70-647 Pro Windows Server 2008 Enterprise Administrator Exam Set 2

You work as an enterprise administrator at YYY.com. The company has offices in multiple cities throughout North America. Each office is represented by an Active Directory site in a single Active Directory Domain Services (AD DS) domain named YYY.com. All servers run Windows Server 2008 R2 and all client computers run Windows 7 Enterprise. Several group policy objects (GPOs) are applied at the domain level. The domain GPOs apply settings to all client computers in the domain. You need to install various software packages to the client computers based on their location. You plan to use GPOs to assign the software to the client computers. The GPOs must not modify settings applied by the existing GPOs. How should you configure the GPOs? A. Create a single GPO linked to the domain with a lower priority than the existing GPOs. B. Create a single GPO linked to the domain with a higher priority than the existing GPOs. C. Create a single GPO linked to the domain with the No Override option selected. D. Create a single GPO linked to the domain and configure the existing GPOs with the No Override option. E. Create a separate GPO linked to the site for each office.


Options are :

  • A
  • B
  • D
  • C
  • E

Answer : E

You work as a Network Administrator at YYY.com. The network consists of a single Active Directory Domain Services (AD DS) domain named YYY.com. The company has a main office and a branch office. The two offices are connected by a slow WAN link. All servers run Windows Server 2008 R2 and all client computers run Windows 7 Professional. A file server named ABC-File1 hosts shared folders that contain large amounts of data. The number of users in the branch office has increased over the last year. Due to the large number of branch office users accessing files on ABC-File1, you have decided to install a file server in the branch office to host a local copy of the shared folders from ABC-File1. You install a Windows Server 2008 R2 named ABC-File2 in the branch office. You want to configure ABC-File1 to replicate the shared folders to ABC-File2. Due to the limited bandwidth of the WAN connection, the files must not be replicated during office hours. How should you configure the file servers?


Options are :

  • You should configure the File Transfer Protocol (FTP) on ABC-File1.
  • . You should install the File Server Resource Manager (FSRM) feature on both file servers. .
  • You should enable scheduled replication using DFS-R (Distributed File System Replication).
  • You should configure BranchCache on ABC-File2

Answer : You should enable scheduled replication using DFS-R (Distributed File System Replication).

70-513 WCF Development with Microsoft .NET Framework 4 Exam Set 1

You work as an enterprise administrator at YYY.com. The corporate network of the company consists of a single Active Directory forest containing a single Active Directory Domain. The company has a main office and two branch offices named Branch1 and Branch2. Each office is configured as an Active Directory site. The main office has a site link to Branch1. Branch1 has a site link to Branch2. The Bridge all site links option is disabled. The main office has two domain controllers that run Windows Server 2008 R2 and four domain controllers that run Windows Server 2003. The branch offices each have two domain controllers that run Windows Server 2003. You want to install a Windows Server 2008 read-only domain controller (RODC) in Branch2. You want to ensure that the minimum number of domain controllers are upgraded to Windows Server 2008 R2. How should you prepare the environment for the installation of and RODC in Branch2.


Options are :

  • You should upgrade both domain controllers in Branch2 to Windows Server 2008 R2.
  • You should upgrade a single domain controller in Branch1 to Windows Server 2008 R2. .
  • You should upgrade a single domain controller in Branch2 to Windows Server 2008 R2. .
  • You should create a site link between Branch2 and the main office

Answer : You should create a site link between Branch2 and the main office

You work as a Network Administrator at YYY.com. The network consists of a single Active Directory Domain Services (AD DS) domain named YYY.com. All servers run Windows Server 2008 R2. The functional level of the YYY.com domain is Windows Server 2008. A top level organizational unit (OU) is named Departments. The Departments OU contains three OUs named Managers, Production and Development. The Managers OU contains the user accounts for the company managers. The Production OU contains the user accounts for the Production users. The Development OU contains the user accounts for the Development team. A global security group named Helpdesk contains the user accounts of the Helpdesk team. You need to provide the Helpdesk team the ability to change passwords for all company users except for company managers using the minimum amount of administrative effort. How can you accomplish this task?


Options are :

  • . By delegating the required permissions to the Helpdesk group on the Production OU and the Development OU
  • . By delegating the required permissions to the Helpdesk group on the domain and blocking Group Policy Object (GPO) inheritance on the Managers OU.
  • By delegating the required permissions to the Helpdesk group on the Departments OU.
  • . By delegating the required permissions to the Helpdesk group on the Departments OU and blocking Group Policy Object (GPO) inheritance on the Managers OU.

