Professional Documents
Culture Documents
70 646
70 646
70 646
Microsoft 70-646
Q&A Demo
Study Tips
This product will provide you questions and answers carefully compiled and written by our
experts. Try to understand the concepts behind the questions instead of cramming the
questions.
Go through the entire document at least twice so that you make sure that you are not missing
anything.
Latest Version
We are constantly reviewing our products. New material is added and old material is revised.
Free updates are available for 120 days after the purchase. You should check your member
zone at Certkey an update 3-4 days before the scheduled exam date.
Feedback
If you spot a possible improvement then please let us know. We always interested in improving
product quality.
Feedback should be send to feedback@certkey.com. You should include the following:
Exam number, version, page number, question number, and your login ID.
Our experts will answer your mail promptly.
Copyright
Each pdf file contains a unique serial number associated with your particular name and contact
information for security purposes. So if we find out that a particular pdf file is being distributed
by you, FREE IT CERTIFICATIONS SERVICES reserves the right to take legal action against you
according to the International Copyright Laws.
A. File screen
B. Access-based enumeration
C. Soft quota
D. Folder target
Answer: B
Question: 2
You are a Windows Server 2008 professional who has two years experience in using Windows
Server 2008. You also have experience in using Windows Vista and the Windows server
system. Your routine job is responsible for the server builds and configuration. Currently you
are employed as a sever administrator in an international company which is named Wiikigo.
You are in charge of the company network and provide technical support for your company.
There is a single Active Directory domain in the company network. Now you receive an order
form your manager, you are asked to make sure that in the domain, Group Policy objects
(GPOs) can be created by support technicians. New GPOs will be created by using
preconfigured settings. To create (GPOs), the support technicians must be provided with a
GPO with the preconfigured settings contained. What action shouldd be performed to achieve
this goal?
A. Before creating a new Starter GPO, the support technicians should be added to the Account
Operators group.
B. Before creating a new Starter GPO, permissions should be assigned on the Sysvol folder.
C. Before creating a new Starter GPO, the support technicians should be added to the Group
Policy Creator Owners group.
D. Before creating an ADML file, the support technicians should be added to the Account
Operators group and control on the Users container should be delegated.
E: Before creating an ADML file, the support technicians should be added to the Account
Operators group and control on the Domain Controllers organizational unit (OU) should be
delegated.
Answer: C
Question: 3
You are a Windows Server 2008 professional who has two years experience in using Windows
Server 2008. You also have experience in using Windows Vista and the Windows server
system. Your routine job is responsible for the server builds and configuration. Currently you
are employed in an international company which is named Wiikigo. You are in charge of the
company network and provide technical support for your company. The company wants to
have a distributed database application deployed. This application runs on multiple Windows
A. An iSCSI disk storage subsystem that supports Virtual Disk Service (VDS). The storage
subsystem should be configured as a RAID 5 array.
B. An iSCSI disk storage subsystem that supports Microsoft Multipath I/O. The storage
subsystem should be configured as a RAID 0 array.
C. A Fibre Channel (FC) disk storage subsystem that supports the Virtual Disk Service (VDS).
The storage subsystem should be configured as a RAID 5 array.
D. A Fibre Channel (FC) disk storage subsystem that supports Microsoft Multipath I/O. The
storage subsystem should be configured as a RAID 0 array.
Answer: A
Question: 4
You are a Windows Server 2008 professional who has two years experience in using Windows
Server 2008. You also have experience in using Windows Vista and the Windows server
system. Your routine job is responsible for the server builds and configuration. Currently you
are employed as a sever administrator in an international company which is named Wiikigo.
You are in charge of the company network and provide technical support for your company.
There is a single Active Directory domain in the company network. There are 50 database
servers in your network. Windows Server 2008 is run by those servers. An organizational unit
(OU) named DBAccount stores the computer accounts for the database servers. Besides, an
OU named Group stores the user accounts for the database administrators. A global group
named Group_Admins contains the database administrators. Now you receive an order from
your company CIO, you are asked to have the database administrators allowed to perform
administrative tasks on the database servers. In addition, you should make sure that the
database administrators must be prevented from performing administrative tasks on other
servers.
In order to achieve the goals above, what action would be performed?
A. In order to achieve the goals above, Group_Admins would be added to the Domain Admins
global group.
B. In order to achieve the goals above, Group_Admins would be added to the Server
Operators domain local group.
C. In order to achieve the goals above, a group policy would be deployed to the DBAccount
OU.
D. In order to achieve the goals above, a group policy would be deployed to the Group OU.
Answer: C
A. Network Access Protection (NAP) with the use of 802.1x enforcement would be
implemented to accomplish your tasks.
B. To accomplish your tasks, a Network Policy Server (NPS) would be implemented and IPsec
would be enabled on the domain controllers.
C. To accomplish your tasks, a Network Policy Server (NPS) would be implemented and
Remote Authentication Dial-In User Service (RADIUS) authentication would be enabled on the
managed switches.
D. Network Access Protection (NAP) with the use of DHCP enforcement would be
implemented to accomplish your tasks.
Answer: A
Question: 6
You are a Windows Server 2008 professional who has two years experience in using Windows
Server 2008. You also have experience in using Windows Vista and the Windows server
system. Your routine job is responsible for the server builds and configuration. Currently you
are employed as a sever administrator in an international company which is named Wiikigo.
You are in charge of the company network and provide technical support for your company.
There is a single Active Directory domain and a branch office named Paris contained in your
network. In Paris office, there is a Read-only Domain Controller (RODC) named RODC1. The
user accounts for administrators are contained in a global group named RODC1-group. In
Paris office, the client computers and servers are managed by administrators.
Now you get an order from the CIO, you are asked to find out a solution for delegating control
of RODC1. According to the requirements of the CIO, the members of the Branch1-admins
group must be allowed to manage RODC1 and Windows Update should be used to change
device drivers and install operating system updates. In addition, the Active Directory objects
must be prevented from being modified by the RODC1-group. What is more, rights on RODC1
only should be provided to the RODC1-group. Which solution below would be used to
accomplish your tasks?
A. The solution of moving the RODC1 computer object to a new organizational unit (OU)
named RODC1-servers and granting Full Control permission on the Branch1-servers OU to
the RODC1-group group would be used to accomplish your tasks.
B. The solution of adding the RODC1-group global group to the Server Operators domain local
group would be used to accomplish your tasks.
C. The solution of adding the RODC1-group global group to the Administrators local group of
RODC1 would be used to accomplish your tasks.
D. The solution of granting Full Control permission on the RODC1 computer object in the
domain to the Branch1-admins group would be used to accomplish your tasks.
Answer: C
Question: 7
You want to create an IPv6 Reverse Lookup zone that holds PTR records for hosts with IPv6
addresses in the fec0::eefd/64 subnet. Your DNS server is called Denver and it is also a
domain controller. DNS on your domain is AD DS integrated. You use Remote Desktop to
connect to Denver and run the Command Console as an administrator. What command do you
enter to create the Reverse Lookup zone?
Answer: B
Question: 8
Which of the following steps must you take before deploying autoenrollment?(Each correct
answer presents part of the solution. Choose two.)
Answer: A, B
Question: 9
Choose the quorum model recommended for clusters with an odd number of nodes.
Answer: B
Question: 10
Your network contains servers that run either Windows Server 2003 or Windows Server 2008.
All client computers run Windows Vista. Your company has a public key infrastructure (PKI)
that includes an offline root certification authority (CA) and two enterprise subordinate CAs. All
CAs run Windows Server 2003. You publish the certificates to the user accounts and the
computer accounts in Active Directory. Your company creates an engineering department. You
need to plan a PKI solution for the Windows Vista client computers and the Windows Server
2008 servers that are in the engineering department. Your solution must meet the following
requirements:
The certificates must support Suite B hashing and encryption algorithms.
The private keys must be stored in Active Directory.
The administrative effort to manage certificates for your network must be minimized.
What should you include in your plan?
Answer: A
Question: 11
Your company has 100 physical servers that have 64-bit hardware and that run Windows
Server 2003. You need to consolidate the 100 physical servers into 30 physical servers that
run Windows Server 2008. You must achieve this goal while meeting the following
requirements:
Maximize resource utilization
Use existing hardware and software
Support 64-bit virtual machines
Maintain separate services among the servers
What should you do?
A. Consolidate services across the physical machines and create the necessary host (A)
records.
