โ† All MCTS 70-640 Flashcard Decks

MCTS 70 640: Active Directory, Configuring Flashcards

7 cards from real MCTS 70-640 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 MCTS 70 640: Active Directory, Configuring flashcards as text
  1. You need to configure Active Directory to allow users in a child domain to access resources in the parent domain without requiring separate credentials. Which trust type is automatically created between parent and child domains in the same forest?

    Answer: Transitive two-way trust

    Parent-child domains in the same forest are automatically joined by a transitive two-way trust, allowing resource access across the domain hierarchy.

  2. An administrator needs to ensure that the Password Replication Policy (PRP) on an RODC allows a specific user's credentials to be cached. Which tool should be used to add the user to the Allowed RODC Password Replication Group?

    Answer: Active Directory Users and Computers

    Active Directory Users and Computers is used to manage the Allowed RODC Password Replication Group membership on an RODC object.

  3. Your company has a single AD DS forest with three domains. You want to reduce authentication latency between two specific domains that frequently access each other's resources. What should you create?

    Answer: Shortcut trust

    A shortcut trust between two domains in the same forest reduces the authentication path, improving performance for cross-domain resource access.

  4. Which attribute of a user account in Active Directory stores the user's logon name in the format required for pre-Windows 2000 compatibility?

    Answer: sAMAccountName

    The sAMAccountName attribute stores the pre-Windows 2000 logon name (DOMAIN\username format) used for legacy compatibility.

  5. You are configuring AD DS to support multiple UPN suffixes so users can log on with their company email address. Where do you add additional UPN suffixes?

    Answer: Active Directory Domains and Trusts

    Additional UPN suffixes are added in Active Directory Domains and Trusts by right-clicking the root node and selecting Properties.

  6. An RODC in a branch office is being decommissioned. Which step must you perform to ensure the RODC's metadata is cleanly removed from AD DS?

    Answer: Use ntdsutil metadata cleanup

    Ntdsutil metadata cleanup removes lingering AD DS metadata for a domain controller that cannot be demoted normally.

  7. You want to delegate the ability to reset passwords for users in a specific OU to a help desk group without granting them Domain Admin rights. What should you use?

    Answer: Use the Delegation of Control Wizard on the OU

    The Delegation of Control Wizard on a specific OU grants granular permissions, such as password resets, without elevating the group's domain-wide privileges.