getcertified4sure.com

70-642 book (211 to 220)




Want to know Pass4sure 70-642 Exam practice test features? Want to lear more about Microsoft TS: Windows Server 2008 Network Infrastructure, Configuring certification experience? Study Download Microsoft 70-642 answers to Latest 70-642 questions at Pass4sure. Gat a success with an absolute guarantee to pass Microsoft 70-642 (TS: Windows Server 2008 Network Infrastructure, Configuring) test on your first attempt.

2021 Sep windows server 2008 exam 70-642 pdf:

Q211. - (Topic 3) 

Your company has a main office and a branch office. The branch office has three servers that run a Server Core installation of Windows Server 2008 R2. The servers are named Server1, Server2, and Server3. 

You want to configure the Event Logs subscription on Server1 to collect events from Server2 and Server3. You discover that you cannot create a subscription on Server1 from another computer. 

You need to configure a subscription on Server1. 

Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.) 

A. Run the wecutil cs subscription.xml command on Server1. 

B. Run the wevtutil im subscription.xml command on Server1. 

C. Create an event collector subscription configuration file. Name the file subscription.xml. 

D. Create a custom view on Server1 by using Event Viewer. Export the custom view to a file named subscription.xml. 

Answer: A,C 

Explanation: 

wecutil {cs | create-subscription } CONFIGURATION_FILE http://msdn.microsoft.com/en-us/library/windows/desktop/bb736545(v=vs.85).aspx 


Q212. - (Topic 1) 

Your network contains an Active Directory forest. The forest contains a member server named Server1 that runs Windows Server 2008 R2. 

You need to create folder quotas on Server1. 

Which server role, role service, or feature should you install? 

A. Routing and Remote Access service (RRAS) 

B. Health Registration Authority (HRA) 

C. Network Load Balancing (NLB) 

D. File Server Resource Manager (FSRM) 

E. Windows Server Update Services (WSUS) 

F. Connection Manager Administration Kit (CMAK) 

G. Wireless LAN Service 

H. Windows Internal Database 

I. Network Policy Server (NPS) 

J. Group Policy Management 

K. Windows System Resource Manager (WSRM) 

L. Simple TCP/IP Services 

M. Services for Network File System (NFS) 

Answer: D 

Explanation: 

http://technet.microsoft.com/en-us/library/cc770989(v=ws.10).aspx 

By using File Server Resource Manager (FSRM) to create a quota for a volume or folder, 

you can limit the disk space that is allocated for it. The quota limit applies to the entire 

folder subtree. 

You can create either a hard quota or a soft quota: 

A hard quota prevents users from saving files after the space limit is reached and 

generates notifications when the volume of data reaches each configured threshold. 

A soft quota does not enforce the quota limit but generates all configured notifications. 


Q213. - (Topic 2) 

Your network contains a Distributed File System (DFS) target folder named Folder1 that contains 100 GB of data. 

You plan to create a new DFS replica of Folder1 on a server named Server2. 

You need to prestage the data in Folder1 on Server2. The solution must ensure that the amount of initial DFS replication traffic is minimized. 

Which tool should you use to prestage the Folder1 data? 

A. Dfscmd 

B. Dfsrmig 

C. Dfsutil 

D. Wbadmin 

Answer: D 

Explanation: 

Distributed File System (DFS) replication is a new technology that has been included in Microsoft Windows Server starting in Microsoft Windows Server 2003 R2. Some Microsoft TechNet articles discuss the concept of prestaging to reduce network traffic during the initial synchronization of DFS data. Whether data that is located on each replication partner is considered the same depends on the hashing algorithm that is applied to the file, to the file permissions (discretionary access control lists), and to the file audit properties (system access control lists). 

The hashes of prestaged data are affected by the following: 

Permissions 

Audit properties 

Inheritance 

The copy tool, such as Robocopy.exe or Xcopy.exe, that is used Because the possible combinations of these factors are so wide and varied, predicting the success of prestaging operations is very difficult. However, the Backup program in Windows Server is a reliable mechanism to prestage data. 

How to use the Backup program to prestage DFSR data Back up the data by using the 

Backup program. You can back up to tape or to a file. 

Transfer the backup to the destination server. 

Restore the backup to the destination server. 

The hashes that are computed by DFSR for each server should be identical for files that have not changed. 

http://support.microsoft.com/kb/947726 


Q214. - (Topic 1) 

Your network contains an Active Directory domain. The domain contains an enterprise certification authority (CA) named Server1 and a server named Server2. 

On Server2, you deploy Network Policy Server (NPS) and you configure a Network Access Protection (NAP) enforcement policy for IPSec. 

From the Health Registration Authority snap-in on Server2, you set the lifetime of health certificates to four hours. 

You discover that the validity period of the health certificates issued to client computers is one year. 

You need to ensure that the health certificates are only valid for four hours. 

What should you do? 

A. Modify the Request Handling settings of the certificate template used for the health certificates. 

B. Modify the Issuance Requirements settings of the certificate template used for the health certificates. 

C. On Server1, run certutil.exe -setreg policy\editflags +editf_attributeenddate. 

D. On Server1, run certutil.exe Csetregdbflags +dbflags_enablevolatilerequests. 

Answer: C 

Explanation: 

Configure template validity period override 

Use the following procedure to allow the CA to issue the new health certificate template. 

This procedure applies to an enterprise NAP CA only. 

To allow template validity period override 

On the NAP CA, click Start, click Run, right-click Command Prompt, and then click Run as administrator. 

In the command window, type Certutil.exe -setreg policy\EditFlags 

+EDITF_ATTRIBUTEENDDATE, and then press ENTER. 

In the command window, type net stop certsvc && net start certsvc, and then press 

ENTER. 

Verify that Active Directory Certificate Services (AD CS) stops and starts successfully. 

http://technet.microsoft.com/en-us/library/dd296906(v=ws.10).aspx 

Reference URL : http://technet.microsoft.com/en-us/library/dd296906(v=ws.10).aspx 


Q215. - (Topic 4) 

Your network contains an Active Directory forest named contoso.com. The forest contains a server named Server1 that is configured as an enterprise certification authority (CA). The forest contains a server named Server2 that has the Network Policy Server (NPS) role service installed. 

You deploy Network Access Protection (NAP). 

You discover that Server1 fails to issue health certificates. 

You need to ensure that health certificates can be issued. 

What should you do? 

A. Publish the Kerberos Authentication certificate template on Server1. 

B. From the Network Policy Server console, modify the Windows System Health Validators settings. 

C. From the Network Policy Server console, create a new health policy. 

D. Install an additional server, configure the new server as a standalone CA, and then configure the Health Registration Authority (HRA) to use the CA. 

Answer: A 

Explanation: In order to issue NAP health certificates from an enterprise certification authority (CA), you must configure certificate templates. 

After you create a health certificate template, it must be published so that the NAP certification authority (CA) can issue certificates to NAP client computers. 

Note: 

* NPS is the Microsoft implementation of a Remote Authentication Dial-in User Service (RADIUS) server, and as such, performs connection authentication, authorization, and accounting for many types of network access, including wireless and virtual private network (VPN) connections. NPS also functions as a health evaluation server for Network Access Protection (NAP). 

Reference: Create Health Certificate Templates 


70-642 test engine

Update examcollection 70-642:

Q216. DRAG DROP - (Topic 4) 

Your network contains an Active Directory domain. The domain contains a server named Server1 that runs Windows Server 2008 R2. 

Server1 contains a folder named Folder1. A domain user named User1 does not have NTFS Read permission for Folder1. 

You need User1 to create a backup copy of Folder1. User1 must NOT be able to restore the backup copy on Server1. What should you do? 

To answer, move the appropriate actions from the Possible Actions list to the Necessary Actions area and arrange them in the correct order. 

Answer: 


Q217. - (Topic 3) 

You have 10 standalone servers that run Windows Server 2008 R2. You install the Windows Server Update Services (WSUS) server role on a server named Server1. 

You need to configure all of the servers to receive updates from Server1. 

What should you do? 

A. Configure the Windows Update settings on each server by using the Control Panel. 

B. Run the wuauclt.exe /detectnow command on each server. 

C. Run the wuauclt.exe /reauthorization command on each server. 

D. Configure the Windows Update settings on each server by using a local group policy. 

Answer: D 

Explanation: 

In a non-Active Directory environment, you can configure Automatic Updates by using any of the following methods: 

-Using Group Policy Object Editor and editing the Local Group Policy object (Computer 

Configuration > 

= Administrative Templates > Windows Components > Windows Update. ) 

-Editing the registry directly by using the registry editor (Regedit.exe) 

-Centrally deploying these registry entries by using System Policy in Windows NT 4.0 style 


Q218. - (Topic 1) 

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 that runs Windows Server 2008 R2 Service Pack 1 (SP1). Server1 has the Windows Server Update Services (WSUS) server role installed. 

Server1 downloads updates from Microsoft Update every day. 

You have an isolated test network that is not connected to the production network. 

On the test network, you implement a WSUS server named Server2. Server2 has the same WSUS configuration as Server1. 

You need to ensure that Server2 can distribute the same updates as Server1. 

Which actions should you perform? (Each correct answer present part of the solution. Choose three.) 

A. On Server2, run wsusutil.exe and specify the import parameter. 

B. On Server1, run wsusutil.exe and specify the export parameter. 

C. On Server2, restore the system state. 

D. On Server1, back up the system state. 

E. Copy the WSUSContent folder from Server1 to Server2. 

Answer: A,B,E 

Explanation: 

http://technet.microsoft.com/en-us/library/cc463370(v=ws.10).aspx#BKMK_V3 


Q219. - (Topic 4) 

A company has an Active Directory domain named fabrikam.com. All servers run Windows Server 2008 R2. 

The topology of the Active Directory site is configured as shown in the exhibit. (Click the Exhibit button.) 

Server1 and Server2 host a Distributed File System (DFS) replica named \\fabrikam.com\dfs\Folderl. 

Client computers in Site3 and Site4 always contact Server1 when they access files in \\fabrikam.com\dfs\Folderl. 

You need to ensure that client traffic from Site3 and Site4 is distributed between Server1 and Server2. 

What should you do? 

A. From the properties of the \\fabrikam.com\dfs\Folder1 folder, modify the Advanced settings. 

B. From the properties of the \\fabrikam.com\dfs\Folder1 folder, modify the Referrals settings. 

C. From the properties of the \\fabrikam.com\dfs namespace, modify the Polling settings of the namespace. 

D. From the properties of the \\fabrikam.com\dfs namespace, modify the ordering method of the namespace. 

Answer: D 


Q220. DRAG DROP - (Topic 4) 

Your network contains a Windows Server Update Services (WSUS) server named Server1. All client computers are configured to download updates from Server1. Server1 is configured only to synchronize manually to Microsoft Update. 

Your company deploys a new Microsoft application. 

You discover that the new application is not listed on the Products and Classifications list. 

You synchronize the WSUS server. 

You need to ensure that updates for the new application are available to all of the client computers. 

What should you do? 

To answer, move the appropriate actions from the Possible Actions list to the Necessary Actions area and arrange them in the correct order. 

Answer: