โ† All MCTS 70-640 Flashcard Decks

Professional Standards & Competencies Flashcards

7 cards from real MCTS 70-640 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Professional Standards & Competencies flashcards as text
  1. Which principle of access control is most aligned with Microsoft's recommendation for Active Directory service accounts?

    Answer: Apply the principle of least privilege, granting only the permissions the service requires

    Least privilege limits the blast radius of a compromised service account by restricting it to only the permissions necessary for its function.

  2. A company must comply with PCI-DSS and needs to enforce distinct password complexity requirements for different user groups. What Windows Server 2008 feature best supports this?

    Answer: Fine-Grained Password Policies (Password Settings Objects) applied to global security groups

    Fine-Grained Password Policies allow distinct password and lockout settings to be applied at the group or user level, independent of the domain-wide policy.

  3. According to best practices, where should the PDC Emulator FSMO role be placed in a multi-site environment?

    Answer: On a domain controller in the hub site with the best connectivity to all other sites

    The PDC Emulator handles time synchronization, password changes, and account lockouts, making it critical that it resides in a well-connected, central hub site.

  4. What is the professional standard for monitoring Active Directory replication health in an enterprise environment?

    Answer: Use repadmin /replsummary and repadmin /showrepl regularly, combined with alerting on replication failures

    Regular use of repadmin tools combined with automated alerting ensures replication failures are detected and resolved before they affect directory integrity.

  5. When deploying a Read-Only Domain Controller (RODC) to a branch office, what is the recommended approach for the Password Replication Policy (PRP)?

    Answer: Configure a restricted PRP allowing only branch-user and computer accounts to cache passwords

    A restricted PRP limits cached credentials to only those accounts that regularly authenticate at the branch, reducing exposure if the RODC is compromised.

  6. A forest trust has been established between two organizations. What security measure should be applied to limit which domains within a forest can be accessed via the trust?

    Answer: Enable selective authentication on the forest trust to control resource access per user group

    Selective authentication forces explicit permission grants on resources, preventing any trusted-forest user from automatically accessing resources in the trusting forest.

  7. What is the recommended professional standard for validating that Group Policy is applying correctly after a new GPO deployment?

    Answer: Run gpresult /r or use GPMC's Group Policy Results and Modeling features to verify effective policy

    gpresult and the GPMC's built-in reporting tools provide definitive evidence of which GPOs are applied and in what order, enabling rapid troubleshooting.