15 tips on How to 70-648 Test Like a Badass [121 to 135]

100% Correct of 70-648 free draindumps materials and free samples for Microsoft certification for customers, Real Success Guaranteed with Updated 70-648 pdf dumps vce Materials. 100% PASS TS:Upgrading MCSA on Wndws Serv 2003 to Wndws Serv 2008 exam Today!

2016 Apr 70-648 Study Guide Questions:

Q121. Your company has an Active Directory forest that runs at the functional level of Windows Server 2008. You implement Active Directory Rights Management Services (AD RMS). You install Microsoft SQL Server 2005. 

When you attempt to open the AD RMS administration Web site, you receive the following error message: 

"SQL Server does not exist or access denied." 

You need to open the AD RMS administration Web site. 

Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.) 

A. Restart IIS. 

B. Install Message Queuing. 

C. Start the MSSQLSVC service. 

D. Manually delete the Service Connection Point in Active Directory Domain Services (AD DS) and restart AD RMS. 

Answer: AC


Q122. Your company has a single Active Directory domain. The company network is protected by a firewall. Remote users connect to your network through a VPN server by using PPTP. When the users try to connect to the VPN server, they receive the following error message: "Error 721: The remote computer is not responding." 

You need to ensure that users can establish a VPN connection. 

What should you do? 

A. Open port 1423 on the firewall. 

B. Open port 1723 on the firewall. 

C. Open port 3389 on the firewall. 

D. Open port 6000 on the firewall. 

Answer: B


Q123. You manage a domain controller that runs Windows Server 2008 R2 and the DNS Server server role. The DNS server hosts an Active Directory-integrated zone for your domain. 

You need to provide a user with the ability to manage records in the zone. The user must not be able to modify the DNS server settings. 

What should you do? 

A. Add the user to the DNSUpdateProxy Global security group. 

B. Add the user to the DNSAdmins Domain Local security group. 

C. Grant the user permissions on the zone. 

D. Grant the user permissions on the DNS server. 

Answer: C


Q124. Your network contains an Active Directory domain. All domain controllers run Windows Server 2008 R2. 

You need to create a snapshot of Active Directory. 

What should you do? 

A. Create a Data Collector Set (DCS). 

B. Run the ntdsutil.exe command. 

C. Run the eventcreate.exe command. 

D. Run the dsquery.exe command. 

E. Run the Get-ADForest cmdlet. 

F. Run the dsamain.exe command. 

G. Configure the Active Directory Diagnostics Data Collector Set (DCS). 

H. Create custom views from Event Viewer. 

I. Configure subscriptions from Event Viewer. 

J. Run the repadmin.exe command. 

Answer: B


Q125. Your network contains a Network Policy Server (NPS) named NPS1. NPS1 is configured for remote access account lockout. A domain user named User1 has been locked out by NPS1. 

You need to unlock the User1 user account on NPS1. 

What should you use? 

A. the Netsh tool 

B. the Network Policy Server console 

C. the Registry Editor 

D. the Routing and Remote Access console 

Answer: C


70-648 test

Most up-to-date 70-648 free practice test:

Q126. RAG DROP 

You need to perform an offline defragmentation of an Active Directory database. 

Which four actions should you perform in sequence? (To answer, move the appropriate four actions from the list of actions to the answer area and arrange them in the correct order.) 


Answer: 



Q127. Your network contains two servers named Server1 and Server2 that run Windows Server 2008 R2. From 

Server1, you create a collector-initiated subscription that uses Server2 as a source computer. You verify the event subscription and discover the error message shown in the exhibit. (Click the Exhibit button.) 


You need to ensure that the subscription collection runs successfully. 

What should you do? 

A. On Server1, run winrm quickconfig. 

B. On Server2, run winrm quickconfig. 

C. From the properties of the subscription, modify the User Account options. 

D. From the properties of the subscription, modify the Protocol and Port options. 

Answer: C


Q128. You are installing an application on a computer that runs Windows Server 2008 R2. During installation, the application will need to add new attributes and classes to the Active Directory database. 

You need to ensure that you can install the application. 

What should you do? 

A. Change the functional level of the forest to Windows Server 2008 R2. 

B. Log on by using an account that has Server Operator rights. 

C. Log on by using an account that has Schema Administrator rights and the appropriate rights to install the application. 

D. Log on by using an account that has the Enterprise Administrator rights and the appropriate rights to install the application. 

Answer: C


Q129. Your network contains an Active Directory domain. The relevant servers in the domain are configured as shown in the following table: 


You need to ensure that all device certificate requests use the MD5 hash algorithm. 

What should you do? 

A. On Server2, run the Certutil tool. 

B. On Server1, update the CEP Encryption certificate template. 

C. On Server1, update the Exchange Enrollment Agent (Offline Request) template. 

D. On Server3, set the value of the HKLM\Software\Microsoft\Cryptography\MSCEP\ HashAlgorithm \HashAlgorithm registry key. 

Answer: D


Q130. Your network contains an Active Directory domain named contoso.com. The domain contains two domain controllers named DC1 and DC2 that run Windows Server 2008 R2. DC1 hosts a primary zone for contoso.com. DC2 hosts a secondary zone for contosto.com. 

You need to ensure that DNS zone data is encrypted when the data replicates across the network. DC2 must provide authoritative responses to client computers. 

What should you do? 

A. Configure the contoso.com zone to use DNSSEC. 

B. Create a new delegation in the contoso.com zone. 

C. Modify the zone transfer settings of the contoso.com zone. 

D. Convert the contoso.com zone to an Active Directory-integrated zone. 

Answer: D


70-648 download

Breathing 70-648 testing material:

Q131. You have an enterprise subordinate certification authority (CA). The CA issues smart card logon certificates. 

Users are required to log on to the domain by using a smart card. 

Your company's corporate security policy states that when an employee resigns, his ability to log on to the network must be immediately revoked. 

An employee resigns. 

You need to immediately prevent the employee from logging on to the domain. 

What should you do? 

A. Revoke the employee's smart card certificate. 

B. Disable the employee's Active Directory account. 

C. Publish a new delta certificate revocation list (CRL). 

D. Reset the password for the employee's Active Directory account. 

Answer: B


Q132. Your company uses Network Access Protection (NAP) to enforce policies on client computers that connect to the network. Client computers run Windows 7. A Group Policy is used to configure client computers to obtain updates from Windows Server Update Services (WSUS). Company policy requires that updates labeled Important and Critical must be applied before client computers can access network resources. 

You need to ensure that client computers meet the company policy requirement. 

What should you do? 

A. Enable automatic updates on each client. 

B. Enable the Security Center on each client. 

C. Quarantine clients that do not have all available security updates installed. 

D. Disconnect the connection until the required updates are installed. 

Answer: C


Q133. Your network contains an Active Directory domain named contoso.com. The network has a branch office site that contains a read-only domain controller (RODC) named RODC1. RODC1 runs Windows Server 2008 R2. A user named User1 logs on to a computer in the branch office site. You discover that the password of User1 is not stored on RODC1. 

You need to ensure that User1's password is stored on RODC1. 

What should you modify? 

A. the Member Of properties of RODC1 

B. the Member Of properties of User1 

C. the Security properties of RODC1 

D. the Security properties of User1 

Answer: B


Q134. Your network contain 10 domain controller that run Windows Server 2008 R2. The network contain a member server that is configured to collect all of events that occur on the domain controllers. 

Your need to ensure that administrators are notified when a specific event occurs on any of the domain controllers. You want to achieve the goal by using the minimum amount effort. 

What should you do? 

A. From Event Viewer on the member server, create a subscription. 

B. From Event Viewer on each domain controller, create a subscription. 

C. From Event Viewer on the member server, run the Create Basic Task Wizard. 

D. From Event Viewer on each domain controller,run the Create Basic Task Wizard. 

Answer: C


Q135. Your network contains a server that runs Windows Server 2008 R2. You plan to create a custom script. 

You need to ensure that each time the script runs, an entry is added to the Application event log. 

Which tool should you use? 

A. Eventcreate 

B. Eventvwr 

C. Wecutil 

D. Wevtutil 

Answer: A