Microsoft.testInside.70 290.v2010!01!03

download Microsoft.testInside.70 290.v2010!01!03

of 98

Transcript of Microsoft.testInside.70 290.v2010!01!03

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    1/98

    Testinside_Complement_for_Dundar_177Qs_by_cchelo

    Number: 000-177Passing Score: 800Time Limit: 120 minFile Version: 177Qs

    TestInside Microsoft 70-290

    Microsoft 70-290 Managing & Maintaining a Microsoft Windows Server 2003 Environment

    Complement for Dundar (Microsoft.TestInside.70-290.v9.5.by.Dundar.corrected.vce)177QsBy cchelo

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    2/98

    Exam A

    QUESTION 1You are the network administrator for your company. The network consists of a single Active Directory domain.All domain controllers run Windows Server 2003. All client computers run Windows XP Professional withdefault settings. Some users have portable computers, and the rest have desktop computers.

    You need to ensure that all users are authenticated by a domain controller when they log on.

    How should you modify the local security policy?

    A. Require authentication by a domain controller to unlock the client computer.

    B. Cache zero interactive logons.

    C. Cache 50 interactive logons.

    D. Grant the Log on locally user right to the Users group.

    Answer: BSection: (none)

    Explanation/Reference:

    QUESTION 2You have a server that runs Windows Server 2003 Service Pack 2 (SP2).

    You need to ensure that a defragmentation of the server's hard disk drive runs each night.

    What should you do?

    A. Create a scheduled task that runs Dfrg.msc.

    B. Create a scheduled task that runs Defrag.exe.

    C. From Computer Management, run Disk Management.D. From Computer Management, run Disk Defragmenter.

    Answer: BSection: (none)

    Explanation/Reference:

    QUESTION 3Your network contains a server named Server1 that runs Windows Server 2003 Service Pack (SP2).

    You install a new network adapter on Server1.

    You need to view the media access control (MAC) address for the new network adapter.

    What should you do?

    A. At the command prompt, run Ipconfig /all.

    B. At the command prompt, run Net view \\server1.

    C. From the Device Manager snap-in, view the properties of the network adapter.

    D. From the Services snap-in, view the properties on the Network Connections service.

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    3/98

    Answer: ASection: (none)

    Explanation/Reference:

    QUESTION 4You have a server that runs Windows Server 2003 Service Pack 2 (SP2).

    You need to identify all the unsigned drivers that are installed on the server.

    What should you do?

    A. Run Chkdsk.exe.

    B. Run Sigverif.exe.

    C. Review %systemroot%\repair\setup.log.

    D. Open Device Manager and review all the devices that contain a warning.

    Answer: BSection: (none)

    Explanation/Reference:

    QUESTION 5Your network consists of a single Active Directory domain. All servers run Windows Server 2003 Service Pack2 (SP2). All client computers run Windows XP Professional Service Pack 3 (SP3).

    A domain user named User1 attempts to log on to a computer named Computer1. After several failed logonattempts, User1 receives the following error message.

    You reset the password for User1 and provide the new password to User1.

    You need to ensure that User1 can log on immediately.

    What should you do?

    A. Modify the Account settings for User1.

    B. Modify the Session settings for User1.

    C. Disable User1 and then enable User1.

    D. Disable Computer1 and then enable Computer1.

    Answer: ASection: (none)

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    4/98

    Explanation/Reference:

    QUESTION 6Your network consists of a single Active Directory domain. All servers run Windows Server 2003 Service Pack2 (SP2). All client computers run Windows XP Professional Service Pack 3 (SP3).

    You create an account for a new user named User1. User1 reports that when she first attempts to log on to thedomain, she receives the following message.

    Other users report that they can log on to the domain from User1's computer.

    You need to ensure that User1 can log on to the domain.

    What should you do?

    A. Modify the properties of User1's account.

    B. Modify the properties of the computer account.

    C. On User1's computer, create a local user account.

    D. On User1's computer, modify the local security policy.

    Answer: ASection: (none)

    Explanation/Reference:

    QUESTION 7Your network consists of a single Active Directory domain. The domain contains a server named Server1 thatruns Windows Server 2003 Service Pack 2 (SP2).

    Your company's security policy states that domain users must be prevented from logging on to Server1 if adomain controller is unavailable.

    You disconnect Server1 from the network and discover that you can log on to Server1.

    You need to configure Server1 to comply with the company's security policy.

    What should you do on Server1?

    A. From the local security policy, modify the Security Options.

    B. From the local security policy, modify the User Rights Assignment.

    C. From Active Directory Users and Computers, modify the properties of the Server1 account.

    D. From Active Directory Users and Computers, modify the properties of the Domain Computers group.

    Answer: A

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    5/98

    Section: (none)

    Explanation/Reference:

    QUESTION 8

    Your network consists of a single Active Directory domain. All servers run Windows Server 2003 Service Pack2 (SP2). All client computers run Windows XP Professional Service Pack 3 (SP3).

    You have a server that contains two volumes named C and D. Volume C contains a folder named Data thatcontains over 10,000 files and folders.

    You need to copy the Data folder to volume D. The solution must maintain the current ownership settings.

    Which tool should you use?

    A. Copy

    B. Move

    C. Xcacls

    D. Xcopy

    Answer: DSection: (none)

    Explanation/Reference:

    QUESTION 9Your network consists of a single Active Directory domain. All servers run Windows Server 2003 Service Pack2 (SP2).

    You have two global groups named Research and ResearchManagers. The Research group contains all usersin a department named Research. The ResearchManagers group contains all managers in the Researchdepartment. All members of the ResearchManagers group are members of the Research group.

    You create a shared folder named Research. The permissions for the Research share are shown in the exhibit.(Click the Exhibit button.)

    You need to modify the share permissions to ensure that only members of the ResearchManagers group canadd

    and modify files over the network.

    What should you do?

    Exhibit:

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    6/98

    A. Remove the Domain Users group.

    B. Change the permission assigned to the Research group to Allow - Read.

    C. Remove the Research group. Change the Domain Users permission to Allow - Change.

    D. Remove the Research group. Add the ResearchManagers group and assign the group Allow - Changepermission.

    Answer: DSection: (none)

    Explanation/Reference:

    QUESTION 10Your network consists of a single Active Directory domain. All servers run Windows Server 2003 Service Pack2 (SP2). The primary group for all users is Domain Users.

    You share a folder named Data. The shared folder is located on a server named Server1.

    A user in the Research group named User1 reports that she cannot access files in the Data shared folder. Youverify that User1 is not listed in the access control list of the shared folder.

    You examine the properties of the User1 account. The properties are shown in the exhibit. (Click the Exhibitbutton.)

    Other members of the Research group can add and modify files in the Data shared folder.

    You need to ensure that User1 can access files in the Data shared folder.

    What should you do?

    Exhibit:

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    7/98

    A. Remove User1 from the IT group.

    B. Assign the Change permission to User1.C. Remove User1 from the Domain Users group.

    D. Add User1 to the Server Operators group on Server1.

    Answer: ASection: (none)

    Explanation/Reference:

    QUESTION 11You have a server that runs Windows Server 2003 Service Pack 2 (SP2).

    You create two shares as shown in the following table.

    The NTFS permissions for the HR folder are configured as shown in the exhibit. (Click the Exhibit button.)

    You need to ensure that only members of the HR group can access files in the HR folder without affecting other

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    8/98

    users' access to files in the CorpData folder.

    What should you do?

    Exhibit:

    A. Modify the NTFS permissions on the HR folder to deny Read access to the Domain Users group.

    B. Disable NTFS permission inheritance on the HR folder and copy the inherited permissions.

    C. Move the HR folder to D:\. Share D:\HR as HRData and assign the HR group Allow - Change.

    D. Modify the share permissions for the HRData share to deny read access to the Domain Users group.

    Answer: CSection: (none)

    Explanation/Reference:

    QUESTION 12You manage a software update infrastructure by using Windows Server Update Services (WSUS) 3.0.

    All client computers run Windows XP Professional Service Pack 3 (SP3). The client computers receiveAutomatic Updates from the WSUS server, and they are configured to install Automatic Updates immediately.

    From the Update Services console, you approve a required security update for all client computers.

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    9/98

    You need to force a client computer to apply the required security update as soon as possible.

    Which tool should you use?

    A. Secedit

    B. Wuauclt

    C. Wsusutil

    D. Gpupdate

    Answer: BSection: (none)

    Explanation/Reference:

    QUESTION 13You have a server named Server1. You install Windows Server Update Services (WSUS) 3.0 on Server1. Youconfigure Server1 to download all updates from Microsoft Update.

    Two weeks later, you notice that Server1 has not downloaded all updates.

    You need to ensure that Server1 downloads all updates.

    What should you do?

    A. From the command prompt, run WSUSUTIL /Reset.

    B. From the command prompt, run wuauclt.exe /detectnow.

    C. From IIS Manager, right-click WSUSPOOL, and then click Recycle.

    D. From the Update Services console, configure Server1 to use SSL when it synchronizes update information.

    Answer: A

    Section: (none)

    Explanation/Reference:

    QUESTION 14Your network consists of a single Active Directory domain. You have two servers named Server1 and Server2that run Windows Server 2003 Service Pack 2 (SP2).

