70-648 pdf(76 to 90) for examinee: Mar 2016 Edition

High quality of 70-648 download materials and pdf for Microsoft certification for IT candidates, Real Success Guaranteed with Updated 70-648 pdf dumps vce Materials. 100% PASS Today!

2016 Mar 70-648 Study Guide Questions:

Q76. Your network contains a DNS server named Server1 that runs Windows Server 2008 R2. Root hints for 

Server1 are configured as shown in the exhibit. (Click the Exhibit button.) 


You need to add root hints to Server1. 

What should you do first? 

A. Disable recursion. 

B. Delete the "." (root) zone. 

C. Restart the DNS Server service. 

D. Remove all conditional forwarders. 

Answer: B


Q77. Your company has an Active Directory domain. All servers run Windows Server 2008 R2. Your company uses an Enterprise Root certification authority (CA) and an Enterprise Intermediate CA. 

The Enterprise Intermediate CA certificate expires. 

You need to deploy a new Enterprise Intermediate CA certificate to all computers in the domain. 

What should you do? 

A. Import the new certificate into the Intermediate Certification Store on the Enterprise Root CA server. 

B. Import the new certificate into the Intermediate Certification Store on the Enterprise Intermediate CA server. 

C. Import the new certificate into the Intermediate Certification Store in the Default Domain Controllers group policy object. 

D. Import the new certificate into the Intermediate Certification Store in the Default Domain group policy object. 

Answer: D


Q78. Your network consists of a single Active Directory domain. The domain contains a server named Server1 that runs Windows Server 2008 R2. All client computers run Windows 7. All computers are members of the Active Directory domain. You assign the Secure Server (Require Security) IPsec policy to Server1 by using a Group Policy object (GPO). Users report that they fail to connect to Server1. 

You need to ensure that users can connect to Server1. All connections to Server1 must be encrypted. 

What should you do? 

A. Restart the IPsec Policy Agent service on Server1. 

B. Assign the Client (Respond Only) IPsec policy to Server1. 

C. Assign the Server (Request Security) IPsec policy to Server1. 

D. Assign the Client (Respond Only) IPsec policy to all client computers. 

Answer: D


Q79. Your network contains an Active Directory forest. The forest contains two domains. You have a standalone root certification authority (CA). On a server in the child domain, you run the Add Roles Wizard and discover that the option to select an enterprise CA is disabled. 

You need to install an enterprise subordinate CA on the server. 

What should you use to log on to the new server? 

A. an account that is a member of the Certificate Publishers group in the child domain 

B. an account that is a member of the Certificate Publishers group in the forest root domain 

C. an account that is a member of the Schema Admins group in the forest root domain 

D. an account that is a member of the Enterprise Admins group in the forest root domain 

Answer: D


Q80. Your network contains a single Active Directory domain. All servers run Windows Server 2008 R2. You deploy a new server that runs Windows Server 2008 R2. The server is not connected to the internal network. 

You need to ensure that the new server is already joined to the domain when it first connects to the internal network. 

What should you do? 

A. From a domain controller, run sysprep.exe and specify the /oobe parameter. From the new server, run sysprep.exe and specify the /generalize parameter. 

B. From a domain controller, run sysprep.exe and specify the /generalize parameter. From the new server, run sysprep.exe and specify the /oobe parameter. 

C. From a domain-joined computer, run djoin.exe and specify the /provision parameter. From the new server, run djoin.exe and specify the /requestodj parameter. 

D. From a domain-joined computer, run djoin.exe and specify the /requestodj parameter. From the new server, run djoin.exe and specify the /provision parameter. 

Answer: C


70-648 free practice questions

Up to the immediate present 70-648 free practice questions:

Q81. Your company has a main office and two branch offices that are connected by WAN links. The main office runs the DNS Server service on three domain controllers. The zone for your domain is configured as an Active Directory-integrated zone. Each branch office has a single member server that hosts a secondary zone for the domain. The DNS servers in the branch offices use the main office DNS server as the DNS Master server for the zone. 

You need to minimize DNS zone transfer traffic over the WAN links. 

What should you do? 

A. Decrease the Retry Interval setting in the Start of Authority (SOA) record for the zone. 

B. Decrease the Refresh Interval setting in the Start of Authority (SOA) record for the zone. 

C. Increase the Refresh Interval setting in the Start of Authority (SOA) record for the zone. 

D. Disable the netmask ordering option in the properties of the DNS Master server for the zone. 

Answer: C


Q82. Your network contains an Active Directory domain named contoso.com. All domain controllers run Windows Server 2008 R2. The functional level of the domain is Windows Server 2008 R2. The functional level of the forest is Windows Server 2008. You have a member server named Server1 that runs Windows Server 2008. 

You need to ensure that you can add Server1 to contoso.com as a domain controller. 

What should you run before you promote Server1? 

A. dcpromo.exe /CreateDCAccount 

B. dcpromo.exe /ReplicaOrNewDomain:replica 

C. Set-ADDomainMode -Identity contoso.com -DomainMode Windows2008Domain 

D. Set-ADForestMode -Identity contoso.com -ForestMode Windows2008R2Forest 

Answer: C


Q83. Your network contains an Active Directory domain. The domain contains a server named Server1. Server1 runs Windows Server 2008 R2. 

You need to mount an Active Directory Lightweight Directory Services (AD LDS) snapshot from Server1. 

What should you do? 

A. Run ldp.exe and use the Bind option. 

B. Run diskpart.exe and use the Attach option. 

C. Run dsdbutil.exe and use the snapshot option. 

D. Run imagex.exe and specify the /mount parameter. 

Answer: C


Q84. Your company has an Active Directory forest that contains Windows Server 2008 R2 domain controllers and DNS servers. All client computers run Windows XP SP3. 

You need to use your client computers to edit domain-based GPOs by using the ADMX files that are stored in the ADMX central store. 

What should you do? 

A. Add your account to the Domain Admins group. 

B. Upgrade your client computers to Windows 7. 

C. Install .NET Framework 3.0 on your client computers. 

D. Create a folder on PDC emulator for the domain in the PolicyDefinitions path. Copy the ADMX files to the PolicyDefinitions folder. 

Answer: B


Q85. Your network contains an Active Directory forest. The forest contains three domain trees. Each domain tree contains multiple domains. You have an Active Directory-integrated DNS zone. You install a Web server named Web1. All of the users in the company will use Web1. You need to ensure that the users can access Web1 by using the URL http://web1. 

You want to achieve this goal by using the minimum amount of administrative effort. 

What should you do? 

A. Configure a GlobalNames zone and add a Host (A) resource record for Web1. 

B. Create an Alias (CNAME) resource record for Web1 in the forest root domain zone. 

C. Create a reverse lookup zone and add an Alias (CNAME) resource record for Web1. 

D. Create a Host Information (HINFO) resource record for Web1 in the forest root domain zone. 

Answer: A


70-648 test question

Approved 70-648 free practice exam:

Q86. Your company has an Active Directory forest. The company has three locations. Each location has an organizational unit and a child organizational unit named Sales. The Sales organizational unit contains all users and computers of the sales department. The company plans to deploy a Microsoft Office 2007 application on all computers within the three Sales organizational units. 

You need to ensure that the Office 2007 application is installed only on the computers in the Sales organizational units. 

What should you do? 

A. Create a Group Policy Object (GPO) named SalesAPP GPO. Configure the GPO to assign the application to the computer account. Link the SalesAPP GPO to the domain. 

B. Create a Group Policy Object (GPO) named SalesAPP GPO. Configure the GPO to assign the application to the user account. Link the SalesAPP GPO to the Sales organizational unit in each location. 

C. Create a Group Policy Object (GPO) named SalesAPP GPO. Configure the GPO to publish the application to the user account. Link the SalesAPP GPO to the Sales organizational unit in each location. 

D. Create a Group Policy Object (GPO) named SalesAPP GPO. Configure the GPO to assign the application to the computer account. Link the SalesAPP GPO to the Sales organizational unit in each location. 

Answer: D


Q87. Your company has a main office and a branch office. The company has a single-domain Active Directory forest. The main office has two domain controllers named DC1 and DC2 that run Windows Server 2008 R2. The branch office has a Windows Server 2008 R2 read-only domain controller (RODC) named DC3. All domain controllers hold the DNS Server server role and are configured as Active Directory- integrated zones. The DNS zones only allow secure updates. 

You need to enable dynamic DNS updates on DC 3. 

What should you do? 

A. Run the Ntdsutil.exe DS Behavior commands on DC3. 

B. Run the Dnscmd.exe /ZoneResetType command on DC3. 

C. Reinstall Active Directory Domain Services on DC3 as a writable domain controller. 

D. Create a custom application directory partition on DC1. Configure the partition to store Active Directoryintegrated zones. 

Answer: C


Q88. Your network contains an Active Directory forest. All domain controllers run Windows Server 2008 Standard. 

The functional level of the domain is Windows Server 2003. You have a certification authority (CA). 

The relevant servers in the domain are configured as shown in the following table: 


You need to ensure that you can install the Active Directory Certificate Services (AD CS) Certificate Enrollment Web Service on the network. 

What should you do? 

A. Upgrade Server1 to Windows Server 2008 R2. 

B. Upgrade Server2 to Windows Server 2008 R2. 

C. Raise the functional level of the domain to Windows Server 2008. 

D. Install the Windows Server 2008 R2 Active Directory Schema updates. 

Answer: D


Q89. Your network contains a server named Server1 that runs Windows Server 2008 R2. Server1 has the Routing and Remote Access service (RRAS) role service installed. 

You need to view all inbound VPN packets. The solution must minimize the amount of data collected. 

What should you do? 

A. From RRAS, create an inbound packet filter. 

B. From Network Monitor, create a capture filter. 

C. From the Registry Editor, configure file tracing for RRAS. 

D. At the command prompt, run netsh.exe ras set tracing rasauth enabled. 

Answer: B


Q90. Your company has deployed Network Access Protection (NAP) enforcement for VPNs. 

You need to ensure that the health of all clients can be monitored and reported. 

What should you do? 

A. Create a Group Policy object (GPO) that enables Security Center and link the policy to the domain. 

B. Create a Group Policy object (GPO) that enables Security Center and link the policy to the DomainControllers organizational unit (OU). 

C. Create a Group Policy object (GPO) and set the Require trusted path for credential entry option to Enabled.Link the policy to the domain. 

D. Create a Group Policy object (GPO) and set the Require trusted path for credential entry option to Enabled.Link the policy to the Domain Controllers organizational unit (OU). 

Answer: A


Microsoft 70-648 Certification Sample Questions and Answers: http://www.braindumpsall.net/70-648-dumps/

P.S. New 70-648 dumps PDF: http://www.4easydumps.com/70-648-dumps-download.html