70-647 Pro Windows Server 2008 Enterprise Administrator Exam Set 4

You work as an enterprise administrator at YYY.com. The company network consists of a single Active Directory Domain Services (AD DS) domain named YYY.com. All servers run Windows Server 2008 R2. The client computers run a mix of Windows 7 Professional, Windows XP Professional and Windows 2000 Professional. Two Windows Server 2008 R2 servers named ABC-DC1 and ABC-DC2 are configured as domain controllers and DHCP servers for the domain. A Windows Server 2008 R2 server named ABC-RootCA runs the Active Directory Certificate Services (AD CS) role and is configured as a root certification authority for the domain. Other network servers include six Windows Server 2008 R2 servers running the File Services role, two Windows Server 2008 R2 servers running the Web Server (IIS) role and a Windows Server 2008 R2 server named ABC-RRAS1 which runs the Routing and Remote Access role. You want to configure a Network Access Protection (NAP) environment to improve the security of the network. You install in the Network Policy Service (NPS) role with the Health Registration Authority feature on ABC-RRAS1. You configure the DHCP and IPSec enforcement methods on ABC-RRAS1. After testing your security configuration, you discover that non-domain member client computers are still able to access shared folders on the file servers. How can you prevent non-domain member computers accessing network resources in the domain?


Options are :

  • By configuring the secure server IPsec policy on all network servers
  • By configuring NAP Enforcement for VPN on ABC-RRAS1.
  • . By configuring NAP Enforcement for 802.1x on ABC-RRAS1 and configuring the Network Device Enrollment Service (NDES) on ABC-RootCA. .
  • By installing computer certificates from ABC-RootCA on all network servers.

Answer : By configuring the secure server IPsec policy on all network servers

You work as an enterprise administrator at YYY.com. The corporate network of ABC consists of a single Active Directory Domain Services (AD DS) domain. The company has a main office and 20 branch offices, which are connected through unreliable WAN links to the main office. All servers in the domain run Windows Server 2008 R2 and all client computers run Windows 7 Professional. The branch offices of the company are managed by the local administrator of the branch office. You need to design a Windows Update management strategy for the company. Only Windows Updates that have been approved by the main office are allowed to be installed in the branch offices. From the updates approved by the main office, the branch office administrators must be able to decide which updates are installed. You install a Windows Server 2008 R2 server running Windows Server Update Services (WSUS) 3.0 in each office. You need to configure the WSUS servers before configuring the client computers to download updates from the local WSUS servers. How should you configure the WSUS servers? (Choose three) A. Configure the main office WSUS server to download updates from Microsoft. B. Configure the main office WSUS server as a replica server. C. Configure the branch office WSUS servers as standalone servers. D. Configure the branch office WSUS servers as child servers. E. Configure the branch office WSUS servers as replica servers. F. Configure the branch office WSUS servers to download updates from Microsoft. G. Configure the branch office WSUS servers to download updates from the main office WSUS server.


Options are :

  • B,C,D
  • F,G,A
  • A,D,G
  • C,D,E

Answer : A,D,G

70-646 Pro Windows Server 2008,Server Administrator Test Set 3

You work as an enterprise administrator at YYY.com. The YYY.com network has a forest that runs at the forest functional level of Windows Server 2008. All servers in the YYY.com network run Windows Server 2008 R2. The domain runs at the Windows Server 2008 functional level. The computer accounts for all client computers in the domain are in an organizational unit (OU) named ABCClients. The user accounts for all users in the domain are in an organizational unit (OU) named ABCUsers. The company has two departments named Production and Sales. A global group named ProductionUsers contains all Production department user accounts. A global group named SalesUsers contains all Sales department user accounts. You need to provide the Production manager the ability to manage the user accounts for all users in the Production department. You also need to provide the Sales manager the ability to manage the user accounts for all users in the Sales department. You create an organizational unit (OU) named Production and delegate the required administrative permissions to the Production manager. You then create an organizational unit (OU) named Sales and delegate the required administrative permissions to the Sales manager. What should you do next?


Options are :

  • You should move the Production computer accounts to the Production OU and move the Sales computer accounts to the Sales OU.
  • You should move the Production OU and the Sales OU into the ABCUsers OU then run the Delegation of Control Wizard on the ABCUsers OU.
  • You should move the ProductionUsers group to the Production OU and move the SalesUsers group to the Sales OU. X
  • You should move the Production user accounts to the Production OU and move the Sales user accounts to the Sales OU. .

Answer : You should move the Production user accounts to the Production OU and move the Sales user accounts to the Sales OU. .

You work as an enterprise administrator at YYY.com. The corporate network of ABC consists of an Active Directory Domain Services (AD DS) domain. The company has a main office and 10 branch offices. Each branch office is connected to the main office by a WAN link. All servers in the main office run Windows Server 2008 R2. The branch offices do not currently contain any servers. You have been assigned the task of deploying domain controllers to the branch offices. To improve the security of the domain controllers, you want to ensure that the minimum number of services are running on the domain controllers. You need to ensure that any branch office user can be authenticated in their branch office in the event of a WAN link failure Which three of the following options should you perform to accomplish this task? (Choose three). A. Install Active Directory Domain Services (AD DS). B. Deploy a Server Core installation of Windows Server 2008 R2 in each branch office. C. Configure the server as a read-only domain controller (RODC). D. Deploy a full installation of Windows Server 2008 R2 in each branch office. E. Configure the server as a domain controller. F. Install Active Directory Federation Services (AD FS).


Options are :

  • D,E,F
  • C,D,A
  • B,C,D
  • A,B,C

Answer : A,B,C

You work as an enterprise administrator at YYY.com. The corporate network of ABC consists of a single Windows 2000 Native Mode Active Directory domain. All domain controllers run Windows Server 2003. The network contains four Windows Server 2003 servers named ABC-SR05, ABC-SR06, ABCSR07, and ABC-SR08. ABC-SR05 is configured as a Terminal Services licensing server. The other three servers are configured as Terminal Servers. You install a Windows Server 2008 R2 server named ABC-SR09. You install the Remote Desktop Session Host role on ABC-SR09. You have been asked to perform regular software audits. You want to implement a reporting solution to ease the task of tracking the issuance of Terminal Services client access licenses (TS CALs). Which of the following options would you choose to accomplish this task?


Options are :

  • aise the functional level of the domain to Windows Server 2003.
  • . Install the Remote DesABCop Web Access role on the servers that have the Terminal Services server role installed.
  • Upgrade ABC-SR06, ABC-SR07, and ABC-SR08 to Windows Server 2008 R2. R
  • Upgrade ABC-SR05 to Windows Server 2008 R2.
  • Upgrade all domain controllers to Windows Server 2008.

Answer : Upgrade ABC-SR05 to Windows Server 2008 R2.

Microsoft Windows Server 2016 Certification: Exam 70-741 Set 4

You work as an enterprise administrator at YYY.com. The corporate network of ABC consists of an Active Directory Domain Services (AD DS) domain. The company has a main office and 10 branch offices. Each branch office is connected to the main office by a WAN link. All servers in the main office run Windows Server 2008 R2. The branch offices do not currently contain any servers. YYY.com users frequently travel between offices. You have been assigned the task of deploying domain controllers to the branch offices. To improve the security of the domain controllers, you want to ensure that the minimum number of services are running on the domain controllers. You also need to ensure that any YYY.com user can be authenticated in a branch office in the event of a WAN link failure. Which three of the following options should you perform to accomplish this task? (Choose three). A. Install Active Directory Domain Services (AD DS). B. Deploy a Server Core installation of Windows Server 2008 R2 in each branch office. C. Configure the server as a read-only domain controller (RODC). D. Deploy a full installation of Windows Server 2008 R2 in each branch office. E. Configure the server as a domain controller. F. Install Active Directory Federation Services (AD FS). G. Install Active Directory Lightweight Directory Services (AD LDS).


Options are :

  • D,A,C
  • A,C,D
  • A,B,E
  • B,D,A

Answer : A,B,E

You work as an enterprise administrator at YYY.com. The corporate network of the company consists of an Active Directory forest that runs at the functional level of Windows Server 2003. The forest root domain is named YYY.com. All the domain controllers in the root domain run Windows Server 2003 and the functional level of the domain is Windows Server 2003. A child domain named Corp.YYY.com contains domain controllers running Windows Server 2008 R2. The functional level of the Corp.YYY.com domain is Windows Server 2003. You want to deploy a Windows Server 2008 R2 read-only domain controller (RODC) in the What do you need to do before installing the RODC?


Options are :

  • Raise the functional level of the Corp.YYY.com domain to Windows Server 2008
  • Run the adprep /rodc command from the Windows Server 2008 R2 installation DVD on any computer in the forest.
  • Run the adprep /domainprep command from the Windows Server 2008 R2 installation DVD on the infrastructure master in the Corp.YYY.com domain.
  • Install a Windows Server 2008 R2 domain controller in the YYY.com root domain.

Answer : Run the adprep /rodc command from the Windows Server 2008 R2 installation DVD on any computer in the forest.

You work as an enterprise administrator at YYY.com. The corporate network of ABC consists of a single Active Directory forest that contains a single root domain named YYY.com and 4 child domains named Research.YYY.com, Engineering.YYY.com, Development.YYY.com and Manufacturing.YYY.com. All servers in the YYY.com root domain run Windows Server 2008 R2. All servers in the child domains run Windows Server 2003. The functional level of the YYY.com root domain is Windows Server 2008. The functional level of each child domain is Windows Server 2003. You receive reports from users in the YYY.com root domain that they are no longer able to access resources in the Research.YYY.com child domain. While investigating the issue, you discover that the IP address of the authoritative DNS servers for the Research.YYY.com domain has changed. You update the name server (NS) records on the DNS servers in the YYY.com domain and the issue is resolved. You want to ensure that this problem does not happen again. How can you ensure that name resolution is not affected in the event of child domain administrators changing the IP addresses of their DNS servers?