    Server1 is the site license server for the Default-First-Site-Name site.

    You need to configure Server2 to be the site license server.

    What should you do?

    A. From the Licensing console on Server1, modify the Products View configuration.

    B. From the Licensing Control Panel applet on Server2, modify the Replication configuration.

    C. From the Active Directory Sites and Services console, modify the Licensing Site Settings.

    D. From the Active Directory Users and Computers console, modify the AdminSDHolder object.

    Answer: CSection: (none)

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    10/98

    Explanation/Reference:

    QUESTION 15Your network contains a server named Server1 that runs Windows Server 2003 Service Pack 2 (SP2).

    Server1 has a shared printer named Printer1.

    Users report that when they attempt to connect to Printer1 they receive the following error message:

    "The Server for `Color Laser 1000' printer does not have the correct printer driver installed. If you want tosearch for the proper driver click OK. Otherwise, click Cancel and contact your network administrator or originalequipment manufacturer for the correct printer driver."

    On Server1, you can print a test page on Printer1.

    You need to ensure that when users connect to Printer1, the correct printer driver is installed.

    What should you do?

    A. Configure the printer to use the LPT1 local port.

    B. Configure Advanced settings in Printing Preferences.

    C. Add an additional driver from the properties of Printer1.

    D. Add the Allow Manage Printers permission to CREATOR OWNER.

    Answer: CSection: (none)

    Explanation/Reference:

    QUESTION 16You have a print server that runs Windows Server 2003 Service Pack 2 (SP2).

    You need to receive a notification each time a document fails to print.

    What should you do?

    A. From the Performance console, create an alert.

    B. From the Event Viewer console, create a new filter.

    C. From the Printer Server properties, modify the Advanced settings.

    D. From the Services console, enable and configure the Messenger service.

    Answer: ASection: (none)

    Explanation/Reference:

    QUESTION 17You have a standalone server named Server1 that runs Windows Server 2003 Service Pack 2 (SP2).

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    11/98

    You install the FTP Server Windows component on Server1. You create several folders under the Ftproot folderas shown in the exhibit. (Click the Exhibit button.)

    A user named User1 connects to ftp://server1 and reports that he can view the Localuser folder and all of itssubfolders. A user named User2 reports the same problem.

    You need to ensure that when users connect to ftp://server1, they can only view the content located under theiruser folder.

    What should you do?

    Exhibit:

    A. From the properties of the Default FTP Site, change the directory listing style to Unix.

    B. From the properties of the Default FTP Site, change the FTP site directory to c:\inetpub\ftproot\localuser.C. From the properties of each user account, modify the home folder. Remove the Users group from the

    access control list of c:\inetpub\ftproot.

    D. Delete the Default FTP Site. Create a new FTP site. Select the option to isolate users and specify the FTPsite directory of c:\inetpub\ftproot.

    Answer: DSection: (none)

    Explanation/Reference:

    QUESTION 18You have a server named Server1 that runs Windows Server 2003 Service Pack 2 (SP2).

    Server1 is configured as an enterprise root certification authority (CA).

    You need to back up the CA's database and log files. You must achieve this goal by using the minimum amountof disk space.

    What should you run?

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    12/98

    A. Certreq.exe by using the -new parameter

    B. Certutil.exe by using the -backup parameter

    C. Cipher.exe by using the /k parameter

    D. Ntbackup.exe by using the systemstate parameter

    Answer: B

    Section: (none)

    Explanation/Reference:

    QUESTION 19Your network consists of a single Active Directory domain. All servers run Windows Server 2003 Service Pack2 (SP2).

    You have a server named Server1. Server1 is configured as an enterprise root certification authority (CA).

    You perform a complete backup of Server1 that includes the system state.

    Server1 fails. You install a new server named Server1.

    You need to recover the enterprise root CA.

    What should you do?

    A. Restore the system state backup.

    B. Restore the %systemroot%\system32\certsrv folder.

    C. From the Certificates snap-in, import the enterprise root CA certificate.

    D. From the Certificates snap-in, import the enterprise root CA certificate revocation list (CRL).

    Answer: A

    Section: (none)

    Explanation/Reference:

    QUESTION 20You have a Web server named Server1 that runs Windows Server 2003 Service Pack 2 (SP2).

    You replace the network adapter.

    Users report that they are unable to access Server1.

    You need to ensure that users can access Server1.

    What should you do?

    A. From Network Connections, configure the Provider Order settings.

    B. From Network Connections, configure the Adapters and Bindings settings.

    C. From the Local Area Connection properties, configure the Internet Protocol (TCP/IP) settings.

    D. From the Local Area Connection properties, configure the File and Printer Sharing for Microsoft Networkssettings.

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    13/98

    Answer: CSection: (none)

    Explanation/Reference:

    QUESTION 21Your network contains a server named Server1 that runs Windows Server 2003 Service Pack 2 (SP2). Server1is configured as shown in the following table.

    Disk1 fails. You remove Disk1 from the computer and replace it with a 250-GB basic disk named Disk2.

    You open the Disk Management snap-in and remove Disk1 from the mirrored volume. You are unable to addDisk2 to the mirrored volume.

    You need to ensure that you can add Disk2 to the mirrored volume for drive C.

    What should you do?

    A. Convert Disk2 to a dynamic disk.

    B. On Disk2, create a 160-GB simple volume.

    C. From the Action menu, select Rescan disks.

    D. Replace Disk2 with another disk that is the same size as Disk0.

    Answer: ASection: (none)

    Explanation/Reference:

    QUESTION 22Your network contains a server named Server1 that runs Windows Server 2003 Service Pack 2 (SP2). Server1is configured as shown in the following table.

    Disk1 fails. You remove Disk1 from the computer and install Disk4.

    You open the Disk Management snap-in and discover that the status of Disk1 is Missing. You bring Disk4online as a dynamic disk. Disk4 has no volume on it.

    You need to add Disk4 to the RAID-5 volume for drive C.

    What should you do from the Disk Management snap-in?

    A. From the Action menu, select Rescan disks.

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    14/98

    B. Right-click on Disk4 and create a spanned volume.

    C. Right-click on Disk2 and then click Repair Volume.

    D. Right-click on Disk1 and then click Reactivate Disk.

    Answer: CSection: (none)

    Explanation/Reference:

    QUESTION 23Your organization includes two servers named Server1 and Server2 that run Windows Server 2003 ServicePack 2 (SP2).

    Server1 and Server2 host the same Web sites.

    You need to back up the server configuration on Server1 every hour and then apply the configuration toServer2.

    Which command should you use?

    A. IISBack.vbs /backup

    B. IISBack.vbs /list

    C. IISCnfg.vbs /copy

    D. IISCnfg.vbs /save

    Answer: CSection: (none)

    Explanation/Reference:

    QUESTION 24You have a server that runs Windows Server 2003 Service Pack 2 (SP2). The server has a backup tape driveinstalled.

    You need to schedule a backup to tape. The tape must be ejected when the backup job is complete.

    Which commands should you include in the scheduled task?

    A. Devcon.exe and Poolmon.exe

    B. Ntbackup.exe and Devcon.exe

    C. Ntbackup.exe and Rsm.exe

    D. Rsm.exe and Poolmon.exe

    Answer: CSection: (none)

    Explanation/Reference:

    QUESTION 25

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    15/98

    You have a server that runs Windows Server 2003 Service Pack 2 (SP2). The server contains one volume.

    You install Certificate Services.

    You need to back up the Certif icates Services database by using the minimum amount of storage space.

    Which tool should you use?

    A. Certification Authority snap-in

    B. Certificates snap-in

    C. Certificate Templates snap-in

    D. Windows Backup

    Answer: ASection: (none)

    Explanation/Reference:

    QUESTION 26You are the network administrator for your company's Active Directory domain. The domain includes WindowsServer 2003 domain controllers and Windows XP Professional client computers.

    A new administrator named Paul is hired to assist you in deploying Windows XP Professional to 100 newcomputers. Paul installs the operating system on a new computer named Client1.

    However, when Paul tries to log on to the domain from Client1, he is unsuccessful. The logon dialog box doesnot allow him to view and select the domain name.

    You need to ensure that Paul can log on to the domain from Client1.

    What should you do?

    A. Enable the computer account for Client1.

    B. Configure Client1 as a member of the domain.

    C. Add Paul's user account to the Enterprise Admins group.

    D. Add Paul's user account to the Server Operators group.

    Answer: CSection: (none)

    Explanation/Reference:

    QUESTION 27You have a server that runs Windows Server 2003 Service Pack 2 (SP2). The server is configured as shown inthe following table.

    You need to create a software mirror of Disk1.

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    16/98

    What should you do first?

    A. Convert Disk3 to a dynamic disk.

    B. Create a new NTFS volume on Disk3.

    C. Run the Extend Volume Wizard on Disk1.

    D. Convert Disk3 to a GUID Partition Table (GPT) disk.

    Answer: ASection: (none)

    Explanation/Reference:

    QUESTION 28You have a server named Server1 that runs Windows Server 2003 Service Pack 2 (SP2).

