Certificate Templates H. Authorization Manager I. Certificates Correct Answer: E /Reference: QUESTION 21 Your network contains an Active Directory forest named adatum.com. All domain controllers currently run Windows Server 2003 Service Pack 2 (SP2). The functional level of the forest and the domain is Windows Server You need to deploy a read-only domain controller (RODC) that runs Windows Server 2008 R2. What should you do first? A. Deploy a writable domain controller that runs Windows Server 2008 R2. B. Raise the functional level of the forest to Windows Server C. Run adprep.exe. D. Raise the functional level of the domain to Windows Server Correct Answer: C /Reference: QUESTION 22 Your network contains two Active Directory forests named contoso.com and nwtraders.com. Active Directory Rights Management Services (AD RMS) is deployed in each forest. You need to ensure that users from the nwtraders.com forest can access AD RMS protected content in the contoso.com forest. A. Add a trusted user domain to the AD RMS cluster in the nwtraders.com domain. B. Add a trusted user domain to the AD RMS cluster in the contoso.com domain. C. Create an external trust from nwtraders.com to contoso.com. D. Create an external trust from contoso.com to nwtraders.corn. Correct Answer: B /Reference:

61 QUESTION 23 Your network contains an Active Directory forest. All users have a value set for the Department attribute. From Active Directory Users and computers, you search a domain for all users who have a Department attribute value of Marketing. The search returns 50 users. From Active Directory Users and Computers, you search the entire directory for all users who have a Department attribute value of Marketing. The search does not return any users. You need to ensure that a search of the entire directory for users in the marketing department returns all of the users who have the Marketing Department attribute. A. Install the Windows Search Service role service on a global catalog server. B. From the Active Directory Schema snap-in, modify the properties of the Department attribute. C. Install the Indexing Service role service on a global catalog server. D. From the Active Directory Schema snap-in, modify the properties of the user class. Correct Answer: B /Reference: QUESTION 24 A corporate network includes a single Active Directory Domain Services (AD DS) domain. The AD DS infrastructure is shown in the following graphic.

62 When the Montreal site domain controller is offline, authentication requests for Montreal branch office users are sent to the Toronto site domain controller. You need to ensure that when the Montreal Site domain controller is offline, authentication requests for Montreal branch office users are sent to the Quebec City site domain controller. A. Create a site link bndge between the Montreal site and the Quebec City site. B. Enable the global catalog role on the Montreal site domain controller. C. Modify the Default Domain Policy Group Policy Object. D. Delete the Toronto-Montreal Site Link Correct Answer: C /Reference: QUESTION 25 Your network contains an Active Directory domain. You need to activate the Active Directory Recycle Bin in the domain.

63 Which tool should you use? A. Dsamain B. Set-ADDomain C. Add-WindowsFeature D. Ldp Correct Answer: D /Reference:

64 Exam F QUESTION 1 Your network contains an Active Directory domain named contoso.com. The Administrator deletes an OU named OU1 accidentally. You need to restore OU1. Which cmdlet should you use? A. Set-ADObject cmdlet. B. Set-ADOrganizationalUnit cmdlet. C. Set-ADUser cmdlet. D. Set-ADGroup cmdlet. Correct Answer: A /Reference: QUESTION 2 Your network contains an Active Directory domain. The domain is configured as shown in the exhibit. You have a Group Policy Object (GPO) linked to the domain. You need to ensure that the settings in the GPO are not processed by user accounts or computer accounts in the Finance organizational unit (OU). You must achieve this goal by using the minimum amount of administrative effort. A. Modify the Group Policy Permission. B. Configure WMI filtering. C. Enable block inheritance. D. Enable loopback processing in replace mode. E. Configure the link order. F. Configure Group Policy Preferences. G. Link the GPO to the Human Resources OU. H. Configure Restricted Groups. I. Enable loopback processing in merge mode. J. Link the GPO to the Finance OU. Correct Answer: C /Reference: QUESTION 3 Your network contains an Active Directory forest. All users have a value set for the Department attribute. From Active Directory Users and Computers, you search a domain for all users who have a Department

65 attribute value of Marketing. The search returns 50 users. From Active Directory Users and Computers, you search the entire directory for all users who have a Department attribute value of Marketing. The search does not return any users. You need to ensure that a search of the entire directory for users in the marketing department returns all of the users who have the Marketing Department attribute. A. Install the Windows Search Service role service on a global catalog server. B. From the Active Directory Schema snap-in modify the properties of the Department attribute. C. Install the Indexing Service role service on a global catalog server. D. From the Active Directory Schema snap-in modify the properties of the user class. Correct Answer: B /Reference: QUESTION 4 Your network contains an Active Directory forest. The forest contains one domain named contoso.com. You discover the following event in the Event log of domain controllers: "The request for a new accountidentifier pool failed. The operation will be retried until the request succeeds. The error is " %1 "" You need to ensure that the domain controllers can acquire new account-identifier pools successfully. A. Move the PDC emulator role. B. Move the schema master role. C. Move the global catalog server. D. Move the domain naming master role. E. Move the infrastructure master role. F. Move the RID master role. G. Restart the Active Directory Domain Services (AD DS) service. H. Deploy an additional global catalog server. I. Move the bridgehead server. J. Install a read-only domain controller (RODC). Correct Answer: F /Reference: QUESTION 5 Your network contains an Active Directory domain named contoso.com. You need to create one password policy for administrators and another password policy for all other users.

66 Which tool should you use? A. Ntdsutil B. Active Directory Users and Computers C. ADSI Edit D. Group Policy Management Console (GPMC) Correct Answer: C /Reference: QUESTION 6 Your network contains an Active Directory forest named contoso.com. You need to identify whether a fine-grained password policy is applied to a specific group. Which tool should you use? A. Active Directory Sites and Services B. Authorization Manager C. Local Security Policy D. ADSI Edit Correct Answer: D /Reference: The link below instructs you to access the "Attribute Editor" via Active Directory Users and Computers. However the "Attribute Editor" can also be accessed by right-clicking on a user or group in ADSI Edit. QUESTION 7 A corporate network includes an Active Directory-integrated zone. All DNS servers that host the zone are domain controllers. You add multiple DNS records to the zone. You need to ensure that the new records are available on all DNS servers as soon as possible. Which tool should you use? A. Repadmin B. Active Directory Domains and Trusts console C. Ldp D. Ntdsutil Correct Answer: A

67 /Reference: QUESTION 8 Your network contains two Active Directory forests named contoso.com and fabrikam.com. Each forest contains a single domain. A two-way forest trust exists between the forests. Selective authentication is enabled on the trust. Contoso.com contains a group named Group 1. Fabrikam.com contains a server named Server1. You need to ensure that users in Group1 can access resources on Server1. What should you modify? A. the permissions of the Group1 group B. the UPN suffixes of the contoso.com forest C. the UPN suffixes of the fabrikam.com forest D. the permissions of the Server1 computer account Correct Answer: D /Reference: Please Check Answer QUESTION 9 Your network contains an Active Directory domain named contoso.com. You have an organizational unit (OU) named Sales and an OU named Engineering. Users in the Sates OU frequently log on to client computers in the Engineering OU. You need to meet the following requirements: - All of the user settings in the Group Policy objects (GPOs) linked to both the Sales OU and the Engineering OU must be applied to sales users when they log on to client computers in the Engineering OU. - Only the policy settings in the GPOs linked to the Sales OU must be applied to sales users when they log on to client computers in the Sales OU. - Policy settings in the GPOs linked to the Sales OU must not be applied to users in the Engineering OU. A. Modify the Group Policy permissions. B. Enable block inheritance. C. Configure the link order. D. Enable loopback processing in merge mode. E. Enable loopback processing in replace mode. F. Configure WMI filtering. G. Configure Restricted Groups. H. Configure Group Policy Preferences. I. Link the GPO to the Sales OU. J. Link the GPO to the Engineering OU.

