TS: Windows Server 2008 Active Directory, Configuring (70-640) — Questions and Answers
Question 1: Management requests a report on which service accounts have passwords that never expire, for a security review. Which PowerShell command retrieves this information?
- Both A and C return the correct results (Correct answer)
- Get-ADUser -Filter {PasswordNeverExpires -eq $true} -Properties PasswordNeverExpires, ServicePrincipalName
- Netuser /domain | findstr /i service
- Dsquery user -pwdneverexpires
Correct answer: Both A and C return the correct results
Both the PowerShell Get-ADUser filter for PasswordNeverExpires and Dsquery with -pwdneverexpires return user accounts with non-expiring passwords, supporting security review reporting.
Question 2: An auditor needs to verify that only authorized administrators have rights to link GPOs to the domain root. Where are these delegation settings reviewed and documented?
- Active Directory Users and Computers > Domain Properties > Security tab
- Secedit /export /cfg report.txt
- Group Policy Management Console > Domain > Delegation tab (Correct answer)
- Auditpol /get /subcategory:'Policy Change'
Correct answer: Group Policy Management Console > Domain > Delegation tab
The Delegation tab on the domain object in GPMC shows which users and groups have permission to link GPOs, providing the auditor with the authorization documentation they require.
Question 3: A junior administrator accidentally ran 'dcpromo /forceremoval' on an active DC without properly demoting it. What is the immediate next step to clean up the AD DS environment?
- Rebuild the DC from a backup
- Seize all FSMO roles to another DC
- Run dcdiag on remaining DCs
- Perform metadata cleanup using ntdsutil (Correct answer)
Correct answer: Perform metadata cleanup using ntdsutil
Force removal leaves the DC's metadata in AD DS; ntdsutil metadata cleanup must be run to remove the stale DC object and associated records.
Question 4: Based on Microsoft's evidence-based guidance for AD DS forests with multiple UPN suffixes, what must be configured so that users can log on with an alternate UPN suffix?
- Add the suffix to the schema naming context
- Add the alternate UPN suffix in Active Directory Domains and Trusts, then assign it to user accounts (Correct answer)
- Configure DNS conditional forwarders for each suffix
- Create a new child domain for each UPN suffix
Correct answer: Add the alternate UPN suffix in Active Directory Domains and Trusts, then assign it to user accounts
Alternate UPN suffixes are registered in Active Directory Domains and Trusts under the forest root, then assigned per-user in the Account tab of their AD object.
Question 5: Which Active Directory feature enables different password and lockout policies for different users or groups within a single domain?
- Security Configuration Wizard
- Password Policy GPO per OU
- Default Domain Policy
- Fine-Grained Password Policy (Correct answer)
Correct answer: Fine-Grained Password Policy
Fine-Grained Password Policies, configured via Password Settings Objects (PSOs), allow multiple password policies within one domain — overcoming the single-policy-per-domain limitation.
Question 6: According to Windows Server 2008 best practice research, what is the recommended approach for AD sites and site links to ensure predictable replication costs?
- Assign lower cost values to faster, more reliable WAN links so the KCC prefers them (Correct answer)
- Assign higher cost values to all links to slow replication
- Use default cost of 100 for all site links regardless of bandwidth
- Disable site link bridging and create direct site links between all sites
Correct answer: Assign lower cost values to faster, more reliable WAN links so the KCC prefers them
Lower cost site links are preferred by the KCC when generating the replication topology, so faster links should receive lower costs to optimize replication paths.
Question 7: A department head wants to know which computers in their OU have not logged into the domain in over 90 days, for an asset review report. Which command identifies these stale computer accounts?
- Get-ADComputer -Filter {LastLogonDate -lt (Get-Date).AddDays(-90)}
- Dsquery computer -inactive 13
- Search-ADAccount -ComputersOnly -AccountInactive -TimeSpan 90.00:00:00
- All of the above are valid approaches (Correct answer)
Correct answer: All of the above are valid approaches
PowerShell Get-ADComputer with a LastLogonDate filter, Dsquery with the -inactive flag (weeks), and Search-ADAccount with -AccountInactive all identify stale computer accounts for asset reporting.
Question 8: How should MCTS 70-640 professionals prioritize identified risks?
- Based on likelihood of occurrence combined with severity of potential impact (Correct answer)
- Alphabetically
- Randomly
- By cost to mitigate only
Correct answer: Based on likelihood of occurrence combined with severity of potential impact
This is fundamental to MCTS 70-640 Exam practice. Based on likelihood of occurrence combined with severity of potential impact represents the professional standard for risk management in the MCTS 70-640 certification framework.
Question 9: Which DNS zone type automatically replicates zone data to all DNS servers running on domain controllers in the forest?
- Standard secondary zone
- Standard primary zone
- Active Directory-integrated zone with ForestDNSZones scope (Correct answer)
- Active Directory-integrated zone with DomainDNSZones scope
Correct answer: Active Directory-integrated zone with ForestDNSZones scope
Forest-wide AD-integrated zones replicate through the ForestDNSZones application partition to all DNS-enabled DCs across the entire forest.
Question 10: In which SYSVOL subfolder are GPO templates stored on a domain controller?
- SYSVOL\domain\Users
- SYSVOL\domain\GPTemplates
- SYSVOL\domain\Policies (Correct answer)
- SYSVOL\domain\Scripts
Correct answer: SYSVOL\domain\Policies
Each GPO's template files (ADM/ADMX files and settings) are stored in SYSVOL\domain\Policies\{GPO-GUID}\ on every domain controller.
Question 11: An administrator must implement an AD DS site topology. What professional guideline determines where site links should be configured?
- Place all domain controllers in the Default-First-Site-Name site for simplicity
- Create a single site link connecting all sites equally regardless of bandwidth
- Create site links that mirror the physical WAN connection paths and their available bandwidth (Correct answer)
- Use manual replication only to avoid site link configuration overhead
Correct answer: Create site links that mirror the physical WAN connection paths and their available bandwidth
Site links should reflect actual WAN paths and bandwidth so the KCC can calculate optimal replication schedules that respect network capacity.
Question 12: What is a DNS delegation, and when is it used?
- Replicating a zone to a secondary server
- Caching root hints locally
- Transferring authority for a subdomain to a different set of DNS servers (Correct answer)
- Forwarding all external queries to an ISP DNS server
Correct answer: Transferring authority for a subdomain to a different set of DNS servers
A delegation passes authority for a child DNS zone to different name servers, allowing decentralized management of the DNS namespace.
Question 13: Which service is responsible for downloading and applying Group Policy on domain members?
- Task Scheduler
- Winlogon process
- Netlogon service
- Group Policy Client service (Correct answer)
Correct answer: Group Policy Client service
The Group Policy Client service (gpsvc) handles the processing and application of Group Policy on Windows Vista/Server 2008 and later.
Question 14: What is the minimum permission required for a user to edit a GPO in Active Directory?
- Domain Admin membership
- Enterprise Admin membership
- Schema Admin membership
- Read and Write permissions on the GPO (Correct answer)
Correct answer: Read and Write permissions on the GPO
A user needs Read and Write (Edit Settings) permissions on the GPO object in Active Directory to modify its settings.
Question 15: Which AD DS feature allows you to prove to auditors that no unauthorized changes were made to the AD schema by comparing against a known-good state?
- AD Snapshot (ntdsutil snapshot) (Correct answer)
- AD Audit Policy with directory service changes
- AD Recycle Bin
- Replication metadata (repadmin /showobjmeta)
Correct answer: AD Snapshot (ntdsutil snapshot)
AD snapshots created with ntdsutil allow you to mount and compare a point-in-time copy of the AD database against the current state without impacting production.
Question 16: An IT director wants a report comparing GPO settings across two organizational units to ensure consistent policy application. Which tool facilitates this comparison for stakeholder review?
- Auditpol /get /category:*
- Netdom query workstation
- Secedit /analyze
- Group Policy Management Console (GPMC) with GPO comparison or Resultant Set of Policy reporting (Correct answer)
Correct answer: Group Policy Management Console (GPMC) with GPO comparison or Resultant Set of Policy reporting
The GPMC supports comparing GPO settings and generating Resultant Set of Policy reports for different OUs, making it ideal for communicating policy consistency to IT directors.
Question 17: What is the value of written documentation in MCTS 70-640 professional communication?
- It is optional
- It creates permanent records, ensures clarity, and provides legal protection (Correct answer)
- It is only for formal occasions
- It replaces verbal communication
Correct answer: It creates permanent records, ensures clarity, and provides legal protection
This is fundamental to MCTS 70-640 Exam practice. It creates permanent records, ensures clarity, and provides legal protection represents the professional standard for communication in the MCTS 70-640 certification framework.
Question 18: Which Group Policy preference item type allows you to map network drives per user?
- Folder Redirection under User Configuration → Windows Settings
- Registry under Computer Configuration → Preferences
- Drive Maps under User Configuration → Preferences → Windows Settings (Correct answer)
- Scripts under Computer Configuration → Windows Settings
Correct answer: Drive Maps under User Configuration → Preferences → Windows Settings
Drive Maps in User Configuration → Preferences → Windows Settings lets you create, update, replace, or delete mapped drives for targeted users.
Question 19: What is the significance of the 'Global Catalog' in a multi-domain Active Directory forest?
- It stores a full writable copy of all objects in the forest
- It is required only for single-domain forests
- It replicates only security group membership data
- It stores a partial read-only copy of all objects in the forest to speed up cross-domain searches (Correct answer)
Correct answer: It stores a partial read-only copy of all objects in the forest to speed up cross-domain searches
The Global Catalog holds a partial, read-only replica of all objects in the forest, enabling fast searches across domains without requiring referrals to each domain's DC.
Question 20: Which event ID in the Windows Security event log indicates a successful user account logon in Windows Server 2008?
- 4648
- 4625
- 4740
- 4624 (Correct answer)
Correct answer: 4624
Event ID 4624 is logged when an account successfully logs on to the system.
Question 21: What is the maximum character length of a pre-Windows 2000 compatible logon name (SAMAccountName) in Active Directory?
- 256 characters
- 128 characters
- 20 characters (Correct answer)
- 64 characters
Correct answer: 20 characters
The SAMAccountName is limited to 20 characters to maintain backward compatibility with older Windows systems.
Question 22: An executive stakeholder wants a high-level view of Active Directory site topology to understand inter-office communication paths. Which tool visualizes AD site links and replication topology?
- Repadmin /showrepl
- Active Directory Sites and Services (Correct answer)
- Active Directory Users and Computers
- Netdom Query
Correct answer: Active Directory Sites and Services
Active Directory Sites and Services provides a graphical representation of site topology, site links, and replication connections that can be used in stakeholder presentations.
Question 23: What is the effect of setting a DNS zone's 'Allow zone transfers' to 'Only to servers listed on the Name Servers tab'?
- Forces all updates through the PDC emulator
- Allows any server to pull the zone
- Restricts zone transfers to only authoritative secondary DNS servers (Correct answer)
- Disables all zone transfers
Correct answer: Restricts zone transfers to only authoritative secondary DNS servers
Restricting zone transfers to listed name servers prevents unauthorized DNS servers from retrieving zone data, improving security.
Question 24: When delegating control in Active Directory, what is the recommended best practice for applying permissions to OUs?
- Use the Delegation of Control Wizard and assign permissions at the appropriate OU level (Correct answer)
- Apply permissions directly to individual user accounts
- Grant Domain Admin rights to all IT staff who need to manage OUs
- Modify the default AdminSDHolder object to allow broader delegation
Correct answer: Use the Delegation of Control Wizard and assign permissions at the appropriate OU level
The Delegation of Control Wizard provides a structured, least-privilege approach to assigning granular AD permissions at the OU level without granting full admin rights.
Question 25: In Windows Server 2008 DNS, what does enabling 'dynamic updates' set to 'Secure only' enforce?
- Only IPv6 records can be dynamically updated
- Only domain-joined computers authenticated via Kerberos can update their DNS records (Correct answer)
- Only administrators can update DNS records
- Only DCs can register DNS records
Correct answer: Only domain-joined computers authenticated via Kerberos can update their DNS records
Secure dynamic updates restrict DNS record registration to authenticated domain members, preventing rogue machines from poisoning the zone.
Question 26: What must occur before you can convert a Universal security group to a Global group?
- Remove all members from other domains (Correct answer)
- Raise the domain functional level
- Convert it to a Distribution group first
- Remove all nested Universal groups
Correct answer: Remove all members from other domains
Global groups can only contain members from their own domain, so any cross-domain members must be removed before converting a Universal group to Global.
Question 27: Which repadmin command provides a summary of replication success and failure counts for all domain controllers in the forest?
- repadmin /showrepl
- repadmin /syncall
- repadmin /replsummary (Correct answer)
- repadmin /showchanges
Correct answer: repadmin /replsummary
repadmin /replsummary shows a concise table of replication success and failure statistics across all domain controllers.
Question 28: Which wizard in Active Directory Users and Computers allows an administrator to grant specific administrative permissions over an OU to a designated user or group?
- Administrative Template Wizard
- New Object Wizard
- Role Assignment Wizard
- Delegation of Control Wizard (Correct answer)
Correct answer: Delegation of Control Wizard
The Delegation of Control Wizard allows administrators to delegate specific AD tasks over an OU without granting broader domain-level permissions.
Question 29: Under Kerberos authentication standards in Windows Server 2008 AD DS, what is the maximum allowed clock skew between a client and a domain controller by default?
- 1 hour
- 30 minutes
- 10 minutes
- 5 minutes (Correct answer)
Correct answer: 5 minutes
Kerberos requires clocks within 5 minutes of each other by default; exceeding this skew causes authentication failures and is mitigated by AD's time synchronization hierarchy.
Question 30: After promoting a new domain controller, which Netlogon log file confirms that DNS SRV records were successfully registered?
- C:\Windows\ntds\ntds.log
- C:\Windows\System32\dns\dns.log
- C:\Windows\debug\netlogon.log (Correct answer)
- C:\Windows\Logs\dcpromo.log
Correct answer: C:\Windows\debug\netlogon.log
The Netlogon service logs DNS registration activity to netlogon.log in the Windows\debug folder, showing success or failure of SRV record registration.
TS: Windows Server 2008 Active Directory, Configuring (70-640)
The MCTS 70-640 exam validates skills in configuring Windows Server 2008 Active Directory, covering DNS integration, AD infrastructure, directory objects, additional server roles, and environment maintenance. It is part of the Microsoft Certified Technology Specialist (MCTS) track.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds