← All MCTS 70-640 Flashcard Decks

Case Studies & Practical Application Flashcards

7 cards from real MCTS 70-640 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Case Studies & Practical Application flashcards as text
  1. Contoso Ltd. has a single-domain forest. Users in the Marketing OU report they cannot log on after a new GPO was linked to that OU. The GPO was intended to enforce password complexity. What is the most likely cause?

    Answer: The GPO contains a Deny Logon Locally setting inadvertently applied

    A Deny Logon Locally right in the GPO would prevent affected users from logging on interactively.

  2. Fabrikam needs users in Branch Office A to authenticate even when the WAN link to the main site is down. No writable DC exists in Branch Office A. What should you deploy?

    Answer: A read-only domain controller (RODC)

    An RODC provides local authentication for branch offices while limiting security exposure if the DC is compromised.

  3. Adventure Works has a two-domain forest. A user in domain A needs access to a resource in domain B. The administrator confirms a two-way transitive trust exists. The user still gets 'Access Denied'. What should be checked first?

    Answer: NTFS permissions on the resource in domain B

    Even with a valid trust, the ACL on the resource itself must grant the cross-domain user or their group access.

  4. Northwind Traders runs Windows Server 2008 R2 DCs. They want to enforce a stricter password policy for the Domain Admins group without affecting all users. What feature should they use?

    Answer: Fine-Grained Password Policies (PSOs)

    PSOs (Password Settings Objects) allow different password and lockout policies to be applied to specific users or groups within the same domain.

  5. A client running Windows 7 joined to a domain cannot apply a new GPO that enforces IE proxy settings. The GPO is linked at the domain level with no WMI filters. GPRESULT shows the policy is not applied. What is the most likely reason?

    Answer: The client's computer account is in an OU with 'Block Policy Inheritance'

    Block Policy Inheritance on the OU containing the computer account prevents domain-level GPOs from applying.

  6. Trey Research is merging with Coho Winery. Both companies have separate AD forests. Users from Trey Research must access SharePoint resources in Coho Winery's forest. What trust type should be configured?

    Answer: Forest trust between the two forest root domains

    A forest trust allows all domains in both forests to authenticate across organizational boundaries.

  7. Litware Inc. needs to ensure that deleted AD objects can be recovered without restoring from backup. The forest is at Windows Server 2008 R2 functional level. What feature should be enabled?

    Answer: Active Directory Recycle Bin

    The AD Recycle Bin, introduced in Windows Server 2008 R2, allows restoration of deleted objects with all attributes intact.