TS: Windows Server 2008 Active Directory, Configuring (70-640) — Questions and Answers
Question 1: What is the professional standard for monitoring Active Directory replication health in an enterprise environment?
- Use repadmin /replsummary and repadmin /showrepl regularly, combined with alerting on replication failures (Correct answer)
- Manually check replication once a month
- Rely solely on event log spot-checks by helpdesk staff
- Disable replication monitoring to reduce log noise
Correct answer: Use repadmin /replsummary and repadmin /showrepl regularly, combined with alerting on replication failures
Regular use of repadmin tools combined with automated alerting ensures replication failures are detected and resolved before they affect directory integrity.
Question 2: Management requests a report on which service accounts have passwords that never expire, for a security review. Which PowerShell command retrieves this information?
- Get-ADUser -Filter {PasswordNeverExpires -eq $true} -Properties PasswordNeverExpires, ServicePrincipalName
- Dsquery user -pwdneverexpires
- Netuser /domain | findstr /i service
- Both A and C return the correct results (Correct answer)
Correct answer: Both A and C return the correct results
Both the PowerShell Get-ADUser filter for PasswordNeverExpires and Dsquery with -pwdneverexpires return user accounts with non-expiring passwords, supporting security review reporting.
Question 3: What is the purpose of the Resultant Set of Policy (RSoP) tool in Windows Server 2008?
- To replicate GPOs between domain controllers
- To create new GPOs
- To simulate or view the effective Group Policy settings applied to a user or computer (Correct answer)
- To delete conflicting GPOs
Correct answer: To simulate or view the effective Group Policy settings applied to a user or computer
RSoP reports the net result of all GPOs applied to a specific user or computer, helping administrators troubleshoot policy conflicts.
Question 4: Research shows that bridgehead server failures cause entire site replication to stall. What is the evidence-based best practice to prevent a single point of failure?
- Designate multiple preferred bridgehead servers per site
- Disable ISTG and configure manual connection objects
- Deploy a dedicated bridgehead server with more RAM
- Allow AD to use automatic bridgehead server selection rather than manually designating preferred bridgehead servers (Correct answer)
Correct answer: Allow AD to use automatic bridgehead server selection rather than manually designating preferred bridgehead servers
Manual preferred bridgehead designation creates a single point of failure; automatic selection lets the ISTG elect multiple candidates and failover automatically.
Question 5: Which audit policy category should be enabled to track changes made to Active Directory objects such as user accounts and OUs?
- Audit account management
- Audit directory service access (Correct answer)
- Audit object access
- Audit privilege use
Correct answer: Audit directory service access
Audit directory service access records access to Active Directory objects and is needed to track changes to AD objects.
Question 6: Which Group Policy section contains settings like Account Lockout Policy and Password Policy?
- User Configuration → Administrative Templates → System
- Computer Configuration → Administrative Templates → Network
- Computer Configuration → Windows Settings → Security Settings → Account Policies (Correct answer)
- User Configuration → Windows Settings → Scripts
Correct answer: Computer Configuration → Windows Settings → Security Settings → Account Policies
Account Policies including Password Policy and Account Lockout Policy are found under Computer Configuration → Windows Settings → Security Settings → Account Policies.
Question 7: An executive stakeholder wants a high-level view of Active Directory site topology to understand inter-office communication paths. Which tool visualizes AD site links and replication topology?
- Active Directory Sites and Services (Correct answer)
- Repadmin /showrepl
- Netdom Query
- Active Directory Users and Computers
Correct answer: Active Directory Sites and Services
Active Directory Sites and Services provides a graphical representation of site topology, site links, and replication connections that can be used in stakeholder presentations.
Question 8: A risk assessment identifies that BitLocker recovery keys stored in AD can be read by all Domain Admins. Which control limits access to only the security team?