Options are :

  • By upgrading the DNS servers in the child domains to Windows Server 2008 R2.
  • By configuring conditional forwarders on the DNS servers in the YYY.com root domain.
  • By upgrading the domain controllers in the child domains to Windows Server 2008 R2 and raising the functional level of the child domains to Windows Server 2008. .
  • By configuring Stub Zones on the DNS servers in the YYY.com root domain.

Answer : By configuring Stub Zones on the DNS servers in the YYY.com root domain.

70-646 Pro Windows Server 2008 - Server Administrator Exam Set 5

You work as a Network Administrator at YYY.com. The network consists of a single Active Directory Domain Services (AD DS) domain named YYY.com. All servers run Windows Server 2008 R2 and all client computers run Windows 7 Professional. The computer accounts for the client computers are located in an organizational unit (OU) named ABC-Clients. The computer accounts for the servers are located in an OU named ABC-Servers. The user accounts for all YYY.com managers are located in an OU named ABC-Managers. The user accounts for all other employees are located in an OU named ABC-Users. You need to design an application deployment strategy to deploy two new applications. The installation time for each application is more than one hour. Your application deployment strategy must meet the following goals: An application named ManagersApp must be deployed to YYY.com managers only. An application named AllUsersApp must be deployed to all company users including the managers. Both applications must be uninstalled every month and an updated version installed. All users must be able to access the applications using file invocation or using Start menu shortcuts. Disruption to the users must be minimized during the applications updating. How should you deploy the applications?


Options are :

  • In the Computer section of a GPO linked to the ABC-Users OU, assign AllUsersApp. In the Computer section of a GPO linked to the ABC-Managers OU, assign ManagersApp
  • In the Users section of a GPO linked to the ABC-Users OU, publish AllUsersApp. In the Users section of a GPO linked to the ABC-Managers OU, publish ManagersApp.
  • Install the Remote Desktop Session Host role on a Windows Server 2008 R2 server and publish both applications as RemoteApps.
  • . In the Users section of a GPO linked to the ABC-Users OU, assign AllUsersApp. In the Users section of a GPO linked to the ABC-Managers OU, assign ManagersApp.

Answer : Install the Remote Desktop Session Host role on a Windows Server 2008 R2 server and publish both applications as RemoteApps.

You work as an enterprise administrator at YYY.com. The corporate network of the company consists of an Active Directory forest that runs at the functional level of Windows Server 2003. The forest root domain is named YYY.com. All the domain controllers in the root domain run Windows Server 2003 and the functional level of the domain is Windows Server 2003. A child domain named Corp.YYY.com contains domain controllers running Windows Server 2008 R2. The functional level of the Corp.YYY.com domain is Windows Server 2003. You want to deploy a Windows Server 2008 R2 domain controller in the YYY.com root domain. What should you do first


Options are :

  • Run the adprep /forest command from the Windows Server 2008 R2 installation DVD on the schema master in the YYY.com domain
  • Run the adprep /domainprep command from the Windows Server 2008 R2 installation DVD on the infrastructure master in the YYY.com domain
  • Install a Windows Server 2008 domain controller in the YYY.com root domain
  • Raise the functional level of the forest to Windows Server 2008.

Answer : Run the adprep /domainprep command from the Windows Server 2008 R2 installation DVD on the infrastructure master in the YYY.com domain

You work as an enterprise administrator at YYY.com. The YYY.com network has a domain named YYY.com. All servers in the YYY.com network run Windows Server 2008 R2 and all client computers run Windows 7 Professional. A Windows Server 2008 R2 server named ABC-Web1 runs the Web Services (IIS) role. ABCWeb1 hosts a corporate Intranet Web site. The Intranet Web site is accessible by internal and external users using HTTPS connections only. Remote users sometime require access to file servers located on the internal network. You have been assigned the task of ensuring that the remote users can connect to the file servers securely without requiring the opening of any additional TCP ports on the firewall. Which of the following types of solutions would you choose to accomplish this task?


Options are :

  • Configure a PPTP VPN connection.
  • . Configure an L2TP/IPSec VPN connection.
  • . Configure an SSTP VPN connection.
  • . Configure a Remote Desktop connection.

Answer : . Configure an SSTP VPN connection.

70-646 Pro Windows Server 2008 - Server Administrator Exam Set 1

You work as a Network Administrator at YYY.com. The network consists of a single Active Directory Domain Services (AD DS) domain named YYY.com. You are in the process of upgrading the network servers to Windows Server 2008 R2. Four Windows Server 2003 servers named ABC-SQL1, ABC-SQL2, ABC-SQL3 and ABC-SQL4 are configured as a failover cluster. The four cluster nodes run the Microsoft Clustering Service (MSCS) with a shared quorum. You need to create a plan for upgrading the four cluster nodes to Windows Server 2008 R2. The cluster must remain online during the upgrade. What steps should you include in your plan?


Options are :

  • Evict one passive node at a time and rebuild the cluster by using Windows Server 2008 R2.
  • . Upgrade one node at a time while it is still part of the cluster.
  • . Evict all the nodes except one node from the cluster. Install Windows Server 2008 R2 on the node that was left and then install Windows Server 2008 R2 on the other three nodes and add them to the cluster again.
  • Evict the active node and rebuild the cluster by using Windows Server 2008 R2. .

Answer : Evict one passive node at a time and rebuild the cluster by using Windows Server 2008 R2.

You work as an enterprise administrator at YYY.com. The corporate network of ABC consists of a single Active Directory Domain Services (AD DS) forest. The ABC forest contains a root domain named YYY.com. All servers in the YYY.com domain run Windows Server 2008 R2. A Windows Server 2008 R2 server named ABC-DC1 is configured as a domain controller for the YYY.com domain and hosts all five FSMO roles. A partner company of ABC named Willow Bridge Ltd also consists of single Active Directory Domain Services (AD DS) forest. The Willow Bridge forest contains a root domain named WillowBridge.com. All servers in the WillowBridge.com domain run Windows Server 2008 R2. A Windows Server 2008 R2 server named WB-DC1 is configured as a domain controller for the WillowBridge.com domain and hosts all five FSMO roles. ABC and Willow Bridge have decided to merge companies. The WillowBridge.com domain resources will be migrated into the YYY.com domain. How can you migrate the WillowBridge.com domain resources into the YYY.com domain?


Options are :

  • By installing and running the Active Directory Migration Tool (ADMT) on ABC-DC1.
  • By installing and running the Microsoft Windows User State Migration Tool (USMT) on ABCDC1.
  • By installing and running the Microsoft Windows User State Migration Tool (USMT) on WBDC1.
  • . By installing and running the movetree.exe tool on ABC-DC1.

Answer : By installing and running the Active Directory Migration Tool (ADMT) on ABC-DC1.

You work as an enterprise administrator at YYY.com. The corporate network of ABC consists of a single Active Directory Domain Services (AD DS) forest. The ABC forest contains a root domain named YYY.com. All servers in the YYY.com domain run Windows Server 2008 R2. A Windows Server 2008 R2 server named ABC-DC1 is configured as a domain controller for the YYY.com domain and hosts all five FSMO roles. A partner company of ABC named Willow Bridge Ltd also consists of single Active Directory Domain Services (AD DS) forest. The Willow Bridge forest contains a root domain named WillowBridge.com. All servers in the WillowBridge.com domain run Windows Server 2008 R2. A Windows Server 2008 R2 server named WB-DC1 is configured as a domain controller for the WillowBridge.com domain and hosts all five FSMO roles. ABC and Willow Bridge have decided to merge companies. The WillowBridge.com domain resources will be migrated into the YYY.com domain. You plan to use Active Directory Migration Tool (ADMT) v3.2 to migrate the WillowBridge.com user and group accounts into the YYY.com domain. What should you do first?


Options are :

  • . You should create a one-way external domain trust where the YYY.com domain trusts the WillowBridge.com domain.
  • You should configure a Federation Trust between the two domains using Active Directory Federation Services.
  • You should create a child domain named WillowBridge.YYY.com in the YYY.com forest
  • You should create a one-way external domain trust where the WillowBridge.com domain trusts the YYY.com domain.

Answer : You should create a one-way external domain trust where the WillowBridge.com domain trusts the YYY.com domain.

Microsoft 70-243 Administering Deploying System Manager Exam Set 1

You work as an enterprise administrator at YYY.com. The corporate network of ABC consists of a single Active Directory Domain Services (AD DS) forest. The ABC forest contains a root domain is named YYY.com. All servers in the YYY.com domain run Windows Server 2008 R2. A partner company of ABC named Willow Bridge Ltd also consists of single Active Directory Domain Services (AD DS) forest. The Willow Bridge forest contains a root domain named WillowBridge.com. All servers in the WillowBridge.com domain run Windows Server 2008 R2. The YYY.com domain contains a Windows Server 2008 R2 server named ABC-App1. Members of a global security group named ABCAppUsers in the WillowBridge.com domain need to access ABC-App1. A forest trust exists between the two forests to cater for this need. You discover that all WillowBridge.com users can access all network resources in the YYY.com domain. You need to restrict members of the ABCAppUsers group so that they can access ABC-App1 only. All other WillowBridge.com should not be able to access network resources in the YYY.com domain. You need to configure the required access. You modify the forest trust to allow selective authentication only. What should you do next?


Options are :

  • You should add the ABCAppUsers group to the local Users group on ABC-App1. .
  • You should deny the Allowed to Authenticate permission to the YYY.com\Domain Users.
  • You should grant the Allowed to Authenticate permission to the ABCAppUsers group on the computer object for ABC-App1
  • You should grant the ABCAppUsers group the “Access this computer from the network” user right in the local security policy of ABC-App1. .

Answer : You should grant the Allowed to Authenticate permission to the ABCAppUsers group on the computer object for ABC-App1

You work as a Network Administrator at YYY.com. The network consists of a single Active Directory domain named YYY.com. The company has a main office and a branch office. The two offices are connected by a slow WAN link. All servers run Windows Server 2003. All domain controllers are located in the main office. The functional level of the domain is Windows 2000 Server Mixed mode. The number of users in the branch office has increased over the last year. The company has recently employed an IT Technician named Mia Hamm in the branch office to maintain the branch office computers. Users in the branch office complain that it takes a long time to log on to their computers. You decide to install a Windows Server 2008 R2 Read-Only Domain Controller (RODC) in the branch office to improve log on times. You install a writeable Windows Server 2008 R2 domain controller in the main office. You need to configure the domain to support a Windows Server 2008 R2 Read-Only Domain Controller (RODC). What is the minimum domain and forest functional level required to support a Windows Server 2008 R2 Read-Only Domain Controller (RODC)? (Choose two). A. Windows 2000 Native domain functional level. B. Windows 2003 domain functional level. C. Windows 2008 domain functional level. D. Windows 2008 R2 domain functional level. E. Windows 2000 forest functional level. F. Windows 2003 forest functional level. G. Windows 2008 forest functional level. H. Windows 2008 R2 forest functional level.


Options are :

  • A,B
  • B,F
  • C,D
  • G,H

Answer : B,F

You work as an enterprise administrator at YYY.com. The corporate network of the company consists of an Active Directory forest that runs at the functional level of Windows Server 2003. The forest root domain is named YYY.com. All the domain controllers in the root domain run Windows Server 2003 and the functional level of the domain is Windows Server 2003. A child domain named Corp.YYY.com contains domain controllers running Windows Server 2008 R2. The functional level of the Corp.YYY.com domain is Windows Server 2003. You plan to deploy a Windows Server 2008 R2 domain controller in the YYY.com root domain. You need to run the adprep /domainprep command from the Windows Server 2008 R2 installation DVD to prepare the domain for a Windows Server 2008 R2 domain controller. On which domain controller to you need to run adprep /domainprep command?


Options are :

  • . The domain controller that holds the Infrastructure Master role. .
  • The domain controller that holds the Schema Master role.
  • The domain controller that holds the RID Master role.
  • The domain controller that holds the Domain Naming Master role

Answer : . The domain controller that holds the Infrastructure Master role. .

Microsoft 70-642 Windows Server Network Infrastructure Exam Set 3

You work as a Network Administrator at YYY.com. The network consists of a single Active Directory Domain Services (AD DS) domain named YYY.com. The company has a main office and a branch office. The two offices are connected by a WAN link. The network servers run either Windows Server 2003 or Windows Server 2008 R2. The domain functional level is Windows Server 2000. The main office contains two domain controllers that run Windows Server 2008 R2. The branch office contains two domain controllers that run Windows Server 2003. Due to the lack of physical security of the branch office domain controllers, you have been asked to encrypt the drives using Windows BitLocker Drive Encryption (BitLocker). What do you need to do before you can enable BitLocker on the branch office domain controllers


Options are :

  • You need to upgrade the domain controllers to Windows Server 2003 R2.
  • You need to upgrade the domain controllers to Windows Server 2003 Service Pack 2.
  • You need to raise the functional level of the domain to Windows Server 2003
  • You need to upgrade the domain controllers to Windows Server 2008 R2.

Answer : You need to upgrade the domain controllers to Windows Server 2008 R2.

You work as an enterprise administrator at YYY.com. The YYY.com network has a domain that runs at the domain functional level of Windows Server 2008. All servers in the domain run Windows Server 2008 R2 and all client computers run Windows 7 Professional. The default Users container currently holds all user accounts. The company contains six departments named Sales, Marketing, Production, Manufacturing, Research and Development. Each department has a junior manager. The junior managers need to be able to reset passwords for users in their department. Three senior managers are each responsible for two departments. One senior manager is responsible for the Sales and Marketing departments. One senior manager is responsible for the Production and Manufacturing departments. The third senior manager is responsible for the Research and Development departments. The senior managers need to be able to manage user accounts in each department that they are responsible for. If users are moved between departments, only their new junior and senior manager should be able to modify their user accounts. You need to design an organizational unit structure to enable you to delegate the required permissions to the managers. You need to minimize the number of OUs. How should you design your OU structure?


Options are :

  • Three top level OUs, each containing two OUs that contain user accounts for a single department. .
  • Six OUs, each containing user accounts for a single department
  • Three OUs, one containing the Sales and Marketing users, one containing the Production and Manufacturing and one containing the Research and Development users. .
  • One OU containing all user accounts.

Answer : Six OUs, each containing user accounts for a single department

You work as an enterprise administrator at YYY.com. The corporate network of the company consists of an Active Directory forest that runs at the functional level of Windows Server 2003. The forest root domain is named YYY.com. All the domain controllers in the domain run Windows Server 2003 and the functional level of the domain is Windows Server 2003. You plan to create a child domain in the YYY.com forest. The child domain will have domain controllers running Windows Server 2008 R2. What should you do before installing the first Windows Server 2008 R2 domain controller in the new child domain?


Options are :

  • You should install a domain controller running Windows Server 2003.
  • You should install a Windows Server 2008 R2 domain controller in the root domain. .
  • You should run the adprep /forestprep command on the domain controller in the root domain that holds the schema operations master role.
  • You should run the adprep /domainprep command on a domain controller in the root domain. .

Answer : You should run the adprep /forestprep command on the domain controller in the root domain that holds the schema operations master role.

70-646 Pro Windows Server 2008 - Server Administrator Exam Set 5

You work as a Network Administrator at YYY.com. The network consists of a single Active Directory Domain Services (AD DS) domain named YYY.com. All servers run Windows Server 2008 R2 and all client computers run Windows 7 Professional. The internal network is separated from the internet by a corporate firewall. The network includes virtual machines (VMs) running on Windows Server 2008 R2 Hyper-V host servers. Four virtual machines (VMs) named ABC-RDS1, ABC-RDS2, ABC-RDS3 and ABC-RDS4 all run Windows Server 2008 R2 with the Remote Desktop Session Host (RDSH) role. A server named ABC-Web1 runs Windows Server 2008 R2 with the Web Server (IIS) role. ABCWeb1 hosts a corporate Intranet Web site. The four RDSH servers host applications published as RemoteApps. The RemoteApps are made available to the users through the corporate Intranet Web site. You need to ensure that the resources used by the RemoteApps are shared evenly between the company users. Which two of the following actions should you take to ensure that each user has access to the same amount of CPU resources on the RDSH servers? (Choose two). A. You should configure a Terminal Services resource authorization policy (TS RAP). B. You should configure a resource-allocation policy. C. You should install Windows Rights Management Services (WRMS) on the four Remote Desktop Session Host servers. D. You should install Windows System Resource Manager (WSRM) on the four Remote Desktop Session Host servers. E. You should install Windows System Resource Manager (WSRM) on the ABC-WEB1. F. You should install Windows Network Load Balancing on the four Remote Desktop Session Host servers. G. You should configure an equal host priority on the four Remote Desktop Session Host servers.


Options are :

  • A,B
  • B,D
  • D,C
  • A,C

Answer : B,D

Microsoft 70-647 Windows Enterprise Administrator Exam Set 1

You work as an enterprise administrator at YYY.com. The network consists of a single Active Directory Domain Services (AD DS) domain named YYY.com. All servers on the network run Windows Server 2008 R2. YYY.com has its main office in Chicago and branch offices in Boston, Atlanta, Miami and Dallas. Each branch office is connected to the main office by a slow WAN link.1 The Chicago office has writeable domain controllers running Windows Server 2008 R2. Each branch office has a Read Only Domain Controller (RODC) running Windows Server 2008 R2. The company hires two IT Technicians in the Boston and Atlanta branch offices. The IT Technicians will provide technical support for the computers in the branch offices. The company plans to hire more IT Technicians in the future. You need to configure password replication to enable the IT Technicians in the Boston and Atlanta branch offices to log on to all computers in their respective office. You need to minimize the number of locations that the passwords are replicated to. How should you configure the password replication to meet the requirements whilst ensuring that administrative effort is minimized when extra IT Technicians are hired?


Options are :

  • You should add the computer accounts and the IT Technician’s user accounts for the Boston and Atlanta branch offices to a global group for each office. Add the global groups to the Password Replication Policy for each office.
  • . You should add the computer accounts and the IT Technician’s user accounts for the Boston and Atlanta branch offices to a single global group. Add the global group to the Password Replication Policy for each office.
  • You should add the computer accounts and the IT Technician’s user accounts for the Boston and Atlanta branch offices to the Password Replication Policy for each office.
  • . You should enable Universal Group Membership Caching in the Boston and Atlanta branch offices. Instruct the IT Technicians to log on to each client computer.

