web analytics

[Pass Ensure VCE Dumps] The Best PassLeader 70-642 Exam Questions With Free VCE Download (381-400)

Want To Pass The New 70-642 Exam Easily? DO NOT WORRY! PassLeader now is supplying the latest and 100 percent pass ensure version 448q 70-642 PDF dumps and VCE dumps, the new updated 70-642 braindumps are the most accurate with all the new changed 70-642 exam questions, it will help you passing 70-642 exam easily and quickly. Now visit the our site passleader.com and get the valid 448q 70-642 VCE and PDF exam questions and FREE VCE PLAYER!

keywords: 70-642 exam,448q 70-642 exam dumps,448q 70-642 exam questions,70-642 pdf dumps,70-642 vce dumps,70-642 braindumps,70-642 practice tests,70-642 study guide,TS: Windows Server 2008 Network Infrastructure, Configuring Exam

QUESTION 381
You need to identify all failed logon attempts on the domain controllers. What should you do?

A.    Run Event Viewer.
B.    View the Netlogon.log file.
C.    Run the Security Configuration Wizard.
D.    View the Security tab on the domain controller computer object.

Answer: A

QUESTION 382
You create 200 new user accounts. The users are located in six different sites. New users report that they receive the following error message when they try to log on: “The username or password is incorrect.” You confirm that the user accounts exist and are enabled. You also confirm that the user name and password information supplied are correct. You need to identify the cause of the failure. You also need to ensure that the new users are able to log on. Which utility should you run?

A.    Rsdiag
B.    Rstools
C.    Repadmin
D.    Active Directory Domains and Trusts

Answer: C

QUESTION 383
You need to validate whether Active Directory successfully replicated between two domain controllers. What should you do?

A.    Run the DSget command.
B.    Run the Dsquery command.
C.    Run the RepAdmin command.
D.    Run the Windows System Resource Manager.

Answer: C

QUESTION 384
Your network consists of a single Active Directory domain.? All domain controllers run Windows Server 2008 R2. You need to identify the Lightweight Directory Access Protocol (LDAP) clients that are using the largest amount of available CPU resources on a domain controller. What should you do?

A.    Review performance data in Resource Monitor.
B.    Review the Hardware Events log in the Event Viewer.
C.    Run the LAN Diagnostics Data Collector Set. Review the LAN Diagnostics report.
D.    Run the Active Directory Diagnostics Data Collector Set. Review the Active Directory Diagnostics report.

Answer: D

QUESTION 385
Your network consists of a single Active Directory domain. All domain controllers run Windows Server 2008 R2. You need to capture all replication errors from all domain controllers to a central location. What should you do?

A.    Configure event log subscriptions.
B.    Start the System Performance data collector set.
C.    Start the Active Directory Diagnostics data collector set.
D.    Install Network Monitor and create a new capture.

Answer: A

QUESTION 386
You have an Active Directory domain that runs Windows Server 2008 R2. You need to implement a certification authority (CA) server that meets the following requirements:
– Allows the certification authority to automatically issue certificates
– Integrates with Active Directory Domain Services
What should you do?

A.    Install and configure the Active Directory Certificate Services server role as a Standalone Root CA.
B.    Install and configure the Active Directory Certificate Services server role as an Enterprise Root CA.
C.    Purchase a certificate from a third-party certification authority. Install and configure the Active Directory Certificate Services server role as a Standalone Subordinate CA.
D.    Purchase a certificate from a third-party certification authority. Import the certificate into the computer store of the schema master.

Answer:

QUESTION 387
Your network contains an Active Directory forest named adatum.com. You need to create an Active Directory Rights Management Services (AD RMS) licensing-only cluster. What should you install before you create the AD RMS root cluster?

A.    The Failover Cluster feature
B.    The Active Directory Certificate Services (AD CS) role
C.    Microsoft Exchange Server 2010
D.    Microsoft SharePoint Server 2010
E.    Microsoft SQL Server 2008

Answer: E

QUESTION 388
Your network contains an Active Directory domain named contoso.com. The contoso.com domain contains a domain controller named DC1. You create an Active Directory-integrated GlobalNames zone. You add an alias (CNAME) resource record named Server1 to the zone. The target host of the record is server2.contoso.com. When you ping Server1, you discover that the name fails to resolve. You are able to successfully ping server2.contoso.com. You need to ensure that you can resolve names by using the GlobalNames zone. Which command should you run?

A.    Dnscmd DCl.contoso.com /ZoneAdd GlobalNames /DsPrimary /DP /domain
B.    Dnscmd DCl.contoso.com /config /Enableglobalnamessupport forest
C.    Dnscmd DCl.contoso.com/config/Enableglobalnamessupport 1
D.    Dnscmd DCl.contoso.com /ZoneAdd GlobalNames /DsPrimary /DP /forest

Answer: C

QUESTION 389
You deploy an Active Directory Federation Services (AD FS) Federation Service Proxy on a server named Server1. You need to configure the Windows Firewall on Server1 to allow external users to authenticate by using AD FS. Which protocol should you allow on Server1?

A.    Kerberos
B.    SSL
C.    SMB
D.    RPC

Answer: B

QUESTION 390
Your network contains an Active Directory domain named contoso.com. Contoso.com contains a member server that runs Windows Server 2008 R2 Standard. You need to create an enterprise subordinate certification authority (CA) that can issue certificates based on version 3 certificate templates. You must achieve this goal by using the minimum amount of administrative effort. What should you do first?

A.    Run the certutil.exe – addenrollmentserver command.
B.    Install the Active Directory Certificate Services (AD CS) role on the member server.
C.    Upgrade the member server to Windows Server 2008 R2 Enterprise.
D.    Run the certutil.exe – installdefaulttemplates command.

Answer: C


http://www.passleader.com/70-642.html

QUESTION 391
Your network contains a server named Server1. The Active Directory Rights Management Services (AD RMS) server role is installed on Server1. An administrator changes the password of the user account that is used by AD RMS. You need to update AD RMS to use the new password. Which console should you use?

A.    Active Directory Rights Management Services
B.    Active Directory Users and Computers
C.    Local Users and Groups
D.    Services

Answer: A

QUESTION 392
Your network contains an Active Directory domain. The domain contains several domain controllers. You need to modify the Password Replication Policy on a read-only domain controller (RODC). Which tool should you use?

A.    Group Policy Management
B.    Active Directory Domains and Trusts
C.    Active Directory Users and Computers
D.    Computer Management
E.    Security Configuration Wizard

Answer: C

QUESTION 393
Your network contains an enterprise certification authority (CA) that runs Windows Server 2008 R2 Enterprise. You need to approve a pending certificate request. Which snap-in should you use?

A.    Active Directory Users and Computers
B.    Authorization Manager
C.    Certification Authority
D.    Group Policy Management
E.    Certificate Templates
F.    TPM Management
G.    Certificates
H.    Enterprise PKI
I.    Security Templates

Answer: C

QUESTION 394
Your network contains an Active Directory domain named adatum.com. You need to ensure that IP addresses can be resolved to fully qualified domain names (FQDNs). Under which node in the DNS snap-in should you add a zone?

A.    Reverse Lookup Zones
B.    adatum.com
C.    Forward Lookup Zones
D.    Conditional Forwarders
E.    _msdcs.adatum.com

Answer: A

QUESTION 395
Your network contains an Active Directory domain named adatum.com. The domain contains a domain controller named DC1. DC1 has an IP address of 192.168.200.100. You need to identify the zone that contains the Pointer (PTR) record for 0C1. Which zone should you identify?

A.    adatum.com
B.    _msdcs.adatum.com
C.    100.168.192.in-addr.arpa
D.    200.168.192.in-addr.arpa

Answer: D

QUESTION 396
Your network contains an Active Directory forest named adatum.com. The DNS infrastructure fails. You rebuild the DNS infrastructure. You need to force the registration of the Active Directory Service Locator (SRV) records in DNS. Which service should you restart on the domain controllers?

A.    Netlogon
B.    DNS Server
C.    Network Location Awareness
D.    Network Store Interface Service
E.    Online Responder Service

Answer: A

QUESTION 397
Your network contains an Active Directory domain named adatum.com. The password policy of the domain requires that the passwords for all user accounts be changed every 50 days. You need to create several user accounts that will be used by services. The passwords for these accounts must be changed automatically every 50 days. Which tool should you use to create the accounts?

A.    Active Directory Administrative Center
B.    Active Directory Users and Computers
C.    Active Directory Module for Windows PowerShell
D.    ADSI Edit
E.    Active Directory Domains and Trusts

Answer: C

QUESTION 398
Hotspot Questions
Your network contains an Active Directory forest named contoso.com. All client computers run Windows 7 Enterprise. You need to automatically create a local group named PowerManagers on each client computer that contains a battery. The solution must minimize the amount of administrative effort. Which node in Group Policy Management Editor should you use? To answer, select the appropriate node in the answer area.

Answer:

QUESTION 399
Drag and Drop Questions
Your network contains two forests named contoso.com and fabrikam.com. The functional level of all the domains is Windows Server 2003. The functional level of both forests is Windows 2000. You need to create a trust between contoso.com and fabrikam.com. The solution must ensure that users from contoso.com can only access the servers in fabrikam.com that have the Allowed to Authenticate permission set. What should you do? To answer, move the appropriate actions from the Possible Actions list to the Necessary Actions area and arrange them in the correct order.

Answer:

QUESTION 400
Your network has an internal network and a perimeter network. A firewall named Firewall1 separates the perimeter network and the Internet. You deploy a server named Server1 to the perimeter network. You configure Server1 as a PPTP VPN server. You need to ensure that users from the Internet can establish VPN connections to Server1. The solution must minimize the number of open ports on Firewall1. What should you open on the firewall? (Each correct answer presents part of the solution. Choose three.)

A.    UDP 1723
B.    UDP 4500
C.    TCP 500
D.    TCP 4500
E.    UDP 500
F.    Protocol 50
G.    TCP 1723
H.    Protocol 47

Answer: AGH
Explanation:
http://www.speedguide.net/port.php?port=1723


http://www.passleader.com/70-642.html

Theme: Overlay by Kaira