- Encrypt BitLocker recovery keys using a domain CA before storing them in AD
- Configure a DACL on the computer object to grant Read to the security group and deny all others (Correct answer)
- Delegate Read access on the ms-FVE-RecoveryInformation object only to the security team OU
- Store BitLocker recovery keys in a separate forest controlled by the security team
Correct answer: Configure a DACL on the computer object to grant Read to the security group and deny all others
Configuring a DACL on computer objects to grant Read on ms-FVE-RecoveryInformation only to a specific security group restricts who can retrieve BitLocker recovery keys from AD.
Question 9: What is the maximum character length of a pre-Windows 2000 compatible logon name (SAMAccountName) in Active Directory?
- 20 characters (Correct answer)
- 256 characters
- 128 characters
- 64 characters
Correct answer: 20 characters
The SAMAccountName is limited to 20 characters to maintain backward compatibility with older Windows systems.
Question 10: Which Windows Server 2008 R2 feature allows administrators to manage multiple domains from a single pane using ADUC?
- Forest trust
- Domain connection (Connect to Domain) (Correct answer)
- Trust relationship
- Selective authentication
Correct answer: Domain connection (Connect to Domain)
In ADUC, you can use 'Connect to Domain' or 'Change Domain' to switch between domains and manage objects across multiple domains.
Question 11: An evidence-based approach to AD disaster recovery testing requires verifying authoritative restore capability. Which tool and method performs an authoritative restore of a deleted OU?
- repadmin /restore with the OU distinguished name
- Active Directory Users and Computers 'Restore' context menu
- ntdsutil 'authoritative restore' 'restore subtree <OU DN>' (Correct answer)
- wbadmin restore with /authsysvol flag
Correct answer: ntdsutil 'authoritative restore' 'restore subtree <OU DN>'
ntdsutil's authoritative restore command increments USN values on restored objects so they replicate outbound and overwrite the deletion on other DCs.
Question 12: A penetration test reveals that an expired user account was used to authenticate to a file server three months after termination. Which AD control would have prevented this risk?
- Configuring a fine-grained password policy with a maximum password age
- Enabling automatic account expiration and monitoring via audit logs (Correct answer)
- Moving terminated accounts to a disabled OU with restricted permissions
- Adding terminated user accounts to a Deny Logon GPO
Correct answer: Enabling automatic account expiration and monitoring via audit logs
Setting the account expiration date at termination and monitoring audit events 4625/4768 ensures expired accounts cannot authenticate after the expiry date.
Question 13: What is a Universal Group Membership Caching (UGMC) and when would you enable it?
- Storing user passwords in a local cache on workstations
- Caching DNS results for universal groups
- Caching of universal group memberships on a DC in a site without a global catalog server, to avoid WAN lookups at logon (Correct answer)
- Replicating the global catalog to all DCs in a site
Correct answer: Caching of universal group memberships on a DC in a site without a global catalog server, to avoid WAN lookups at logon
UGMC lets a DC in a remote site cache universal group memberships locally so logon doesn't require a WAN round-trip to a global catalog server.
Question 14: During an AD migration project, the change management board requires weekly status updates on object migration progress. Which approach best provides accurate counts of migrated objects?
- Manually counting objects in ADUC
- Using ADMT (Active Directory Migration Tool) logs and reports (Correct answer)
- Running ping sweeps on migrated computers
- Reviewing DHCP lease logs
Correct answer: Using ADMT (Active Directory Migration Tool) logs and reports
ADMT generates detailed migration logs and reports that document how many users, computers, and groups have been successfully migrated, supporting change board communications.
Question 15: The helpdesk manager wants a report showing all disabled user accounts in the domain for quarterly review. Which PowerShell command produces this list most efficiently?
- Get-ADComputer -Filter * | Where Enabled -eq $false
- Search-ADAccount -AccountDisabled
- Get-ADUser -Filter {Enabled -eq $false} -Properties DisplayName
- Both A and C are correct (Correct answer)
Correct answer: Both A and C are correct
Both Get-ADUser with a filter for disabled accounts and Search-ADAccount -AccountDisabled return lists of disabled user accounts, giving administrators flexibility in reporting.
Question 16: An IT director wants a report comparing GPO settings across two organizational units to ensure consistent policy application. Which tool facilitates this comparison for stakeholder review?
- Group Policy Management Console (GPMC) with GPO comparison or Resultant Set of Policy reporting (Correct answer)
- Secedit /analyze
- Auditpol /get /category:*
- Netdom query workstation
Correct answer: Group Policy Management Console (GPMC) with GPO comparison or Resultant Set of Policy reporting
The GPMC supports comparing GPO settings and generating Resultant Set of Policy reports for different OUs, making it ideal for communicating policy consistency to IT directors.
Question 17: You want to audit all successful and failed logon attempts in your domain. Where in Group Policy should you configure this setting?
- Computer Configuration > Administrative Templates > Windows Components > Logon
- User Configuration > Windows Settings > Security Settings > Audit Policy
- User Configuration > Administrative Templates > System > Audit
- Computer Configuration > Windows Settings > Security Settings > Local Policies > Audit Policy (Correct answer)
Correct answer: Computer Configuration > Windows Settings > Security Settings > Local Policies > Audit Policy
Audit Policy under Computer Configuration > Windows Settings > Security Settings > Local Policies controls logon auditing.
Question 18: Which DNS zone type automatically replicates zone data to all DNS servers running on domain controllers in the forest?
- Standard primary zone
- Active Directory-integrated zone with ForestDNSZones scope (Correct answer)
- Standard secondary zone
- Active Directory-integrated zone with DomainDNSZones scope
Correct answer: Active Directory-integrated zone with ForestDNSZones scope
Forest-wide AD-integrated zones replicate through the ForestDNSZones application partition to all DNS-enabled DCs across the entire forest.
Question 19: In the AGDLP best-practice model for group nesting, what does the letter 'L' represent?
- Link
- Limit
- Level
- Domain Local group (Correct answer)
Correct answer: Domain Local group
AGDLP stands for Accounts → Global groups → Domain Local groups → Permissions; the 'L' represents Domain Local groups where resource permissions are assigned.
Question 20: What command verifies that a domain controller has registered its DNS SRV records correctly?
- nslookup -type=SRV _ldap._tcp.<domain> (Correct answer)
- tracert <dc>
- netstat -an
- ping <domain>
Correct answer: nslookup -type=SRV _ldap._tcp.<domain>
Using nslookup with the SRV type query against _ldap._tcp.<domain> confirms that the DC's LDAP SRV records are present and resolving.
Question 21: What is the purpose of a stub zone in DNS?
- To replicate all DNS records to all domain controllers
- To cache all records from a primary zone
- To contain only NS, SOA, and A records for a zone to resolve names in that zone (Correct answer)
- To block external DNS queries
Correct answer: To contain only NS, SOA, and A records for a zone to resolve names in that zone
A stub zone holds only NS, SOA, and glue A records so the DNS server knows the authoritative servers for that zone.
Question 22: Which DNS record maps an IPv4 address back to a hostname in reverse lookup zones?
- PTR record (Correct answer)
- CNAME record
- A record
- AAAA record
Correct answer: PTR record
PTR (pointer) records exist in reverse lookup zones and map IP addresses to fully qualified domain names for reverse DNS resolution.
Question 23: What is the role of the AD DS Schema Master in a Windows Server 2008 R2 forest?
- It handles all Kerberos authentication requests
- It is the only DC that can make changes to the Active Directory schema (Correct answer)
- It controls all write operations in the domain
- It manages the pool of unique security identifiers
Correct answer: It is the only DC that can make changes to the Active Directory schema
The Schema Master is a forest-wide FSMO role; only the DC holding it can make schema modifications that are then replicated forest-wide.
Question 24: When configuring DNS on a new Windows Server 2008 domain controller, which zone should be created to support AD DS?
- A forward lookup zone for the AD domain (Correct answer)
- A reverse lookup zone only
- An MX-only zone
- A secondary zone pointing to the PDC
Correct answer: A forward lookup zone for the AD domain
A forward lookup zone for the Active Directory domain name is essential so clients and DCs can resolve domain names to IP addresses and locate AD services.
Question 25: What statement regarding Active Directory Lightweight Directory Services is accurate?
- When you install AD LDS it completely reconfigures the operating system
- AD LDS is a total copy of all the files and features of Active Directory
- AD LDS is an application (Correct answer)
- AD LDS is a based on Microsoft SQL Server
Correct answer: AD LDS is an application
Active Directory Lightweight Directory Services (AD LDS) is an application-specific directory service that runs as a standalone service on Windows Server. Unlike full Active Directory Domain Services (AD DS), AD LDS does not require a domain controller or domain membership. It provides directory services to applications without the overhead and infrastructure requirements of a complete Active Directory deployment.
Question 26: After enabling AD Recycle Bin, an IT manager wants to communicate its capabilities to the helpdesk team. Which statement accurately describes the AD Recycle Bin's restoration capability?
- Restored objects are placed in the Lost and Found container by default
- It requires a forest functional level of Windows Server 2003
- It restores deleted objects with all attributes intact, including group memberships, without requiring a restart or authoritative restore (Correct answer)
- It only restores user objects, not groups or OUs
Correct answer: It restores deleted objects with all attributes intact, including group memberships, without requiring a restart or authoritative restore
The AD Recycle Bin, available at Windows Server 2008 R2 forest functional level, restores deleted objects with all linked attributes intact and does not require domain controller restarts.
Question 27: The server manager is a fantastic tool for controlling the majority of your server settings and setup from a single location. Which of the following features of the server manager is used to manage the public key infrastructure?
- WINS Server
- Active Directory Certificate Services (Correct answer)
- Domain Name Service
- Dynamic Host Configuration Server
Correct answer: Active Directory Certificate Services
In Server Manager, the 'Active Directory Certificate Services' role is the designated feature for managing the Public Key Infrastructure (PKI). This role allows administrators to deploy, configure, and manage Certificate Authorities (CAs) within their organization. These CAs are essential for issuing and managing digital certificates, which are critical for secure communication, user and device authentication, and data encryption.
Question 28: When multiple GPOs are linked to the same OU, what determines the order in which they are processed?
- Alphabetical order of GPO names
- Link order configured in GPMC (Correct answer)
- GPO creation date
- GPO file size
Correct answer: Link order configured in GPMC
The link order set in the Group Policy Management Console determines GPO precedence; higher link order numbers are processed first, with lower numbers (higher priority) applied last.
Question 29: Which command-line tool is used to move an Active Directory user object from one OU to another?
- NTDSUTIL
- DSMOVE (Correct answer)
- CSVDE
- REPADMIN
Correct answer: DSMOVE
DSMOVE is the directory service command used to move or rename Active Directory objects, including relocating users between OUs.
Question 30: Which PowerShell cmdlet is used to create a new group object in Active Directory?
- Set-ADGroup
- Add-ADGroup
- New-ADGroup (Correct answer)
- Create-ADGroup
Correct answer: New-ADGroup
New-ADGroup is the correct PowerShell cmdlet for creating Active Directory group objects, following the standard Verb-ADNoun naming convention.
Question 31: A client running Windows 7 joined to a domain cannot apply a new GPO that enforces IE proxy settings. The GPO is linked at the domain level with no WMI filters. GPRESULT shows the policy is not applied. What is the most likely reason?
- GPRESULT does not show policies from the domain level
- The client has a local Group Policy that blocks domain policies
- The GPO requires a minimum Windows 8 client version
- The client's computer account is in an OU with 'Block Policy Inheritance' (Correct answer)
Correct answer: The client's computer account is in an OU with 'Block Policy Inheritance'
Block Policy Inheritance on the OU containing the computer account prevents domain-level GPOs from applying.
Question 32: You need to verify which domain controller holds the RID Master FSMO role in your domain. Which command-line tool provides this information?
- netdom query fsmo (Correct answer)
- nltest /dsgetdc
- dcdiag /test:ridmanager
- repadmin /showrepl
Correct answer: netdom query fsmo
The command 'netdom query fsmo' displays all five FSMO role holders for the current domain and forest.
Question 33: A CIO wants to understand the communication impact if the PDC Emulator FSMO role holder goes offline. Which critical AD function would be most immediately affected?
- Password changes, account lockouts, and time synchronization for the domain would be disrupted (Correct answer)
- All AD replication across sites would halt until the PDC Emulator is restored
- DNS name resolution for all domain resources would stop
- Kerberos ticket granting for all domain users would fail immediately
Correct answer: Password changes, account lockouts, and time synchronization for the domain would be disrupted
The PDC Emulator processes password changes, manages account lockout policy, and acts as the authoritative time source; its loss disrupts these functions most immediately and visibly.
Question 34: What does the 'Block Inheritance' option on an OU do?
- Prevents child OUs from inheriting GPOs from the blocked OU
- Blocks all security settings from being applied
- Disables all GPOs in the domain
- Prevents GPOs from a parent container from applying to the OU (Correct answer)
Correct answer: Prevents GPOs from a parent container from applying to the OU
Block Inheritance stops GPOs linked at parent containers (domain or higher-level OUs) from flowing down to the OU where it is set.
Question 35: A Windows Server 2008 domain administrator needs to research which user last modified a specific AD object attribute. Which tool with which option retrieves this metadata?
- repadmin /showobjmeta (Correct answer)
- adsiedit.msc viewing object properties
- dsquery with -attr
- ldp.exe with a base search
Correct answer: repadmin /showobjmeta
repadmin /showobjmeta displays per-attribute replication metadata including the originating DC, USN, and timestamp of the last change for each attribute.
Question 36: What is the effect of setting a DNS zone's 'Allow zone transfers' to 'Only to servers listed on the Name Servers tab'?
- Restricts zone transfers to only authoritative secondary DNS servers (Correct answer)
- Allows any server to pull the zone
- Forces all updates through the PDC emulator
- Disables all zone transfers
Correct answer: Restricts zone transfers to only authoritative secondary DNS servers
Restricting zone transfers to listed name servers prevents unauthorized DNS servers from retrieving zone data, improving security.
Question 37: What is the default Group Policy refresh interval for computers (excluding domain controllers)?
- 30 minutes
- Every startup only
- 60 minutes
- 90 minutes with a random offset of up to 30 minutes (Correct answer)
Correct answer: 90 minutes with a random offset of up to 30 minutes
By default, computers refresh Group Policy every 90 minutes with a random 0–30 minute offset to prevent all machines from contacting DCs simultaneously.
Question 38: What is the importance of data security in MCTS 70-640 digital applications?
- Security slows down work
- Security is unnecessary for professional data
- Protecting sensitive information from unauthorized access, breaches, and loss is essential (Correct answer)
- Only financial data needs protection
Correct answer: Protecting sensitive information from unauthorized access, breaches, and loss is essential
This is fundamental to MCTS 70-640 Exam practice. Protecting sensitive information from unauthorized access, breaches, and loss is essential represents the professional standard for technology in the MCTS 70-640 certification framework.
Question 39: A compliance officer requires documentation proving that Active Directory backups are current. Which Windows Server Backup feature provides a verifiable backup status report?
- Repadmin /showbackup
- Backup log in Event Viewer under Windows Logs > Application with source Microsoft-Windows-Backup (Correct answer)
- ADUC account properties
- Netlogon.log
Correct answer: Backup log in Event Viewer under Windows Logs > Application with source Microsoft-Windows-Backup
Windows Server Backup writes detailed success and failure events to the Application event log under the Microsoft-Windows-Backup source, providing auditable backup status records.
Question 40: What is a DNS delegation, and when is it used?
- Replicating a zone to a secondary server
- Transferring authority for a subdomain to a different set of DNS servers (Correct answer)
- Forwarding all external queries to an ISP DNS server
- Caching root hints locally
Correct answer: Transferring authority for a subdomain to a different set of DNS servers
A delegation passes authority for a child DNS zone to different name servers, allowing decentralized management of the DNS namespace.
Question 41: After a forest trust is established, the partner organization's IT team needs confirmation the trust is functioning. Which command tests and reports trust authentication status?
- Both A and C provide trust health verification (Correct answer)
- Nltest /sc_verify:<domain>
- Ping <trusted domain>
- Netdom query trust
Correct answer: Both A and C provide trust health verification
Nltest /sc_verify verifies the secure channel to the trusted domain, while Netdom query trust lists existing trusts; together they confirm trust configuration and authentication functionality.
Question 42: A department head wants to know which computers in their OU have not logged into the domain in over 90 days, for an asset review report. Which command identifies these stale computer accounts?
- Get-ADComputer -Filter {LastLogonDate -lt (Get-Date).AddDays(-90)}
- Dsquery computer -inactive 13
- Search-ADAccount -ComputersOnly -AccountInactive -TimeSpan 90.00:00:00
- All of the above are valid approaches (Correct answer)
Correct answer: All of the above are valid approaches
PowerShell Get-ADComputer with a LastLogonDate filter, Dsquery with the -inactive flag (weeks), and Search-ADAccount with -AccountInactive all identify stale computer accounts for asset reporting.
Question 43: What is reflective practice in MCTS 70-640 Exam professional development?
- Only reflecting on successes
- Systematically examining experiences to gain insight and improve future practice (Correct answer)
- Avoiding past mistakes
- Writing personal diaries
Correct answer: Systematically examining experiences to gain insight and improve future practice
This is fundamental to MCTS 70-640 Exam practice. Systematically examining experiences to gain insight and improve future practice represents the professional standard for practical in the MCTS 70-640 certification framework.
Question 44: In what order are Group Policy Objects (GPOs) applied in Active Directory?
- OU, Domain, Site, Local
- Local, Site, Domain, OU (Correct answer)
- Domain, Site, OU, Local
- Site, Domain, OU (local applied last)
Correct answer: Local, Site, Domain, OU
GPOs are applied in LSDOU order: Local, Site, Domain, then Organizational Unit, with later policies able to override earlier ones.
Question 45: What is a conditional forwarder in DNS?
- A DNS server that forwards queries for a specific domain to designated servers (Correct answer)
- A secondary zone that forwards updates to the primary
- A forwarder that strips DNSSEC signatures
- A forwarder that only works during business hours
Correct answer: A DNS server that forwards queries for a specific domain to designated servers
A conditional forwarder directs queries for a specific DNS namespace to particular DNS servers instead of using the standard forwarder.
Question 46: Management wants a weekly summary of failed logon attempts across the domain. Which audit policy category must be enabled to collect this data for the report?
- Audit Account Logon Events (Correct answer)
- Audit System Events
- Audit Object Access
- Audit Policy Change
Correct answer: Audit Account Logon Events
Enabling 'Audit Account Logon Events' captures authentication attempts on domain controllers, providing the data needed for failed logon summary reports.
Question 47: A company requires that password changes in Active Directory meet complexity requirements. Which Group Policy setting enforces this rule?
- Enforce password history
- Minimum password length
- Password must meet complexity requirements (Correct answer)
- Account lockout threshold
Correct answer: Password must meet complexity requirements
'Password must meet complexity requirements' enforces rules such as mixed case, numbers, and special characters in passwords.
Question 48: Which tool allows an administrator to perform an authoritative restore of accidentally deleted AD objects?
- wbadmin start recovery
- dcpromo /forceremoval
- repadmin /syncall
- ntdsutil with authoritative restore (Correct answer)
Correct answer: ntdsutil with authoritative restore
Ntdsutil is used in Directory Services Restore Mode to mark objects as authoritative so they replicate back to other DCs.
Question 49: Which event ID in the Windows Security event log indicates a successful user account logon in Windows Server 2008?
- 4740
- 4625
- 4624 (Correct answer)
- 4648
Correct answer: 4624
Event ID 4624 is logged when an account successfully logs on to the system.
Question 50: A branch office manager requests to be notified when their site's domain controller goes offline. Which Windows feature enables proactive DC availability monitoring and notification?