Answer : You should add the computer accounts and the IT Technician’s user accounts for the Boston and Atlanta branch offices to a global group for each office. Add the global groups to the Password Replication Policy for each office.

You work as an enterprise administrator at YYY.com. The YYY.com network consists of a single Active Directory Domain Services (AD DS) named YYY.com. YYY.com has its headquarters in Chicago and branch offices in Boston and Atlanta. The Boston and Atlanta offices are connected to the Chicago by reliable WAN links. All servers in the Chicago office run Windows Server 2008 R2. All servers in the branch offices run Windows Server 2003 R2. All client computers in the domain run Windows 7 Professional. The branch offices each have two Windows Server 2003 R2 servers. The servers in each office are both configured as Domain Controllers and File and Print servers The company is concerned about the lack of physical security of the branch office servers. They have released a new security policy that states that only the passwords of the branch office users should be replicated to the branch office servers. Furthermore, the data stored on the servers must be protected in the event of server hardware theft. Which two of the following actions should you perform to comply with the company security policy? (Choose two). A. You should replace the branch office servers with Windows Server 2008 R2 read-only domain controllers (RODCs) and configure password replication policies for each branch office. B. You should disable Universal Group Caching on the branch office servers. C. You should encrypt the data using Encrypting File System (EFS). D. You should encrypt the data using BitLocker Drive Encryption. E. You should replace the branch office servers with Windows Server 2008 R2 writeable domain controllers and configure fine grained password policies for each branch office.


Options are :

  • B,C
  • A,D
  • A,B
  • B,E

Answer : A,D

You work as a Network Administrator at YYY.com. The network consists of a single Active Directory domain named YYY.com. The company has a main office and a branch office. The two offices are connected by a fast reliable WAN link. All servers on the network run Windows Server 2003 R2. The functional level of the domain is Windows Server 2003. The main office contains six Windows Server 2003 R2 domain controllers. You upgrade one domain controller to Windows Server 2008 R2. You want to deploy a Read-Only Domain Controller (RODC) to the branch office. How can you prepare the Active Directory for the installation of an RODC in the branch office?


Options are :

  • By running the adprep /rodcprep on a domain controller. .
  • By upgrading the remaining domain controllers to Windows Server 2008 R2 and raising the domain functional level to Windows Server 2008.
  • By installing a writeable Windows Server 2008 domain controller in the branch office
  • By running the adprep /domainprep /gpprep on the domain controller that holds the infrastructure operations master role. .

Answer : By running the adprep /rodcprep on a domain controller. .

Microsoft 70-647 Windows Enterprise Administrator Exam Set 3

You work as an enterprise administrator at YYY.com. The YYY.com network has a domain named YYY.com. All servers in the YYY.com network run Windows Server 2008 R2. YYY.com has its headquarters in Chicago. The company also has large Sales and Production divisions in separate locations in the Chicago. Each division has its own computer technician that manages the local area network (LAN) for that location. Only the headquarters has domain controllers. You want to have domain controllers installed in the Sales and Production divisions. You want the technician at each location to log on and manage device drivers on the domain controller in their respective location only. How would you accomplish this task? (Each correct option will form a part of the answer. Select TWO.) A. By adding a read-only domain controller (RODC) in the Sales and Production divisions. B. By adding a Server Core Installation to the domain controller in the Sales and Production divisions. C. By adding the local technician to the Administrators role for the RODC in their respective location. D. By adding the local technician to the Domain Admins role for the RODC in their respective office. E. By adding the local technician to the Server Operators domain local group. F. By adding the local technician to the Read-only Domain Controllers group.


Options are :

  • A,B
  • A,E
  • C,D
  • A,C

Answer : A,C

You work as a Network Administrator at YYY.com. The network consists of a single Active Directory Domain Services (AD DS) domain named YYY.com. All servers on the network run Windows Server 2008 R2 and all client computers run Windows 7 Enterprise. The company has started work on a project involving a partner company named Weyland Industries. The Weyland Industries network consists of a single Active Directory Domain Services (AD DS) domain named WeylandIndustries.com. There is no trust relationship between the domain networks of YYY.com and WeylandIndustries.com. Users in the Weyland Industries need to access files hosted on file servers and database servers in the YYY.com domain. You need to implement a solution that enables users from both companies to be able to search for and access the files using a Web browser. YYY.com security policy states that Project Managers in YYY.com must be able to restrict access to the files using NTFS permissions and that all file access is audited. How should you provide the required access?


Options are :

  • You should install a server running Microsoft SharePoint Server 2010.
  • . You should configure a domain trust where YYY.com trusts WeylandIndustries.com.
  • . You should install a server running the FTP Server role. .
  • You should install a server running Microsoft SharePoint Foundation.

Answer : You should install a server running Microsoft SharePoint Server 2010.