B. Install Microsoft Virtual PC and convert the physical machines into virtual machines.
C. Install Microsoft Virtual Server 2005 R2 and convert the physical machines into virtual
machines.
Answer: D
Question: 12
Your company has a branch office that contains a Windows Server 2008 server. The server
runs Windows Server Update Services (WSUS). The company opens four new satellite offices.
Each satellite office connects to the branch office by using a dedicated WAN link. You need to
design a strategy for patch management that meets the following requirements:
WSUS updates are approved from a central location. WAN traffic is minimized between the
branch office and the satellite offices. What should you include in your design
A. In each satellite office, install a WSUS server. Configure each satellite office WSUS server
as a replica of the branch office WSUS server.
B. In each satellite office, install a WSUS server. Configure each satellite office WSUS server
as an autonomous server that synchronizes to the branch office WSUS server.
C. On the branch office WSUS server, create a computer group for each satellite office. Add
the client computers in each satellite office to their respective computer groups.
D. For each satellite office, create an organizational unit (OU). Create and link a Group Policy
object (GPO) to each OU. Configure different schedules to download updates from the branch
office WSUS server to the client computers in each satellite office.
Answer: A
Question: 13
Your network consists of a single Active Directory domain. All domain controllers run Windows
Server 2008. There are five servers that run Windows Server 2003. The Windows Server 2003
servers have the Terminal Server component installed. A firewall server runs Microsoft Internet
Security and Acceleration (ISA) Server 2006. All client computers run Windows Vista. You plan
to give remote users access to the Terminal Server servers.
You need to create a remote access strategy for the Terminal Server servers that meets the
following requirements:
Minimizes the number of open ports on the firewall server
Encrypts all remote connections to the Terminal Server servers
Prevents network access to client computers that have Windows Firewall disabled
What should you do?
A. Implement port forwarding on the ISA Server. Implement Network Access Quarantine
Control on the ISA Server.
B. Upgrade a Windows Server 2003 server to Windows Server 2008. On the Windows Server
2008 server, implement the Terminal Services Gateway (TS Gateway) role, and implement
Network Access Protection (NAP).
C. Upgrade a Windows Server 2003 server to Windows Server 2008. On the Windows Server
2008 server, implement the Terminal Services Gateway (TS Gateway) role, and configure a
Answer: B
Question: 14
Your network consists of a single Active Directory domain. Your network contains 10 servers
and 500 client computers. All domain controllers run Windows Server 2008. A Windows Server
2008 server has Terminal Services installed. All client computers run Windows XP Service
Pack 2. You plan to deploy a new line-of-business application. The application requires
desktop themes to be enabled.
You need to recommend a deployment strategy that meets the following requirements:
Only authorized users must be allowed to access the application.
Authorized users must be able to access the application from any client computer.
Your strategy must minimize changes to the client computers.
Your strategy must minimize software costs.
What should you recommend?
A. Upgrade all client computers to Windows Vista. Deploy the application to all client
computers by using a Group Policy object (GPO).
B. Upgrade all client computers to Windows Vista. Deploy the application to the authorized
users by using a Group Policy object (GPO).
C. Deploy the Remote Desktop Connection (RDC) 6.0 software to the client computers. Install
the application on the terminal server. Implement Terminal Services Session Broker (TS
Session Broker).
D. Deploy the Remote Desktop Connection (RDC) 6.0 software to the client computers.
Enable the Desktop Experience feature on the terminal server. Install the application on the
terminal server.
Answer: D
Question: 15
Your company plans to deploy eight file servers that run Windows Server 2008. All file servers
will connect to Ethernet switches.
You need to plan a data storage solution that meets the following requirements:
Allocates storage to the servers as needed
Utilizes the existing network infrastructure
Maximizes performance
Maximizes fault tolerance
Which actions should you include in your plan?
A. Install Windows Server 2008 Datacenter on each server. Deploy the servers in a failover
Answer: A
Question: 16
Your network contains three servers that run Windows 2000 Server. Each server has a custom
application installed. The applications:
Are incompatible with each other
Are incompatible with Windows Server 2008
Consume less than 10 percent of the system resources
A company policy states that all new physical servers must run Windows Server 2008.
You need to plan the migration of the applications to new Windows Server 2008 servers. You
want to achieve this goal while minimizing hardware costs.
What actions should you include in your plan?