- DFS replication conflict reporting
- System Center Operations Manager (SCOM) or configuring Windows event forwarding with availability monitors (Correct answer)
- DHCP failover notifications
- Active Directory-integrated DNS scavenging alerts
Correct answer: System Center Operations Manager (SCOM) or configuring Windows event forwarding with availability monitors
SCOM or Windows event forwarding with custom availability monitors provides automated alerting when a domain controller stops responding, enabling proactive communication with branch managers.
Question 51: Which service is responsible for downloading and applying Group Policy on domain members?
- Group Policy Client service (Correct answer)
- Task Scheduler
- Winlogon process
- Netlogon service
Correct answer: Group Policy Client service
The Group Policy Client service (gpsvc) handles the processing and application of Group Policy on Windows Vista/Server 2008 and later.
Question 52: What does the DNS TTL value control?
- The replication interval between AD-integrated DNS zones
- The maximum number of DNS queries per second
- How long a zone transfer takes
- How long a resolver caches a DNS record before requesting a fresh copy (Correct answer)
Correct answer: How long a resolver caches a DNS record before requesting a fresh copy
TTL (Time to Live) specifies in seconds how long a DNS record can be cached by resolvers before they must query the authoritative server again.
Question 53: Which Windows Server 2008 R2 feature allows you to install a domain controller without local administrator intervention at the remote site?
- Unattended dcpromo with answer file
- Staged RODC installation (Correct answer)
- BitLocker-protected promotion
- Server Core promotion
Correct answer: Staged RODC installation
Staged RODC installation lets an administrator pre-create the RODC computer account in AD, then delegate installation to a non-admin local user at the branch site.
Question 54: Which tool is used to manually register DNS SRV records for a domain controller on Windows Server 2008?
- dcdiag /fix
- ipconfig /registerdns (Correct answer)
- nltest /dsregdns
- net logon restart
Correct answer: ipconfig /registerdns
Running 'ipconfig /registerdns' forces the DNS client and Netlogon service to re-register all DNS records for the domain controller.
Question 55: You have two servers, Server1 and Server2, respectively. Windows Server 2008 is used by both servers. R2. Enterprise root certification authority (CA) configuration is set up on Server1. <br> On Server2, you set up the Online Responder role service. <br> Server1 must be set up to handle the Online Responder. <br> What ought you to do?
- Import the enterprise root CA certificate.
- Configure the Certificate Revocation List Distribution Point extension.
- Configure the Authority Information Access (AIA) extension. (Correct answer)
- Add the Server2 computer account to the CertPublishers group.
Correct answer: Configure the Authority Information Access (AIA) extension.
To enable an Online Responder (OCSP) to function correctly with a Certification Authority (CA), the CA must be configured to include the Online Responder's URL in the Authority Information Access (AIA) extension of issued certificates. This configuration allows clients to discover and use the Online Responder to check the revocation status of certificates. Without this, clients wouldn't know where to find the OCSP service.
Question 56: Which Windows Server 2008 R2 AD DS tool helps you identify stale user and computer accounts that have not logged in within a specified number of days for compliance cleanup?
- repadmin
- dsquery (Correct answer)
- Active Directory Administrative Center
- ntdsutil
Correct answer: dsquery
The 'dsquery user -inactive <weeks>' command identifies accounts that have not logged on within the specified number of weeks.
Question 57: A risk scenario involves an insider threat where a help desk technician resets passwords for executives and uses the credentials. Which AD control provides a detective control for this behavior?
- Enable Kerberos armoring (FAST) for executive accounts
- Use Protected Users group to prevent help desk from resetting executive passwords
- Configure fine-grained password policies to require executives to change passwords immediately
- Audit account management events to log password reset actions with the initiator's identity (Correct answer)
Correct answer: Audit account management events to log password reset actions with the initiator's identity
Auditing account management events (event 4723/4724) records who reset a password, providing a detective control to identify insider abuse of password reset privileges.
Question 58: Which attribute of a user account in Active Directory stores the user's logon name in the format required for pre-Windows 2000 compatibility?
- cn
- distinguishedName
- sAMAccountName (Correct answer)
- userPrincipalName
Correct answer: sAMAccountName
The sAMAccountName attribute stores the pre-Windows 2000 logon name (DOMAIN\username format) used for legacy compatibility.