    Server1 has a folder named D:\data. The folder is shared as Data.

    You need to enable users to recover files that are deleted from the Data shared folder.

    What should you do on Server1?

    A. From the D volume properties, modify the Shadow Copies settings.

    B. From the Sharing and Security settings of D:\data, modify the Caching settings.

    C. From the %systemroot%\system32\clients\twclient\x86 folder, install twcli32.msi.

    D. From the Services snap-in, modify the startup type of the Volume Shadow Copy Service (VSS).

    Answer: ASection: (none)

    Explanation/Reference:

    QUESTION 29Your network contains a database server named Server1 that runs Windows Server 2003 Service Pack 2(SP2).

    Server1 has the following hardware configurations:

    . A single processor that supports hyper-threading

    Dual processor motherboard

    Two hard disks

    2 GB of RAM

    The first disk contains all the files for the operating system and applications. The second disk is empty.

    Hyper-threading is disabled in the BIOS.

    Users report a slow response when they query the database on Server1.

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    17/98

    You monitor Server1 for one day and receive the performance statistics shown in the following table.

    You need to improve database performance.

    What should you do?

    A. Upgrade the RAM to 4 GB.

    B. Install a second processor.

    C. Enable hyper-threading in the BIOS.

    D. Move the database to the second disk.

    Answer: DSection: (none)

    Explanation/Reference:

    QUESTION 30Your network contains a database server named Server1. Server1 runs the 32-bit version of Windows Server2003 Enterprise Edition Service Pack 2 (SP2) and has 16 GB of RAM.

    On Server1, you open Task Manager and discover that the total physical memory shows only 4 GB of RAM.

    You need to ensure that Server1 has access to all 16 GB of RAM.

    What should you do?

    A. In the Boot.ini file, add the /PAE switch and then restart the server.

    B. In the Boot.ini file, add the /3GB switch and then restart the server.

    C. From Performance Options, set Memory Usage to Programs.

    D. From Performance Options, change the initial size of the paging file to 16 GB and then restart the server.

    Answer: ASection: (none)

    Explanation/Reference:

    QUESTION 31Your network contains a server named Server1 that runs Windows Server 2003 Service Pack (SP2).

    You install a new network adapter on Server1.

    You need to view the media access control (MAC) address for the new network adapter.

    What should you do?

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    18/98

    A. At the command prompt, run Ipconfig /all.

    B. At the command prompt, run Net view \\server1.

    C. From the Device Manager snap-in, view the properties of the network adapter.

    D. From the Services snap-in, view the properties on the Network Connections service.

    Answer: ASection: (none)

    Explanation/Reference:

    QUESTION 32Your network contains a database server that runs Windows Server 2003 Standard Edition Service Pack 2(SP2). The server has 1 GB of RAM and a single hard disk.

    Queries against the databases on the server are very slow. You discover that the hard disk on the server is veryactive.

    You are evaluating whether to add RAM to the server.

    You need to use System Monitor to find out whether adding RAM will decrease disk activity.

    Which performance counter should you monitor?

    A. LogicalDisk : % Free Space

    B. Memory : Pages Faults/sec

    C. Memory : Free System Page Table Entries

    D. Server Work Queues : Queue Length

    Answer: B

    Section: (none)

    Explanation/Reference:

    QUESTION 33Your network contains an application server named Server1 that runs Windows Server 2003 Service Pack(SP2).

    You open the Performance tab in Task Manager as shown in the exhibit. (Click the Exhibit button.)

    You need to improve the performance of Server1.

    What should you do?

    Exhibit:

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    19/98

    A. Install additional RAM.

    B. Install a second processor.

    C. Decrease the size of the paging file.

    D. Add the /PAE switch to the Boot.ini file.

    Answer: ASection: (none)

    Explanation/Reference:

    QUESTION 34You have a print server named Server1 that runs Windows Server 2003 Service Pack (SP2). Server1 isconfigured as shown in the following table.

    All the hard disks are 136 GB and are connected to a SCSI controller.

    You need to identify which disk configuration will provide the best performance for printing.

    Which disk configuration should you implement?

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    20/98

    A. one RAID-0 volume

    B. one RAID-1 volume

    C. one RAID-5 volume

    D. two RAID-1 volumes

    Answer: ASection: (none)

    Explanation/Reference:

    QUESTION 35You have a file server named Server1 that runs Windows Server 2003 Service Pack 2 (SP2). Server1 has onebasic disk that contains one partition.

    You monitor the PhysicalDisk : Avg. Disk Bytes/Read counter for one year and discover that the value hasdecreased by 25 percent.

    You need to increase the disk performance of Server1.

    What should you do?

    A. Compress the volume.

    B. Defragment the volume.

    C. Convert the disk to a dynamic disk.

    D. Enable Shadow Copies on the volume.

    Answer: BSection: (none)

    Explanation/Reference:

    QUESTION 36You have a server named Server1 that runs Windows Server 2003 Service Pack 2 (SP2). Server1 runs acustom database application. The database files are stored on drive D.

    Server1 experiences a power failure. Upon restart, the database engine reports that the log files fail to replaybecause a log file is corrupt.

    You need to minimize the risk of a log file becoming corrupt if the power fails.

    What should you do?

    A. Enable hibernation.

    B. Enable volume shadow copies.

    C. Disable read caching on drive D.

    D. Disable write caching on drive D.

    Answer: DSection: (none)

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    21/98

    Explanation/Reference:

    QUESTION 37You have a server that runs Windows Server 2003 Service Pack 2 (SP2) and is configured as a domaincontroller.

    You run Windows Update and install a number of device drivers.

    You restart the server. During the startup process, the server stops.

    You receive the following stop error message: "0x000000D1 (0x0000000c, 0x00000002, 0x00000000,0xf27b4e8e) IRQL_NOT_LESS_OR_EQUAL."

    You need to identify which device or service is causing the error.

    What should you do?

    A. Restart the server by using the Safe Mode option. Review the contents of the ntbtlog.txt file.

    B. Restart the server by using the Last Known Good Configuration option. Review the spupdsvc.log file.

    C. Restart the server by using the Directory Services Restore Mode option. Review the contents of thentdtcsetup.log file.

    D. Restart the server by using the Safe Mode with Networking option. Review the contents of theWindowsUpdate.log file.

    Answer: ASection: (none)

    Explanation/Reference:

    QUESTION 38You have two servers named Server1 and Server2 that run Windows Server 2003 Service Pack (SP2).

    You connect a USB drive to Server1 and copy several files to the USB drive.

    You connect the USB drive to Server2. You receive a message that the drive installed successful and is ready-to-use.

    You open Windows Explorer and the USB drive does not appear.

    You need to ensure that you can access the files stored on the USB drive.

    What should you do?

    A. From the command prompt, run Convert.exe.

    B. From the Disk Management snap-in, change the drive letter.

    C. From the Services snap-in, restart the Removable Storage service.

    D. From the Device Manager snap-in, scan for a hardware change.

    Answer: BSection: (none)

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    22/98

    Explanation/Reference:

    QUESTION 39You have a file server named Server1 that runs Windows Server 2003 Service Pack (SP2).

    Server1 has a 10-gigabit network adapter and is connected to a 100-Mb switch.

    You replace the 100-Mb switch by using a 1-GB switch.

    You discover that copying files to Server1 over the network is slow.

    You need to reduce the amount of time it takes to copy files to Server1 over the network.

    Which connection type should you specify for the network adapter?

    A. 1-gigabit half-duplex

    B. 1-gigabit full-duplex

    C. 10-gigabit half-duplex

    D. 10-gigabit full-duplex

    Answer: BSection: (none)

    Explanation/Reference:

    QUESTION 40You have a file server named Server1 that runs Windows Server 2003 Service Pack 2 (SP2).

    You run a full backup of Server1, update the device driver for the network adapter, and then restart Server1.

    You log on to Server1 and receive an error message that the network adapter driver failed to load.

    You need to ensure that the network adapter driver starts. You must achieve this goal in the minimum amountof time.

    What should you do?

    A. Use the Roll Back Driver option.

    B. Use Windows Backup to restore the system state.

    C. Restart the server and select the Safe Mode option.

    D. Restart the server and select the Last Known Good Configuration option.

    Answer: ASection: (none)

    Explanation/Reference:

    QUESTION 41You have a server that runs Windows Server 2003 Service Pack 2 (SP2).

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    23/98

    You need to identify all the unsigned drivers that are installed on the server.

    What should you do?

    A. Run Chkdsk.exe.

    B. Run Sigverif.exe.

    C. Review %systemroot%\repair\setup.log.

    D. Open Device Manager and review all the devices that contain a warning.

    Answer: BSection: (none)

    Explanation/Reference:

    QUESTION 42You have a server named Server1 that runs Windows Server 2003 Service Pack 2 (SP2). Server1 is used fortesting.

    You need to ensure that Server1 administrators can install any driver on Server1 without receiving a warningmessage.

    What should you do?

