您好,欢迎来到江浙沪招生考试网 !

设为首页|加入收藏|联系我们|网站地图|

江浙沪招生考试网

您现在的位置: test4exam >> 计算机考试 >> 微软认证考试 >> 正文

MCITP认证考试微软认证专业IT人士70-640考试练习题

日期:2014/9/19 12:41:16 来源:本站原创 访问量:
he SalesAPP GPO to the Sales organizational unit in each location.

  D.

  Create a Group Policy Object (GPO) named SalesAPP GPO. Configure the GPO to assign the application to the computer account. Link the SalesAPP GPO to the Sales organizational unit in each location.

  Answers: D

  18: Single

  Your company has a server that runs an instance of Active Directory Lightweight Directory Services (AD LDS). You need to create new organizational units in the AD LDS application directory partition. What should you do?

  A.

  Use the Active Directory Users and Computers snap-in to create the organizational units on the AD LDS application directory partition.

  B.

  Use the ADSI Edit snap-in to create the organizational units on the AD LDS application directory partition.

  C.

  Use the dsadd OU command to create the organizational units.

  D.

  Use the dsmod OU command to create the organizational units.

  Answers: B

  19: Single

  Your company has an Active Directory forest that contains a single domain. The domain member server has an Active Directory Federation Services (AD FS) server role installed. You need to configure AD FS to ensure that AD FS tokens contain information from the Active Directory domain. What should you do?

  A.

  Add and configure a new account store.

  B.

  Add and configure a new account partner.

  C.

  Add and configure a new resource partner.

  D.

  Add and configure a Claims-aware application.

  Answers: A

  20: Single

  Your company has an Active Directory Rights Management Services (AD RMS) server. Users have Windows Vista computers. An Active Directory domain is configured at the Windows Server 2003 functional level. You need to configure AD RMS so that users are able to protect their documents. What should you do?

  A.

  Install the AD RMS client 2.0 on each client computer.

  B.

  Add the RMS service account to the local administrators group on the AD RMS server.

  C.

  Establish an e-mail account in Active Directory Domain Services (AD DS) for each RMS user.

  D.

  Upgrade the Active Directory domain to the functional level of Windows Server 2008.

  Answers: C

  21: Multiple

  You have two servers named Server1 and Server2. Both servers run Windows Server 2008. Server1 is configured as an Enterprise Root certification authority (CA). You install the Online Responder role service on Server2. You need to configure Server2 to issue certificate revocation lists (CRLs) for the enterprise root CA. Which two tasks should you perform? (Each correct answer presents part of the solution. Choose two.)

  A.

  Import the enterprise root CA certificate.

  B.

  Import the OCSP Response Signing certificate.

  C.

  Add the Server1 computer account to the CertPublishers group.

  D.

  Set the Startup Type of the Certificate Propagation service to Automatic.

  Answers: A B

  22: Single

  Your company has an Active Directory domain. You install an Enterprise Root certification authority (CA) on a member server named Server1. You need to ensure that only the Security Manager is authorized to revoke certificates that are supplied by Server1. What should you do?

  A.

  Remove the Request Certificates permission from the Domain Users group.

  B.

  Remove the Request Certificates permission from the Authenticated Users group.

  C.

  Assign the Allow - Manage CA permission to only the Security Manager user account.

  D.

  Assign the Allow - Issue and Manage Certificates permission to only the Security Manager user account.

  Answers: D

  23: Single

  You have a Windows Server 2008 Enterprise Root CA. Security policy prevents port 443 and port 80 from being opened on domain controllers and on the issuing CA. You need to allow users to request certificates from a Web interface. You install the Active Directory Certificate Services (AD CS) server role. What should you do next?

  A.

  Configure the Online Responder Role Service on a member server.

  B.

  Configure the Online Responder Role Service on a domain controller.

  C.

  Configure the Certification Authority Web Enrollment Role Service on a member server.

  D.

  Configure the Certification Authority Web Enrollment Role Service on a domain controller.

  Answers: C

  24: Multiple

  Your company has an Active Directory domain. You plan to install the Active Directory Certificate Service (AD CS) server role on a member server that runs Windows Server 2008. You need to ensure that members of the Account Operators group are able to issue smartcard credentials. They should not be able to revoke certificates. Which three actions should you perform? (Each correct answer presents part of the solution. Choose three.)

  A.

  Install the AD CS server role and configure it as an Enterprise Root CA.

  B.

  Install the AD CS server role and configure it as a Standalone CA.

  C.

  Restrict enrollment agents for the Smartcard logon certificate to the Account Operator group.

  D.

  Restrict certificate managers for the Smartcard logon certificate to the Account Operator group.

  E.

  Create a Smartcard logon certificate.

  F.

  Create an Enrollment Agent certificate.

  Answers: A C E

  25: Single

  Your company has an Active Directory forest. You plan to install an Enterprise certification authority (CA) on a dedicated stand-alone server. When you attempt to add the Active Directory Certificate Services (AD CS) server role, you find that the Enterprise CA option is not available. You need to install the AD CS server role as an Enterprise CA. What should you do first?

  A.

  Add the DNS Server server role.

  B.

  Join the server to the domain.

  C.

  Add the Web Server server role and the AD CS server role.

  D.

  Add the Active Directory Lightweight Directory Services (AD LDS) server role.

  Answers: B

  26: Single

  Your company has an Active Directory domain. You log on to the domain controller. The Active Directory Schema snap-in is not available in the Microsoft Management Console (MMC). You need to access the Active Directory Schema snap-in. What should you do?

  A.

  Register Schmmgmt.dll.

  B.

  Log off and log on again by using an account that is a member of the Schema Admins group.

  C.

  Use the Ntdsutil.exe command to connect to the schema master operations master and open the schema for writing.

  D.

  Add the Active Directory Lightweight Directory Services (AD LDS) role to the domain controller by using Server Manager.

  Answers: A

  27: Single

  You need to deploy a read-only domain controller (RODC) that runs Windows Server 2008. What is the minimal forest functional level that you should use?

  A.

  Windows Server 2008

  B.

  Windows Server 2003 Interim mode

  C.

  Windows 2000 Native mode

  D.

  Windows Server 2003 Native mode

  Answers: D

  28: Single

  Your company has three Active Directory domains in a single forest. You install a new Active Directoryenabled application. The application adds new user attributes to the Active Directory schema. You discover that the Active Directory replication traffic to the Global

上一页  [1] [2] [3] [4] [5] [6] [7] [8] [9] [10]  ... 下一页  >> 

相关阅读
·推荐文章

Copyright ©2013-2015 江浙沪招生考试网 All Rights Reserved.
地址: 苏州市姑苏区阊胥路483号(工投创业园)  电话:0512-85551931 邮编: 214000
邮箱: [email protected] 版权所有:苏州迈峰教育科技有限公司 苏ICP备15050684号-2