EnsurepassQUESTION 521 Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named DC1. You have a member server named Server1. Both DC1 and Server1 have the DNS Server role installed. On DC1, you create an Active Directory-integrated zone named adatum.com. You need to ensure that Server1 receives a copy of the zone. Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)   Create a secondary Read more [...]
EnsurepassQUESTION 511 Your network contains an Active Directory domain named contoso.com. The domain contains a domain controller named DC1. You install Active Directory Lightweight Directory Services (AD LDS) on a member server named Server2. On Server2, you create a directory partition named fabrikam.com. You need to configure the MS-AdamSyncConfig.xml file to synchronize data from contoso.com to fabrikam.com. What should you do?   To answer, select the appropriate options in the answer area. Read more [...]
EnsurepassQUESTION 501 Your network contains an Active Directory forest. The forest contains two domains. The forest contains four domain controllers. The domain controllers are configured as shown in the following table.     All user accounts are located in the child.contoso.com domain. Users in the child.contoso.com domain are members of several security groups in the contoso.com domain. Your company decides to change the naming standard of user accounts. You rename all of the user accounts Read more [...]
EnsurepassQUESTION 491 Your network contains an Active Directory forest named contoso.com. The functional level of the forest is Windows Server 2008 R2. You have four Active Directory sites. Each site has multiple Active Directory subnets. You need to identify all of the authentication requests that originate from client computers that are not associated to an Active Directory subnet. What should you use?   The %Systemroot%System32Network_llu.log log file The %Systemroot%DebugNetsetup.log Read more [...]
EnsurepassQUESTION 461 Your network contains an Active Directory domain. The domain is configured as shown in the exhibit.     You need to ensure that when users log on to client computers, they are added automatically to the local Administrators group. The users must be removed from the group when they log off of the client computers. What should you do?   Modify the Group Policy permissions. Enable block inheritance. Configure the link order. Enable loopback processing in merge Read more [...]
EnsurepassQUESTION 481 You are the administrator of an organization with a single Active Directory domain. A user who left the company returns after 16 weeks. The user tries to log onto their old computer and receives an error stating that authentication has failed. The user`s account has been enabled. You need to ensure that the user is able to log onto the domain using that computer. What do you do?   Reset the computer account in Active Directory. Disjoin the computer from the domain and Read more [...]
EnsurepassQUESTION 471 You are the network administrator for the Contoso Company. Your network consists of two DNS servers named DNS1 and DNS2. The users who are configured to use DNS2 complain because they are unable to connect to Internet websites. The following table shows the configuration of both servers:     The users connected to DNS2 need to be able to access the Internet. What needs to be done?   Build a new Active Directory Integrated zone on DNS2. Delete the .(root) Read more [...]
EnsurepassQUESTION 451 Your network contains an Active Directory domain named contoso.com. The Active Directory sites are configured as shown in the Sites exhibit.     You need to ensure that DC1 and DC4 are the only servers that replicate Active Directory changes between the sites. What should you do?   Configure DC1 as a preferred bridgehead server for IP transport. Configure DC4 as a preferred bridgehead server for IP transport. From the DC4 server object, create a Connection Read more [...]
EnsurepassQUESTION 441 A corporate environment includes a Windows Server 2008 R2 Active Directory Domain Services (AD DS) domain. You need to enable Universal Group Membership Caching on several domain controllers in the domain. Which tool should you use?   Dsmod Dscmd Ntdsutil Active Directory Sites and Services console   Correct Answer: D     QUESTION 442 Your network contains an Active Directory forest. The forest contains three domains. All domain controllers have the Read more [...]
EnsurepassQUESTION 431 Your network contains an Active Directory domain. The domain contains two Active Directory sites named Site1 and Site2. Site1 contains two domain controllers named DC1 and DC2. Site2 contains two domain controller named DC3 and DC4. The functional level of the domain is Windows Server 2008 R2. The functional level of the forest is Windows Server 2003. Active Directory replication between Site1 and Site2 occurs from 20:00 to 01:00 every day. At 07:00, an administrator deletes Read more [...]
EnsurepassQUESTION 421 Your network contains an Active Directory forest named fabrikam.com. The forest contains the following domains:   Fabrikam.com Eu.fabrikam.com Na.fabrikam.com Eu.contoso.com Na.contoso.com   You need to configure the forest to ensure that the administrators of any of the domains can specify a user principal name (UPN) suffix of contoso.com when they create user accounts from Active Directory Users and Computers. Which tool should you use?   Active Directory Read more [...]
EnsurepassQUESTION 411 A corporate network includes an Active Directory-integrated zone. All DNS servers that host the zone are domain controllers. You add multiple DNS records to the zone. You need to ensure that the new records are available on all DNS servers as soon as possible. Which tool should you use?   Repadmin Active Directory Domains and Trusts console Ldp Ntdsutil   Correct Answer: A     QUESTION 412 Your network contains an Active Directory forest named contoso.com. Read more [...]
EnsurepassQUESTION 401 Your network contains an Active Directory domain. You need to activate the Active Directory Recycle Bin in the domain. Which tool should you use?   Dsamain Set-ADDomain Add-WindowsFeature Ldp   Correct Answer: D     QUESTION 402 Your network contains an Active Directory domain named contoso.com. You need to create a script that runs the Best Practices Analyzer (BPA) each week for all of the server roles that BPA supports on each domain controller. You Read more [...]
EnsurepassQUESTION 391 Your network contains an Active Directory domain named contoso.com. Contoso.com contains two domain controllers named DC1 and DC2. DC1 and DC2 are configured as DNS servers and host the Active Directory-integrated zone for contoso.com. From DNS Manager on DC1, you enable scavenging for the contoso.com zone. You discover stale DNS records in the zone. You need to ensure that the stale DNS records are deleted from contoso.com. What should you do?   From DNS Manager, enable Read more [...]
EnsurepassQUESTION 371 All vendors belong to a global group named vendors. You place three file servers in a new organizational unit (OU) named ConfidentialFileServers. The three file servers contain confidential data located in shared folders. You need to record any failed attempts made by the vendors to access the confidential data. Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)   Create a new Group Policy Object (GPO) and link it to Read more [...]
EnsurepassQUESTION 381 Your network contains an Active Directory forest. The forest contains one domain named contoso.com. You discover the following event in the Event log of client computers: "The time provider NtpClient was unable to find a domain controller to use as a time source. NtpClient will try again in %1 minutes." You need to ensure that the client computers can synchronize their clocks properly. What should you do?   Move the domain naming master role. Restart Active Directory Read more [...]
EnsurepassQUESTION 361 Your network contains an Active Directory domain named contoso.com. You need to ensure that IP addresses can be resolved to fully qualified domain names (FQDNs). Under which node in the DNS snap-in should you add a zone?   To answer, select the appropriate node in the answer area.   Point and Shoot:   Correct Answer:   QUESTION 362 Your company has two domain controllers named DC1 and DC2. DC1 hosts all domain and forest operations master roles. DC1 fails. You need to Read more [...]
EnsurepassQUESTION 351 Your network contains an Active Directory forest. The DNS infrastructure fails. You rebuild the DNS infrastructure. You need to force the registration of the Active Directory Service Locator (SRV) records in DNS. Which service should you restart on the domain controllers?   To answer, select the appropriate service in the answer area.   Point and Shoot:   Correct Answer:     QUESTION 352 Your network contains an Active Directory forest named contoso.com. The password Read more [...]
EnsurepassQUESTION 341 Your network contains an Active Directory forest. The forest contains domain controllers that run Windows Server 2008 R2. The functional level of the forest is Windows Server 2003. The functional level of the domain is Windows Server 2008. From a domain controller, you need to perform an authoritative restore of an organizational unit (OU). What should you do first?   Raise the functional level of the forest Modify the tombstone lifetime of the forest. Restore the Read more [...]
EnsurepassQUESTION 331 Your network contains an enterprise certification authority (CA) that runs Windows Server 2008 R2 Enterprise. You enable key archival on the CA. The CA is configured to use custom certificate templates for Encrypted File System (EFS) certificates. You need to archive the private key for all new EFS certificates. Which snap-in should you use?   Active Directory Users and Computers Authorization Manager Group Policy Management Enterprise PKI Security Templates TPM Read more [...]
EnsurepassQUESTION 321 You install an Active Directory domain in a test environment. You need to reset the passwords of all the user accounts in the domain from a domain controller. Which two Windows PowerShell commands should you run? (Each correct answer presents part of the solution, choose two.)   $ newPassword = * Import-Module ActiveDirectory Import-Module WebAdministration Get- AdUser -filter * | Set- ADAccountPossword - NewPassword $ newPassword - Reset Set- ADAccountPossword - Read more [...]
EnsurepassQUESTION 311 Your network contains a domain controller that runs Windows Server 2008 R2. You run the following command on the domain controller:   dsamain.exe C dbpath c:$SNAP_201006170326_VOLUMEC$WindowsNTDSntds.dit C ldapport 389 - allowNonAdminAccess   The command fails. You need to ensure that the command completes successfully. How should you modify the command?   Change the value of the -dbpath parameter. Include the path to Dsamain. Change the value of the -ldapport Read more [...]