Do you want to pass the 70-642 Examsavior exam? What are the new questions of the latest 70-642 exam? Examsavior 70-642 VCE dumps and 70-642 PDF dumps will tell you all about the 70-642 Examsavior exam.Here are the Examsavior newest and covered all new added questions and answers, which will help you 100% passing 70-642 Examsavior exam.Hurry up and get the free exam from here!
NOW FREE DOWNLOAD
QUESTION 31
Your company has an Active Directory forest. All domain controllers run the DNS Server server role. The
company plans to decommission the WINS service. You need to enable forest-wide single name
resolution. What should you do?
A. Enable WINS-R lookup in DNS
B. Create Service Location (SRV) records for the single name resources
C. Create an Active Directory-integrated zone named LegacyWINS. Create host (A) records for the single
name resources
D. Create an Active Directory-integrated zone named GlobalNames. Create an alias host (CNAME)
records for the single name resources
Correct Answer: D
QUESTION 32
You manage a domain controller that runs Windows Server 2008 R2 and the DNS Server server role. The
DNS server hosts an Active Directory-integrated zone for your domain. You need to provide a user with
the ability to manage records in the zone. The user must not be able to modify the DNS server settings.
What should you do?
A. Add the user to the DNSUpdateProxy Global security group.
B. Add the user to the DNSAdmins Domain Local security group.
C. Grant the user permissions on the zone.
D. Grant the user permissions on the DNS server.
Correct Answer: C
QUESTION 33
Your network contains an Active Directory domain named contoso.com. All domain controllers run
Windows Server 2008 R2 and are configured as DNS servers. All client computers run Windows 7. You
create a new zone named secure.contoso.com and configure the zone to use DNSSEC. You need to
ensure that all client computers verify whether the name and address information of secure.contoso.com
is validated by the DNS servers. What should you configure from Group Policy?
A. an IPSec Security policy
B. the DNS Client settings
C. the Public Key policies
D. a Name Resolution Policy rule
Correct Answer: D
QUESTION 34
Your company has a main office and two branch offices that are connected by WAN links. The main office
runs the DNS Server service on three domain controllers. The zone for your domain is configured as an
Active Directory-integrated zone. Each branch office has a single member server that hosts a secondary
zone for the domain. The DNS servers in the branch offices use the main office DNS server as the DNS
Master server for the zone. You need to minimize DNS zone transfer traffic over the WAN links. What
should you do?
A. Decrease the Retry Interval setting in the Start of Authority (SOA) record for the zone.
B. Decrease the Refresh Interval setting in the Start of Authority (SOA) record for the zone.
C. Increase the Refresh Interval setting in the Start of Authority (SOA) record for the zone.
D. Disable the netmask ordering option in the properties of the DNS Master server for the zone.
Correct Answer: C
QUESTION 35
Your network contains an Active Directory domain. The domain contains an enterprise certification
authority (CA) named Server1 and a server named Server2. On Server2, you deploy Network Policy
Server (NPS) and you configure a Network Access Protection (NAP) enforcement policy for IPSec. From
the Health Registration Authority snap-in on Server2, you set the lifetime of health certificates to four
hours. You discover that the validity period of the health certificates issued to client computers is one year.
You need to ensure that the health certificates are only valid for four hours. What should you do?
A. Modify the Request Handling settings of the certificate template used for the health certificates.
B. Modify the Issuance Requirements settings of the certificate template used for the health certificates.
C. On Server1, run certutil.exe -setreg policy\editflags +editf_attributeenddate.
D. On Server1, run certutil.exe Csetregdbflags +dbflags_enablevolatilerequests.
Correct Answer: C
QUESTION 36
Your company has a single Active Directory domain. All servers run Windows Server 2008 R2. You install
an additional DNS server that runs Windows Server 2008 R2. You need to delete the pointer record for the
IP address 10.3.2.127. What should you do?
A. Use DNS manager to delete the 127.in-addr.arpa zone.
B. Run the dnscmd /RecordDelete 10.3.2.127 command at the command prompt.
C. Run the dnscmd /ZoneDelete 127.in-addr.arpa command at the command prompt.
D. Run the dnscmd /RecordDelete 10.in-addr.arpa. 127.2.3 PTR command at the command prompt.
Correct Answer: D
QUESTION 37
Your company has a server that runs Windows Server 2008 R2. You have a new application that locates
remote resources by name. The new application requires IPv6. You need to ensure that the application
can locate remote resources by using IPv6. What should you do?
A. Create a new Pointer (PTR) DNS record.
B. Create a new Quad-A (AAAA) DNS record.
C. Create a new Signature (SIG) DNS record.
D. Create a new Route Through (RT) DNS record.
Correct Answer: B
QUESTION 38
You are building a test environment to evaluate DNS Security Extensions (DNSSEC). You have a domain
controller named Server1 that runs Windows Server 2008 R2 in your test environment. Server1 has the
DNS Server server role installed. You need to configure Server1 to support the DNSSEC evaluation.
Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)
A. Create a new Quad-A (AAAA) DNS record.
B. Create a new Signature (SIG) DNS record.
C. Create a new Public key (KEY) DNS record.
D. Create a new Well-known service (WKS) DNS record.
Correct Answer: BC
QUESTION 39
Your company has a domain controller that runs Windows Server 2008 R2 and the DNS role. The DNS
domain is named contoso.com. You need to ensure that inquiries about contoso.com are sent to
dnsadmin@contoso.com. What should you do?
A. Create a Signature (SIG) record for the domain controller.
B. Modify the Name Server (NS) record for the domain controller.
C. Modify the Service Location (SRV) record for the domain controller.
D. Modify the Start of Authority (SOA) record on the domain controller.
Correct Answer: D
QUESTION 40
Your company has a domain controller named Server1 that runs Windows Server 2008 R2 and the DNS
server role. A server named Server2 runs Windows Server 2003 and Microsoft Exchange Server 2007.
The company wants to deploy a new Exchange server named Server3 to receive all inbound e- mail
traffic. You need to configure DNS to direct incoming e-mail traffic to the Exchange servers. You also
need to ensure that higher priority is given to Server3. What should you do?
A. Set the priority value of the Server2 Mail Exchanger (MX) record to 20. Create a new Mail Exchanger
(MX) record for Server3. Set the priority value to 5.
B. Set the priority value of the Server2 Mail Exchanger (MX) record to 5. Create a new Mail Exchanger
(MX) record for Server3. Set the priority value to 20.
C. Create a new Service Location (SRV) record in the domain for Server3. Set the port number value to
25. Configure the priority setting to 20.
D. Create a new Service Location (SRV) record in the domain for Server3. Set the port number value to
110. Configure the priority setting to 5.
Correct Answer: A
QUESTION 41
Your company has a domain controller named Server1 that runs Windows Server 2008 R2 and the DNS
Server role. A server named Server2 runs a custom application. You need to configure DNS to include the
following parameters for the custom application:
Service
Priority
Weight
Protocol
Port number
Host offering this service
Which record should you create?
A. Host Info (HINFO)
B. Service Location (SRV)
C. Canonical Name (CNAME)
D. Well-Known Service (WKS)
Correct Answer: B
QUESTION 42
Your network contains an Active Directory domain. The domain contains DNS servers that run Windows
Server 2008 R2. The network has two external links. One link connects to the Internet. The other link
directly connects to the network of a partner company. The partner companys network is not connected to
the Internet. You need to ensure that users on your network can access resources on the partner
companys network. The solution must ensure that the users on your network can continue to access
resources on the Internet. Which two actions should you perform on the DNS servers? (Each correct
answer presents a complete solution. Choose two.)
A. Configure conditional forwarding.
B. Add a stub zone.
C. Modify the root hints.
D. Add a reverse lookup zone.
E. Add a trust anchor.
Correct Answer: AC
QUESTION 43
Your company has a main office and two branch offices. Domain controllers in the main office host an
Active Directory-integrated zone. The DNS servers in the branch offices host a secondary zone for the
domain and use the main office DNS servers as their DNS Master servers for the zone. The company
adds a new branch office. You add a member server named Branch3 and install the DNS Server server
role on the server. You configure a secondary zone for the domain. The zone transfer fails. You need to
configure DNS to provide zone data to the DNS server in the new branch office. What should you do?
A. Run dnscmd by using the ZoneResetMasters option.
B. Run dnscmd by using the ZoneResetSecondaries option.
C. Add the new DNS server to the Zone Transfers tab on one of the DNS servers in the main office.
D. Add the new DNS server to the DNSUpdateProxy Global security group in Active Directory Users and
Computers.
Correct Answer: C
QUESTION 44
Your network contains a Windows Server Update Services (WSUS) server named Server1. All client
computers are configured to download updates from Server1. Server1 is configured only to synchronize
manually to Microsoft Update. Your company deploys a new Microsoft application. You discover that the
new application is not listed on the Products and Classifications list. You need to ensure that updates for
the new application are available to all of the client computers. What should you do first?
A. Run the Server Cleanup Wizard.
B. Approve updates.
C. Synchronize the WSUS server.
D. Modify the Products and Classifications settings.
Correct Answer: C
QUESTION 45
You have a perimeter network that contains 20 servers. All of the servers run Windows Server 2008 R2
and are members of a workgroup. You add an additional server named Server21 to the perimeter network.
You plan to configure Server21 to collect events forwarded from the other servers. You need to ensure
that the events are available on Server21 as quickly as possible. Which event delivery optimization option
should you enable?
