Welcome to TestSimulate

Pass Your Next Certification Exam Fast!

Everything you need to prepare, learn & pass your certification exam easily.

365 days free updates. First attempt guaranteed success.

Microsoft TS: Upgrading MCSA on Windows serv 2003 to Windows Serv 2008 (70-648) Free Practice Test

Question 1
Your network contains a Windows Server Update Services (WSUS) server named Server1.
You need to configure all WSUS client computers to download approved updates directly from the Microsoft Update servers. The solution must ensure that all WSUS client computers report successful installation of updates to Server1.
What should you do?

Correct Answer: B
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 2
Your company uses a Windows 2008 Enterprise certificate authority (CA) to issue certificates.
You need to implement key archival.
What should you do?

Correct Answer: A
Question 3
Your company has an Active Directory domain. You plan to install the Active Directory Certificate Services (AD CS) server role on a member server that runs Windows Server 2008 R2.
You need to ensure that members of the Account Operators group are able to issue smartcard credentials. They should not be able to revoke certificates.
Which three actions should you perform? (Each correct answer presents part of the solution. Choose three.)

Correct Answer: C,D,F
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 4
Your network contains an Active Directory domain named contoso.com.
The Administrator deletes an OU named OU1 accidentally.
You need to restore OU1. Which cmdlet should you use?

Correct Answer: C
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 5
ABC.com has an Active Directory forest on a single domain. The domain operates Windows Server 2008.
A new administrator accidentally deletes the entire organizational unit in the Active Directory database that
hosts 6,000 objects.
You have backed up the system state data using third-party backup software. To restore backup, you start
the domain controller in the Directory Services Restore Mode (DSRM).
You need to perform an authoritative restore of the organizational unit and restore the domain controller to
its original state.
Which three actions should you perform?
Build List and Reorder:
Correct Answer:

Explanation:
If you are performing authoritative restore on a domain controller that has already received replication of the
deletions, perform the following procedures on the recovery domain controller:
(...)
2.(...)Restore from backup requires restarting the domain controller in DSRM. Taking the domain controller offline by stopping AD DS is not sufficient to run Ntdsutil procedures to restore from backup.
3.Restore AD DS from Backup (Nonauthoritative Restore)
4.Mark an Object or Objects as Authoritative(...) (MY NOTE: See 2nd article below where we are explicitly told this requires ntdsutil)
5.Restart the domain controller normally. (MY NOTE: Obviously restarting in Safe Mode won't help us much! The DC would not be able to synchronize!)
Reference: http://technet.microsoft.com/en-us/library/cc816878.aspx
You can use this procedure to mark Active Directory objects as authoritative when you perform an authoritative restore. In this procedure, you use the ntdsutil command to select objects that are to be marked authoritative when they replicate to other domain controllers.Reference: http://technet.microsoft.com/en-us/library/cc816813.aspx
Question 6
Your company has a main office and 50 branch offices. Each office contains multiple subnets.
You need to automate the creation of Active Directory subnet objects.
What should you use?

Correct Answer: B
Question 7
Your network contains a server named Server1 that runs Windows Server 2008 R2. You plan to deploy
DirectAccess on Server1.
You need to configure Windows Firewall on Server1 to support DirectAccess connections.
What should you allow from Windows Firewall on Server1?

Correct Answer: B
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 8
A corporate network includes a single Active Directory Domain Services (AD DS) domain.
The HR department has a dedicated organizational unit (OU) named HR. The HR OU has two sub-OUs: HR Users and HR Computers. User accounts for the HR department reside in the HR Users OU. Computer accounts for the HR department reside in the HR Computers OU. All HR department employees belong to a security group named HR Employees. All HR department computers belong to a security group named HR PCs.
Company policy requires that passwords are a minimum of 6 characters.
You need to ensure that, the next time HR department employees change their passwords, the passwords are required to have at least 8 characters. The password length requirement should not change for employees of any other department.
What should you do?

Correct Answer: A
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 9
Your network contains a server named Server1 that runs Windows Server 2008 R2.
You enable IPSec on Server1.
You need to identify which client computers have active IPSec associations to Server1.
Which administrative tool should you use to achieve this task?
To answer, select the appropriate tool from the answer area.
Hot Area:
Correct Answer:

Explanation:
Newer IPSec settings must be managed through WFAS now, a centralized location for security concerns on Windows Server.
"Firewall settings are now integrated with Internet Protocol security (IPsec) settings"
References:
http://technet.microsoft.com/en-us/library/cc748991%28v=ws.10%29.aspx http://technet.microsoft.com/en-us/library/cc753765.aspx
Question 10
Your network contains two Active Directory sites named Site1 and Site2. Site1 contains a server named Server1. Server1 runs a custom application named App1.
Users in Site2 report that they cannot access App1 on Server1. Users in Site1 can access App1.
Server1 has a Windows Firewall with Advanced Security rule named Rule1. You discover that Rule1 blocks the connection to App1.
You verify that Server1 has no connection security rules. You need to ensure that the Site2 users can connect to Server1.
What should you modify in Rule1?

Correct Answer: D
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 11
Your company has an Active Directory forest. All domain controllers run the DNS Server server role. The company plans to decommission the WINS service.
You need to enable forest-wide single name resolution.
What should you do?

Correct Answer: A
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 12
You have a domain controller named Server1 that runs Windows Server 2008 R2.
You need to determine the size of the Active Directory database on Server1.
What should you do?

Correct Answer: D
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 13
You create a new Active Directory domain. The functional level of the domain is Windows Server 2008 R2.
The domain contains five domain controllers.
You need to monitor the replication of the group policy template files.
Which tool should you use?

Correct Answer: C
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).
Question 14
You deploy an Active Directory Federation Services (AD FS) Federation Service Proxy on a server named Server1.
You need to configure the Windows Firewall on Server1 to allow external users to authenticate by using AD FS.
Which protocol should you allow on Server1?

Correct Answer: D
Explanation: Only visible for TestSimulate members. You can sign-up / login (it's free).