70-640 Microsoft Real Questions Pass4Sure Free Tests 96-100

Ensurepass

d6. Ensurepass has an Active Directory domain. All servers run Windows Server 2008 R2. Ensurepass uses an Enterprise Root certification authority (CA) and an Enterprise Intermediate CA.
The Enterprise Intermediate CA certificate expires.
You need to deploy a new Enterprise Intermediate CA certificate to all computers in the domain.
What should you do?
A. Import the new certificate into the Intermediate Certification Store on the Enterprise Root CA server.
B. Import the new certificate into the Intermediate Certification Store on the Enterprise Intermediate CA server.
C. Import the new certificate into the Intermediate Certification Store in the Default Domain Controllers group policy object.
D. Import the new certificate into the Intermediate Certification Store in the Default Domain group policy object.
Answer: D

87. Ensurepass has an Active Directory domain.
You plan to install the Active Directory Certificate Services (AD CS) server role on a member server that runs Windows Server 2008 R2.
You need to ensure that members of the Account Operators group are able to issue smartcard credentials. They should not be able to revoke certificates.
Which three actions should you perform? (Each correct answer presents part of the solution. Choose three.)
A. Install the AD CS server role and configure it as an Enterprise Root CA.
B. Install the AD CS server role and configure it as a Standalone CA.
C. Restrict enrollment agents for the Smartcard logon certificate to the Account Operator group.
D. Restrict certificate managers for the Smartcard logon certificate to the Account Operator group.
E. Create a Smartcard logon certificate.
F. Create an Enrollment Agent certificate.
Answer: ACE

88. Your network consists of a single Active Directory domain. The functional level of the forest is Windows Server 2008 R2.
You need to create multiple password policies for users in your domain.
What should you do?
A. From the Active Directory Schema snap-in, create multiple class schema objects.
B. From the ADSI Edit snap-in, create multiple Password Setting objects.
C. From the Security Configuration Wizard, create multiple security policies.
D. From the Group Policy Management snap-in, create multiple Group Policy objects.
Answer: B

89. Ensurepass has an Active Directory domain. All servers run Windows Server 2008 R2. Ensurepass uses an Enterprise Root certificate authority (CA).
You need to ensure that revoked certificate information is highly available.
What should you do?
A. Implement an Online Certificate Status Protocol (OCSP) responder by using Network Load Balancing.
B. Implement an Online Certificate Status Protocol (OCSP) responder by using an Internet Security and Acceleration Server array.
C. Publish the trusted certificate authorities list to the domain by using a Group Policy Object (GPO).
D. Create a new Group Policy Object (GPO) that allows users to trust peer certificates. Link the GPO to the domain.
Answer: A