A. Normal
B. Custom
C. Minimize Bandwidth
D. Minimize Latency
Correct Answer: D
QUESTION 46
Your company has an Active Directory domain named ad.contoso.com. All client computers run Windows
7. The company has recently acquired a company that has an Active Directory domain named ad.
fabrikam.com. A two-way forest trust is established between the ad.fabrikam.com domain and the ad.
contoso.com domain. You need to edit the ad.contoso.com domain Group Policy object (GPO) to enable
users in the ad.contoso.com domain to access resources in the ad.fabrikam.com domain. What should
you do?
A. Configure the DNS Suffix Search List option to ad.contoso.com, ad.fabrikam.com.
B. Configure the Allow DNS Suffix Appending to Unqualified Multi-Label Name Queries option to True.
C. Configure the Primary DNS Suffix option to ad.contoso.com, ad.fabrikam.com. Configure the Primary
DNS Suffix Devolution option to True.
D. Configure the Primary DNS Suffix option to ad.contoso.com, ad.fabrikam.com. Configure the Primary
DNS Suffix Devolution option to False.
Correct Answer: A
QUESTION 47
Your company has a single Active Directory forest that has a domain in North America named na.contoso.
com and a domain in South America named sa.contoso.com. The client computers run Windows 7. You
need to configure the client computers in the North America office to improve the name resolution
response time for resources in the South America office. What should you do?
A. Configure a new Group Policy object (GPO) that disables the Local-Link Multicast Name Resolution
feature. Apply the policy to all the client computers in the North America office.
B. Configure a new Group Policy object (GPO) that enables the Local-Link Multicast Name Resolution
feature. Apply the policy to all the client computers in the North America office.
C. Configure a new Group Policy object (GPO) that configures the DNS Suffix Search List option to sa.
contoso.com, na.contoso.com. Apply the policy to all the client computers in the North America office.
D. Configure the priority value for the Service Location (SRV) records on each of the North America
domain controllers to 5.
Correct Answer: C
QUESTION 48
Your network contains an Active Directory domain named fabrikam.com. The domain contains five
domain controllers named DC1, DC2, DC3, DC4, and DC5. All domain controllers run Windows Server
2008 R2 and have the DNS server role installed. On DC5, you create a new Active Directory-integrated
DNS zone named adatum.com. You need to ensure that the adatum.com DNS zone is only replicated to
DC5 and DC2. The solution must ensure that all zone replication traffic is encrypted. What should you do
first?
A. Create an application directory partition.
B. Create a primary zone.
C. Modify the zone transfer settings.
D. Change the zone replication scope.
Correct Answer: A
QUESTION 49
Your network contains a server named Server1 that runs Windows Server 2008 R2. On Server1, you run
route add 192.168.10.0 mask 255.255.255.0 172.23.1.2 metric 10. You restart Server1, and then run the
route command as shown in the exhibit. You need to ensure that after you restart Server1, Server1 routes
all of the traffic for 192.168.10.0/24 by using the router that has an IP address of 172.23.1.2. Which
command should you run on Server1?
![2016NEW Microsoft.70-642 EXAM] Windows Server 2008 Network Infrastructure, Configuring EXAM A PART2 (31-50) VCE DUMPS FOR FREE DOWNLOAD WITH 100%PASS ENSURE 2016NEW Microsoft.70-642 EXAM] Windows Server 2008 Network Infrastructure, Configuring EXAM A PART2 (31-50) VCE DUMPS FOR FREE DOWNLOAD WITH 100%PASS ENSURE](http://sugarexam.com/wp-content/uploads/2016/08/wpsDCA0.tmp_.jpg)
A. netstat -p ip 172.23.1.2
B. netstat -f 172.23.1.2
C. route add 192.168.10.0 mask 255.255.255.0 172.23.1.2 metric 10 -p
D. route add 192.168.10.0 mask 255.255.255.128 172.23.1.2 metric 1 -f
Correct Answer: C
QUESTION 50
Your company has 10 servers that run Windows Server 2008 R2. The servers have Remote Desktop
Protocol (RDP) enabled for server administration. RDP is configured to use default security settings. All
administrators’ computers run Windows 7. You need to ensure the RDP connections are as secure as
possible. Which two actions should you perform? (Each correct answer presents part of the solution.
Choose two.)
A. Set the security layer for each server to the RDP Security Layer.
B. Configure the firewall on each server to block port 3389.
C. Acquire user certificates from the internal certification authority.
D. Configure each server to allow connections only to Remote Desktop client computers that use Network
Level Authentication.
Correct Answer: CD
Latest online browsing the 70-642 exam!
70-642 PDF dumps & 70-642 VCE dumps: http://examsavior.com/70-642
100% Pass:http://examsavior.com/
No comments:
Post a Comment