68 Correct Answer: D /Reference: Please Check Answer Loopback with Merge In the case of Loopback with Merge, the Group Policy object list is a concatenation. The default list of GPOs for the user object is obtained, as normal, but then the list of GPOs for the computer (obtained during computer startup) is appended to this list. Because the computer's GPOs are processed after the user's GPOs, they have precedence if any of the settings conflict. QUESTION 10 You have an Active Directory domain named contoso.com. You need to view the account lockout threshold and duration for the domain. Which tool should you use? A. Computer Management B. Net Config C. Active Directory Users and Computers D. Gpresult Correct Answer: C /Reference: QUESTION 11 Your network contains an Active Directory domain named adatum.com. All servers run Windows Server 2008 R2. The network contains an enterprise certification authority (CA). You need to ensure that all of the members of a group named Managers can view the event log entries for Certificate Services. Which snap-in should you use? A. Active Directory Administrative Center B. Authorization Manager C. Certificate Templates D. Certificates E. Certification Authority F. Enterprise PKI G. Group Policy Management H. Security Configuration Wizard I. Share and Storage Management Correct Answer: G

69 /Reference: There is mention of an Event Log Reader Group. Membership should be able to be configured in AD Users and Groups. Check this answer. In the MMFSH dump he has the anwser AD Users and Groups, however this is not a option here so I have left it Group Policy Management. QUESTION 12 Your network contains an Active Directory domain named adatum.com. All servers run Windows Server 2008 R2 Enterprise. All client computers run Windows 7 Professional. The network contains an enterprise certification authority (CA). You need to approve a pending certificate request. Which snap-in should you use? A. Active Directory Administrative Center B. Authorization Manager C. Certificate Templates D. Certificates E. Certification Authority F. Enterprise PKI G. Group Policy Management H. Security Configuration Wizard I. Share and Storage Management Correct Answer: E /Reference: QUESTION 13 Your network contains an Active Directory domain named contoso.com. You have an organizational unit (OU) named Sales and an OU named Engineering. You have a Group Policy object (GPO) linked to the domain. You need to ensure that the settings in the GPO are not processed by user accounts or computer accounts in the Sales OU. You must achieve this goal by using the minimum amount of administrative effort. A. Modify the Group Policy permissions. B. Enable block inheritance. C. Configure the link order. D. Enable loopback processing in merge mode. E. Enable loopback processing in replace mode. F. Configure WMI filtering. G. Configure Restricted Groups. H. Configure Group Policy Preferences.

70 I. Link the GPO to the Sales OU. J. Link the GPO to the Engineering OU. Correct Answer: B /Reference: QUESTION 14 A corporate network includes a single Active Directory Domain Services (AD DS) domain. The domain contains 10 domain controllers. The domain controllers run Windows Server 2008 R2 and are configured as DNS servers. You plan to create an Active Directory-integrated zone. You need to ensure that the new zone is replicated to only four of the domain controllers. What should you do first? A. Use the ntdsutil tool to modify the DS behavior for the domain. B. Use the ntdsutil tool to add a naming context. C. Create a new delegation in the ForestDnsZones application directory partition. D. Use the dnscmd tool with the /zoneadd parameter. Correct Answer: D /Reference: QUESTION 15 A corporate network includes a single Active Directory Domain Services (AD DS) domain and two AD DS sites. The AD DS sites are named Toronto and Montreal. Each site has multiple domain controllers. You need to determine which domain controller holds the Inter-Site Topology Generator role for the Toronto site. A. Use the Active Directory Sites and Services console to view the NTDS Site Settings for the Toronto site. B. Use the Ntdsutil tool with the roles parameter. C. Use the Ntdsutil tool with the LDAP policies parameter. D. Use the Active Directory Sites and Services console to view the properties of each domain controller in the Toronto site. Correct Answer: A /Reference: QUESTION 16 Your network contains an Active Directory domain. The domain contains five sites. One of the sites contains a

71 read-only domain controller (RODC) named RODC1. You need to identify which user accounts can have their password cached on RODC1. Which tool should you use? A. Repadmin B. Dcdiag C. Get-ADDomainControllerPasswordReplicationPolicyUsage D. Adtest Correct Answer: A /Reference: The Get-ADDomainControllerPasswordReplicationPolicyUsage gets the user or computer accounts that are authenticated by a read-only domain controller (RODC) or that have passwords that are stored on that RODC. The list of accounts that are stored on a RODC is known as the revealed list. QUESTION 17 A network contains an Active Directory forest. The forest contains three domains and two sites. You remove the global catalog from a domain controller named DC2. DC2 is located in Site1. You need to reduce the size of the Active Directory database on DC2. The solution must minimize the impact on all users in Site1. What should you do first? A. On DC2, start the Protected Storage service. B. On DC2, stop the Active Directory Domain Services service. C. Start DC2 in Safe Mode. D. Start DC2 in Directory Services Restore Mode. Correct Answer: B /Reference: QUESTION 18 You have an enterprise subordinate certification authority (CA). You have a custom certificate template that has a key length of 1,024 bits. The template is enabled for autoenrollment. You increase the template key length to 2,048 bits. You need to ensure that all current certificate holders automatically enroll for a certificate that uses the new template. Which console should you use?

72 A. Group Policy Management MMC Snap-In B. Certificates MMC Snap-In on the Certificate Authority C. Certificate Templates MMC Snap-In D. Certification Authority MMC Snap-In Correct Answer: C /Reference: QUESTION 19 Your network contains an Active Directory forest. The forest contains one domain named contoso.com. You attempt to create a new child domain and you receive the following error message: "An LDAP read of operational attributes failed." You need to ensure that you can add a new child domain to the forest. A. Move the PDC emulator role. B. Move the RID master role. C. Move the infrastructure master role. D. Move the schema master role. E. Move the domain naming master role. F. Move the global catalog server. G. Move the bridgehead server. H. Install a read-only domain controller (RODC). I. Deploy an additional global catalog server. J. Restart the Active Directory Domain Services (AD DS) service. Correct Answer: E /Reference: QUESTION 20 Your network contains an Active Directory domain named contoso.com. You have an organizational unit (OU) named Sales and an OU named Engineering. You need to ensure that when users log on to client computers, they are added automatically to the local Administrators group. The users must be removed from the group when they log off of the client computers. A. Modify the Group Policy permissions. B. Enable block inheritance. C. Configure the link order. D. Enable loopback processing in merge mode. E. Enable loopback processing in replace mode.

73 F. Configure WMI filtering. G. Configure Restricted Groups. H. Configure Group Policy Preferences. I. Link the Group Policy object (GPO) to the Sales OU. J. Link the Group Policy object (GPO) to the Engineering OU. Correct Answer: H /Reference: QUESTION 21 Your network contains an Active Directory forest named contoso.com. The forest contains two member servers named Server1 and Server2. Server1 and Server2 have the DNS Server server role installed. Server1 hosts a standard primary zone for contoso.com. Server2 is configured as a secondary name server for contoso.com. You experience issues with the copy of the zone on Server2, You verify that both copies of the zone have the same serial number. You need to transfer a complete copy of the zone from Server1 to Server2. What should you do on Server2? A. From DNS Manager, right-click contoso.com and click Transfer from Master. B. From Services, right-click DNS Server and click Refresh. C. From Services, right-click DNS Server and click Restart. D. From DNS Manager, right-click contoso.com and click Reload. E. From DNS Manager, right-click contoso.com and click Transfer a new copy of zone from Master. Correct Answer: E /Reference: Please Check Answer QUESTION 22 Your network contains an Active Directory domain. The domain contains two Active Directory sites named Site1 and Site2. Site1 contains two domain controllers named DC1 and DC2. Site2 contains two domain controller named DC3 and DC4, The functional level of the domain is Windows Server 2008 R2. The functional level of the forest is Windows Server Active Directory replication between Site1 and Site2 occurs from 20:00 to 01:00 every day. At 07:00, an administrator deletes a user account while he is logged on to DC1. "A Composite Solution With Just One Click" - Certification Guaranteed 266 Microsoft Exam You need to restore the deleted user account. You want to achieve this goal by using the minimum amount of administrative effort.