Question 59: A compliance officer asks you to produce a report showing all changes made to user account properties in the past week. Which log should you review?
- Directory Service event log
- Application event log
- System event log
- Security event log with Audit Account Management enabled (Correct answer)
Correct answer: Security event log with Audit Account Management enabled
With Audit Account Management enabled, the Security event log records all changes to user accounts including attribute modifications.
Question 60: At what minimum domain functional level must a domain operate to support Password Settings Objects (PSOs) for fine-grained password policies?
- Windows Server 2003
- Windows Server 2008 (Correct answer)
- Windows Server 2012
- Windows Server 2000 Native
Correct answer: Windows Server 2008
Fine-Grained Password Policies using PSOs require the domain functional level to be set to Windows Server 2008 or higher.
Question 61: Which wizard in Active Directory Users and Computers allows an administrator to grant specific administrative permissions over an OU to a designated user or group?
- Administrative Template Wizard
- Delegation of Control Wizard (Correct answer)
- Role Assignment Wizard
- New Object Wizard
Correct answer: Delegation of Control Wizard
The Delegation of Control Wizard allows administrators to delegate specific AD tasks over an OU without granting broader domain-level permissions.
Question 62: What is the minimum permission required for a user to edit a GPO in Active Directory?
- Enterprise Admin membership
- Read and Write permissions on the GPO (Correct answer)
- Schema Admin membership
- Domain Admin membership
Correct answer: Read and Write permissions on the GPO
A user needs Read and Write (Edit Settings) permissions on the GPO object in Active Directory to modify its settings.
Question 63: What is the primary purpose of an Organizational Unit (OU) in Active Directory?
- To define a security boundary within the forest
- To organize objects and delegate administrative control (Correct answer)
- To establish inter-domain trust relationships
- To create separate DNS namespaces per department
Correct answer: To organize objects and delegate administrative control
OUs serve two main purposes: logically organizing directory objects and enabling granular delegation of administrative control without granting domain-wide rights.
Question 64: A technician at City Power & Light seizes the RID Master role because the original holder crashed and cannot be recovered. Two weeks later, the original DC is restored. What must be done before bringing the old DC back online?
- The restored DC must be demoted or its AD database discarded before rejoining (Correct answer)
- Transfer the RID Master role back to the restored DC using ADUC
- Run netdom resetpwd on the restored DC to sync its machine account
- Nothing; AD will automatically resolve the duplicate FSMO holder
Correct answer: The restored DC must be demoted or its AD database discarded before rejoining
Bringing a seized FSMO holder back online causes dual FSMO conflict; the old DC must be demoted or kept permanently offline.
Question 65: A risk assessment identifies that users can enumerate all objects in Active Directory via anonymous LDAP queries. Which setting eliminates this risk?
- Disable the LDAP service on all domain controllers
- Set the 'dsHeuristics' attribute to disable anonymous LDAP operations (Correct answer)
- Configure LDAP signing to require signing only
- Enable LDAP over SSL (LDAPS) on port 636
Correct answer: Set the 'dsHeuristics' attribute to disable anonymous LDAP operations
Setting the dsHeuristics attribute (specifically bit 7) disables anonymous LDAP searches, preventing unauthenticated enumeration of directory objects.
Question 66: How should an MCTS 70-640 professional present complex information to non-experts?
- Provide written reports only
- Translate into accessible language, use visuals, and check for understanding (Correct answer)
- Use full technical terminology
- Skip complex topics entirely
Correct answer: Translate into accessible language, use visuals, and check for understanding
This is fundamental to MCTS 70-640 Exam practice. Translate into accessible language, use visuals, and check for understanding represents the professional standard for communication in the MCTS 70-640 certification framework.
TS: Windows Server 2008 Active Directory, Configuring (70-640)
The MCTS 70-640 exam validates skills in configuring Windows Server 2008 Active Directory, covering DNS integration, AD infrastructure, directory objects, additional server roles, and environment maintenance. It is part of the Microsoft Certified Technology Specialist (MCTS) track.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds