Professional Standards & Competencies Flashcards
7 cards from real MCTS 70-640 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Professional Standards & Competencies flashcards as text
An organization's IT policy requires regular disaster recovery testing for Active Directory. What must be validated during a DR test for AD DS?
Answer: The ability to perform an authoritative restore, verify replication convergence, and confirm FSMO role availability post-recovery
A complete AD DR test must verify authoritative restores, replication health post-recovery, and FSMO role seizure or transfer to confirm full directory service continuity.
According to Microsoft's Active Directory tiered administration model, where should highly privileged accounts such as Schema Admins be used?
Answer: Only when performing specific privileged tasks, and never used for email or browsing
Highly privileged accounts should exist solely for specific administrative tasks and never be exposed to routine workstation use, reducing attack surface.
When planning a Certificate Authority hierarchy for an enterprise PKI integrated with AD DS, what is the recommended two-tier design?
Answer: An offline root CA with one or more online subordinate issuing CAs
Keeping the root CA offline protects the trust anchor while subordinate issuing CAs handle day-to-day certificate operations, limiting exposure of the root key.
A company needs to raise the forest functional level to Windows Server 2008. What is the professional pre-requisite to validate before doing so?
Answer: Confirm all domain controllers in all domains in the forest are running Windows Server 2008 or later
Raising the forest functional level requires every domain controller in every domain of the forest to be running the target OS version or higher.
What professional standard applies when transferring FSMO roles during planned domain controller decommissioning?
Answer: Transfer FSMO roles gracefully while the source DC is online, then verify role ownership before decommissioning
Graceful transfer while the source is online ensures role consistency; seizure should only be used when the original role holder is unavailable.
Which approach best meets the professional standard for securing the SYSVOL share on domain controllers running Windows Server 2008?
Answer: Ensure SYSVOL uses DFSR replication and apply NTFS permissions limiting write access to Domain Admins and SYSTEM
DFSR provides more reliable SYSVOL replication, and restricting NTFS write permissions prevents unauthorized modification of Group Policy templates and logon scripts.
An administrator must implement an AD DS site topology. What professional guideline determines where site links should be configured?
Answer: Create site links that mirror the physical WAN connection paths and their available bandwidth
Site links should reflect actual WAN paths and bandwidth so the KCC can calculate optimal replication schedules that respect network capacity.