Answer : . By delegating the required permissions to the Helpdesk group on the Production OU and the Development OU

You work as an enterprise administrator at YYY.com. The YYY.com network has a domain named YYY.com. All servers in the YYY.com network run Windows Server 2008 R2 and all client computers run Windows 7 Enterprise. Your environment includes servers running Remote Desktop Session Host (RDSH). The Accounts department at TesKing.com needs to run two versions of the same Accounting application on the client computers in the department. One is the current version of the Accounting application and one is an older version. However, the two versions of the Accounting applications cannot be used simultaneously on the same client computer. Which two of the following options could you choose to allow the Accounts department users to use both versions of the Accounting application simultaneously? (Choose two. Each answer represents a complete solution). A. Install both versions of the Accounting application on an RDSH server and publish both versions as RemoteApps. B. Install one version of the Accounting application on the Accounting client computers. Install the other version on an RDSH server and publish it as a RemoteApp. C. Install one version of the Accounting application on one RDSH server and publish it as a RemoteApp. Install the other version of the Accounting application on another RDSH server and publish it as a RemoteApp. D. Use a Group Policy Object (GPO) to assign one version of the Accounting application to the client computers. Use another Group Policy Object (GPO) to assign the other version of the Accounting application to the Accounting department users. E. Use a Group Policy Object (GPO) to assign one version of the Accounting application to the client computers. Use another Group Policy Object (GPO) to publish the other version of the Accounting application to the Accounting department users.


Options are :

  • C,D
  • B,C
  • A,B
  • A,E

Answer : B,C

70-642 Windows Server 2008 Network Infrastructure Exam Set 1

You work as a Network Administrator at YYY.com. The network consists of a single Active Directory Domain Services (AD DS) domain named YYY.com. All servers in the domain run Windows Server 2008 R2. Two servers in the network run UNIX. The company includes a Development department. Users in the Development department use their computers to develop and test software applications for use by other company departments and customers. The Development department users each have a client computer running Windows 7 Professional and another client computer running UNIX. The Windows 7 Professional client computers are members of the YYY.com domain. The UNIX client computers and UNIX servers are configured as a UNIX realm. The UNIX realm contains user accounts that use the same naming convention as the YYY.com domain user accounts. You have been asked by the manager of the Development department to enable the development department users to access the Windows file servers in the domain from their UNIX client computers. Which two of the following steps should you perform to configure the required access from a single logon to the UNIX client computers? (Choose two) A. You should install the “Subsystem for UNIX-based applications” feature on the Windows file servers. B. You should enable IPv6 on the UNIX computers and the Windows file servers. C. You should install Services for Network File System (NFS) on the Windows file servers. D. You should configure a realm trust between the UNIX realm and the YYY.com domain. E. You should configure simple User Name Mapping between the Active Directory domain and the UNIX realm.


Options are :

  • A,D
  • B,D
  • C,E
  • A,C

Answer : C,E

70-513 WCF Development with Microsoft .NET Framework 4 Exam Set 2

You work as an enterprise administrator at YYY.com. The YYY.com network has a domain named YYY.com. All servers in the YYY.com network run Windows Server 2008. The YYY.com network has two domain controllers named ABC-DC01 and ABC-DC02. ABC-DC01 hosts the relative identifier (RID) operations master role. ABC-SR01 suffers a catastrophic failure. How would you restore the RID master role?


Options are :

  • . By installing a new domain controller named ABC-DC03 and running the dcpromo /adv command. .
  • By installing a new domain controller named ABC-DC03 and forcing replication from ABCDC02.
  • . By using ntdsutil to seize the RID operations master role to ABC-DC02.
  • By using Active Directory Sites and Services to assign the RID operations master role to ABCDC02. x

Answer : . By using ntdsutil to seize the RID operations master role to ABC-DC02.

You work as a Network Administrator at YYY.com. The network consists of a two Active Directory domains named YYY.com and Corp.YYY.com. All servers in the YYY.com domain run Windows Server 2008 R2. All servers in the Corp.YYY.com domain run Windows Server 2003. The functional level of both domains is Windows 2000 Native. The functional level of the forest is Windows 2000. The YYY.com domain contains a research department. You have been asked to implement a stricter password policy for the research department users than for the rest of the company users. Your solution should use the minimum administrative effort. Which of the following actions should you perform to support multiple password policies in the YYY.com domain?


Options are :

  • Raise the domain functional level of the Tesking.com domain to Windows Server 2008.
  • . Upgrade the domain controllers in the Corp.YYY.com domain to Windows Server 2008 R2. Raise domain functional level of both domains to Windows Server 2008.
  • Raise the domain functional level of both domains to Windows Server 2003. .
  • . Upgrade the domain controllers in the Corp.YYY.com domain to Windows Server 2008 R2. Raise the forest functional level to Windows Server 2008

Answer : Raise the domain functional level of the Tesking.com domain to Windows Server 2008.

You work as a Network Administrator at YYY.com. The network consists of a single Active Directory Domain Services (AD DS) domain named YYY.com. The internal network is separated from the internet by a corporate firewall. The network includes virtual machines (VMs) running on Windows Server 2008 R2 Hyper-V host servers. Four virtual machines (VMs) named ABC-RDS1, ABC-RDS2, ABC-RDS3 and ABC-RDS4 all run Windows Server 2008 R2 with the Remote Desktop Session Host (RDSH) role. You have been asked to enable remote users to connect to the four RDSH servers. From the RDSH servers, users must be able to access internal network resources. You install a new Windows Server 2008 R2 server named ABC-RDGW1. You install the Remote Desktop Gateway role on ABC-RDGW1 and configure a TS CAP (Terminal Services connection authorization policy) and a TS RAP (Terminal Services resource authorization policy) You now need to configure the corporate firewall to allow external connections to ABC-RDGW1. You must open the minimum number of required ports. Which port or ports should you open on the firewall?


Options are :

  • TCP port 80
  • . TCP port 3389
  • TCP ports 80 and 443 . X
  • TCP port 443 .

Answer : TCP port 443 .

Microsoft 70-647 Windows Enterprise Administrator Exam Set 11

You work as an enterprise administrator at YYY.com. The YYY.com network has a domain named and YYY.com. All servers in the YYY.com network run Windows Server 2008. The YYY.com network has two file servers named ABC-SR07 and ABC-SR08. YYY.com has a subsidiary company named TestLabs, Inc. The TestLabs, Inc. network has a forest named and testlabs.com. TestLabs, Inc. users must be able to access shared folders on ABC-SR07 and ABC-SR08 while YYY.com users do not need access to any network resources at testlabs.com. How would you accomplish this task? (Each correct option will form a part of the answer. Select TWO.) A. By establishing a two-way forest trust between YYY.com and testlabs.com. B. By establishing a one-way forest trust from testlabs.com to YYY.com C. By establishing a one-way forest trust from YYY.com to testlabs.com. D. By configuring domain-wide authentication on the trust. E. By configuring a fine-grained password policy. F. By configuring selective authentication on the trust


Options are :

  • A,B
  • B,F
  • C,D
  • B,E

Answer : B,F

You work as a Network Administrator at YYY.com. The network consists of a single Active Directory Domain Services (AD DS) domain named YYY.com. The company has a main office and a branch office. The two offices are connected by a slow WAN link. All servers run Windows Server 2008 R2 and all client computers run Windows 7 Professional. All domain controllers are located in the main office. The number of users in the branch office has increased over the last year. The company has recently employed an IT Technician named Mia Hamm in the branch office to maintain the branch office computers. Users in the branch office complain that it takes a long time to log on to their computers. You decide to install a Windows Server 2008 R2 Read-Only Domain Controller in the branch office to improve log on times. You need to provide Mia the ability to manage the RODC. Mia needs to be able to install Windows Updates and update device drivers on the RODC. How can you assign Mia the necessary permissions to manage the RODC


Options are :

  • . By granting Mia’s domain user account Full Control permission on an Organizational Unit (OU) containing the computer account for the RODC.
  • By adding Mia’s domain user account to the local administrators group on the RODC.
  • By adding Mia’s domain user account to the Domain Admins group.
  • . By adding Mia’s domain user account to the Power Users group on the RODC

Answer : By adding Mia’s domain user account to the local administrators group on the RODC.

