โ† All MCTS 70-640 Flashcard Decks

Research & Evidence-Based Practice Flashcards

7 cards from real MCTS 70-640 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Research & Evidence-Based Practice flashcards as text
  1. An auditor requires evidence that privileged group membership changes are being tracked in Windows Server 2008 AD. Which built-in report source captures additions and removals from Domain Admins?

    Answer: Security event log with Audit Account Management enabled

    Enabling 'Audit Account Management' causes Windows to log event 4728/4729 whenever members are added or removed from security groups.

  2. A compliance officer needs to prove that the AD schema has not been modified since a specific date. Which approach provides the best forensic evidence?

    Answer: Check the schemaInfo attribute version number and compare to a known baseline

    The schemaInfo attribute in the schema NC root contains a version number that increments with each schema extension, providing a clear modification indicator.

  3. Which Windows Server 2008 feature allows administrators to configure different password complexity and lockout policies for different groups of users without creating multiple domains?

    Answer: Fine-Grained Password Policies (PSOs)

    Fine-Grained Password Policies use Password Settings Objects (PSOs) stored in the Password Settings Container to apply different policies to specific users or groups.

  4. When gathering evidence of unauthorized LDAP queries against AD, which component should be configured to log search operations?

    Answer: LDAP Interface Events diagnostic logging on the domain controller

    Setting the 'LDAP Interface Events' registry value under NTDS\Diagnostics to level 5 logs all LDAP operations to the Directory Service event log.

  5. An AD DS recovery plan requires documenting the current tombstone lifetime. Where is this value stored in Active Directory?

    Answer: tombstoneLifetime attribute on the Directory Service object in the configuration partition

    The tombstoneLifetime attribute is stored on CN=Directory Service,CN=Windows NT,CN=Services,CN=Configuration,DC=... and defaults to 180 days in Windows Server 2008.

  6. To produce evidence that AD DS backups are occurring within the 60-day tombstone lifetime requirement, which event ID should be monitored in the Application log?

    Answer: Event ID 2089 (backup latency warning)

    Event ID 2089, logged by the AD DS database, warns that a naming context has not been backed up within a percentage of the tombstone lifetime.

  7. A Windows Server 2008 domain administrator needs to research which user last modified a specific AD object attribute. Which tool with which option retrieves this metadata?

    Answer: repadmin /showobjmeta

    repadmin /showobjmeta displays per-attribute replication metadata including the originating DC, USN, and timestamp of the last change for each attribute.