A. Deploy three new servers that run Windows Server 2008 Standard Edition. Configure
Windows 2000 compatibility mode for each application.
B. Deploy one new server that runs Windows Server 2008 Datacenter Edition. Install the
Desktop Experience feature.
C. Deploy one new server that runs Windows Server 2008 Enterprise Edition. Install the
Windows System Resource Manager (WSRM) feature on the new server.
D. Deploy one new server that runs Windows Server 2008 Enterprise Edition. Install the
Hyper-V feature on the new server. Create three child virtual machines.
Answer: D
Question: 17
You need to recommend a Windows Server 2008 server configuration that meets the following
requirements:
Supports the installation of Microsoft SQL Server 2005
Provides redundancy for SQL services if a single server fails
What should you recommend?
A. Install a Server Core installation of Windows Server 2008 Enterprise Edition on two servers.
Configure failover clusters on the two servers.
B. Install a full installation of Windows Server 2008 Standard Edition on two servers. Configure
Answer: D
Question: 18
CertIdea.com has employed you as an Enterprise administrator. The CertIdea.com network
consists of a single Active Directory domain named CertIdea.com. The CertIdea.com network
contains 250 Windows Server 2003 that uses 64-bit hardware. Half the client computers run
Windows XP Professional, and the rest run Windows Vista. You have received instructions
from the CIO to combine the 250 servers in to 50 Windows Server 2008 servers. However, you
need to make use of the hardware and software Support 64-bit child virtual machines of the
Windows Server 2003 server. You also need to make the most of the resource utilization and
you need to keep the services separate on the 50 Windows Server 2008 servers.
What should you do?
A. The best option is to install the Hyper-V feature on 50 Windows Server 2008 servers and
change the servers into virtual machines.
B. The best option is to install the Windows System Resource Manager (WSRM).
C. The best option is to install a two-node failover cluster after consolidating services across to
the 50 Windows Server 2008 servers.
D. The best option is to make use a 64-bit version of Windows Server 2008 Datacenter Edition.
You should thereafter change the physical machines into virtual machines.
Answer: A
Question: 19
CertIdea.com has employed you as an Enterprise administrator. The CertIdea.com network
consists of a single Active Directory domain named CertIdea.com. CertIdea.com contains a
Windows Server 2008 server named CERTIDEA-SR11 that has the DHCP installed. You have
received instructions from the CIO to plan the automated deployment of the following:Support
the deployments of Windows Vista and Windows Server 2008.Pre-boot Execution
Environment (PXE) network adapter should be supported on the computers.Reduce the
servers installed.
What should you do?
A. The best option is to make use of a new server and install the Windows Automated
Installation Kit (WAIK).
B. The best option is to make use Multiple Activation Key (MAK) Independent Activation and
Windows Deployment Services (WDS).
C. The best option is to use of Key Management Service (KMS).
Answer: D
Question: 20
You work as the network administrator at CertIdea.com. The CertIdea.com network consists of
a single Active Directory forest named CertIdea.com. The CertIdea.com network servers run
Windows Server 2008 and the client computers run Microsoft Windows Vista. CertIdea.com is
planning to install a new child domain named us.CertIdea.com that will have two domain
controllers that will host the DNS server role. All the employees at CertIdea.com and the
computers at the child domain will be members of us.CertIdea.com. However, the CIO wants
us.CertIdea.com to have the following criteria:Fully qualified domain names should be used to
access resources in the root domain and child domain.Name resolution services should be
implemented in the event of a server failure.New DNS servers should be automatically
recognize when added to or removed from the CertIdea.com domain.
What should you do?
A. The best option is to use Public Key Policies at that domain for us.CertIdea.com on the two
domain controllers.
B. The best option is to use Microsoft Virtual Server 2005 R2 on both the domain controllers
and on the other domain controller you should create an Active Directory integrated zone for
us.CertIdea.com.
C. The best option is to use Network Access Protection (NAP), on both the domain controllers
and on the other domain controller you should create an Active Directory integrated zone for
us.CertIdea.com.
D. The best option is to create an Active Directory Integrated zone for us.CertIdea.com and an
Active Directory Integrated stub zone for CertIdea.com, on one of the domain controller.
Answer: D
Question: 21
CertIdea.com has employed you as a Enterprise administrator. The CertIdea.com network
consists of a single Active Directory domain named CertIdea.com. All servers on the
CertIdea.com network run Windows Server 2008. Half the client computers run Windows XP
Professional, and the rest run Windows Vista. CertIdea.com has headquarters in London and
branch offices in Paris, Berlin and Milan. The headquarters and the branch offices contains
Active Directory domain controller. You have received instructions from the CIO to create a
DNS infrastructure with the following criteria:The client computers must register DNS names
within their respective offices.The client computers need to resolve names for hosts in all
offices.
What should you do?
A. The best option is to use conditional forwarder for all the offices.
Answer: D
Question: 22
You are the newly appointed an Enterprise administrator at CertIdea.com. The CertIdea.com
network consists of a single Active Directory domain named CertIdea.com. All servers on the
CertIdea.com network run Windows Server 2008 and all client computers run Windows Vista.
The domain controllers at CertIdea.com run Windows Server 2008. You have received
instructions from the CIO to implement a network access solution with the following criteria:
Client computers with the recent service packs can access the network, if not it should be
redirected to a specific Web site.
What should you do?
A. The best option is to use the Event Trace Sessions Data Collector Set.
B. The best option is to use multiple downstream servers
C. The best option is to use Windows System Resource Manager (WSRM).
D. The best option is to use Network Access Protection (NAP)
Answer: D
Question: 23
CertIdea.com has employed you as an Enterprise administrator. The CertIdea.com network
consists of a single Active Directory domain named CertIdea.com. The CertIdea.com network
servers run Windows Server 2008 and the client computers run Microsoft Windows Vista.
CertIdea.com contains three Network Policy Server (NPS) servers named CERTIDEA-SR11,
CERTIDEA-SR12 and CERTIDEA-SR13. The Remote Authentication Dial-In User Service
(RADIUS) server is installed on these servers. CERTIDEA-SR11 is configured to run Microsoft
SQL Server 2005. Furthermore, CertIdea.com contains 20 wireless access points that is set up
as RADIUS client. You have received instructions from the CIO to implement a method to audit
all access to the wireless access points with the following criteria:Data should be stored in a
central location.It should also record all RADIUS attributes.It should also record all RADIUS
vendor-specific attributesData in a format that is straightforward to query
What should you do? (Choose TWO. Each answer forms a part of the solution.)
A. The best option is to install Microsoft Windows Reliability and Performance Monitor.
B. The best option is to audit for logon events on the CERTIDEA-SR11.
C. The best option is to set up RADIUS accounting by using SQL logging on each server
D. The best option is to set up the Windows System Resource Manager (WSRM).
E. The best option is to set up users containers.
F. The best option is to forward all security events from CERTIDEA-SR12 and
Answer: C, F
Question: 24
You need to recommend a solution for promoting the RODC in the new branch office. What
should you include in the recommendation?
Answer: C
Question: 25
You need to recommend a solution for improving the automated deployment of servers. The
solution must meet the company's technical requirements.
What should you include in the recommendation?
Answer: A
Question: 26
You need to recommend a solution for users in the branch office to access files in the main
office. What should you include in the recommendation?
Answer: B
Question: 27
You need to recommend a data management solution that meets the company's technical
requirements. What should you include in the recommendation?
A. DFS Management
B. File Server Resource Manager (FSRM)
Answer: C
Question: 28
You need to recommend a solution for managing the service accounts for SQL1 and SQL2.
The solution must meet the company's security requirements.
What should you include in the recommendation?
Answer: D
Question: 29
You need to recommend an RD Gateway configuration that meets the company's technical
requirements. What should you recommend?
A. Create two Remote Desktop connection authorization policies (RD CAPs) and one Remote
Desktop resource authorization policy (RD RAP).
B. Create one Remote Desktop connection authorization policy (RD CAP) and two Remote
Desktop resource authorization policies (RD RAPs).
C. Create one Remote Desktop resource authorization policy (RD RAP) and deploy the
Remote Desktop Connection Broker (RD Connection Broker) role service.
D. Create one Remote Desktop connection authorization policy (RD CAP) and deploy the
Remote Desktop Connection Broker (RD Connection Broker) role service.
Answer: B
Question: 30
You need to recommend a solution for the file servers that meets the company's technical
requirements. What should you include in the recommendation?
Answer: D