You work as a Network Administrator at YYY.com. The network consists of a single Active Directory domain named YYY.com. All servers on the network run Windows Server 2003 R2. The functional level of the domain is Windows 2000 Native. The company contains a research department. You have been asked to implement a stricter password policy for the research department users than for the rest of the company users. Which two of the following actions should you perform to support multiple password policies in the YYY.com domain? (Choose two). A. Raise the domain functional level to Windows Server 2003. B. Upgrade the domain controllers to Windows Server 2008 R2. C. Raise the domain functional level to Windows Server 2008 R2. D. Deploy a Windows Server 2008 R2 read-only domain controller (RODC) in the domain. E. Install Active Directory Rights Management Services (AD RMS) on a domain controller


Options are :

  • D,E
  • B,C
  • A,B
  • C,D

Answer : B,C

70-646 Pro Windows Server 2008,Server Administrator Test Set 1

You work as an enterprise administrator at YYY.com. The company network consists of a single Active Directory Domain Services (AD DS) domain named YYY.com. The company is in the process of implementing a PKI (Public Key Infrastructure). You have installed a Windows Server 2008 R2 server named ABC-RootCA which runs the Active Directory Certificate Services (AD CS) role and is configured as a root certification authority for the domain. You install a second Windows Server 2008 R2 server named ABC-CA1. ABC-CA1 runs the Active Directory Certificate Services (AD CS) role and is configured as a subordinate CA to ABCRootCA. A Windows Server 2008 R2 server named ABC-Web1 runs the Web Server role and is used to provide an interface to the certification authority. A company security policy states that all network devices should receive certificates from the certification authority. You configure the certification authority to assign certificates to all domain servers and client computers through Active Directory. You now need to configure the network routers to automatically request certificates using Simple Certificate Enrollment Protocol (SCEP). How would you accomplish this task?


Options are :

  • You should install and configure the AD CS Online Responder service on ABC-CA1.
  • You should install Active Directory Domain Services (AD DS) on ABC-RootCA. .
  • You should create computer objects in Active Directory for the network routers.
  • . You should install and configure the Network Device Enrollment Service on ABC-Web1

Answer : . You should install and configure the Network Device Enrollment Service on ABC-Web1

You work as an enterprise administrator at YYY.com. The YYY.com network has a forest with two domains named YYY.com and intl.YYY.com. All servers in the YYY.com network run Windows Server 2008. The YYY.com domain has two has domain controllers named ABC-SR05 and ABCSR06 and the intl.YYY.com domain has two domain controllers named ABC-SR07 and ABCSR08. Active Directory-integrated DNS zones are hosted on the domain controllers for their respective domains. You need to develop a name resolution strategy that allows clients to use the DNS server in their domain to resolve names in either domain. Which of the following options would you choose to accomplish this task? (Each correct option will form a part of the answer. Select TWO.) A. By configuring conditional forwarders on ABC-SR05 to point to ABC-SR07. B. By installing a DHCP Relay Agent in the intl.YYY.com domain. C. By adding the YYY.com DNS zone to the ForestDNSZones partition. D. By creating a stub DNS zone for YYY.com on ABC-SR07. E. By adding the intl.YYY.com DNS zone to the ForestDNSZones partition. F. By installing a DHCP server in the YYY.com domain. G. By configuring conditional forwarders on ABC-SR07 to point to ABC-SR05


Options are :

  • C,E
  • A,D
  • A,B
  • F,G

Answer : C,E

You work as an enterprise administrator at YYY.com. The YYY.com network has a domain that runs at the domain functional level of Windows Server 2008. All servers in the YYY.com network run Windows Server 2008. The YYY.com network has Research, Development and Marketing divisions that are organized into separate organizational units (OUs). You need to enable the use of removable storage devices on all computers. You also need to allow users in the Marketing division to copy files to any removable storage device. However, users in the Development division should only copy files to company issued devices. Which of the following options would you choose to accomplish the desired goal? (Each correct option will form a part of the answer. Select TWO.) A. Create a single GPO and link it to the Marketing OU and the Development OU. B. Alter the Default Domain Policy. C. Alter the Default Domain Controllers Policy. D. Create a new OU for all client computers. E. Create two new GPOs with one linked to the Marketing OU and the other linked to the Development OU. F. Create a GPO and link it to the new OU


Options are :

  • C,D
  • A,D
  • A,C
  • B,E

Answer : B,E

Microsoft 70-243 Administering Deploying System Manager Exam Set 1

You work as an enterprise administrator at YYY.com. The company network consists of a single Active Directory Domain Services (AD DS) domain named YYY.com. The company has a main office and two branch offices. The three offices are connected by fast WAN links. The main office has four domain controllers running Windows Server 2008 R2. The branch offices each have two domain controllers running Windows Server 2008 R2. An Active Directory site exists for each office. Each office has a site link to the other two offices. The site links are configured with the default cost. Site link bridging is disabled. You want to ensure that the branch office domain controllers replicate with domain controllers in the main office only. The branch office domain controllers should only replicate with the other branch office domain controllers if a WAN link fails. What should you do?


Options are :

  • You should increase the cost of the site link between the branch offices. .
  • You should lower the cost of the site link between the branch offices.
  • . You should delete the site link between the branch offices
  • You should increase the cost of the site links between the branch offices and the main office.

Answer : You should increase the cost of the site link between the branch offices. .

You work as an enterprise administrator at YYY.com. The YYY.com network has a domain named YYY.com and a workgroup named ABCGROUP. All servers in the YYY.com network run Windows Server 2008 and all the client computers run Windows Vista. The YYY.com network has five servers named ABC-SR04, ABC-SR05, ABC-SR06, ABC-SR07 and ABC-SR08. ABC-SR04 and ABC-SR05 are configured as domain controllers with ABC-SR04 having the Active Directory Domain Services (AD DS) installed and ABC-SR05 having the Dynamic Host Configuration Protocol (DHCP) service installed. ABC-SR06 and ABC-SR07 are configured as VPN servers with the Routing and Remote Access Services (RRAS) installed and ABC-SR08 is configured as a RADIUS server with the Network Policy Service (NPS) installed. You configure ABC-SR06 and ABC-SR07 as RADIUS clients. You now need to configure the protocols and authentication methods for the VPN connections. You also want to configure access permissions for specific user groups. Which of the following options would you choose to accomplish this task with minimal administrative effort? Select all that apply. Each selected option will form a part of the answer


Options are :

  • . Create a local computer policy on ABC-SR06
  • Create a network policy on ABC-SR07. .
  • Create a network policy on ABC-SR08.
  • Create a network policy on ABC-SR06. .

Answer : Create a network policy on ABC-SR08.

You work as an enterprise administrator at YYY.com. The YYY.com network has a domain named YYY.com. All servers in the YYY.com network run Windows Server 2008. YYY.com has its headquarters in Chicago and and sub-divisions in Boston, Atlanta, Miami and Dallas. Each subdivision is organized into a separate site. The YYY.com network has four domain controllers named ABC-DC01, ABC-DC02, ABC-DC03 and ABC-DC04 that are installed in the Chicago office. You have to install a domain controller in the each of the locations at Boston, Atlanta, Miami and Dallas divisions that will be used to authenticate users in the respective division and will allow for the application of Group Policy objects (GPOs) linked to the domain. However, the domain controllers must not store the log on credentials of all YYY.com users. Which of the following solutions would apply?


Options are :

  • . Install a server core installation of Windows Server 2008 in the Boston, Atlanta, Miami and Dallas divisions. ]
  • Install a writeable domain controller in the Boston, Atlanta, Miami and Dallas divisions..
  • . Create organizational units for each of the Boston, Atlanta, Miami and Dallas divisions and add the domain controller computer account to that OU. .
  • Install a read-only domain controller (RODC) in the Boston, Atlanta, Miami and Dallas divisions

Answer : Install a read-only domain controller (RODC) in the Boston, Atlanta, Miami and Dallas divisions

70-642 Windows Server 2008 Network Infrastructure Exam Set 6

You work as an enterprise administrator at YYY.com. The YYY.com network has a domain named YYY.com. All servers in the YYY.com network run Windows Server 2008 and all client computers run Windows XP. YYY.com wants to migrate to Windows Vista by decommissioning all Windows XP client computers. However, users in the Marketing division use a custom application named ABCApp1.exe that is not compatible with Windows Vista. How can you ensure that users in the Marketing department can still use ABCApp1.exe when the network is migrated to Windows Vista?


Options are :

  • By configuring a new partition on the client computers using the FAT file system and installing ABCApp1.exe on the new partition
  • By installing the application on the client computers. Instruct the users to run ABCApp1.exe in Windows XP compatibility mode. .
  • By using Hyper-V to configure a virtual machine running Windows 95 and ABCApp1.exe. Tell the marketing users to connect to the virtual machine.
  • . By configuring Windows Vista computers to have a virtual machine running Windows XP and ABCApp1.exe. .

Answer : . By configuring Windows Vista computers to have a virtual machine running Windows XP and ABCApp1.exe. .