You work as a Network Administrator at YYY.com. The network consists of a single Active Directory Domain Services (AD DS) domain named YYY.com. All servers on the network run Windows Server 2008 R2 and all client computers run Windows 7 Enterprise. The company has started work on a project involving a partner company named Weyland Industries. The Weyland Industries network consists of a single Active Directory Domain Services (AD DS) domain named WeylandIndustries.com. There is no trust relationship between the domain networks of YYY.com and WeylandIndustries.com. Users from the Weyland Industries Research department need to access files hosted on file servers in the YYY.com Research department. YYY.com management is worried about the security of sensitive research data. You have been asked to implement a solution that enables YYY.com Research users to share files with Weyland Industries Research users. You need to ensure that any files that have been copied to Weyland Industries Research computers cannot be printed or opened by unauthorized users. Which two of the following actions should you perform? (Choose two) A. You should implement Active Directory Rights Management Services (AD RMS) on the YYY.com network. B. You should configure NTFS permissions to Deny-Print to everyone and Allow-Read to only the appropriate users. C. You should implement Active Directory Federation Services (AD FS). D. You should configure the YYY.com domain to trust the WeylandIndustries.com domain. E. You should encrypt the files using Encrypting File System (EFS) and distribute the encryption keys to the WeylandIndustries.com Research users.


Options are :

  • A,C
  • B,C
  • D,E
  • C,D

Answer : A,C

Microsoft 70-642 Windows Server Network Infrastructure Exam Set 8

You work as an enterprise administrator at YYY.com. The YYY.com network has a domain named YYY.com. The servers in the YYY.com network run either Windows Server 2003 or Windows Server 2008 R2. All client computers run Windows 7 Professional. The physical network consists of 6 subnets. A Windows Server 2008 R2 application server hosts an application named App1. Client computers in all 6 subnets access App1 using it’s NetBIOS name. A Windows Server 2003 server runs the Windows Internet Naming Service (WINS) service. Client computers use the WINS service to resolve the IP address of the application server. You are in the process of upgrading the Windows Server 2003 servers to Windows Server 2008 R2. You want to decommission the WINS server during the upgrade. You need to ensure that all client computers can still access App1 using a single name after the WINS server is decommissioned. Which of the following options would you choose to accomplish this task?


Options are :

  • . You should configure a Service Locator (SRV) records for the application server
  • . You should configure a GlobalNames DNS zone.
  • . You should configure a DNS Suffix on the application server.
  • You should configure an Active Directory-integrated (ADI) DNS zone.

Answer : . You should configure a GlobalNames DNS zone.

You work as an enterprise administrator at YYY.com. The YYY.com network has a forest with five domains. All servers in the YYY.com network run Windows Server 2008 R2. All client computers run Windows 7 Professional. Network applications hosted on Windows Server 2008 R2 application servers in all five domains are accessed by NetBIOS names. You are planning to migrate the entire network from IPv4 addressing to IPv6 addressing. You need to implement a solution that will enable client computers to resolve NetBIOS names after the transition to IPv6. Which of the following options would you choose to accomplish this task?


Options are :

  • . You should select the “Use WINS forward lookup” option on the DNS forward lookup zones
  • You should configure Active Directory-integrated (ADI) DNS zones for each domain. .
  • You should install the Windows Internet Naming Service (WINS) service in each domain. .
  • You should configure a GlobalNames DNS zone in each domain.

Answer : You should configure a GlobalNames DNS zone in each domain.

You work as an enterprise administrator at YYY.com. The corporate network of ABC consists of a single Active Directory Domain Services forest. The ABC forest contains a root domain is named YYY.com and a child domain named corp.YYY.com. A partner company of ABC called Willow Bridge Ltd also consists of a single Active Directory Domain Services forest. The Willow Bridge forest contains a root domain named WillowBridge.com and a child domain named corp.willowbridge.com. The corp.YYY.com domain contains a Windows Server 2008 R2 server named ABC-App1. The corp.willowbridge.com domain contains a Windows Server 2008 R2 server named WB-App1. Users in the corp.YYY.com domain need to access WB-App1. Users in the corp.willowbridge.com domain need to access ABC-App1. Company security states that access to ABC-App1 or WB-App1 must be secured using Kerberos authentication. How can you configure the required access to ABC-App1 and WB-App1 using the required security?


Options are :

  • By configuring two one-way external trusts between the corp.YYY.com domain and the corp.willowbridge.com domain
  • By implementing Active Directory Federation Services (AD FS) in each domain and configuring an AD FS trust between the two domains.
  • By configuring a forest trust with selective authentication between the two forests. .
  • By implementing Active Directory Rights Management Services (AD RMS) in each domain. .

Answer : By configuring a forest trust with selective authentication between the two forests. .

70-662 Microsoft Exchange Server 2010 Configuring Exam Set 4

Comment / Suggestion Section
Point our Mistakes and Post Your Suggestions