    A. Run Driverquery.exe.

    B. Modify the Driver Signing option.

    C. Modify the Load and unload device drivers user right.

    D. Modify the permissions for the %systemroot%\system32\drivers folder.

    Answer: BSection: (none)

    Explanation/Reference:

    QUESTION 43You have a server that runs Windows Server 2003 Service Pack 2 (SP2).

    You have a third-party hardware device installed. The device uses a third-party driver. The device worksproperly.

    The driver's hardware manufacturer provides a new device driver. You update the device driver, but the devicefails to work.

    You need to ensure that you can use the new hardware device.

    What should you do?

    A. Connect to Windows Update and install all driver updates.

    B. From the properties of the device, select Roll Back Driver.

    C. From Device Manager, uninstall the device and then restart the server.

    D. From Device Manager, disable the device and then click Scan for hardware changes.

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    24/98

    Answer: BSection: (none)

    Explanation/Reference:

    QUESTION 44Your network consists of a single domain. All domain controllers run Windows Server 2003 Service Pack 2(SP2). All client computers run Windows XP Professional Service Pack 3 (SP3).

    You need to ensure that users' personal settings are the same when they log on to different client computers inthe domain.

    What should you do?

    A. From the properties of each user account, configure a profile path.

    B. From the properties of each user account, configure a home folder path.

    C. From the Default Domain Policy, configure a logon script that runs Loadstate.exe.

    D. From the Default Domain Policy, configure a logon script that runs Scanstate.exe.

    Answer: ASection: (none)

    Explanation/Reference:

    QUESTION 45Your network consists of a single Active Directory domain. All computers on the network are joined to thedomain.

    You have a server named Server1 that runs Windows Server 2003 Service Pack 2 (SP2). You install a network

    management application named App1 on Server1.

    A user named Admin1 logs on to Server1 and reports that the shortcut to App1 does not exist. You log on toServer1 as a local administrator and verify that the shortcut to App1 exists.

    You need to ensure that a shortcut to App1 is available for Admin1 on Server1 only.

    What should you do?

    A. Log on to Server1 as a local administrator. Create a shortcut to App1 in the Default User profile.

    B. Log on to Server1 as a local administrator. Create a shortcut to App1 in the All Users profile.

    C. In the Netlogon share on a domain controller, create a folder named Default User. Create a shortcut forApp1 in

    the new folder.

    D. In the Netlogon share on a domain controller, create a folder named All Users. Create a shortcut for App1 inthe new folder.

    Answer: BSection: (none)

    Explanation/Reference:

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    25/98

    QUESTION 46Your network consists of a single Active Directory domain. All servers run Windows Server 2003 Service Pack2 (SP2). All client computers run Windows XP Professional Service Pack 3 (SP3).

    A user named User1 frequently logs on to several different computers.

    You need to ensure that the documents and shortcuts User1 stores on his desktop are available on the desktopof each computer he uses.

    Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)

    A. From Active Directory Users and Computers, modify the properties of the User1 account.

    B. From Active Directory Users and Computers, modify the properties for each computer account used byUser1.

    C. On a file server, create a shared folder named Profiles and assign the Change share permission toEveryone group.

    D. On a file server, create a shared folder named Profiles and assign the Full Control share permission to the

    Everyone group.

    Answer: ADSection: (none)

    Explanation/Reference:

    QUESTION 47Your network consists of a single Active Directory domain. All servers run Windows Server 2003 Service Pack2 (SP2). All client computers run Windows XP Professional Service Pack 3 (SP3).

    A user named User1 has a computer named Computer1.

    You need to prevent changes made to User1's desktop from being saved when User1 logs off of Computer1.

    What should you do?

    A. Log on to Computer1 as an administrator. Rename User1's user profile folder to User1.man.

    B. Log on to Computer1 as an administrator. In User1's user profile, rename ntuser.ini to ntuser.man.

    C. Implement a roaming user profile for User1. In User1's roaming user profile, rename ntuser.dat to ntuser.man.

    D. Implement a roaming user profile for User1. In User1's roaming user profile, deny User1 the Readpermission for ntuser.ini.

    Answer: CSection: (none)

    Explanation/Reference:

    QUESTION 48Your network consists of a single Active Directory domain. All servers run Windows Server 2003 Service Pack2 (SP2). All client computers run Windows XP Professional Service Pack 3 (SP3).

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    26/98

    Three client computers are public kiosks. All kiosks are configured to automatically log on as a domain usernamed KioskUser. KioskUser has a roaming rofile.

    Users frequently change the desktop backgrounds on the kiosks.

    You need to prevent changes to the desktop backgrounds from persisting when the kiosks restart.

    What should you do?

    A. In the roaming user profile, rename the ntuser.dat file to ntuser.man.

    B. In the roaming user profile, remove all permissions on the Desktop folder and assign KioskUser the Readpermission for the Desktop folder.

    C. On each kiosk, rename the ntuser.ini file to ntuser.man.

    D. On each kiosk, remove all permissions on the Documents and Settings folder and assign KioskUser theRead permission for the Documents and Settings folder.

    Answer: ASection: (none)

    Explanation/Reference:

    QUESTION 49Your network consists of a single Active Directory domain. All servers run Windows Server 2003 Service Pack2 (SP2). The domain contains a member server named Server1. Server1 is a file server.

    You accidentally delete the computer account for Server1 from the domain.

    You need to ensure that users can access the file shares on Server1 by using their domain user accounts. Youmust achieve this goal by using the minimum amount of administrative effort.

    What should you do?

    A. On Server1, run the Netdom reset command.

    B. On Server1, add the computer to a workgroup and then add the computer to the domain. Restart Server1.

    C. From Active Directory Users and Computers, create a new computer account named Server1 in thedomain.

    Restart Server1.

    D. On a domain controller, perform an authoritative restore in Active Directory for the Server1 computeraccount.

    Restart Server1.

    Answer: BSection: (none)

    Explanation/Reference:

    QUESTION 50You have a domain controller that runs Windows Server 2003 Service Pack 2 (SP2).

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    27/98

    You need to prestage 1,000 computer accounts.

    Which tool should you use?

    A. Compmgmt.msc

    B. Dsadd.exe

    C. Dsmove.exe

    D. Sysdm.cpl

    Answer: BSection: (none)

    Explanation/Reference:

    QUESTION 51Your network consists of a single Active Directory domain. All domain controllers run Windows Server 2003Service Pack 2 (SP2).

    You have an organizational unit (OU) that contains 1,000 computer accounts.

    You need to move the computer accounts to a new OU.

    Which tool should you use?

    A. Active Directory Domains and Trusts

    B. Active Directory Users and Computers

    C. Csvde.exe

    D. Dsmod.exe

    Answer: B

    Section: (none)

    Explanation/Reference:

    QUESTION 52Your network consists of a single Active Directory domain. All servers run Windows Server 2003 Service Pack2 (SP2). You have a server named Server1.

    You try to log on to Server1 and receive the following error message: "Windows cannot connect to the domain,

    either because the domain controller is down or otherwise unavailable, or because your computer account was

    not found. Please try again later. If this message continues to appear, contact your system administrator forassistance."

    You verify that you can contact a domain controller from Server1.

    You need to ensure that you can log on to Server1 by using a domain account.

    What should you do?

    A. Reset the Server1 computer account. Restart Server1.

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    28/98

    B. Delete the Server1 computer account. Restart Server1.

    C. Join Server1 to a workgroup and then join Server1 to the domain. Restart Server1.

    D. Delete the Server1 computer account. Create a new computer account named Server1. Restart Server1.

    Answer: CSection: (none)

    Explanation/Reference:

    QUESTION 53Your network consists of a single Active Directory forest that contains the domains shown in the following table.

    You create a universal security group named Contoso-All in the Contoso domain. You plan to use Contoso-Allto assign permissions only on servers in the contoso.com domain.

    You add a group named Region1-All in the Region1 domain to Contoso\Contoso-All and receive the errormessage shown in the exhibit. (Click the Exhibit button.)

    You need to need to ensure that members of Region1\Region1-All can access resources that have beenassigned to Contoso\Contoso-All.

    What should you change?

    Exhibit:

    A. Contoso\Contoso-All to a domain local security group

    B. Contoso\Contoso-All to a global security group

    C. Region1\Region1-All to a domain local security group

    D. Region1\Region-All to a universal distribution group

    Answer: ASection: (none)

    Explanation/Reference:

    QUESTION 54

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    29/98

    Your network consists of a single Active Directory domain named contoso.com. The functional level of thedomain is Windows Server 2003. Contoso contains two global groups named Users-Global and Managers-Global.

    Contoso contains 10 servers that run Windows Server 2003 Service Pack 2 (SP2). Each server has two localgroups as shown in the following table.

    Each Users-Resources local group has access to the local resources on the server.

    You need to implement a security solution that meets the following requirements:

    Managers-Global members must have access to all the resources that are accessible to Users-Globalmembers.

    The solution must minimize administrative effort.

    What should you do?

    A. Add the Managers-Global group to the Users-Global group.B. Add the Managers-Global group to the Users-Resources local group on each server.

    C. Create two universal groups named Users-Universal and Managers-Universal. Assign the two universalgroups permissions to the resources.