74 A. On DC3, stop Active Directory Domain Services, perform an authoritative restore, and then start Active Directory Domain Services. B. On DC3, run the Restore-ADObject cmdlet. C. On DC1, run the Restore-ADObject cmdlet. D. On DC1, stop Active Directory Domain Services, restore the SystemState, and then start Active Directory Domain Services. Correct Answer: A /Reference: QUESTION 23 Your network contains an Active Directory forest named contoso.com. The functional level of the forest is Windows Server 2008 R2 The DNS zone for contoso.com is Active Directory-integrated. You deploy a read-only domain controller (RODC) named R0DC1. You install the DNS Server server role on R0DC1. You discover that R0DC1 does not have any DNS application directory partitions. You need to ensure that R0DC1 has a copy of the DNS application directory partition of contoso.com. (Each correct answer presents a complete solution. Choose two.) A. From DNS Manager, right-click RODC1 and click Create Default Application Directory Partitions. B. Run ntdsutil.exe. From the Partition Management context, run the create nc command. C. Run dnscmd.exe and specify the /createbuiltindirectorypartitions parameter. D. Run ntdsutil.exe. From the Partition Management context, run the add nc replica command. E. Run dnscmd.exe and specify the /enlistdirectorypartition parameter. Correct Answer: DE /Reference: Please Check but I think this should be A and C and not A and D. I have changed it to A and C. Reason: Once the application directory partition is created, contoso.com should replicate to it. Dnscmd /enlistdirectorypartition --- Adds the DNS server to the specified directory partition's replica set. Dnscmd /createbuiltindirectorypartitions Creates a DNS application directory partition. When DNS is installed, an application directory partition for the service is created at the forest and domain levels. Use this command to create DNS application directory partitions that were deleted or never created. With no parameter, this command creates a built-in DNS directory partition for the domain.

75 To create the default DNS application directory partitions Using the Windows interface Open DNS. In the console tree, right-click the applicable DNS server. Where? DNS/applicable DNS server Click Create Default Application Directory Partitions. Follow the instructions to create the DNS application directory partitions. QUESTION 24 A corporate network includes an Active Directory-integrated zone. All DNS servers that host the zone are domain controllers. You add multiple DNS records to the zone. You need to ensure that the new records are available on all DNS servers as soon as possible. Which tool should you use? A. Ntdsutil B. Dnscmd C. Repadmin D. Nslookup Correct Answer: C /Reference: Please Check Repadmin /syncall Because this is a Active Directory-integrated zone, you can use Repadmin /syncall to update everything encluding DNS records. QUESTION 25 Your network contains three servers named ADFS1, ADFS2, and ADFS3 that run Windows Server 2008 R2. ADFS1 has the Active Directory Federation Services (AD FS) Federation Service role service installed. You plan to deploy AD FS 2.0 on ADFS2 and ADFS3. You need to export the token-signing certificate from ADFS1, and then import the certificate to ADFS2 and ADFS3. A. Personal Information Exchange PKCS #12 (.pfx) B. DER encoded binary X.509 (.cer) C. Cryptographic Message Syntax Standard PKCS #7 (.p7b) D. Base-64 encoded X.S09 (.cer)

76 Correct Answer: A /Reference: QUESTION 26 Your network contains an Active Directory domain named contoso.com. The functional level of the forest is Windows Server 2008 R2. The Default Domain Controller Policy Group Policy object (GPO) contains audit policy settings. On a domain controller named DC1, an administrator configures the Advanced Audit Policy Configuration settings by using a local GPO. You need to identify what will be audited on DC1. Which tool should you use? A. Get-ADObject B. Secedit C. Security Configuration and Analysis D. Auditpol Correct Answer: D /Reference: QUESTION 27 A network contains an Active Directory forest. The forest schema contains a custom attribute for user objects. You need to view the custom attribute value of 500 user accounts in a Microsoft Excel table. Which tool should you use? A. Dsmod B. Csvde C. Ldifde D. Dsrm Correct Answer: B /Reference: QUESTION 28 Your network contains an Active Directory forest named contoso.com. The forest contains a single domain and 10 domain controllers. All of the domain controllers run Windows Server 2008 R2 Service Pack 1 (SP1). The forest contains an application directory partition named dc=app1, dc=contoso,dc=com. A domain controller named DC1 has a copy of the application directory partition.

77 You need to configure a domain controller named DC2 to receive a copy of dc=app1, dc=contoso,dc=corn. Which tool should you use? A. Active Directory Sites and Services B. Dsmod C. Dcpromo D. Dsmgmt Correct Answer: C /Reference: Please Check Answer I don't think this is Dsmod. It is most likely Dcpromo. Dsmod -- Modifies an existing object of a specific type in the directory. QUESTION 29 Your network contains an Active Directory forest. The forest contains three domains. All domain controllers have the DNS Server server role installed. The forest contains three sites named Site1, Site2, and Site3. Each site contains the users, client computers, and domain controllers of each domain. Site1 contains the first domain controller deployed to the forest. "A Composite Solution With Just One Click" - Certification Guaranteed 277 Microsoft Exam The sites connect to each other by using unreliable WAN links. The users in Site2 and Site3 report that is takes a long time to log on to their client computer when they use their user principal name (UPN). The users in Site1 do not experience the same issue. You need to reduce the amount of time it takes for the Site2 users and the Site3 users to log on to their client computer by using their UPN. A. Configure a global catalog server in Site2 and a global catalog server in Site3. B. Reduce the replication interval of the site links. C. Move a primary domain controller (PDC) emulator to Site2 and to Site3. D. Add additional domain controllers to Site2 and to Site3. E. Reduce the cost of the site links. F. Enable universal group membership caching in Site2 and in Site3. Correct Answer: A /Reference: QUESTION 30 You have a client computer named Computer1 that runs Windows 7.

78 On Computer1, you configure a source-initiated subscription. You configure the subscription to retrieve all events from the Windows logs of a domain controller named DC1. The subscription is configured to use the HTTP protocol. You discover that events from the Security log of DC1 are not collected on Computer1. Events from the Application log of DC1 and the System log of DC1 are collected on Computer1. You need to ensure that events from the Security log of DC1 are collected on Computer1. A. Add the computer account of Computer1 to the Event Log Readers group on the domain controller. B. Add the Network Service security principal to the Event Log Readers group on the domain. C. Configure the subscription to use custom Event Delivery Optimization settings. D. Configure the subscription to use the HTTPS protocol. Correct Answer: B /Reference: QUESTION 31 Your network contains an Active Directory domain named litwareinc.com. The domain contains two sites named Sitel and Site2. Site2 contains a read-only domain controller (RODC). You need to identify which user accounts attempted to authenticate to the RODC. Which tool should you use? A. Active Directory Users and Computers B. Ntdsutil C. Get-ADAccountResultantPasswordReplicationPolicy D. Adtest Correct Answer: A /Reference: Get-ADDomainControllerPasswordReplicationPolicyUsage o get accounts that are authenticated by the RODC, use the AuthenticatedAccounts parameter. To get the accounts that have passwords stored on the RODC, use the RevealedAccounts parameter. QUESTION 32 Your network contains an Active Directory forest. The forest schema contains a custom attribute for user objects. You need to generate a file that contains the last logon time and the custom attribute values for each user in the forest. What should you use?

79 A. the Get-ADUser cmdlet B. the Export-CSV cmdlet C. the Net User command D. the Dsquery User tool Correct Answer: A /Reference: QUESTION 33 A company has an Active Directory forest. You plan to install an offline Enterprise root certification authority (CA) on a server named CA1. CA1 is a member of the PerimeterNetwork workgroup and is attached to a hardware security module for private key storage. You attempt to add the Active Directory Certificate Services (AD CS) server role to CA1. The Enterprise CA option is not available. You need to install the AD CS server role as an Enterprise CA on CA1. What should you do first? A. Add the DNS Server server role to CA1. B. Add the Web Server (IIS) server role and the AD CS server role to CA1. C. Add the Active Directory Lightweight Directory Services (AD LDS) server role to CA1. D. Join CA1 to the domain. Correct Answer: D /Reference: QUESTION 34 Your company has an Active Directory forest. Each regional office has an organizational unit (OU) named Marketing. The Marketing OU contains all users and computers in the region's Marketing department. You need to install a Microsoft Office 2007 application only on the computers in the Marketing OUs. You create a GPO named MarketingApps. What should you do next? A. Configure the GPO to assign the application to the computer account. Link the GPO to the domain. B. Configure the GPO to assign the application to the user account. Link the GPO to each Marketing OU. C. Configure the GPO to assign the application to the computer account. Link the GPO to each Marketing OU. D. Configure the GPO to publish the application to the user account. Link the GPO to each Marketing OU. Correct Answer: C

80 /Reference: QUESTION 35 Your network contains an Active Directory domain. The domain is configured as shown in the exhibit. (Click the Exhibit button.) Each organizational unit (OU) contains over 500 user accounts. The Finance OU and the Human Resources OU contain several user accounts that are members of a universal group named Group1. You have a Group Policy object (GPO) linked to the domain. You need to prevent the GPO from being applied to the members of Group1 only. Exhibit: A. Modify the Group Policy permissions. B. Enable block inheritance. C. Configure the link order. D. Enable loopback processing in merge mode. E. Enable loopback processing in replace mode. F. Configure WMI filtering. G. Configure Restricted Groups. H. Configure Group Policy Preferences. I. Link the GPO to the Finance OU. J. Link the GPO to the Human Resources OU.