You work as an enterprise administrator at YYY.com. The YYY.com network has a domain named YYY.com. All servers in the YYY.com network run Windows Server 2008. YYY.com has its headquarters in Chicago and branch offices in Boston, Atlanta, Miami and Dallas. The YYY.com network has four domain controllers named ABC-DC01, ABC-DC02, ABC-DC03 and ABC-DC04 that are installed in the Chicago office. You have been instructed to plan the installation of a domain controller in each of the Boston, Atlanta, Miami and Dallas offices. Your solution must ensure that the least amount of network bandwidth is used when Active Directory Domain Services (AD DS) is installed on the new domain controllers. How would you accomplish this task


Options are :

  • . By using the Media feature Install option to install AD DS on the new domain cont
  • By blocking GPO processing on the new domain controllers. .
  • By installing a Server Core installation of Windows Server 2008 on the new domain controllers.
  • By installing the new domain controllers as read-only domain controllers (RODCs). rollers
  • . By running the dcpromo /adv command on the new domain controllers. .

Answer : . By using the Media feature Install option to install AD DS on the new domain cont

You work as an enterprise administrator at YYY.com. The YYY.com network has a domain named YYY.com. All servers in the YYY.com network run Windows Server 2008 and all client computers run Windows Vista. The YYY.com network has a server named ABC-SR07 that runs Microsoft Visual Studio 2008 and Microsoft SQL Server 2008. You need to achieve the following goals. All the seccurity updates must be installed on ABC-SR07 Updates for Microsoft Visual Studio 2008 and Microsoft SQL Server 2008 must be installed on ABC-SR07 All device driver updates must be installed on ABC-SR07 What is the best option to achieve the goal


Options are :

  • . By using Microsoft Update on ABC-SR07.
  • By using MSCONFIG on ABC-SR07.
  • . By using System Information on ABC-SR07.
  • By using System File Checker (SFC) on ABC-SR07.

Answer : . By using Microsoft Update on ABC-SR07.

Microsoft 70-647 Windows Enterprise Administrator Exam Set 4

You work as a Network Administrator at YYY.com. The network consists of a single Active Directory Domain Services (AD DS) domain named YYY.com. The internal network is separated from the internet by a corporate firewall. The network includes virtual machines (VMs) running on Windows Server 2008 R2 Hyper-V host servers. Four virtual machines (VMs) named ABC-RDS1, ABC-RDS2, ABC-RDS3 and ABC-RDS4 all run Windows Server 2008 R2 with the Remote Desktop Session Host (RDSH) role. You have been asked to enable remote users to connect to the four RDSH servers. From the RDSH servers, users must be able to access internal network resources. You install a new Windows Server 2008 R2 server named ABC-RDGW1. You install the Remote Desktop Gateway role on ABC-RDGW1 and configure a TS CAP (Terminal Services connection authorization policy) to specify which users are allowed to connect. Which two of the following steps should you perform to give remote users the required access using ABC-RDGW1? A. Install and configure the Remote Desktop Web Access role on ABC-RDGW1. B. Configure a TS RAP (Terminal Services resource authorization policy). C. Install and configure the Remote Desktop Virtualization Host role on ABC-RDGW1. D. Configure the corporate firewall to allow inbound TCP port 443. E. Configure the corporate firewall to allow inbound TCP port 3389.


Options are :

  • D,E
  • A,C
  • B,D
  • E,A

Answer : B,D

You work as an enterprise administrator at YYY.com. The company network consists of a single Active Directory Domain Services (AD DS) domain named YYY.com. All domain controllers in the domain run Windows Server 2008 R2. The client computers run a mix of Windows XP Professional and Windows 7 Professional. All client computer accounts are located in an organizational unit (OU) named Client_Computers. All user accounts are located in an organizational unit (OU) named AllUsers. A group policy object (GPO) named Software is linked to the AllUsers OU. The Software GPO assigns standard company software to all company users. ABC has a graphics department. 50 users work in the graphics department. The company has purchased a new graphics application. The graphics application must be used by only members of the graphics department. You need to design a software deployment solution to simplify software deployment and ensure that future users receive the correct software. You create a global security group named Graphics_Users and add the members of the graphics department to the group. How should you configure the software distribution?


Options are :

  • Link the Software GPO to the domain. Create a new GPO linked to the AllUsers OU to assign the graphics application. Block GPO inheritance on the AllUsers OU.
  • Create a new GPO linked to the AllUsers OU to assign the graphics application. Use security permissions to filter the new GPO to the Graphics_Users group.
  • Add the Graphics application to the Software GPO. Use security permissions to filter the Software GPO to the Graphics_Users group.
  • . Create a new OU named GraphicsOU in the Users OU. Move the Graphics_Users group object to GraphicsOU. Create a new GPO linked to the Graphics OU to assign the graphics application. .

Answer : Create a new GPO linked to the AllUsers OU to assign the graphics application. Use security permissions to filter the new GPO to the Graphics_Users group.