    D. Create two domain local groups named Users-Domain-Local and Managers-Domain-Local. Assign the twodomain local groups permissions to the resources.

    Answer: ASection: (none)

    Explanation/Reference:

    QUESTION 55Your network consists of a single Active Directory domain.

    The domain contains more than 300 group objects. The group objects are divided between several regionalorganizational units (OUs).

    You need to create a list of all groups that have names that begin with the word Sales.

    Which command should you use?

    A. Dsget group

    B. Dsquery groupC. Netdom query

    D. Net group

    Answer: BSection: (none)

    Explanation/Reference:

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    30/98

    QUESTION 56Your network contains one Active Directory domain. All domain controllers run Windows Server 2003 ServicePack 2 (SP2).

    You have a comma delimited file that contains information for 2,000 new employees.

    You need to create 2,000 new user accounts by using the information in the file. You must achieve this goal byusing the minimum amount of administrative effort.

    Which tool should you use?

    A. Csvde.exe

    B. Dsmod.exe

    C. ldifde.exe

    D. Ntdsutil.exe

    Answer: ASection: (none)

    Explanation/Reference:

    QUESTION 57Your network consists of a single Active Directory domain. The functional level of the domain is WindowsServer 2003.

    You need to assign the same street address to all user accounts located in the Users container. You must toachieve

    this goal by using the minimum amount of administrative effort.

    Which tool should you use?

    A. Active Directory Users and Computers

    B. Adsiedit.msc

    C. Csvde.exe

    D. Ldifde.exe

    Answer: ASection: (none)

    Explanation/Reference:

    QUESTION 58Your network consists of a single Active Directory domain. The functional level of the domain is WindowsServer 2003.

    You extend the Active Directory Schema to support a custom user attribute.

    You need to assign the same value to the custom attribute for 1,500 users. You must achieve this goal by usingthe minimum amount of administrative effort.

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    31/98

    Which tool should you use?

    A. Adsiedit.msc

    B. Csvde.exe

    C. Dsmod.exe

    D. Ldifde.exe

    Answer: DSection: (none)

    Explanation/Reference:

    QUESTION 59Your network contains one Active Directory domain. All domain controllers run Windows Server 2003 ServicePack 2 (SP2).

    You need to create 2,000 new user accounts and assign each one a 10-character password.

    Which tool should you use?

    A. Csvde.exe

    B. Dsmod.exe

    C. ldifde.exe

    D. Ntdsutil.exe

    Answer: CSection: (none)

    Explanation/Reference:

    QUESTION 60Your network consists of a single Active Directory domain named contoso.com. The functional level of thedomain is Windows Server 2003.

    You have a file server named Server1 that is used to store users' home folders and profiles.

    On Server1, you create a folder named D:\data\ and share the folder as UserData. You create a new useraccount named TemplateUser in Active Directory.

    You need to ensure that each user account you create by copying TemplateUser is configured to have a uniquehome folder stored in the UserData share.

    Which home folder path should you specify?

    A. D:\data\%homedrive%

    B. D:\data\%username%

    C. \\server1\userdata\%homedrive%

    D. \\server1\userdata\%username%

    Answer: DSection: (none)

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    32/98

    Explanation/Reference:

    QUESTION 61Your network consists of a single Active Directory domain named contoso.com. The functional level of thedomain is Windows Server 2003.

    You need to schedule a task to find all user accounts whose passwords have remained unchanged during thepast 60 days.

    Which tool should the scheduled task run?

    A. Dsget.exe

    B. Dsquery.exe

    C. Active Directory Users and Computers

    D. Find.exe

    Answer: B

    Section: (none)

    Explanation/Reference:

    QUESTION 62Your network consists of a single Active Directory domain. All servers run Windows Server 2003 Service Pack2 (SP2).

    You restore the system state on a member server.

    You attempt to log on to the server and receive the following error message: "The system cannot log you on to

    this domain because the system's computer account in its primary domain is missing or the password on thataccount is incorrect."

    You need to ensure that you can successfully log on to the domain from the server.

    What should you do on the server?

    A. Modify the password policy.

    B. Run the Dsrm.exe command.

    C. Restart the Netlogon service.

    D. Run the Netdom.exe reset command.

    Answer: DSection: (none)

    Explanation/Reference:

    QUESTION 63Your network consists of a single Active Directory domain. All network servers run Windows Server 2003Service Pack 2 (SP2).

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    33/98

    You have a computer named ACCT5 that runs Windows XP Professional Service Pack 3 (SP3). Users reportthat they cannot log onto ACCT5 by using their domain credentials.

    You view the properties of the computer account as shown in the exhibit. (Click the Exhibit button.)

    You need to need to ensure that users can log on to ACCT5 by using their domain credentials.

    What should you do?

    Exhibit:

    A. At the command prompt, run the Dsrm command.

    B. At the command prompt, run the Netdom reset command.

    C. From Active Directory Users and Computers, reset the computer account.

    D. From Active Directory Users and Computers, enable the computer account.

    Answer: DSection: (none)

    Explanation/Reference:

    QUESTION 64Your network consists of a single Active Directory domain. All servers run Windows Server 2003 Service Pack2 (SP2). All client computers run Windows XP Professional Service Pack 3 (SP3).

    You have an organizational unit (OU) named Accounting. You create a Group Policy object (GPO) and link it tothe Accounting OU.

    You join a new client computer to the domain.

    You discover that the new client computer fails to receive the settings from the new GPO.

    You need to ensure that the new GPO is applied to the new computer.

    What should you do?

    A. Move the computer account to the Accounting OU.

    B. Modify the Location attribute of the computer account.

    C. Modify the Managed By attribute of the computer account.

    D. Enable the Trust computer for delegation option on the computer account.

    Answer: A

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    34/98

    Section: (none)

    Explanation/Reference:

    QUESTION 65

    Your network consists of a single Active Directory domain. All servers run Windows Server 2003 Service Pack2 (SP2).

    You create a new domain user account named User1 and assign the account a password of P@ssw0rd. Onthe new account, you enable the User must change password at next logon option.

    A week later, you discover that User1 is still using the password P@ssw0rd to log on to the domain.

    You need to ensure that User1 is forced to use a different password the next time she changes her password.

    What should you do first?

    A. In the Default Domain Policy, select Enforce password history.

    B. In the Default Domain Policy, select Passwords must meet complexity requirements.C. From the User's account properties, select Account is sensitive and cannot be delegated.

    D. From the User's account properties, select Store password using reversible encryption.

    Answer: ASection: (none)

    Explanation/Reference:

    QUESTION 66Your network consists of a single Active Directory domain. All servers run Windows Server 2003 Service Pack

    2 (SP2). All client computers run Windows XP Professional Service Pack 3 (SP3).

    You need to ensure that locked out user accounts remain locked out until an administrator unlocks theaccounts.

    What should you do?

    A. In the Default Domain Policy, set the Account lockout duration to 0.

    B. In the Default Domain Policy, set the Account lockout duration to 99999.

    C. From Active Directory Users and Computers, select the Account is trusted for delegation option for all useraccounts.

    D. From Active Directory Users and Computers, select the Account is sensitive and cannot be delegated

    option for all user accounts.

    Answer: ASection: (none)

    Explanation/Reference:

    QUESTION 67Your network consists of a single Active Directory domain. All servers run Windows Server 2003 Service Pack

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    35/98

    2 (SP2). All client computers run Windows XP Professional Service Pack 3 (SP3).

    A user named User1 attempts to log on to a computer named Computer1 and receives the following errormessage.

    You need to ensure that User1 can log on to Computer1.

    What should you do?

    A. From the properties of the User1 account, modify the Log On To setting.

    B. From the properties of the User1 account, modify the Logon Hours setting.

    C. From the properties of the Computer1 account, modify the Managed By setting.

    D. From the local security policy of Computer1, modify the Deny log on locally setting.

    Answer: ASection: (none)

    Explanation/Reference:

    QUESTION 68You have a stand-alone server named Server1 that runs Windows Server 2003 Service Pack 2 (SP2).

    A user named User1 is a member of the Administrators group on Server1.

    User1 attempts to log on to Server1 and receives the following error message.

    Other members of the Administrators group can log on to Server1.

    You need to ensure that User1 can log on to Server1.

    What should you do?

    A. From the properties of the User1 account, modify the Session settings.

    B. From the properties of the User1 account, modify Environment settings.

    C. From the local security policy on Computer1, modify the Deny log on locally setting.

    D. From the local security policy on Server1, modify the Impersonate a client after authentication setting.

    Answer: CSection: (none)

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    36/98

    Explanation/Reference:

    QUESTION 69Your network consists of a single Active Directory domain. You have a member server named Server1 thatruns Windows Server 2003 Service Pack 2 (SP2).

    You need to track all authentication attempts on Server1.

    What should you do?

    A. Enable auditing of logon event events in Server1's local policy.

    B. Enable auditing of logon event events in the Default Domain Controller Policy.

    C. Enable auditing of account logon event events in Server1's local policy.

    D. Enable auditing of account logon event events in the Default Domain Controller Policy.

    Answer: ASection: (none)

    Explanation/Reference:

    QUESTION 70Your network consists of a single Active Directory Domain. You have a VPN server that runs Windows Server2003 Service Pack 2 (SP2).

