Latest Real 70-649 Tests Dumps and VCE Exam Questions 41-50

Ensurepass

QUESTION 41

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1 and a client computer named Computer1. Server1 runs Windows Server 2008 R2. Computer1 runs Windows 7. Server1 has the Remote Desktop Session Host (RD Session Host) role service and the Remote Desktop Web Access (RD Web Access) role service installed. You need to ensure that new RemoteApp programs published on Server1 are automatically added to the Start menu on Computer1. What should you do?

 

A.      From RemoteApp and Desktop Connections on Server1, set up a new connection

B.      From RemoteApp and Desktop Connections on Computer1, set up a new connection.

C.      From RemoteApp Manager on Server1, create an .rdp file. Deploy the .rdp file to Computer1.

D.      From RemoteApp Manager on Server1, create a Windows Installer package. Deploy the package to Computer1.

 

Correct Answer: B

 

 

QUESTION 42

Your network contains a Web server named Server1 that runs Windows Server 2008 R2. You modify the configuration of Server1. You need to restore the previous Web server configuration. What should you run?

 

A.      appcmd.exe

B.      iisback.vbs

C.      iisext.vbs

D.      iisreset.exe

 

Correct Answer: A

 

 

QUESTION 43

Your network contains an Active Directory domain. The domain contains a server named Server1. Server1 runs Windows Server 2008 R2. You need to mount an Active Directory Lightweight Directory Services (AD LDS) snapshot from Server1. What should you do?

 

A.      Run Idp.exe and use the Bind option.

B.      Run diskpart.exe and use the Attach option.

C.      Run dsdbutil.exe and use the snapshot option.

D.      Run imagex.exe and specify the /mount parameter.

 

Correct Answer: C

 

 

QUESTION 44

You manage a member server that runs Windows Server 2008 R2. The server has the Web Server (IIS) server role installed. The Web server hosts a Web site named Intranet1. Only internal Active Directory user accounts have access to the Web site. The authentication settings for Intranet1 are configured as shown in the exhibit.

 

clip_image002

 

You need to ensure that users authenticate to the Web site by using only the:

 

Microsoft Challenge Handshake Authentication Protocol version 2 (MS-CHAPv2) encrypted Active Directory credentials.

 

Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)

 

A.      Add the Digest Authentication role service and the URL Authorization role service to the server.

B.      Add the Windows Authentication role service to IIS. Configure the Windows Authentication setting to Enabled in the Intranet1 properties.

C.      Configure the Basic Authentication setting to Disabled in the Intranet1 properties.

D.      Configure the Default domain field for the Basic Authentication settings on Intranet1 by adding the name of the Active Directory domain.

E.       Configure the Basic Authentication setting to Disabled and the Anonymous Authentication setting to Enabled in the Intranet1 properties.

 

Correct Answer: BC

 

 

QUESTION 45

Your company has a server that runs an instance of Active Directory Lightweight Directory Services (AD LDS). You need to create new organizational units in the AD LDS application directory partition. What should you do?

 

A.      Use the Active Directory Users and Computers snap-in to create the organizational units on the AD LDS application directory partition.

B.      Use the ADSI Edit snap-in to create the organizational units on the AD LDS application directory partition.

C.      Use the dsadd OU <OrganizationalUnitDN> command to create the organizational units.

D.      Use the dsmod OU <OrganizationalUnitDN> command to create the organizational units.

 

Correct Answer: B

 

 

QUESTION 46

Your network contains two Active Directory forests named contoso.com and adatum.com. Active Directory Rights Management Services (AD RMS) is deployed in contoso.com. An AD RMS trusted user domain (TUD) exists between contoso.com and adatum.com. From the AD RMS logs, you discover that some clients that have IP addresses in the adatum.com forest are authenticating as users from contoso.com. You need to prevent users from impersonating contoso.com users. What should you do?

 

A.      Configure trusted e-mail domains.

B.      Enable lockbox exclusion in AD RMS.

C.      Create a forest trust between adatum.com and contoso.com.

D.      Add a certificate from a third-party trusted certification authority (CA).

 

Correct Answer: A

 

 

QUESTION 47

Your company has an Active Directory forest that contains a single domain. The domain member server has an Active Directory Federation Services (AD FS) server role installed. You need to configure AD FS to ensure that AD FS tokens contain information from the Active Directory domain. What should you do?

 

A.      Add and configure a new account store.

B.      Add and configure a new account partner.

C.      Add and configure a new resource partner.

D.      Add and configure a Claims-aware application.

 

Correct Answer: A

 

 

QUESTION 48

Your network contains an Active Directory domain named contoso.com. Contoso.com contains a domain controller named DC1 and a read-only domain controller (RODC) named RODC1. You need to view the most recent user accounts authenticated by RODC1. What should you do first?

 

A.      From Active Directory Sites and Services, right-click the Connection object for DC1, and then click Replicate Now.

B.      From Active Directory Sites and Services, right-click the Connection object for DC2, and then click Replicate Now.

C.      From Active Directory Users and Computers, right-click contoso.com, click Change Domain Controller, and then connect to DC1.

D.      From Active Directory Users and Computers, right-click contoso.com, click Change Domain Controller, and then connect to RODC1.

 

Correct Answer: C

 

 

QUESTION 49

You deploy a new Active Directory Federation Services (AD FS) federation server. You request new certificates for the AD FS federation server. You need to ensure that the AD FS federation server can use the new certificates. To which certificate store should you import the certificates?

 

A.      Computer

B.      IIS Admin Service account

C.      Local Administrator

D.      World Wide Web Publishing Service account

 

Correct Answer: A

 

 

QUESTION 50

Your network contains an Active Directory domain named contoso.com. The domain contains a server named Server1. The Active Directory Federation Services (AD FS) role is installed on Server1. Contoso.com is defined as an account store. A partner company has a Web-based application that uses AD FS authentication. The partner company plans to provide users from contoso.com access to the Web application. You need to configure AD FS on contoso.com to allow contoso.com users to be authenticated by the partner company. What should you create on Server1?

 

A.      a new application

B.      a resource partner

C.      an account partner

D.      an organization claim

 

Correct Answer: D