You work as an enterprise administrator at YYY.com. The network consists of a large single Active Directory forest that contains many domains spanning multiple countries. The root domain in the forest is named YYY.com. Every domain in the forest is a child of the YYY.com root domain. All servers in the forest run Windows Server 2003 R2. The functional level of every domain is Windows Server 2003. The functional level of the forest is Windows Server 2003. Every domain controller in the forest runs Windows Server 2003 and hosts Active Directoryintegrated DNS zones. You are in the process of installing an additional Windows Server 2003 domain controller in a child domain. During the domain controller installation process, you select the option to automatically install and configure DNS. You discover that the DNS installation process takes more than an hour to complete. You restart another domain controller in the same child domain and discover that it takes over an hour to restart. You restart a domain controller in a different child domain and see that it also takes over an hour to restart. How can you reduce the startup time for the domain controllers?


Options are :

  • By upgrading the domain controllers to Windows Server 2008 R2
  • . By enabling incremental DNS zone transfers (IXFR) on the domain controllers.
  • By configuring new DNS servers hosting DNS stub zones in each domain.
  • By installing Windows Server 2008 R2 Read Only Domain Controllers running the DNS service in each domain.

Answer : By upgrading the domain controllers to Windows Server 2008 R2

Microsoft Dynamics Expand and Test Your Skills Practice Test Set 1

You work as a Network Administrator at YYY.com. The network consists of a single Active Directory Domain Services (AD DS) domain named YYY.com. The internal network is separated from the internet by a corporate firewall. The network includes virtual machines (VMs) running on Windows Server 2008 R2 Hyper-V host servers. Four virtual machines (VMs) named ABC-RDS1, ABC-RDS2, ABC-RDS3 and ABC-RDS4 all run Windows Server 2008 R2 with the Remote Desktop Session Host (RDSH) role. You have been asked to enable sales users to connect to the four RDSH servers when they are working away from the office. The sales users are members of a global security group named ABC-SalesUsers. You install a new Windows Server 2008 R2 server named ABC-RDGW1. You enable the corporate firewall to allow inbound connections on TCP port 443. You now need to assign the sales users permission to connect to the network using Remote Desktop Connections. How can you enable only the ABC-SalesUsers group to connect to the network using Remote Desktop Connections


Options are :

  • By configuring a TS CAP (Terminal Services connection authorization policy).
  • By installing the Remote Desktop Web Access role on ABC-RDGW1.
  • . By adding the ABC-SalesUsers group to the Remote Desktop Users group on ABC-RDGW1. .
  • By installing and configuring the Remote Desktop Virtualization Host role on ABC-RDGW1.

Answer : By configuring a TS CAP (Terminal Services connection authorization policy).

You work as an enterprise administrator at YYY.com. The YYY.com network has a domain named YYY.com. All servers in the YYY.com network run Windows Server 2008. YYY.com has its headquarters in Chicago and branch offices in Boston, Atlanta, Miami and Dallas. The Boston, Atlanta, Miami and Dallas offices are connected to the Chicago by WAN links. All domain controllers are installed in the Chicago office. You have been instructed to plan the installation of domain controllers in the Boston, Atlanta, Miami and Dallas offices. How can you ensure that the least amount of network bandwidth is used when Active Directory replication occurs for the first time?


Options are :

  • By installing Active Directory Domain Services (AD DS) on the new domain controllers.
  • By using ntdsutil to create an installation media for the new domain controller. .
  • By running adprep /domainprep on a domain controller in the Chicago office.
  • . By running adprep /forestprep on a domain controller in the Chicago office.

Answer : By using ntdsutil to create an installation media for the new domain controller. .

You work as a Network Administrator at YYY.com. The network consists of a single Active Directory Domain Services (AD DS) domain named YYY.com. All servers on the network run Windows Server 2008 R2. A Windows Server 2008 R2 server named ABC-FW1 runs Microsoft Internet Security and Acceleration (ISA) Server 2006. ABC-FW1 is configured as a firewall that separates the corporate LAN from the Internet. ABC-FW1 is configured to allow only HTTP and HTTPS inbound connections from the Internet. You install a server named ABC-WSS1. You install SharePoint Foundation on ABC-WSS1 and configure SharePoint sites for document collaboration. The SharePoint sites are accessible only from within the corporate LAN. Mobile Sales workers have been issued with PDAs running Windows Mobile 6.0. You have been asked to provide the Sales users with secure access to SharePoint sites from their PDAs. All external connections to the SharePoint sites must be encrypted. How can you provide access to the SharePoint sites from PDAs running Windows Mobile 6.0?


Options are :

  • . By publishing ABC-WSS1 with an SSTP server publishing rule on ABC-FW1
  • . By publishing the SharePoint site with an HTTPS web publishing rule on ABC-FW1.
  • By disabling port 80 access to the SharePoint sites. .
  • By configuring the IPSec Require Security policy on ABC-WSS1.

Answer : . By publishing the SharePoint site with an HTTPS web publishing rule on ABC-FW1.

70-515 Web Applications Development with Microsoft .NET Exam Set 1

You work as an enterprise administrator at YYY.com. The company has a main office in Chicago and branch offices in Boston, Atlanta, Miami and Dallas. Each office is configured as a separate Active Directory site in a single Active Directory Domain Services (AD DS) domain named YYY.com. All servers in each office run Windows Server 2008 R2. All client computers in each office run Windows 7 Enterprise. Each office has an IT department. The IT Managers in each office are members of the Domain Admins group. You download the Administrative Template (admx) files required to manage the Windows 7 client computers using Group Policy Objects (GPOs). You also create a custom admx file. You need to ensure that your admx files are available when IT Managers in any office create or edit GPOs. You also need to ensure that admx files created by any other IT Manager are available in any office. How should you distribute the admx files?


Options are :

  • You should import the admx files into the Default Domain Controllers Policy.
  • You should import the admx files into the Default Domain Policy.
  • . You should create a central store by creating a PolicyDefinitions folder in a network shared folder that is accessible to all offices.
  • . You should create a central store by creating a PolicyDefinitions folder in the SYSVOL\domain\Policies folder on a domain controller

Answer : . You should create a central store by creating a PolicyDefinitions folder in the SYSVOL\domain\Policies folder on a domain controller

You work as an enterprise administrator at YYY.com. The YYY.com network has a domain named YYY.com. All servers in the YYY.com network run Windows Server 2008 and all client computers run Windows Vista with Service Pack 1 (SP1) installed. The YYY.com network has two servers named ABC-SR05 and ABC-SR06. ABC-SR05 is configured with Network Policy and Access Services (NPAS) while ABC-SR06 is configured with Windows SharePoint services (WSS). The YYY.com network also has two file servers named ABC-SR07 and ABC-SR08. YYY.com supports several remote users that connect the network when they work from remote locations. These users complain that they can use their Web browsers to connect to sharepoint sites on ABC-SR06 that use the HTTPS protocol but the firewall at some of the customer locations prevents them from connecting to files on ABC-SR07 and ABC-SR08. You decide to implement a VPN access solution to overcome this problem. What actions should you take?


Options are :

  • . Configure a PPTP VPN connection on ABC-SR07 and ABC-SR08. .
  • . Configure Secure Socket Tunneling Protocol (SSTP) connection on ABC-SR05.
  • Configure a L2TP VPN connection on ABC-SR05.
  • Configure IPsec tunnel mode connection on ABC-SR07 and ABC-SR08.

Answer : . Configure Secure Socket Tunneling Protocol (SSTP) connection on ABC-SR05.

You work as an enterprise administrator at YYY.com. The network consists of a single Active Directory Domain Services (AD DS) domain named YYY.com. All servers on the network run Windows Server 2008 R2. YYY.com has its main office in Chicago and branch offices in Boston, Atlanta, Miami and Dallas. Each office is configured as a separate Active Directory site. All offices are connected to each other by slow WAN links. Four domain controllers named ABC-DC01, ABC-DC02, ABC-DC03 and ABC-DC04 are installed in the Chicago office. The Chicago office domain controllers are located in the default Domain Controllers container in Active Directory. To improve logon times for the branch offices, you been assigned the task of deploying domain controllers in the branch offices. The domain controllers in each office must authenticate users from the local office only. Branch office users should authenticate to the head office domain controllers only if the branch office domain controller fails. Which of the following options would you choose to accomplish this task?


Options are :

  • Increase the cost of the site links between the branch offices.
  • . Apply a Group Policy Object (GPO) to modify the default DNS SRV record registration for the branch office domain controllers.
  • . Configure the branch office domain controllers as Global Catalog servers.
  • Install Active Directory Federation Services (ADFS) on the domain controllers in the branch offices.

Answer : . Apply a Group Policy Object (GPO) to modify the default DNS SRV record registration for the branch office domain controllers.

Microsoft Windows Server 2016 Certification: Exam 70-741 Set 1

Comment / Suggestion Section
Point our Mistakes and Post Your Suggestions