    On the VPN server, you create several remote access policies. You view the properties of an account as shownin the exhibit. (Click the Exhibit button.)

    You need to select the Control access through Remote Access Policy remote access permission for User1.

    What should you do?

    Exhibit:

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    37/98

    A. Add User1 to the Remote Desktop Users group.

    B. Enable RADIUS authentication on the VPN server.C. Raise the functional level of the domain to Windows 2000 native.

    D. Select the Store password using reversible encryption option for User1.

    Answer: CSection: (none)

    Explanation/Reference:

    QUESTION 71

    You have a stand-alone server that runs Windows Server 2003 Service Pack 2 (SP2).

    You attempt to log on to the server by using the Administrator account and receive the following error message.

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    38/98

    You need to log on to the server by using the Administrator account.

    What should you do first?

    A. Restart the server in Safe mode.

    B. Restart the server by using the Last Known Good Configuration option.

    C. Log on to another stand-alone server as an Administrator.

    D. Log on to the server by using an account that is a member of the Power Users group.

    Answer: ASection: (none)

    Explanation/Reference:

    QUESTION 72You have a stand-alone server named Server1 that runs Windows Server 2003 Service Pack (SP2).

    A user attempts to connect to the server by using Remote Desktop Connection and receives the following errormessage.

    You need to ensure that the user can log on to the server by using Remote Desktop Connection.

    What should you do?

    A. On Server1, modify the Remote Control settings for the user account.

    B. On Server1, modify the Remote Access Permission settings for the user account.

    C. Instruct the user to log on to Server1 locally and then to change her password.

    D. Instruct the user to log on to another computer and then connect to Server1 by using Remote Desktop

    Connection.

    Answer: CSection: (none)

    Explanation/Reference:

    QUESTION 73

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    39/98

    You are the administrator of a single Active Directory domain named contoso.com. The network contains a

    member server named Server1 that runs Windows Server 2003 Service Pack 2 (SP2).

    A user named User1 reports that he is unable to log on from Server1. User1 is a member of the Domain Users

    global group.

    You verify the security log on Server1 and discover the following log entry:

    Event Type:Failure Audit

    Event Source: Security

    Event Category: Logon/Logoff

    Event ID:529

    Date: 8/1/2007

    Time: 12:05:51 PM

    User: NT AUTHORITY\SYSTEM

    Computer: SERVER1

    Description:

    Logon Failure:

    Reason: Unknown user name or bad password

    User Name: User1

    Domain: SERVER1

    Logon Type: 10

    Logon Process: User32

    Authentication Package: ?Negotiate

    Workstation Name:???SERVER1

    Caller User Name: SERVER1$

    Caller Domain:CONTOSO

    Caller Logon ID:(0x0,0x3E7)

    Caller Process ID: 3528

    Transited Services:-

    Source Network Address: 192.168.1.19

    Source Port:?55208

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    40/98

    You need to ensure that User1 can successfully log on to Server1.

    What should you do?

    A. Reset User1's password.

    B. Reset Server1's computer account.

    C. Instruct the user to log on as [email protected].

    D. Synchronize Server1's clock to a domain controller.

    Answer: CSection: (none)

    Explanation/Reference:

    QUESTION 74Your network consists of a single Active Directory domain. All client computers are members of the domain andrun Windows XP Professional Service Pack 3 (SP3).

    A user attempts to log on to her portable computer and receives the following error message.

    You need to ensure that the user can log on to the computer by using her domain account.

    What should you do?

    A. Instruct the user to restart her computer.

    B. On a domain controller, run Net time /set /y.

    C. On a domain controller, reset the portable computer's computer account.

    D. On a domain controller, force replication between all domain controllers.

    Answer: ASection: (none)

    Explanation/Reference:

    QUESTION 75You have a stand-alone file server that runs Windows Server 2003 Service Pack 2 (SP2).

    You create an account named Admin1 and add it to the Power Users group.

    You attempt to log on to the server by using the Admin1 account and receive the following message: "The localpolicy of this system does not permit you to log on interactively."

    You review the security settings as shown in the exhibit. (Click the Exhibit button.)

    You need to ensure that the Admin1 account can log on to the console of the server.

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    41/98

    What should you do?

    Exhibit:

    A. Add the Admin1 account to the Administrators group.

    B. Add the Admin1 account to the Allow log on locally policy.

    C. Remove the Admin1 account from the Users group.

    D. Remove the Users group from the Deny log on locally policy.

    Answer: DSection: (none)

    Explanation/Reference:

    QUESTION 76Your company has a main office and a branch office. Your network consists of a single Active Directorydomain. All domain controllers are in the main office. The offices connect to one another by using a wide areanetwork (WAN) link.

    The branch office has a computer named Server1 that runs Windows Server 2003 Service Pack 2 (SP2).

    A domain user named User1 reports that he cannot log on to Server1 when the WAN link is unavailable. Hereports that he can log on to Server1 when the WAN link is available.

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    42/98

    You need to ensure that User1 can log on to Server1 by using his domain account when the WAN link isunavailable.

    What should you do?

    A. Modify the Default Domain Policy.

    B. Modify the Default Domain Controller Policy.

    C. Add User1 to the Domain Admins group in the domain.D. Add User1 to the local Administrators group on Server1.

    Answer: ASection: (none)

    Explanation/Reference:

    QUESTION 77Your network consists of a single Active Directory domain. The functional level of the domain is WindowsServer 2003.

    You install an application that requires a user account enabled for constrained delegation. You create therequired user account.

    When you attempt to configure constrained delegation, you discover that the Delegation tab does not appear inthe user account properties.

    You need to ensure that the Delegation tab appears in the user account properties.

    What should you do?

    A. Raise the forest functional level.

    B. Add the user account to the Domain Admins group.

    C. Register a service principal name (SPN) for the user account.

    D. Select the Trust this computer for delegation to specified services only option on all domain controllers.

    Answer: CSection: (none)

    Explanation/Reference:

    QUESTION 78Your network contains a file server named Server1 that runs Windows Server 2003 Service Pack 2 (SP2).

    Server 1 is configured as shown in the following table.

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    43/98

    You need to configure security to meet the following requirements:

    Enable members of the Sales group to create, modify, and delete files and folders in the Sales folder.

    .Enable members of the Marketing group to create, modify, and delete files and folders in the Marketing folder.

    .Prevent users from modifying permissions when they access the shared files.

    What should you do?

    A. Change the share permission on Userdata to Authenticated Users: Change.

    B. Change the NTFS permission on Userdata to Authenticated Users: Modify.

    C. Change the NTFS permission on Marketing to Marketing-group: Write. Change the NTFS permission onSales

    to Sales-group: Write.

    D. Remove the Userdata share. Share Sales and assign the Sales-Group group Full Control share permission.

    Share Marketing and assign the Marketing-Group group Full Control share permission.

    Answer: ASection: (none)

    Explanation/Reference:

    QUESTION 79Your network contains a file server named Server1 that runs Windows Server 2003 Service Pack 2 (SP2).

    Server 1 is configured as shown in the following table.

    You need to modify permissions to meet the following requirements:

    Enable all users to read all files in the Userdata share.

    .Enable members of the Sales group to create, modify, and delete files and folders in the Sales folder.

    What should you do?

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    44/98

    A. Assign the Sales group the Modify permission for the Sales folder.

    B. Assign the Sales group the Full Control permission for the Userdata share.

    C. Assign Authenticated Users the Read permission for the Userdata share. Assign the Sales group the Full

    Control permission for the Sales folder.

    D. Assign the Sales group the Change permission for the Userdata share. Assign Authenticated Users theRead

    permission for the Userdata share.

    Answer: ASection: (none)

    Explanation/Reference:

    QUESTION 80Your network contains a file server named Server1 that runs Windows Server 2003 Service Pack 2 (SP2).

    Server1 is configured as shown in the following table.

    You need to ensure that only members of the Support group can copy files from the Apps share.

    What should you do?

    A. On the Apps folder, remove Authenticated Users.

    B. On the Apps folder, assign the Full Control permission to the Support group.

    C. On the Apps share, assign the Change permission to the Support group.

    D. On the Apps share, remove Authenticated Users and assign the Change permission to the Support group.

    Answer: ASection: (none)

    Explanation/Reference:

    QUESTION 81Your network contains a file server named Server1 that runs Windows Server 2003 Service Pack 2 (SP2).

    Server1 is configured as shown in the following table.

    A user named User1 belongs to the Helpdesk group and the Support group.

    You need to configure security to meet the following requirements:

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    45/98

    .Prevent User1 from changing files and folders in the Apps share.

    .Allow User1 to open and run applications in the Apps share.

    What should you do?

    A. On the Apps share, assign User1 the Read share permission.

    B. On the Apps folder, deny User1 the Write NTFS permission.C. On the Apps folder, deny User1 the Modify NTFS permission.

    D. On the Apps folder, assign User1 the Read & Execute NTFS permission.

    Answer: BSection: (none)

    Explanation/Reference:

    QUESTION 82Your network consists of a single Active Directory domain named contoso.com. All servers run Windows Server2003 Service Pack 2 (SP2). The domain contains a domain Distributed File System (DFS) root namedDFSroot.

    The network contains the offices shown in the following table.

    Server1 and Server2 currently each host a share named Applications.

    You need to implement a solution to meet the following requirements:

    .Automatically redirect users to the Applications folder in their local site.

    Ensure that the contents of the Applications shares on Server1 and Server2 are automatically synchronized.

    What should you do?

    A. In the DFS root, create one link named Applications that has \\server1\applications and \\server2\applications as targets.

    B. In the DFS root, create a root target that points to \\server1\applications. Create a second root target that

    points to \\server2\applications.C. In the DFS root, create one link named Applications1 that has \\server1\applications as its target. Create a

    second link named Applications2 that has \\server2\applications as its target.

    D. In the Main-office-computers OU, publish the \\server1\applications share. In the Branch-office-computersOU, publish the \\server2\applications share.

    Answer: ASection: (none)

    Explanation/Reference:

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    46/98

    QUESTION 83Your network contains a single Active Directory domain. All servers on the network are members of the domain.

    You have a server named Server1 that runs Windows Server 2003 Service Pack 2 (SP2). Server1 has twoNTFS partitions.

    You create and share a folder named Data in the root of a partition on Server1.

    You log on to your computer by using the domain Administrator account and discover that you cannot modifyfiles in the Data share.

    You need to ensure that the Administrator can modify files in the Data share. The solution must use theminimum amount of permissions.

    What should you do?

    A. Modify the NTFS permissions on the Data folder.

    B. Modify the share permissions on the Data share.

    C. Add the domain administrator to the local Administrator's group on Server1.

    D. Move the Data folder to a new file allocation table (FAT) partition. Share the folder by using the default

    permissions.

    Answer: BSection: (none)

    Explanation/Reference:

    QUESTION 84Your network consists of a single Active Directory domain. The functional level of the domain is WindowsServer 2003. All servers run Windows Server 2003 Service Pack 2 (SP2).

    The network contains 10 file servers. Each file server hosts a share named Apps.

    On each file server, a local group named App-install-local has permissions to the Apps share. A global groupnamed App-install-global belongs to the App-install-local group on each file server. App-install-global is usedonly to control permissions for the Apps share.

    You create a global group named Helpdesk.

    You need to provide the Helpdesk group access to the Apps share on each file server. The Helpdesk groupmust have the same permissions as the App-install-global group. You must achieve this goal by using theminimum amount of administrative effort.

    What should you do?

    A. Add the Helpdesk group to the App-install-global group.

    B. Add the Helpdesk group to the App-install-local group on each file server.

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    47/98

    C. Convert the App-install-global group to a universal group. Add the App-install-global group to the Helpdesk

    group.

    D. Convert the Helpdesk group to a universal group. Add the Helpdesk group to the App-install-local group on

    each file server.

    Answer: ASection: (none)

    Explanation/Reference:

    QUESTION 85Your network consists of a single Active Directory domain. All servers run Windows Server 2003 Service Pack2 (SP2). All client computers run Windows XP Professional Service Pack 3 (SP3).

    You deploy a server named Server1 and install Terminal Server.

    After four months, users report that they can connect to Server1 by using Remote Desktop Connection, but areunable to log on.

    You verify that the user permissions have not changed.

    You need to ensure that users can log on to Server1 by using Remote Desktop Connection.

    What should you do?

    A. Restart Server1.

    B. Restore the system state of Server1.

    C. Install and configure Terminal Server Licensing.

    D. Modify the Terminal Services service account on Server1.

    Answer: CSection: (none)

    Explanation/Reference:

    QUESTION 86You have a terminal server named Server1 that runs Windows Server 2003 Service Pack 2 (SP2).

    Occasionally, users report that they cannot connect to the terminal server.

    You need identify user accounts that have multiple Terminal Services connections to Server1.

    Which tool should you use?

    A. Remote Desktop

    B. Terminal Server Licensing

    C. Terminal Services Configuration

    D. Terminal Services Manager

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    48/98

    Answer: DSection: (none)

    Explanation/Reference:

    QUESTION 87Your network consists of a single Active Directory domain. All servers run Windows Server 2003 Service Pack2 (SP2). All client computers run Windows XP Professional Service Pack 3 (SP3).

    You enable and configure Terminal Server on a server named Server1. A firewall separates Server1 from theinternal network.

    Internal users report that they cannot connect to Server1 by using Remote Desktop Connection.

    You need to ensure that the users can connect to Server1 by using Remote Desktop Connection.

    Which port should you open on the firewall?

    A. 389

    B. 3268

    C. 3389

    D. 5900

    Answer: CSection: (none)

    Explanation/Reference:

    QUESTION 88

    You have a server that runs Windows Server 2003 Service Pack 2 (SP2). The server has Terminal Serverinstalled.

    You have a new multi-user application that you plan to install on the server. The setup program for theapplication is named setup.exe.

    You need to install the application on the server. You must ensure that the application can be used by all users.

    What should you do?

    A. From the command prompt, run setup.exe.

    B. From Add or Remove Programs, add a new program.

    C. In Windows Explorer, use the Run As option to run setup.exe.

    D. In Windows Explorer, use Compatibility mode to run setup.exe.

    Answer: BSection: (none)

    Explanation/Reference:

    QUESTION 89

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    49/98

    You have a server that runs Windows Server 2003 Service Pack 2 (SP2).

    You enable Remote Desktop on the server and add 10 users to the Remote Desktop Users group.

    Users report that they occasionally receive an error message indicating that Terminal Server has reached themaximum number of connections.

    You need to ensure that all 10 users can establish Remote Desktop connections to the server concurrently.

    What should you do?

    A. From Add or Remove Programs, add the Terminal Server component.

    B. From Add or Remove Programs, add the Connection Point Services component.

    C. From the Terminal Services Configuration console, modify the Maximum connections setting.

    D. From the Terminal Services Configuration console, modify the Restrict each user to one session setting.

    Answer: ASection: (none)

    Explanation/Reference:

    QUESTION 90You have a terminal server named Server1 that runs Windows Server 2003 Service Pack 2 (SP2).

    From the Terminal Services Configuration console, you enable remote control of user sessions.

    You log on to Server1 as Administrator and attempt to take remote control of the admin1 user session asshown in the exhibit. (Click the Exhibit button.)

    You need to ensure that you can take remote control of the admin1 user session from the Terminal Services

    Manager console.

    What should you do?

    Exhibit:

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    50/98

    A. Modify the Session settings of the admin1 account.

    B. Modify the Session settings of the Administrator account.

    C. Connect to Server1 by using Remote Desktop Connection.

    D. Add the Administrator account to the HelpServicesGroup group.

    Answer: CSection: (none)

    Explanation/Reference:

    QUESTION 91You have a terminal server named Server1 that runs Windows Server 2003 Service Pack 2 (SP2). WindowsFirewall is disabled on Server1.

    Server1 has two network adapters named NIC1 and NIC2. Both network adapters are connected to the samenetwork segment. The IP address for NIC1 is 192.168.1.11. The IP address for NIC2 is 192.168.1.12. You

    regularly connect to Server1 by using Remote Desktop Connection.

    The NIC1 network adapter fails.

    You attempt to establish a Remote Desktop connection to 192.168.1.12, but the connection fails. Yousuccessfully connect to 192.168.1.12 by using Windows Explorer.

    You verify that IP filtering is disabled and that no IPSec policies are assigned.

    You need to ensure that you can establish Remote Desktop connections to Server1.

    What should you do?

    A. From Windows Firewall, enable the Remote Desktop exception.

    B. From Terminal Services Manager, modify the RDP-TCP settings.

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    51/98

    C. From the properties of NIC1, modify Internet Protocol (TCP/IP) settings.

    D. From Windows Explorer, modify the %systemroot%\system32\drivers\etc\services file.

    Answer: BSection: (none)

    Explanation/Reference:

    QUESTION 92Your network consists of a single Active Directory domain. All servers run Windows Server 2003 Service

    Pack 2 (SP2). All client computers run Windows XP Professional Service Pack 3 (SP3). You have a terminalserver named Server1.

    A user reports that when he connects to Server1 by using Remote Desktop Connection, he cannot print. Otherusers report that they can print when they connect to Server1 by using Remote Desktop Connection.

    You examine the user's account properties as shown in the exhibit. (Click the Exhibit button.)

    You need to ensure that the user can print when he connects to Server1 by using Remote Desktop Connection.

    What should you do?

    Exhibit:

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    52/98

    A. On Server1, modify the RDP-TCP settings.

    B. On Server1, modify the local security policy.C. On the user's computer, modify the Windows Firewall settings.

    D. On the user's computer, modify the Remote Desktop Connection settings.

    Answer: DSection: (none)

    Explanation/Reference:

    QUESTION 93You have two servers named Server1 and Server2 that run Windows Server 2003 Service Pack 2 (SP2).

    From Server2, you connect to Server1 by using Remote Desktop Connection. When you attempt to log on, youreceive the following error message.