81 Correct Answer: A /Reference:

82 Exam G QUESTION 1 Your network contains an Active Directory domain. The domain contains a domain controller named DC1 that runs windows Server 2008 R2 Service Pack 1 (SP1). You need to implement a central store for domain policy templates. To answer, select the source content that should be copied to the destination folder in the answer area. Hot Area: Correct Answer: /Reference: QUESTION 2 Your network contains an Active Directory domain. The password policy for the domain is configured as shown in the Current Policy exhibit, (Click the Exhibit button.)

83 You change the password policy for the domain as shown in the New Policy exhibit. (Click the Exhibit button.) You need to provide users with examples of a valid password. Which password examples should you provide to the users? (Each correct answer presents a complete solution. Choose three.) A !@#$%^ B.!@#$1234ABCD C. passwordl234 D a-b-c-e E. %%PASS1234%% F aaaaaaa Correct Answer: BDE /Reference: Passwords must contain characters from three of the following five categories: Uppercase characters of European languages (A through Z, with diacritic marks, Greek and Cyrillic

84 characters) Lowercase characters of European languages (a through z, sharp-s, with diacritic marks, Greek and Cyrillic characters) Base 10 digits (0 through 9) Nonalphanumeric characters: \(){}[]:;"'<>,.?/ Any Unicode character that is categorized as an alphabetic character but is not uppercase or lowercase. This includes Unicode characters from Asian languages. QUESTION 3 Your network contains an Active Directory forest named contoso.com. The functional level of the forest is Windows Server 2008 R2. The forest contains a single domain. You need to ensure that objects can be restored from the Active Directory Recycle Bin. Which tool should you use? A. Ntdsutil B. Set-ADDomain C. Dsamain D. Enable-ADOptionalFeature Correct Answer: D /Reference: QUESTION 4 Your network contains an Active Directory domain. The domain is configured as shown in the exhibit. (Click the Exhibit button.) Users in the Finance organizational unit (OU) frequently log on to client computers in the Human Resources OU. You need to meet the following requirements: - All of the user settings in the Group Policy objects (GPOs) linked to both the Finance OU and the Human Resources OU must be applied to finance users when they log on to client computers in the Engineering OU. - Only the policy settings in the GPOs linked to the Finance OU must be applied to finance users when they log on to client computers in the Finance OU. - Policy settings in the GPOs linked to the Finance OU must not be applied to users in the Human Resources OU. Exhibit:

85 A. Modify the Group Policy permissions. B. Enable block inheritance. C. Configure the link order. D. Enable loopback processing in merge mode. E. Enable loopback processing in replace mode. F. Configure WMI filtering. G. Configure Restricted Groups. H. Configure Group Policy Preferences. I. Link the GPO to the Finance OU. J. Link the GPO to the Human Resources OU. Correct Answer: D /Reference: QUESTION 5 Your company plans to open a new branch office. The new office will have a low-speed connection to the Internet. You plan to deploy a read-only domain controller (RODC) in the branch office. You need to create an offline copy of the Active Directory database that can be used to install the Active Directory on the new RODC. Which commands should you run from Ntdsutil?

86 To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order. Select and Place: Correct Answer: /Reference: QUESTION 6 Your network contains an Active Directory forest named contoso.com. You need to use Group Policies to deploy the applications shown in the following table.

87 To answer, drag the appropriate deployment method to the correct application in the answer area. Select and Place: Correct Answer: /Reference: QUESTION 7 Your network contains an Active Directory domain named contoso.com. You need to view which password setting object is applied to a user.

88 Which filter option in Attribute Editor should you enable? To answer, select the appropriate filter option in the answer area. Hot Area: Correct Answer: /Reference: QUESTION 8 Your network contains two Active Directory forests named contoso.com and fabrikam.com. A two-way forest trust exists between the forests. Selective authentication is enabled on the trust. Fabrikam.com contains a server named Server1. You assign Contoso\Domain Users the Manage documents permission and the Print permission to a shared printer on Server1. You discover that users from contoso.com cannot access the shared printer on Server1. You need to ensure that the contoso.com users can access the shared printer on Server1. Which permission should you assign to Contoso\Domain Users.

89 To answer, select the appropriate permission in the answer area. Hot Area: Correct Answer:

90 /Reference: QUESTION 9 Your network contains an Active Directory forest named contoso.com. The forest contains two sites named Seattle and Montreal. The Seattle site contains two domain controllers. The domain controllers are configured as shown in the following table. The Montreal site contains a domain controller named DC3. DC3 is the only global catalog server in the forest. You need to configure DC2 as a global catalog server. Which object's properties should you modify? To answer, select the appropriate object in the answer area. Hot Area:

91 Correct Answer: /Reference: To designate a domain controller to be a global catalog server Open Active Directory Sites and Services. In the console tree expand the Sites container, and then expand the site in which you are designating a global catalog server.

92 Expand the Servers container and then expand the Server object for the domain controller that you want to designate as a global catalog server. Right-click the NTDS Settings object for the target server, and then click Properties. Select the Global Catalog check box, and then click OK. QUESTION 10 Your network contains an Active Directory forest named contoso.com. The forest contains two Active Directory sites named Seattle and Montreal. The Montreal site is a branch office that contains only a single read-only domain controller (RODC). You accidentally delete the site link between the two sites. You recreate the site link while you are connected to a domain controller in Seattle. You need to replicate the change to the RODC in Montreal. Which node in Active Directory Sites and Services should you use? To answer, select the appropriate node in the answer area. Hot Area: Correct Answer:

KillTest 䊾 䞣 催 ࢭ ད ᅌ㖦䊛 ᅌ㖦䊛 NZZV ]]] QORRZKYZ TKZ ϔᑈܡ䊏 ᮄ ࢭ

KillTest 䊾 䞣 催 ࢭ ད ᅌ㖦䊛 ᅌ㖦䊛 NZZV ]]] QORRZKYZ TKZ ϔᑈܡ䊏 ᮄ ࢭ KillTest Exam : 70-648 Title : TS: Upgrading MCSA on Windows serv 2003 to Windows Serv 2008 Version : Demo 1 / 8 1.Note : This is part of a series of questions that use the same set of answer choices.

More information

70-742: Identity in Windows Server Course Overview

70-742: Identity in Windows Server Course Overview 70-742: Identity in Windows Server 2016 Course Overview This course provides students with the knowledge and skills to install and configure domain controllers, manage Active Directory objects, secure

More information

Identity with Windows Server 2016 (742)

Identity with Windows Server 2016 (742) Identity with Windows Server 2016 (742) Install and Configure Active Directory Domain Services (AD DS) Install and configure domain controllers This objective may include but is not limited to: Install

More information

Microsoft Exam Bundle

Microsoft Exam Bundle Microsoft 70-640 Exam Bundle Number: 70-640 Passing Score: 700 Time Limit: 900 min File Version: 41.0 http://www.gratisexam.com/ Microsoft 70-640 Exam Bundle Exam Name: Microsoft TS: Windows Server 2008

More information

Microsoft Upgrading from Windows Server 2003 MCSA to Windows Server 2008, Technology Specializations

Microsoft Upgrading from Windows Server 2003 MCSA to Windows Server 2008, Technology Specializations Passing Score: 700 Time Limit: 120 min http://www.gratisexam.com/ Microsoft 70-648 Upgrading from Windows Server 2003 MCSA to Windows Server 2008, Technology Specializations Sections 1. 70-640 2. 70-642

More information

Microsoft MCTS Windows Server 2008, Active Directory. Download Full Version :

Microsoft MCTS Windows Server 2008, Active Directory. Download Full Version : Microsoft 72-640 MCTS Windows Server 2008, Active Directory Download Full Version : http://killexamscom/pass4sure/exam-detail/72-640 Exam K QUESTION 1 Your network contains an Active Directory forest The

More information

Identity with Windows Server 2016 (beta)

Identity with Windows Server 2016 (beta) Identity with Windows Server 2016 (beta) Dumps Available Here at: /microsoft-exam/70-742-dumps.html Enrolling now you will get access to 228 questions in a unique set of 70-742 dumps Question 1 Note: This

More information

TestOut Server Pro 2016: Identity - English 4.0.x LESSON PLAN. Revised

TestOut Server Pro 2016: Identity - English 4.0.x LESSON PLAN. Revised TestOut Server Pro 2016: Identity - English 4.0.x LESSON PLAN Revised 2018-08-06 Table of Contents Introduction Section 0.1: Server Pro 2016: Identity Introduction... 4 Section 0.2: The TestOut Lab Simulator...

