2013年10月29日星期二

Microsoft 070-648 examen pratique questions et réponses

Vous pouvez télécharger tout d'abord une partie de Q&A Certification Microsoft 070-648 pour tester si Pass4Test est vraiment professionnel. Nous pouvons vous aider à réussir 100% le test Microsoft 070-648. Si malheureusement, vous ratez le test, votre argent sera 100% rendu.

Pass4Test vous permet à réussir le test Certification sans beaucoup d'argents et de temps dépensés. La Q&A Microsoft 070-648 est recherchée par Pass4Test selon les résumés de test réel auparavant, laquelle est bien liée avec le test réel.

Code d'Examen: 070-648
Nom d'Examen: Microsoft (TS: Upgrading MCSA on Windows serv 2003 to Windows Serv 2008)
Questions et réponses: 428 Q&As

Si vous travaillez quand même très dur et dépensez beaucoup de temps pour préparer le test Microsoft 070-648, mais ne se savez pas du tout c'est où le raccourci pour passer le test certification, Pass4Test peut vous donner une solution efficace. Vous vous sentirez magiquement jouer un effet multiplicateur.

Vous pouvez télécharger le démo gratuit pour prendre un essai. Vous aurez plus confiance sur Pass4Test. N'hésitez plus à choisir la Q&A Microsoft 070-648 comme votre guide d'étude.

070-648 Démo gratuit à télécharger: http://www.pass4test.fr/070-648.html

NO.1 Your company has an Active Directory domain named contoso.com. FS1 is a member server in
contoso. com.
You add a second network interface card, NIC2, to FS1 and connect NIC2 to a subnet that contains
computers in a DNS domain named fabrikam.com. Fabrikam.com has a DHCP server and a DNS server.
Users in fabrikam.com are unable to resolve FS1 by using DNS. You need to ensure that FS1 has an A
record in the fabrikam.com DNS zone. What are two possible ways to achieve this goal?
(Each correct answer presents a complete solution. Choose two.)
A. Configure the DHCP server in fabrikam.com with the scope option 044 WINS/NBNS Servers.
B. Configure the DHCP server in fabrikam.com by setting the scope option 015 DNS Domain Name to the
domain name fabrikam.com.
C. Configure NIC2 by configuring the Append these DNS suffixes (in order): option.
D. Configure NIC2 by configuring the Use this connection's DNS suffix in DNS registration option.
E. Configure the DHCP server in contoso.com by setting the scope option 015 DNS Domain Name to the
domain name fabrikam.com.
Answer: BD

Microsoft examen   070-648   certification 070-648   certification 070-648   070-648

NO.2 Note : This is part of a series of questions that use the same set of answer choices. Each answer choice
may be used once, more than once, or not at all.
Your network contains an Active Directory domain. All domain controllers run Windows Server 2008 R2.
You need to compact the Active Directory database.
What should you do?
A. Run the repadmin.exe command.
B. Create a Data Collector Set (DCS).
C. Run the dsamain.exe command.
D. Configure the Active Directory Diagnostics Data Contoller Set (DCS).
E. Run the ntdsutil.exe command.
F. Create custom views from Event Viewer.
G. Run the Get-ADForest cmdlet.
H. Run the dsquery.exe command.
I. Configure subscriptions from Event Viewer.
J. Run the eventcreate.exe command.
Answer: E

certification Microsoft   070-648 examen   070-648 examen   070-648

NO.3 Your network contains an Active Directory domain. You have a server named Server1 that runs
Windows Server 2008 R2. Server1 is an enterprise root
certification authority (CA). You have a client computer named Computer1 that runs Windows 7. You
enable automatic certificate
enrollment for all client computers that run Windows 7. You need to verify that the Windows 7 client
computers can automatically enroll for certificates. Which command should you run on Computer1?
A. certreq.exe -retrieve
B. certreq.exe -submit
C. certutil.exe -getkey
D. certutil.exe -pulse
Answer: D