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    53/98

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    54/98

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    55/98

    A. On the Data folder, allow the Write permission.

    B. On the Data folder, allow the Modify permission.

    C. On the Data share, allow the Change permission.

    D. On the Data share, allow the Full Control permission.

    Answer: ASection: (none)

    Explanation/Reference:

    QUESTION 98You have a stand-alone file server that runs Windows Server 2003 Service Pack 2 (SP2).

    The server has a shared folder that contains over 1,000 folders. The folders contain over 100,000 files.

    You need to create a batch file that modifies the permissions of all files that start with the string "report".

    Which command should you include in the batch file?

    A. Attrib.exe

    B. Cacls.exe

    C. Dsacls.exe

    D. Dsmod.exe

    Answer: BSection: (none)

    Explanation/Reference:

    QUESTION 99Your network consists of a single Active Directory domain. All servers run Windows Server 2003 Service Pack2 (SP2). All client computers run Windows XP Professional Service Pack 3 (SP3).

    You assign NTFS permissions to a folder on a file server as shown in the following table.

    You share the folder and assign the Change permission to the Everyone group.

    A user named User1 is a member of Group1, Group2, and Group3.

    You need to identify the least restrictive NTFS permission that User1 has when he accesses the folder over thenetwork.

    Which permission should you identify?

    A. Full Control

    B. Modify

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    56/98

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    57/98

    B. Create a scheduled task to run Attrib.exe.

    C. Create a scheduled task to run Icacls.exe.

    D. Use the Advanced Security settings to change the owner of each file.

    Answer: CSection: (none)

    Explanation/Reference:

    QUESTION 102Your network consists of a single Active Directory domain. All network servers run Windows Server 2003Service Pack 2 (SP2).

    You share a folder named Research. A user named User1 reports that he cannot access files in the Researchshare.

    You confirm that the Domain Users group is granted the Change permission for the Research share.

    You run the Cacls command as shown in the exhibit. (Click the Exhibit button.)

    You need to ensure that User1 can modify files in the Research share. You must prevent User1 from modifying

    permissions for the Research folder.

    To which group should you add User1?

    Exhibit:

    A. Administrators

    B. IT

    C. Research

    D. ResearchManagers

    Answer: DSection: (none)

    Explanation/Reference:

    QUESTION 103Your network consists of a single Active Directory domain. All network servers run Windows Server 2003Service Pack 2 (SP2).

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    58/98

    You create a folder named CorporateData. You share the folder as CorpData and assign the Changepermission to the Domain Users group.

    In the CorporateData folder, you create a folder named HumanResources. On the HumanResources folder,you assign the Modify permission to a global group named HRUsers. You share the HumanResources folder asHRData.

    You confirm that all users in the domain can view the files in the HRData share.

    You need to ensure that only HRUsers and administrators can access files in the HRData share. The solutionmust maintain user access to the CorpData share.

    What should you do?

    A. On the CorpData share, assign the Read permission to Domain Users.

    B. On the CorpData share, remove Domain Users and assign the Change permission to HRUsers.

    C. On the CorporateData folder, disable permission inheritance and remove the inherited permissions.

    D. On the HumanResources folder, disable permission inheritance and remove the inherited permissions.

    Answer: DSection: (none)

    Explanation/Reference:

    QUESTION 104Your network consists of a single Active Directory forest that contains two domains named contoso.com andEU.contoso.com. All network servers run Windows Server 2003 Service Pack 2 (SP2).

    The contoso.com domain contains a domain local group named Contoso-HR. The EU.contoso.com domaincontains a domain local group name EU-HR.

    On a server named Server1 in the contoso.com domain, you create a shared folder named Share1. You assignthe Contoso-HR group the Read permission for Share1.

    You discover that you cannot assign permissions on Share1 to the EU-HR group.

    You need to ensure that the members of the EU-HR group have the Read permission on Share1.

    Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)

    A. Add the EU-HR group to Contoso-HR.

    B. Change the scope of the EU-HR group to global.

    C. Change the scope of the Contoso-HR group to universal.

    D. Configure a shortcut trust between the EU and the Contoso domains.

    Answer: ABSection: (none)

    Explanation/Reference:

    QUESTION 105

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    59/98

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    60/98

    C. Delete some files on the hard disk that contains the Marketing share.

    D. Modify the Quota settings for User1 on the hard disk that contains the Marketing share.

    Answer: BSection: (none)

    Explanation/Reference:

    QUESTION 106Your network consists of a single Active Directory domain. All servers run Windows Server 2003 Service Pack2 (SP2). All client computers run Windows XP Service Pack 3 (SP3).

    A user named User1 is responsible for deleting old, unused files from departmental shared folders. User1performs the task by using a Remote Desktop connection to each file server.

    User1 is a member of a global group named IT.

    User1 attempts to delete a file from the Marketing folder and receives an access denied message.

    The share permissions for the Marketing folder are shown in the Share exhibit. (Click the Exhibit button.)

    The NTFS permissions for the Marketing folder are shown in the Folder exhibit. (Click the Exhibit button.)

    You need to ensure that User1 can delete the file from the Marketing folder.

    Which permission should you grant to User1?

    img-152 (exhibit):

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    61/98

    img-153 (exhibit):

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    62/98

    A. Allow-Write permissions on the Marketing folder.

    B. Allow-Modify permissions on the Marketing folder.

    C. Allow-Change permissions on the Marketing share.

    D. Allow-Full Control permissions on the Marketing share.

    Answer: BSection: (none)

    Explanation/Reference:

    QUESTION 107Your network consists of a single Active Directory domain. All network servers run Windows Server 2003

    Service Pack 2 (SP2).

    The domain includes two global groups named ResearchManagers and ResearchUsers.

    You create a share named ResearchData. On the ResearchData share, you assign the Change permission toResearchUsers and ResearchManagers.

    The ResearchData folder contains a file named ResearchConfidential.rtf. The permissions forResearchConfidential.rtf are configured as shown in the exhibit. (Click the Exhibit button.)

    Members of ResearchUsers report that when they try to open ResearchConfidential.rtf, they receive an access

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    63/98

    denied message. Users report that they can add and modify other files in ResearchData.

    You need to ensure that ResearchUsers members can open ResearchConfidential.rtf. The solution mustprevent ResearchUsers members from modifying the file.

    What should you do?

    Exhibit:

    A. On ResearchData, enable permission inheritance.

    B. On ResearchConfidential.rtf, enable permission inheritance.

    C. On ResearchData, assign the Read permission to ResearchUsers.

    D. On ResearchConfidential.rtf, assign the Read permission to ResearchUsers.

    Answer: DSection: (none)

    Explanation/Reference:

    QUESTION 108Your network consists of a single Active Directory domain. You have a file server named Server1 that runsWindows Server 2003 Service Pack 2 (SP2).

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    64/98

    You create a shared folder named Home. Permissions for the Home shared folder are configured as shown inthe following table.

    From Active Directory Users and Computers, you define a home folder for each user and specify the path \

    \server1\home\%username%.

    Users report that they can access their home folders, but they can also access everyone else's home folders.

    You need to ensure that users can view and save files in their home folders. You must prevent users fromviewing any other home folders.

    What should you do?

    A. On the Home share, remove the share permissions for Domain Users.

    B. On the Home share, deny the Read share permission for Domain Users.

    C. In the Home folder, remove the NTFS permissions for Domain Users.

    D. In the Home folder, change the NTFS permission for Domain Users to Allow - Read.

    Answer: CSection: (none)

    Explanation/Reference:

    QUESTION 109Your network consists of a single Active Directory domain. All servers run Windows Server 2003 Service Pack2 (SP2).

    You enable auditing for failed logon attempts on all domain controllers.

    You need to ensure that a record of failed logon attempts is retained for 90 days on all domain controllers.

    What should you do?

    A. From the Security Templates snap-in, open the hisecdc template. Modify the Retain System Log setting.

    B. From the Security Templates snap-in, open the securedc template. Modify the Retain Security Log setting.

    C. Open the Default Domain Policy. Modify the Retain System Log setting.

    D. Open the Default Domain Controller Policy. Modify the Retain Security Log setting.

    Answer: D

    Section: (none)

    Explanation/Reference:TestInside Microsoft 70-290

    QUESTION 110Your network consists of a single Active Directory domain that contains two domain controllers. Both domaincontrollers run Windows Server 2003 Service Pack 2(SP2).Auditing of successful account logon events is enabled on all computers in the domain.

  • 8/9/2019 Microsoft.testInside.70 290.v2010!01!03

    65/98

    You need to identify the last time a specific user logged on to the domain.

    What should you do?

    A. Examine the System Event Log on the user's computer.

    B. Examine the System Event Log on both domain controllers.

    C. Examine the Security Event Log on both domain controllers.

    D. Examine the Application Event Log on the user's computer.

    Answer: CSection: (none)

    Explanation/Reference:

    QUESTION 111Your network consists of a single Active Directory domain. You have 10 Web servers run Windows Server 2003Service Pack 2 (SP2).

    You need to archive all of the application event logs for all the Web servers. The archived logs must contain allinformation from the original logs.

    What should you do?

    A. Connect to each Web Server by using Event Viewer.