More information

exam.75q. Number: Passing Score: 800 Time Limit: 120 min File Version: 1. Microsoft

exam.75q. Number: Passing Score: 800 Time Limit: 120 min File Version: 1. Microsoft 70-742.exam.75q Number: 70-742 Passing Score: 800 Time Limit: 120 min File Version: 1 Microsoft 70-742 Identity with Windows Server 2016 Exam A QUESTION 1 Note: This question is part of a series of questions

More information

Server : Advanced Services 3 1 x

Server : Advanced Services 3 1 x Server : Advanced Services 3 1 x Revised 2016/05/17 TestOut Server Pro: Advanced Services English 3.1.x Videos: 56 (5:12:20) Demonstrations: 84 (9:20:07) Simulations: 47 Written Lessons: 92 Section Quizzes:

More information

Q&As. Identity with Windows Server Pass Microsoft Exam with 100% Guarantee

Q&As. Identity with Windows Server Pass Microsoft Exam with 100% Guarantee 70-742 Q&As Identity with Windows Server 2016 Pass Microsoft 70-742 Exam with 100% Guarantee Free Download Real Questions & Answers PDF and VCE file from: 100% Passing Guarantee 100% Money Back Assurance

More information

Microsoft TS: Windows Server 2008 Active Directory, Configuring.

Microsoft TS: Windows Server 2008 Active Directory, Configuring. Microsoft 83-640 TS: Windows Server 2008 Active Directory, Configuring http://killexams.com/exam-detail/83-640 B. Set event log subscriptions and configure it C. Initiate the System Performance data collector

More information

Exam Identity with Windows Server 2016

Exam Identity with Windows Server 2016 MCSA / MCSE for Windows Server 2016 Exam 70-742 Identity with Windows Server 2016 Version 15.35 (198 Questions) (70-742) Identify with Windows Server 2016 QUESTION 1 You have a server named Server1 that

More information

70-640_formatted. Number: Passing Score: 800 Time Limit: 120 min File Version: 1.0.

70-640_formatted.  Number: Passing Score: 800 Time Limit: 120 min File Version: 1.0. 70-640_formatted Number: 000-000 Passing Score: 800 Time Limit: 120 min File Version: 1.0 http://www.gratisexam.com/ Microsoft 70-640 TS: Windows Server 2008 Active Directory, Configuring Version: 32.7

More information

straight_evil - 426q ( )

straight_evil - 426q ( ) straight_evil - 426q (2013-04-18) Number: 70-648 Passing Score: 700 Time Limit: 170 min File Version: 2.0 http://www.gratisexam.com/ Exam 70-648 TS: Upgrading from Windows Server 2003 MCSA to, Windows

More information

Microsoft MCSA Exam

Microsoft MCSA Exam Microsoft MCSA 70-412 Exam Vendor: Microsoft Exam Code: 70-412 Exam Name: Configuring Advanced Windows Server 2012 Services www.ensurpeass.com/70-412.html QUESTION 1 You have a DHCP server named Server1.

More information

Vendor: Microsoft. Exam Code: Exam Name: Configuring Advanced Windows Server 2012 Services. Version: Demo

Vendor: Microsoft. Exam Code: Exam Name: Configuring Advanced Windows Server 2012 Services. Version: Demo Vendor: Microsoft Exam Code: 70-412 Exam Name: Configuring Advanced Windows Server 2012 Services Version: Demo DEMO QUESTION 1 Your network contains one Active Directory domain. The domain contains two

More information

Microsoft Exam

Microsoft Exam Volume: 425 Questions Question No: 1 Your company recently deployed a new Active Directory forest named contoso.com. The first domain controller in the forest runs Windows Server 2012 R2. You need to identify

More information

Identity with Windows Server 2016

Identity with Windows Server 2016 Identity with Windows Server 2016 20742B; 5 days, Instructor-led Course Description This five-day instructor-led course teaches IT Pros how to deploy and configure Active Directory Domain Services (AD

More information

Microsoft MCSE Exam

Microsoft MCSE Exam Microsoft MCSE 70-414 Exam Vendor:Microsoft Exam Code: 70-414 Exam Name: Implementing an Advanced Server Infrastructure www.ensurepass.com/70-414.html QUESTION 1 Your network contains an Active Directory

More information

Course Outline 20742B

Course Outline 20742B Course Outline 20742B Module 1: Installing and configuring domain controllers This module describes the features of AD DS and how to install domain controllers (DCs). It also covers the considerations

More information

Identity with Windows Server 2016

Identity with Windows Server 2016 Identity with Windows Server 2016 Course 20742B - 5 Days - Instructor-led, Hands on Introduction This five-day instructor-led course teaches IT Pros how to deploy and configure Active Directory Domain

More information

20742: Identity with Windows Server 2016

20742: Identity with Windows Server 2016 Course Content Course Description: This five-day instructor-led course teaches IT Pros how to deploy and configure Active Directory Domain Services (AD DS) in a distributed environment, how to implement

More information

MOC 6232A: Implementing a Microsoft SQL Server 2008 Database

MOC 6232A: Implementing a Microsoft SQL Server 2008 Database MOC 6232A: Implementing a Microsoft SQL Server 2008 Database Course Number: 6232A Course Length: 5 Days Course Overview This course provides students with the knowledge and skills to implement a Microsoft

More information

M20742-Identity with Windows Server 2016

M20742-Identity with Windows Server 2016 M20742-Identity with Windows Server 2016 Course Number: M20742 Category: Technical Microsoft Duration: 5 days Certification: 70-742 Overview This five-day instructor-led course teaches IT Pros how to deploy

More information

Microsoft Exam

Microsoft Exam Volume: 65 Questions Question: 1 Your company recently deployed a new child domain to an Active Directory forest. You discover that a user modified the Default Domain Policy to configure several Windows

More information

Microsoft Actualanswers Exam Questions & Answers

Microsoft Actualanswers Exam Questions & Answers Microsoft Actualanswers 70-412 Exam Questions & Answers Number: 70-412 Passing Score: 800 Time Limit: 120 min File Version: 25.7 http://www.gratisexam.com/ Microsoft 70-412 Exam Questions & Answers Exam

More information

At Course Completion: Course Outline: Course 20742: Identity with Windows Server Learning Method: Instructor-led Classroom Learning

At Course Completion: Course Outline: Course 20742: Identity with Windows Server Learning Method: Instructor-led Classroom Learning Course Outline: Course 20742: Identity with Windows Server 2016 Learning Method: Instructor-led Classroom Learning Duration: 5.00 Day(s)/ 40 hrs Overview: This five-day instructor-led course teaches IT

More information

METHODOLOGY This program will be conducted with interactive lectures, PowerPoint presentations, discussions and practical exercises.

METHODOLOGY This program will be conducted with interactive lectures, PowerPoint presentations, discussions and practical exercises. CENTER OF KNOWLEDGE, PATH TO SUCCESS Website: IDENTITY WITH WINDOWS SERVER 2016 Course 20742: 5 days; Instructor-Led INTRODUCTION This five-day instructor-led course teaches IT Pros how to deploy and configure

More information

MCSA Windows Server 2012

MCSA Windows Server 2012 MCSA Windows Server 2012 This Training Program prepares and enables learners to Pass Microsoft MCSA: Windows Server 2012 exams 1. MCSA: Windows Server 2012 / 70-410 Exam (Installing and Configuring Windows

More information

Course Content of MCSA ( Microsoft Certified Solutions Associate )

Course Content of MCSA ( Microsoft Certified Solutions Associate ) Course Content of MCSA 2012 - ( Microsoft Certified Solutions Associate ) Total Duration of MCSA : 45 Days Exam 70-410 - Installing and Configuring Windows Server 2012 (Course 20410A Duration : 40 hrs

More information

TS: Upgrading from Windows Server 2003 MCSA to, Windows Server 2008, Technology Specializations

TS: Upgrading from Windows Server 2003 MCSA to, Windows Server 2008, Technology Specializations Microsoft 70-648 TS: Upgrading from Windows Server 2003 MCSA to, Windows Server 2008, Technology Specializations Version: 46.0 Topic 1, Volume A QUESTION NO: 1 Your network contains an Active Directory

More information

Vendor: Microsoft. Exam Code: Exam Name: Administering Windows Server Version: Demo

Vendor: Microsoft. Exam Code: Exam Name: Administering Windows Server Version: Demo Vendor: Microsoft Exam Code: 70-411 Exam Name: Administering Windows Server 2012 Version: Demo DEMO QUESTION 1 You have a server named Server1 that runs Windows Server 2012 R2. You need to configure Server1

More information

MOC 20411B: Administering Windows Server Course Overview

MOC 20411B: Administering Windows Server Course Overview MOC 20411B: Administering Windows Server 2012 Course Overview This course is part two in a series of three courses that provides the skills and knowledge necessary to implement a core Windows Server 2012

More information

Passleader Exam Name: Configuring Advanced Windows Server 2012 Services

Passleader Exam Name: Configuring Advanced Windows Server 2012 Services Passleader-70-412 Number: 70-412 Passing Score: 800 Time Limit: 120 min File Version: 1.0 http://www.gratisexam.com/ Vendor: Microsoft Exam Code: 70-412 Exam Name: Configuring Advanced Windows Server 2012

More information

This course provides students with the knowledge and skills to administer Windows Server 2012.

This course provides students with the knowledge and skills to administer Windows Server 2012. MOC 20411C: Administering Windows Server 2012 Course Overview This course provides students with the knowledge and skills to administer Windows Server 2012. Course Introduction Course Introduction 6m Module

More information

Windows Server 2008 Administration

Windows Server 2008 Administration Hands-On Course Description This course provides hands on experience installing and configuring Windows Server 2008 to work with clients including Windows Vista. Students will perform full and core CD-based

More information

MCSA Windows Server A Success Guide to Prepare- Microsoft Upgrading Your Skills to MCSA Windows Server edusum.

MCSA Windows Server A Success Guide to Prepare- Microsoft Upgrading Your Skills to MCSA Windows Server edusum. 70-417 MCSA Windows Server 2012 A Success Guide to Prepare- Microsoft Upgrading Your Skills to MCSA Windows Server 2012 edusum.com Table of Contents Introduction to 70-417 Exam on Upgrading Your Skills

More information

MCSA Windows Server A Success Guide to Prepare- Microsoft Configuring Advanced Windows Server 2012 Services. edusum.

MCSA Windows Server A Success Guide to Prepare- Microsoft Configuring Advanced Windows Server 2012 Services. edusum. 70-412 MCSA Windows Server 2012 A Success Guide to Prepare- Microsoft Configuring Advanced Windows Server 2012 Services edusum.com Table of Contents Introduction to 70-412 Exam on Configuring Advanced

More information

MCSA Windows Server A Success Guide to Prepare- Microsoft Administering Windows Server edusum.com

MCSA Windows Server A Success Guide to Prepare- Microsoft Administering Windows Server edusum.com 70-411 MCSA Windows Server 2012 A Success Guide to Prepare- Microsoft Administering Windows Server 2012 edusum.com Table of Contents Introduction to 70-411 Exam on Administering Windows Server 2012...

More information

Server : Manage and Administer 3 1 x

Server : Manage and Administer 3 1 x Server : Manage and Administer 3 1 x Revised 2016/05/17 TestOut Server Pro: Manage and Administer English 3.1.x Videos: 56 (4:25:22) Demonstrations: 87 (10:14:13) Simulations: 63 Written Lessons: 72 Section

More information

Microsoft Exactexams Questions & Answers

Microsoft Exactexams Questions & Answers Microsoft Exactexams 70-410 Questions & Answers Number: 70-410 Passing Score: 800 Time Limit: 120 min File Version: 32.7 http://www.gratisexam.com/ Microsoft 70-410 Questions & Answers Exam Name: Installing

More information

Microsoft Recertification for MCSE: Server Infrastructure. Download Full Version :

Microsoft Recertification for MCSE: Server Infrastructure. Download Full Version : Microsoft Recertification for MCSE: Server Infrastructure Download Full Version : https://killexams.com/pass4sure/exam-detail/ Answer: C QUESTION: 99 Your company has an office in New York. Many users

More information

Identity with Windows Server 2016 (20742)

Identity with Windows Server 2016 (20742) Identity with Windows Server 2016 (20742) Formato do curso: Presencial Preço: 1630 Duração: 35 horas This five-day instructor-led course teaches IT Pros how to deploy and configure Active Directory Domain

More information

Microsoft - Configuring Windows Server 2008 Active Directory Domain Services (M6425)

Microsoft - Configuring Windows Server 2008 Active Directory Domain Services (M6425) Microsoft - Configuring Windows Server 2008 Active Directory Domain Services (M6425) Code: 6123 Lengt h: URL: 5 days View Online In this comprehensive course you will not only discuss the crucial concepts

More information

Administering. Windows Server 2012 R2. Exam Wiley. Patrick Regan

Administering. Windows Server 2012 R2. Exam Wiley. Patrick Regan Administering Windows Server 2012 R2 Exam 70-411 Patrick Regan Wiley Contents j Lesson 1: Deploying and Managing Server Images 1 Using Windows Deployment Services 2 Installing the Windows Deployment Services

More information

Exam Name: TS: Upgrading from Windows Server 2003 MCSA to Windows Server 2008,Technology Specializations

Exam Name: TS: Upgrading from Windows Server 2003 MCSA to Windows Server 2008,Technology Specializations Vendor: Microsoft Exam Code: 70-648 Exam Name: TS: Upgrading from Windows Server 2003 MCSA to Windows Server 2008,Technology Specializations Version: DEMO QUESTION 1 Your company has an Active Directory

More information

MCSA Windows Server 2012 Configuring Advanced Services

MCSA Windows Server 2012 Configuring Advanced Services Session 1 MCSA Windows Server 2012 Configuring Advanced Services Section A: Windows Server 412 70-412 Project Network Load Balancing Prerequisites for NLB Install NLB Cluster Configuration Unicast vs.

More information

Configuring Advanced Windows Server 2012 Services (412)

Configuring Advanced Windows Server 2012 Services (412) Configuring Advanced Windows Server 2012 Services (412) Configure and manage high availability Configure Network Load Balancing (NLB) Install NLB nodes, configure NLB prerequisites, configure affinity,

More information

Real4Test. Real IT Certification Exam Study materials/braindumps

Real4Test.   Real IT Certification Exam Study materials/braindumps Real4Test http://www.real4test.com Real IT Certification Exam Study materials/braindumps Exam : 70-742 Title : Identity with Windows Server 2016 Vendor : Microsoft Version : DEMO Get Latest & Valid 70-742

More information

Identity with Microsoft Windows Server 2016 (MS-20742)

Identity with Microsoft Windows Server 2016 (MS-20742) Identity with Microsoft Windows Server 2016 (MS-20742) Modality: Virtual Classroom Duration: 5 Days SATV Value: 5 Days SUBSCRIPTION: Master, Premium About this course Windows Server vnext, which we now

More information

Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services

Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services 6425 - Configuring and Troubleshooting Windows Server 2008 Active Directory Domain Services Duration: 5 days Course Price: $2,975 Software Assurance Eligible Course Description Microsoft Windows Server

More information

Microsoft Pro: Windows Server 2008, Server Administrator. Practice Test. Updated: Jan 19, 2010 Version

Microsoft Pro: Windows Server 2008, Server Administrator. Practice Test. Updated: Jan 19, 2010 Version Microsoft 70-646 70-646 Pro: Windows Server 2008, Server Administrator Practice Test Updated: Jan 19, 2010 Version QUESTION NO: 1 Microsoft 70-646: Practice Exam consists of 200 Windows Server 2008 servers.

More information

exam.164q. Number: Passing Score: 800 Time Limit: 120 min File Version: 1. Microsoft Administering Windows Server 2012

exam.164q. Number: Passing Score: 800 Time Limit: 120 min File Version: 1. Microsoft Administering Windows Server 2012 70-411.exam.164q Number: 70-411 Passing Score: 800 Time Limit: 120 min File Version: 1 Microsoft 70-411 Administering Windows Server 2012 Sections 1. Volume A 2. Volume B Exam A QUESTION 1 Your network

More information

Microsoft PracticeTest v by Murat 95q

Microsoft PracticeTest v by Murat 95q Microsoft PracticeTest 70-412 v2013-02-19 by Murat 95q Number: 70-412 Passing Score: 700 Time Limit: 100 min File Version: 2012-12-05 http://www.gratisexam.com/ Compilation from 70-412 and 70-417. Microsoft

More information

NET EXPERT SOLUTIONS PVT LTD

NET EXPERT SOLUTIONS PVT LTD Module 1: Implementing Advanced Network Services In this module students will be able to configure advanced features for Dynamic Host Configuration Protocol (DHCP) and Domain Name System (DNS), and configure

More information

MCSA Windows Server 2012

MCSA Windows Server 2012 MCSA Windows Server 2012 This course is developed for IT professionals who need to design, plan, implement, manage and support Microsoft Windows 2012 networks or who plan to take the related MCSE and MCSA

More information

MCSE Server Infrastructure. This Training Program prepares and enables learners to Pass Microsoft MCSE: Server Infrastructure exams

MCSE Server Infrastructure. This Training Program prepares and enables learners to Pass Microsoft MCSE: Server Infrastructure exams MCSE Server Infrastructure This Training Program prepares and enables learners to Pass Microsoft MCSE: Server Infrastructure exams 1. MCSE: Server Infrastructure / Exam 70-413 (Designing and Implementing

More information

ASM Educational Center (ASM) Est. 1992

ASM Educational Center (ASM) Est. 1992 MCSA Windows Server 2012 Certification Course Outline 70-410: Installing and Configuring Windows Server 2012 R2 Module 01 - Server 2012 Overview Server 2012 Overview On Premise vs. Cloud Common Cloud Computing

More information

Active Directory Services with Windows Server

Active Directory Services with Windows Server Active Directory Services with Windows Server 10969B; 5 days, Instructor-led Course Description Get hands on instruction and practice administering Active Directory technologies in Windows Server 2012

More information

Install and Configure Active Directory Domain Services

Install and Configure Active Directory Domain Services Active Directory 101 Install and Configure Active Directory Domain Services Sander Berkouwer CTO at SCCT 10-fold Microsoft MVP Active Directory aficionado Daniel Goater Systems Engineer Netwrix Active

More information

Microsoft Exam Windows Server 2008 Active Directory, Configuring Version: 41.0 [ Total Questions: 631 ]

Microsoft Exam Windows Server 2008 Active Directory, Configuring Version: 41.0 [ Total Questions: 631 ] s@lm@n Microsoft Exam 70-640 Windows Server 2008 Active Directory, Configuring Version: 41.0 [ Total Questions: 631 ] Topic break down Topic No. of Questions Topic 1: Volume A 100 Topic 2: Volume B 100

More information

Microsoft. Exam Questions Windows Server 2008 Active Directory - Configuring. Version:Demo

Microsoft. Exam Questions Windows Server 2008 Active Directory - Configuring. Version:Demo Microsoft Exam Questions 70-640 Windows Server 2008 Active Directory - Configuring Version:Demo 1.Your company has an Active Directory domain. You have a two-tier PKI infrastructure that contains an offline

More information

Microsoft Braindumps Exam Questions & Answers

Microsoft Braindumps Exam Questions & Answers Microsoft Braindumps 70-412 Exam Questions & Answers Number: 70-412 Passing Score: 700 Time Limit: 120 min File Version: 23.6 http://www.gratisexam.com/ Microsoft 70-412 Exam Questions & Answers Exam Name:

More information

Exam Questions

Exam Questions Exam Questions 70-980 Recertification for MCSE: Server Infrastructure https://www.2passeasy.com/dumps/70-980/ 1. You need to recommend which type of clustered file server and which type of file share must

More information

Microsoft Server Administrator

Microsoft Server Administrator Microsoft Server Administrator Title : Microsoft Server Administrator Institute Certification : SmartEntry Certified Microsoft Server Administrator Duration: 40 Hrs Fees: 25K Prerequisite : A+ & N+ Description

More information

TestOut Server Pro: Advanced Services English 3.1.x LESSON PLAN. Revised 2016/05/17

TestOut Server Pro: Advanced Services English 3.1.x LESSON PLAN. Revised 2016/05/17 TestOut Server Pro: Advanced Services English 3.1.x LESSON PLAN Revised 2016/05/17 Table of Contents Course Overview... 4 Course Introduction for Instructors... 6 Section 1.1: Multi-Domain Forests... 8

More information

Microsoft Exam Questions & Answers

Microsoft Exam Questions & Answers Microsoft 70-412 Exam Questions & Answers Number: 70-412 Passing Score: 700 Time Limit: 150 min File Version: 12.3 http://www.gratisexam.com/ Microsoft 70-412 Exam Questions & Answers Exam Name: Configuring

More information

Active Directory Services with Windows Server

Active Directory Services with Windows Server Course Code: M10969 Vendor: Microsoft Course Overview Duration: 5 RRP: POA Active Directory Services with Windows Server Overview Get Hands on instruction and practice administering Active Directory technologies

More information

KillTest *KIJGT 3WCNKV[ $GVVGT 5GTXKEG Q&A NZZV ]]] QORRZKYZ IUS =K ULLKX LXKK [VJGZK YKX\OIK LUX UTK _KGX

KillTest *KIJGT 3WCNKV[ $GVVGT 5GTXKEG Q&A NZZV ]]] QORRZKYZ IUS =K ULLKX LXKK [VJGZK YKX\OIK LUX UTK _KGX KillTest Q&A Exam : 70-640 Title : Windows Server 2008 Active Directory. Configuring Version : Demo 1 / 28 1.You have a single Active Directory domain. All domain controllers run Windows Server 2008 and

More information

ACTIVE DIRECTORY SERVICES WITH WINDOWS SERVER

ACTIVE DIRECTORY SERVICES WITH WINDOWS SERVER CENTER OF KNOWLEDGE, PATH TO SUCCESS Website: ACTIVE DIRECTORY SERVICES WITH WINDOWS SERVER Course: 10969A; Duration: 5 Days; Instructor-led WHAT YOU WILL LEARN Get hands-on instruction and practice administering

More information

Exam Questions

Exam Questions Exam Questions 70-685 Pro: Windows 7, Enterprise Desktop Support Technician https://www.2passeasy.com/dumps/70-685/ 1.Portable computer users report that they can use Internet Explorer to browse Internet

More information

Microsoft MCSA Exam

Microsoft MCSA Exam Microsoft MCSA 70-411 Exam Vendor:Microsoft Exam Code: 70-411 Exam Name: Administering Windows Server 2012 www.ensurepass.com/70-411.html QUESTION 1 Your network contains an Active Directory domain named

More information

70-411: Administrating Windows Server 2012

70-411: Administrating Windows Server 2012 70-411: Administrating Windows Server 2012 Course Overview This course provides students with the knowledge and skills to administer a Windows Server 2012 infrastructure in an enterprise environment. Course

More information

This module provides an overview of multiple Access and Information Protection (AIP) technologies

This module provides an overview of multiple Access and Information Protection (AIP) technologies Course Outline Module 1: Overview of Access and Information Protection This module provides an overview of multiple Access and Information Protection (AIP) technologies and services what are available

More information

Best MCSA Training in PUNE & Best MCSA Training Institute in MAHARASHTRA

Best MCSA Training in PUNE & Best MCSA Training Institute in MAHARASHTRA Best MCSA Training in PUNE & Best MCSA Training Institute in MAHARASHTRA RAHITECH is the biggest MCSA training center in PUNE with high tech infrastructure and lab facilities and the options of opting

More information

70-647: Windows Server Enterprise Administration. Course Overview. Course Outline