certification Microsoft   070-648   070-648   070-648   070-648 examen

NO.4 Contoso, Ltd. has an Active Directory domain named ad.contoso.com. Fabrikam, Inc. has an Active
Directory domain named intranet.fabrikam.com. Fabrikam's security policy prohibits the transfer of
internal DNS zone data outside the Fabrikam network. You need to ensure that the Contoso users are
able to resolve names from the intranet.fabrikam.com
domain. What should you do?
A. Create a new stub zone for the intranet.fabrikam.com domain.
B. Configure conditional forwarding for the intranet.fabrikam.com domain.
C. Create a standard secondary zone for the intranet.fabrikam.com domain.
D. Create an Active Directory-integrated zone for the intranet.fabrikam.com domain.
Answer: B

certification Microsoft   070-648   070-648   070-648 examen   certification 070-648

NO.5 Note : This is part of a series of questions that use the same set of answer choices. Each answer choice
may be used once, more than once, or not at all.
Your network contains an enterprise certification authority (CA) that runs Windows Server 2008 R2
Enterprise.
You need to approve a pending certificate request.
Which snap-in should you use?
A. Active Directory Users and Computers.
B. Certificate Templates
C. TPM Management
D. Enterprise PKI
E. Authorization Manager
F. Certificates
G. Certification Authority
H. Security Templates
I. Group Policy Management
Answer: G

Microsoft   070-648 examen   070-648

NO.6 You have a domain controller named DC1 that runs Windows Server 2008 R2. DC1 is configured as a
DNS server for contoso.com.
You install the DNS Server server role on a member server named Server1 and then you create a
standard secondary zone for contoso.com. You configure DC1 as the master server for the zone.
You need to ensure that Server1 receives zone updates from DC1.
What should you do?
A. On Server1, add a conditional forwarder.
B. On DC1, modify the permissions of contoso.com zone.
C. On DC1, modify the zone transfer settings for the contoso.com zone.
D. Add the Server1 computer account to the DNSUpdateProxy group.
Answer: C

Microsoft examen   070-648   070-648 examen   certification 070-648   certification 070-648

NO.7 You have a server named Server1 that has the following Active Directory Certificate Services (AD CS)
role services installed:
-Enterprise root certification authority (CA) -Certificate Enrollment Web Service -Certificate Enrollment
Policy Web Service
You create a new certificate template. External users report that the new template is unavailable when
they request a new certificate. You verify that all other templates are available to the external users. You
need to ensure that the external users can request certificates by using the new template.
What should you do on Server1?
A. Run iisreset.exe /restart.
B. Run gpupdate.exe /force.
C. Run certutil.exe -dspublish.
D. Restart the Active Directory Certificate Services service.
Answer: A

Microsoft examen   070-648   070-648 examen   certification 070-648   070-648

NO.8 Your network contains an enterprise root certification authority (CA). You need to ensure that a
certificate issued by the CA is valid.
What should you do?
A. Run syskey.exe and use the Update option.
B. Run sigverif.exe and use the Advanced option.
C. Run certutil.exe and specify the -verify parameter.
D. Run certreq.exe and specify the -retrieve parameter.
Answer: C

Microsoft examen   certification 070-648   certification 070-648

NO.9 Note : This is part of a series of questions that use the same set of answer choices. Each answer choice
may be used once, more than once, or not at all.
Your network contains an enterprise certification authority (CA) that runs Windows Server 2008 R2
Enterprise.
You enable key archival on the CA. The CA is configured to use custom certificate templates for
Encrypted File System (EFS) certificates.
You need to archieve the private key for all new EFS certificates.
Which snap-in should you use?
A. TPM Management
B. Enterprise PKI
C. Active Directory Users and Computers
D. Certificates
E. Group Policy Management
F. Certificate Templates
G. Certification Authority
H. Security Templates
I. Authorization Manager
Answer: F

Microsoft   070-648 examen   070-648 examen   070-648 examen   070-648 examen

NO.10 Your network contains an Active Directory domain. The relevant servers in the domain are configured
as shown in the following table:
You need to ensure that all device certificate requests use the MD5 hash algorithm. What should you do?
A. On Server2, run the Certutil tool.
B. On Server1, update the CEP Encryption certificate template.
C. On Server1, update the Exchange Enrollment Agent (Offline Request) template.
D. On Server3, set the value of the HKLM\Software\Microsoft\Cryptography\MSCEP\HashAlgorithm
\HashAlgorithm registry key.
Answer: D

certification Microsoft   certification 070-648   070-648

NO.11 Your company has an Active Directory domain named contoso.com. The company network has two
DNS servers named DNS1 and DNS2.
The DNS servers are configured as shown in the following table:
Domain users, who are configured to use DNS2 as the preferred DNS server, are unable to connect to
Internet Web sites.
You need to enable Internet name resolution for all client computers. What should you do?
A. Create a copy of the .(root) zone on DNS1.
B. Update the list of root hints servers on DNS2.
C. Update the Cache.dns file on DNS2. Configure conditional forwarding on DNS1.
D. Delete the .(root) zone from DNS2. Configure conditional forwarding on DNS2.
Answer: D

Microsoft examen   070-648   070-648 examen   070-648

NO.12 Your company has a main office and a branch office. The company has a single-domain Active
Directory forest.
The main office has two domain controllers named DC1 and DC2 that run Windows Server 2008 R2. The
branch office has a Windows Server 2008 R2 read-only domain controller (RODC) named DC3. All
domain controllers hold the DNS Server server role and are configured as Active Directory-integrated
zones. The DNS zones only allow secure updates.
You need to enable dynamic DNS updates on DC3.
What should you do?
A. Run the Ntdsutil.exe DS Behavior commands on DC3.
B. Run the Dnscmd.exe /ZoneResetType command on DC3.
C. Reinstall Active Directory Domain Services on DC3 as a writable domain controller.
D. Create a custom application directory partition on DC1. Configure the partition to store Active
Directory-integrated zones.
Answer: C

Microsoft   070-648   070-648   070-648   certification 070-648   certification 070-648

NO.13 Your network contains an Active Directory domain. The domain contains two domain controllers named
DC1 and DC2.
You perform a full backup of the domain controllers every night by using Windows Server Backup.
You update a script in the SYSVOL folder. The new script fails to run properly.
You need to restore the previous version of the script in the SYSVOL folder. The solution must minimize
the amount of time required to restore the script.
What should you do first?
A. Run the Restore-ADObject cmdlet.
B. Restore the system state to its original location.
C. Run the NTDSUtil.exe command-line tool.
D. Attach the VHD file created by Windows Server Backup.
Answer: D

Microsoft examen   070-648   certification 070-648

NO.14 Note : This is part of a series of questions that use the same set of answer choices. Each answer
choice may be used once, more than once, or not at all.
Your network contains an enterprise certification authority (CA) that runs Windows Server 2008 R2
Enterprise.
You have a custom certificate template named Template1. Template1 is published to the CA.
You need to ensure that all of the members of a group named Group1 can enroll for certificates that use
Template1.
Which snap-in should you use?
A. Security Templates
B. Group Policy Management
C. Certificate Templates
D. Certificates
E. TPM Management
F. Active Directory Users and Computers
G. Certification Authority
H. Enterprise PKI
I. Authorization Manager
Answer: C

Microsoft examen   certification 070-648   certification 070-648

NO.15 Note : This is part of a series of questions that use the same set of answer choices. Each answer choice
may be used once, more than once, or not at all.
Your network contains an Active Directory domain. All domain controllers run Windows Server 2008 R2.
You mount an Active Directory snapshot.
You need to ensure that you can query the snapshot by using LDAP.
What should you do?
A. Run the repadmin.exe command.
B. Create custom views from Event Viewer.
C. Run the eventcreate.exe command.
D. Create a Data Collector Set (DCS).
E. Run the dsamain.exe command.
F. Run the ntdsutil.exe command.
G. Run the dsquery.exe command.
H. Configure the Active Directory Diagnostics Data Collector Set (DCS).
I. Configure subscriptions from Event Viewer.
J. Run the Get-ADForest cmdlet.
Answer: E

Microsoft examen   certification 070-648   certification 070-648   070-648 examen   070-648   070-648 examen

NO.16 Your network consists of an Active Directory forest that contains one domain named contoso.com. All
domain controllers run Windows Server 2008 R2 and are configured as DNS servers. You have two
Active Directory-integrated zones: contoso.com and nwtraders.com.
You need to ensure a user is able to modify records in the contoso.com zone. You must prevent the user
from modifying the SOA record in the nwtraders.com zone. What should you do?
A. From the DNS Manager console, modify the permissions of the contoso.com zone.
B. From the DNS Manager console, modify the permissions of the nwtraders.com zone.
C. From the Active Directory Users and Computers console, run the Delegation of Control Wizard.
D. From the Active Directory Users and Computers console, modify the permissions of the Domain
Controllers organizational unit (OU).
Answer: A

certification Microsoft   certification 070-648   070-648   070-648   certification 070-648   070-648

NO.17 You have a domain controller that runs Windows Server 2008 R2 and is configured as a DNS server.
You need to record all inbound DNS queries to the server. What should you configure in the DNS
Manager console?
A. Enable debug logging.
B. Enable automatic testing for simple queries.
C. Enable automatic testing for recursive queries.
D. Configure event logging to log errors and warnings.
Answer: A

Microsoft   070-648   certification 070-648   certification 070-648   070-648

NO.18 You have an enterprise subordinate certification authority (CA). The CA issues smart card logon
certificates. Users are required to log on to the domain by using a smart card. Your company's corporate
security policy
states that when an employee resigns, his ability to log on to the network must be immediately revoked.
An employee resigns. You need to immediately prevent the employee from logging on to the domain.
What should you do?
A. Revoke the employee's smart card certificate.
B. Disable the employee's Active Directory account.
C. Publish a new delta certificate revocation list (CRL).
D. Reset the password for the employee's Active Directory account.
Answer: B

Microsoft examen   070-648   certification 070-648   070-648

NO.19 Your company, Contoso, Ltd., has a main office and a branch office. The offices are connected by a
WAN link. Contoso has an Active Directory forest that contains a single domain named ad.contoso.com.
The ad.contoso.com domain contains one domain controller named DC1 that is located in the main office.
DC1 is configured as a DNS server for the ad.contoso.com DNS zone. This zone is configured as
a standard primary zone.
You install a new domain controller named DC2 in the branch office. You install DNS on DC2. You need
to ensure that the DNS service can update records and resolve DNS queries in the event that a WAN link
fails.
What should you do?
A. Create a new stub zone named ad.contoso.com on DC2.
B. Configure the DNS server on DC2 to forward requests to DC1.
C. Create a new secondary zone named ad.contoso.com on DC2.
D. Convert the ad.contoso.com zone on DC1 to an Active Directory-integrated zone.
Answer: D

Microsoft   certification 070-648   070-648 examen   070-648

NO.20 Your company has a main office and five branch offices that are connected by WAN links. The
company has an Active Directory domain named contoso.com. Each branch office has a member server
configured as a DNS server. All branch office DNS servers host a secondary zone for contoso.com.
You need to configure the contoso.com zone to resolve client queries for at least four days in the event
that a WAN link fails.
What should you do?
A. Configure the Expires after option for the contoso.com zone to 4 days.
B. Configure the Retry interval option for the contoso.com zone to 4 days.
C. Configure the Refresh interval option for the contoso.com zone to 4 days.
D. Configure the Minimum (default) TTL option for the contoso.com zone to 4 days.
Answer: A

Microsoft   070-648   certification 070-648

NO.21 Your network contains a server that runs Windows Server 2008 R2. The server is configured as an
enterprise root certification authority (CA). You have a Web site that uses x.509 certificates for
authentication. The Web site is configured to use a
many-to-one mapping.
You revoke a certificate issued to an external partner. You need to prevent the external partner from
accessing the Web site. What should you do?
A. Run certutil.exe -crl.
B. Run certutil.exe -delkey.
C. From Active Directory Users and Computers, modify the membership of the IIS_IUSRS group.
D. From Active Directory Users and Computers, modify the Contact object for the external partner.
Answer: A

Microsoft   070-648 examen   070-648 examen

NO.22 You add an Online Responder to an Online Responder Array. You need to ensure that the new Online
Responder resolves synchronization conflicts for all members of the Array. What should you do?
A. From Network Load Balancing Manager, set the priority ID of the new Online Responder to 1.
B. From Network Load Balancing Manager, set the priority ID of the new Online Responder to 32.
C. From the Online Responder Management Console, select the new Online Responder, and then select
Set as Array Controller.
D. From the Online Responder Management Console, select the new Online Responder, and then select
Synchronize Members with Array Controller.
Answer: C

Microsoft   certification 070-648   070-648   certification 070-648   070-648

NO.23 Your company has two domain controllers that are configured as internal DNS servers. All zones on
the DNS servers are Active Directory-integrated zones. The zones allow all dynamic updates. You
discover that the contoso.com zone has multiple entries for the host names of computers that do not exist.
You need to configure the contoso.com zone to automatically remove expired records.
What should you do?
A. Enable only secure updates on the contoso.com zone.
B. Enable scavenging and configure the refresh interval on the contoso.com zone.
C. From the Start of Authority tab, decrease the default refresh interval on the contoso.com zone.
D. From the Start of Authority tab, increase the default expiration interval on the contoso.com zone.
Answer: B

certification Microsoft   certification 070-648   070-648

NO.24 Your network consists of an Active Directory forest that contains two domains. All servers run
Windows Server 2008 R2. All domain controllers are configured as DNS servers. You have a standard
primary zone for dev.contoso.com that is stored on a member server. You need to ensure that all domain
controllers can resolve names from the dev.contoso.com zone. What should you do?
A. On the member server, create a stub zone.
B. On the member server, create a NS record for each domain controller.
C. On one domain controller, create a conditional forwarder. Configure the conditional forwarder to
replicate to all DNS servers in the forest.
D. On one domain controller, create a conditional forwarder. Configure the conditional forwarder to
replicate to all DNS servers in the domain.
Answer: C

certification Microsoft   070-648   certification 070-648   certification 070-648

NO.25 Your network contains two Active Directory forests named contoso.com and adatum.com. The
functional level of both forests is Windows Server 2008 R2. Each forest contains one domain. Active
Directory Certificate Services (AD CS) is configured in the contoso.com forest to allow users from both
forests to automatically enroll user certificates.
You need to ensure that all users in the adatum.com forest have a user certificate from the contoso.com
certification authority (CA).
What should you configure in the adatum.com domain?
A. From the Default Domain Controllers Policy, modify the Enterprise Trust settings.
B. From the Default Domain Controllers Policy, modify the Trusted Publishers settings.
C. From the Default Domain Policy, modify the Certificate Enrollment policy.
D. From the Default Domain Policy, modify the Trusted Root Certification Authority settings.
Answer: C

certification Microsoft   certification 070-648   certification 070-648   070-648   070-648 examen

NO.26 Your network consists of an Active Directory forest named contoso.com. All servers run Windows
Server
2008 R2. All domain controllers are configured as DNS servers. The contoso.com DNS zone is stored in
the ForestDnsZones Active Directory application partition. You have a member server that contains a
standard primary DNS zone for dev.contoso.com. You need to ensure that all domain controllers can
resolve names for dev.contoso.com. What should you do?
A. Create a NS record in the contoso.com zone.
B. Create a delegation in the contoso.com zone.
C. Create a standard secondary zone on a Global Catalog server.
D. Modify the properties of the SOA record in the contoso.com zone.
Answer: B

Microsoft   070-648   070-648   070-648

NO.27 Your company has an Active Directory domain named ad.contoso.com. The domain has two domain
controllers named DC1 and DC2. Both domain controllers have the DNS Server server role installed. You
install a new DNS server named DNS1.contoso.com on the perimeter network. You configure DC1 to
forward all unresolved name requests to DNS1.contoso.com.
You discover that the DNS forwarding option is unavailable on DC2. You need to configure DNS
forwarding on the DC2 server to point to the DNS1.contoso.com server. Which two actions should you
perform? (Each correct answer presents part of the solution. Choose two.)
A. Clear the DNS cache on DC2.
B. Delete the Root zone on DC2.
C. Configure conditional forwarding on DC2.
D. Configure the Listen On address on DC2.
Answer: BC

Microsoft examen   certification 070-648   070-648   070-648 examen

NO.28 Your network consists of an Active Directory forest that contains one domain. All domain controllers
run
Windows Server 2008 R2 and are configured as DNS servers. You have an Active Directory-integrated
zone. You have two Active Directory sites. Each site contains five domain controllers. You add a new NS
record to the zone. You need to ensure that all domain controllers immediately receive the new NS record.
What should you do?
A. From the DNS Manager console, reload the zone.
B. From the Services snap-in, restart the DNS Server service.
C. From the command prompt, run repadmin /syncall.
D. From the DNS Manager console, increase the version number of the SOA record.
Answer: C

Microsoft   070-648   070-648

NO.29 Note : This is part of a series of questions that use the same set of answer choices. Each answer choice
may be used once, more than once, or not at all.
Your network contains an Active Directory domain. All domain controllers run Windows Server 2008 R2.
You need to create a snapshot of Active Directory.
What should you do?
A. Configure subscriptions from Event Viewer.
B. Create custom views from Event Viewer.
C. Create a Data Collector Set (DCS).
D. Run the dsquery.exe command.
E. Run the dsamain.exe command.
F. Configure the Active Directory Diagnostics Data Controller Set (DCS).
G. Run the repadmin.exe command.
H. Run the ntdsutil.exe command.
I. Run the eventcreate.exe command.
J. Run the GET-ADForest cmdlet.
Answer: H

Microsoft   070-648   070-648   070-648

NO.30 Your network contains an Active Directory forest. All domain controllers run Windows Server 2008 R2
and are configured as DNS servers. You have an Active Directory-integrated zone for contoso.com. You
have a UNIX-based DNS server.
You need to configure your Windows Server 2008 R2 environment to allow zone transfers of the contoso.
com zone to the UNIX-based DNS server.
What should you do in the DNS Manager console?
A. Disable recursion.
B. Create a stub zone.
C. Create a secondary zone.
D. Enable BIND secondaries.
Answer: D

certification Microsoft   070-648 examen   070-648 examen   certification 070-648   certification 070-648

Beaucoup de travailleurs espèrent obtenir quelques Certificat IT pour avoir une plus grande space de s'améliorer. Certains certificats peut vous aider à réaliser ce rêve. Le test Microsoft 070-648 est un certificat comme ça. Mais il est difficile à réussir. Il y a plusieurs façons pour se préparer, vous pouvez dépenser plein de temps et d'effort, ou vous pouvez choisir une bonne formation en Internet. Pass4Test est un bon fournisseur de l'outil formation de vous aider à atteindre votre but. Selons vos connaissances à propos de Pass4Test, vous allez faire un bon choix de votre formation.

没有评论:

发表评论