70-647: Windows Server Enterprise Administration. Course Overview. Course Outline 70-647: Windows Server Enterprise Administration Course Overview Windows Server Enterprise Administration teaches the student how to maintain the Windows Server 2008 R2 environment. Students will learn

More information

MOC 20410B: Installing and Configuring Windows Server 2012

MOC 20410B: Installing and Configuring Windows Server 2012 MOC 20410B: Installing and Configuring Windows Server 2012 Course Overview This course is part one of a three-part series that provides the skills and knowledge necessary to implement a core Windows Server

More information

Step-by-step guide to Install an Additional Domain Controller by Using IFM

Step-by-step guide to Install an Additional Domain Controller by Using IFM Step-by-step guide to Install an Additional Domain Controller by Using IFM Teacher s copy 3 Votes You can create an additional domain controller in a domain by installing Active Directory Domain Services

More information

Microsoft Windows Server 2008 Functionality Changes. Powered by Microsoft TechNet

Microsoft Windows Server 2008 Functionality Changes. Powered by Microsoft TechNet Microsoft Windows Server 2008 Functionality Changes Powered by Microsoft TechNet 2 Table of Contents Chapter 1 New in Active Directory Certificate Services... 3 Chapter 2 What's New in Active Directory

More information

Microsoft Certified Solutions Associate (MCSA)

Microsoft Certified Solutions Associate (MCSA) Microsoft Certified Solutions Associate (MCSA) Installing and Configuring Windows Server 2012 (70-410) Module 1: Deploying and Managing Windows Server 2012 Windows Server 2012 Overview Overview of Windows

More information

COURSE OUTLINE MOC 10969: ACTIVE DIRECTORY SERVICES WITH WINDOWS SERVER MODULE 1: OVERVIEW OF ACCESS AND INFORMATION PROTECTION

COURSE OUTLINE MOC 10969: ACTIVE DIRECTORY SERVICES WITH WINDOWS SERVER MODULE 1: OVERVIEW OF ACCESS AND INFORMATION PROTECTION COURSE OUTLINE MOC 10969: ACTIVE DIRECTORY SERVICES WITH WINDOWS SERVER MODULE 1: OVERVIEW OF ACCESS AND INFORMATION PROTECTION This module provides an overview of multiple Access and Information Protection

More information

Vendor: Microsoft. Exam Code: Exam Name: Installing and Configuring Windows Server Version: Demo

Vendor: Microsoft. Exam Code: Exam Name: Installing and Configuring Windows Server Version: Demo Vendor: Microsoft Exam Code: 70-410 Exam Name: Installing and Configuring Windows Server 2012 Version: Demo DEMO QUESTION 1 You have a server named Core1 that has a Server Core Installation of Windows

More information

Course 10969: Active Directory services with Windows Server

Course 10969: Active Directory services with Windows Server Course 10969: Active Directory services with Windows Server Overview Get Hands on instruction and practice administering Active Directory technologies in Windows Server 2012 and Windows Server 2012 R2

More information

Microsoft Certified Solutions Expert (MCSE)

Microsoft Certified Solutions Expert (MCSE) Microsoft Certified Solutions Expert (MCSE) Installing and Configuring Windows Server 2012 (70-410) Module 1: Deploying and Managing Windows Server 2012 Windows Server 2012 Overview Overview of Windows

More information

Microsoft Active Directory Services with Windows Server

Microsoft Active Directory Services with Windows Server 1800 ULEARN (853 276) www.ddls.com.au Microsoft 10969 - Active Directory Services with Windows Server Length 5 days Price $4290.00 (inc GST) Version B Overview Get hands-on instruction and practice administering

More information

"Charting the Course... MOC B Active Directory Services with Windows Server Course Summary

Charting the Course... MOC B Active Directory Services with Windows Server Course Summary Description Course Summary Get Hands on instruction and practice administering Active Directory technologies in Windows Server 2012 and Windows Server 2012 R2 in this 5-day Microsoft Official Course. You

More information

Number: Passing Score: 800 Time Limit: 120 min File Version:

Number: Passing Score: 800 Time Limit: 120 min File Version: 70-410 Number: 000-000 Passing Score: 800 Time Limit: 120 min File Version: 1.0 Экзамен A QUESTION 1 You work as an administrator at ABC.com. The ABC.com network consists of a single domain named ABC.com.

More information

MOC 20410C: Installing and Configuring Windows Server 2012

MOC 20410C: Installing and Configuring Windows Server 2012 MOC 20410C: Installing and Configuring Windows Server 2012 Course Overview This course provides students with the knowledge and skills to implement a core Windows Server 2012 infrastructure in an existing

More information

5.1. Functional Level

5.1. Functional Level 5.1. Functional Level A functional level is a set of operation constraints that determine the functions that can be performed by an Active Directory domain or forest. A functional level defines: Which

More information

IN YOUR LIFE GO STRAIGHT AND TURN RIGHT

IN YOUR LIFE GO STRAIGHT AND TURN RIGHT 70-412 Number: 000-000 Passing Score: 810 Time Limit: 143 min File Version: 1.0 http://www.gratisexam.com/ Microsoft 70-412 Configuring Advanced Windows Server 2012 Services Version: 15.0 S. F. Albalooshi

More information

70-414: Implementing an Advanced Server Infrastructure - Microsoft

70-414: Implementing an Advanced Server Infrastructure - Microsoft 70-414: Implementing an Advanced Server Infrastructure - Microsoft Number: 000-001 Passing Score: 800 Time Limit: 120 min File Version: 1.0 http://www.gratisexam.com/ 70-414: Implementing an Advanced Server

More information

MICROSOFT EXAM QUESTIONS & ANSWERS

MICROSOFT EXAM QUESTIONS & ANSWERS MICROSOFT 70-410 EXAM QUESTIONS & ANSWERS Number: 70-410 Passing Score: 800 Time Limit: 120 min File Version: 38.5 http://www.gratisexam.com/ MICROSOFT 70-410 EXAM QUESTIONS & ANSWERS Exam Name: Installing

More information

10969B: Active Directory Services with Windows Server

10969B: Active Directory Services with Windows Server 10969B: Active Directory Services with Windows Server Course Details Course Code: Duration: Notes: 10969B 5 days This course syllabus should be used to determine whether the course is appropriate for the

More information

Updating Your Windows Server 2003 Technology Skills to Windows Server 2008

Updating Your Windows Server 2003 Technology Skills to Windows Server 2008 6416D: Updating Your Windows Server 2003 Technology Skills to Windows Server 2008 Page 1 of 10 Updating Your Windows Server 2003 Technology Skills to Windows Server 2008 Course 6416D: 4 days; Instructor-Led

More information

Course No. MCSA Days Instructor-led, Hands-on

Course No. MCSA Days Instructor-led, Hands-on MCSA: Windows Server 2012 Course No. MCSA2012 9 Days Instructor-led, Hands-on Introduction In this accelerated course nine day course, students will gain the skills and knowledge necessary to administer

More information

Active Directory Services with Windows Server

Active Directory Services with Windows Server Active Directory Services with Windows Server Duration: 5 Days Course Code: 10969B About this course Get Hands on instruction and practice administering Active Directory technologies in Windows Server

More information

10969: Active Directory Services with Windows Server

10969: Active Directory Services with Windows Server Let s Reach For Excellence! TAN DUC INFORMATION TECHNOLOGY SCHOOL JSC Address: 103 Pasteur, Dist.1, HCMC Tel: 08 38245819; 38239761 Email: traincert@tdt-tanduc.com Website: www.tdt-tanduc.com; www.tanducits.com

More information

(Installation, Storage, and Compute with Windows Server 2016)

(Installation, Storage, and Compute with Windows Server 2016) MCSA 2016 SERVER CURRICULUM 70-740 (Installation, Storage, and Compute with Windows Server 2016) EXAM CODE 740 Module 1: Installing, upgrading, and migrating servers and workloads This module describes

More information

70-647: Windows Server Enterprise Administration Course 01 Planning for Active Directory

70-647: Windows Server Enterprise Administration Course 01 Planning for Active Directory 70-647: Windows Server Enterprise Administration Course 01 Planning for Active Directory Slide 1 Course 1 Planning for Active Directory Planning the Domains and Forest Structure Planning for Sites and

More information