TS: Windows Server 2008 Active Directory, Configuring (70-640) — Questions and Answers
Question 1: In AD FS, what is a 'relying party trust'?
- A trust between two AD forests for Kerberos authentication
- A certificate trust used to validate the AD FS SSL certificate
- A Kerberos delegation setting for AD FS service accounts
- A configuration entry representing an application or partner that accepts claims from the Federation Service (Correct answer)
Correct answer: A configuration entry representing an application or partner that accepts claims from the Federation Service
A relying party trust defines the application or partner organization that will consume tokens issued by the AD FS Federation Service.
Question 2: Which DNS record type is required for domain controllers to be located by clients in Active Directory?
- MX record
- PTR record
- A record
- SRV record (Correct answer)
Correct answer: SRV record
SRV (Service Locator) records are registered by domain controllers so clients can locate AD services like LDAP and Kerberos.
Question 3: Which DNS zone type automatically replicates zone data to all DNS servers running on domain controllers in the forest?
- Active Directory-integrated zone with DomainDNSZones scope
- Active Directory-integrated zone with ForestDNSZones scope (Correct answer)
- Standard secondary zone
- Standard primary zone
Correct answer: Active Directory-integrated zone with ForestDNSZones scope
Forest-wide AD-integrated zones replicate through the ForestDNSZones application partition to all DNS-enabled DCs across the entire forest.
Question 4: Your security team needs to receive email alerts whenever a privileged group membership changes in Active Directory. Which solution best automates this notification?
- Enabling SNMP on all domain controllers
- Manually reviewing ADUC weekly
- Configuring audit policies and using Windows Event Log subscriptions with a SMTP-capable alerting tool (Correct answer)
- Scheduled Netdom queries
Correct answer: Configuring audit policies and using Windows Event Log subscriptions with a SMTP-capable alerting tool
Combining audit policies for group membership changes with event log forwarding and an SMTP alerting tool provides automated, real-time notification to the security team.
Question 5: What is the purpose of 'Security Filtering' on a GPO link?
- To block external GPO imports
- To restrict which users or computers a GPO applies to within the linked container (Correct answer)
- To scan GPO settings for security vulnerabilities
- To encrypt GPO contents
Correct answer: To restrict which users or computers a GPO applies to within the linked container
Security Filtering controls which security principals (users, groups, computers) within the linked OU actually receive the GPO's settings.
Question 6: What is the significance of the 'Global Catalog' in a multi-domain Active Directory forest?
- It stores a partial read-only copy of all objects in the forest to speed up cross-domain searches (Correct answer)
- It stores a full writable copy of all objects in the forest
- It is required only for single-domain forests
- It replicates only security group membership data
Correct answer: It stores a partial read-only copy of all objects in the forest to speed up cross-domain searches
The Global Catalog holds a partial, read-only replica of all objects in the forest, enabling fast searches across domains without requiring referrals to each domain's DC.
Question 7: Management requests a report on which service accounts have passwords that never expire, for a security review. Which PowerShell command retrieves this information?
- Netuser /domain | findstr /i service
- Dsquery user -pwdneverexpires
- Both A and C return the correct results (Correct answer)
- Get-ADUser -Filter {PasswordNeverExpires -eq $true} -Properties PasswordNeverExpires, ServicePrincipalName
Correct answer: Both A and C return the correct results
Both the PowerShell Get-ADUser filter for PasswordNeverExpires and Dsquery with -pwdneverexpires return user accounts with non-expiring passwords, supporting security review reporting.
Question 8: During an AD migration project, the change management board requires weekly status updates on object migration progress. Which approach best provides accurate counts of migrated objects?
- Running ping sweeps on migrated computers
- Using ADMT (Active Directory Migration Tool) logs and reports (Correct answer)
- Manually counting objects in ADUC
- Reviewing DHCP lease logs
Correct answer: Using ADMT (Active Directory Migration Tool) logs and reports
ADMT generates detailed migration logs and reports that document how many users, computers, and groups have been successfully migrated, supporting change board communications.
Question 9: What is the significance of a code of conduct for MCTS 70-640 professionals?
- It limits professional freedom
- It applies only to new practitioners
- It establishes expected behaviors and ethical standards that protect the public and profession (Correct answer)
- It is merely symbolic
Correct answer: It establishes expected behaviors and ethical standards that protect the public and profession
This is fundamental to MCTS 70-640 Exam practice. It establishes expected behaviors and ethical standards that protect the public and profession represents the professional standard for professional standards in the MCTS 70-640 certification framework.
Question 10: What is reflective practice in MCTS 70-640 Exam professional development?
- Only reflecting on successes
- Avoiding past mistakes
- Systematically examining experiences to gain insight and improve future practice (Correct answer)
- Writing personal diaries
Correct answer: Systematically examining experiences to gain insight and improve future practice
This is fundamental to MCTS 70-640 Exam practice. Systematically examining experiences to gain insight and improve future practice represents the professional standard for practical in the MCTS 70-640 certification framework.
Question 11: What is the purpose of the Infrastructure Master FSMO role?
- Manages the AD schema
- Assigns RIDs to domain controllers
- Updates cross-domain group-to-user references (Correct answer)
- Handles password changes for pre-Windows 2000 clients
Correct answer: Updates cross-domain group-to-user references
The Infrastructure Master updates references to objects in other domains, such as group memberships.
Question 12: Which AD DS component must be present in each domain in a forest for users in that domain to successfully log on to resources in other domains?
- RODC (Read-Only Domain Controller)
- DNS delegated zone
- Infrastructure Master FSMO role holder
- Global Catalog server (Correct answer)
Correct answer: Global Catalog server
Global Catalog servers store a partial replica of all objects in the forest, enabling universal group membership lookups required during cross-domain logon.
Question 13: In which SYSVOL subfolder are GPO templates stored on a domain controller?
- SYSVOL\domain\GPTemplates
- SYSVOL\domain\Scripts
- SYSVOL\domain\Users
- SYSVOL\domain\Policies (Correct answer)
Correct answer: SYSVOL\domain\Policies
Each GPO's template files (ADM/ADMX files and settings) are stored in SYSVOL\domain\Policies\{GPO-GUID}\ on every domain controller.
Question 14: A stakeholder requests confirmation that all domain controllers are communicating properly after a network change. Which command-line tool provides a comprehensive DC health and connectivity report?
- Dcdiag /test:replications /v (Correct answer)
- Ping /a
- Ipconfig /all
- Netstat -an
Correct answer: Dcdiag /test:replications /v
Dcdiag with the replications test and verbose switch performs comprehensive AD replication health checks and outputs a detailed report suitable for stakeholder review.
Question 15: A regulatory audit finds that your domain lacks a legal warning banner before logon. Which Group Policy setting displays a logon message to users?
- Legal Notice Caption and Text
- Interactive logon: Message title for users attempting to log on
- Interactive logon: Do not display last user name
- Both A and C together (Correct answer)
Correct answer: Both A and C together
Both 'Interactive logon: Message title for users attempting to log on' (caption) and the corresponding text setting must be configured together to display a legal banner.
Question 16: Which audit policy category should be enabled to track changes to Active Directory objects, per Microsoft security baseline recommendations?
- Audit Account Logon Events only
- Audit Privilege Use only
- Audit Directory Service Access and Directory Service Changes (Correct answer)
- Audit System Events only
Correct answer: Audit Directory Service Access and Directory Service Changes
Enabling Audit Directory Service Access and Directory Service Changes captures who modified AD objects and what was changed, satisfying compliance and forensic requirements.
Question 17: Which Group Policy preference item type allows you to map network drives per user?
- Registry under Computer Configuration → Preferences
- Folder Redirection under User Configuration → Windows Settings
- Drive Maps under User Configuration → Preferences → Windows Settings (Correct answer)
- Scripts under Computer Configuration → Windows Settings
Correct answer: Drive Maps under User Configuration → Preferences → Windows Settings
Drive Maps in User Configuration → Preferences → Windows Settings lets you create, update, replace, or delete mapped drives for targeted users.
Question 18: A compliance requirement states that failed logon attempts must be limited to 5 before lockout. After investigation, accounts are locking out after only 3 failures. What is the most likely cause?
- The Default Domain Policy has not been refreshed
- A fine-grained password policy with stricter settings is applied to the affected group (Correct answer)
- The PDC emulator is offline
- Kerberos pre-authentication is disabled
Correct answer: A fine-grained password policy with stricter settings is applied to the affected group
Fine-grained password policies (PSOs) applied to a user's group take precedence over the Default Domain Policy if the PSO has a lower precedence value (higher priority).
Question 19: What does the Infrastructure Master FSMO role do?
- Controls domain naming operations
- Manages schema updates
- Updates cross-domain object references (phantom objects) when objects in other domains are renamed or moved (Correct answer)
- Issues RID pools to domain controllers
Correct answer: Updates cross-domain object references (phantom objects) when objects in other domains are renamed or moved
The Infrastructure Master updates phantom object references so that group memberships and other cross-domain links reflect changes made in other domains.
Question 20: A CIO wants to understand the communication impact if the PDC Emulator FSMO role holder goes offline. Which critical AD function would be most immediately affected?
- Kerberos ticket granting for all domain users would fail immediately
- DNS name resolution for all domain resources would stop
- Password changes, account lockouts, and time synchronization for the domain would be disrupted (Correct answer)
- All AD replication across sites would halt until the PDC Emulator is restored
Correct answer: Password changes, account lockouts, and time synchronization for the domain would be disrupted
The PDC Emulator processes password changes, manages account lockout policy, and acts as the authoritative time source; its loss disrupts these functions most immediately and visibly.
Question 21: What is the purpose of the Resultant Set of Policy (RSoP) tool in Windows Server 2008?
- To delete conflicting GPOs
- To create new GPOs
- To simulate or view the effective Group Policy settings applied to a user or computer (Correct answer)
- To replicate GPOs between domain controllers
Correct answer: To simulate or view the effective Group Policy settings applied to a user or computer
RSoP reports the net result of all GPOs applied to a specific user or computer, helping administrators troubleshoot policy conflicts.
Question 22: Which tab in an OU's Properties dialog must be accessed to remove accidental deletion protection before the OU can be deleted?
- Managed By
- Security
- Object (Correct answer)
- General
Correct answer: Object
The Object tab in the OU Properties dialog contains the 'Protect object from accidental deletion' checkbox that must be unchecked before deletion.
Question 23: When creating an Organizational Unit (OU), which option should be enabled to prevent accidental deletion?
- Enable Tombstone Protection
- Set Deny Delete permission explicitly
- Protect object from accidental deletion (Correct answer)
- Enable Object Auditing
Correct answer: Protect object from accidental deletion
The 'Protect object from accidental deletion' checkbox adds a Deny Delete ACE to the object, preventing inadvertent removal from the directory.
Question 24: Alpine Ski House needs to audit all successful and failed logon attempts for privileged accounts. Which Group Policy node contains the relevant settings?
- Computer Configuration > Administrative Templates > System > Audit
- Computer Configuration > Windows Settings > Security Settings > Local Policies > Audit Policy (Correct answer)
- User Configuration > Windows Settings > Security Settings > Audit Policy
- User Configuration > Administrative Templates > Windows Components > Event Log
Correct answer: Computer Configuration > Windows Settings > Security Settings > Local Policies > Audit Policy
Logon auditing settings are under Computer Configuration > Windows Settings > Security Settings > Local Policies > Audit Policy.
Question 25: Which Active Directory group type can be used to assign permissions to resources such as file shares and printers?
- Mail-enabled group
- Security group (Correct answer)
- Administrative group
- Distribution group
Correct answer: Security group
Only Security groups can be used to control access to resources; Distribution groups are used solely for email distribution and have no security token.
Question 26: You are reviewing your Active Directory backup strategy. Which Windows Server 2008 feature allows you to perform a non-authoritative restore of AD DS?
- Volume Shadow Copy Service
- Active Directory Recycle Bin
- Windows Server Backup with Directory Services Restore Mode (Correct answer)
- Shadow Copies of Shared Folders
Correct answer: Windows Server Backup with Directory Services Restore Mode
A non-authoritative restore is performed by booting into Directory Services Restore Mode (DSRM) and restoring from a Windows Server Backup system state backup.
Question 27: Which tool is used to manually register DNS SRV records for a domain controller on Windows Server 2008?
- ipconfig /registerdns (Correct answer)
- net logon restart
- nltest /dsregdns
- dcdiag /fix
Correct answer: ipconfig /registerdns
Running 'ipconfig /registerdns' forces the DNS client and Netlogon service to re-register all DNS records for the domain controller.
Question 28: What is a conditional forwarder in DNS?
- A DNS server that forwards queries for a specific domain to designated servers (Correct answer)
- A forwarder that strips DNSSEC signatures
- A secondary zone that forwards updates to the primary
- A forwarder that only works during business hours
Correct answer: A DNS server that forwards queries for a specific domain to designated servers
A conditional forwarder directs queries for a specific DNS namespace to particular DNS servers instead of using the standard forwarder.
Question 29: A compliance team requires evidence that the AD database is replicated to a secondary location for disaster recovery. Which Windows Server feature facilitates this replication and provides status reporting?
- DFS-R conflict and health reports
- Shadow copies of the SYSVOL
- Active Directory replication with monitoring via Repadmin /replsummary across sites (Correct answer)
- Windows Server Backup schedule reports
Correct answer: Active Directory replication with monitoring via Repadmin /replsummary across sites
AD's native multi-master replication ensures the database is replicated across all DCs including remote sites; Repadmin /replsummary provides the status evidence required by compliance teams.
Question 30: What is the purpose of a 'child domain' in an Active Directory forest?
- To create a subdomain that shares the forest schema but has its own domain partition (Correct answer)
- To host a Global Catalog without replication overhead
- To create a completely separate forest with its own schema
- To store additional FSMO roles outside the root domain
Correct answer: To create a subdomain that shares the forest schema but has its own domain partition
A child domain is a subdomain of a parent domain within the same forest, inheriting the forest schema and configuration but maintaining its own domain partition and domain-level FSMO roles.
Question 31: During an AD audit, the auditor asks how inter-site replication latency is monitored. Which tool provides replication lag statistics between specific domain controllers?
- Netlogon debug logging
- Repadmin /showrepl and Repadmin /replsummary (Correct answer)
- Active Directory Sites and Services GUI only
- Performance Monitor with AD counters
Correct answer: Repadmin /showrepl and Repadmin /replsummary
Repadmin /showrepl displays replication status per DC pair, while /replsummary provides an aggregate view of replication health including failure counts and latency across the domain.
Question 32: Which application partition stores DNS zone data replicated only to domain controllers within the same domain?
- Schema partition
- ForestDNSZones
- Configuration partition
- DomainDNSZones (Correct answer)
Correct answer: DomainDNSZones
The DomainDNSZones application partition replicates DNS data to all DNS-enabled domain controllers within the same AD domain.
Question 33: A compliance officer requires documentation proving that Active Directory backups are current. Which Windows Server Backup feature provides a verifiable backup status report?
- Backup log in Event Viewer under Windows Logs > Application with source Microsoft-Windows-Backup (Correct answer)
- ADUC account properties
- Netlogon.log
- Repadmin /showbackup
Correct answer: Backup log in Event Viewer under Windows Logs > Application with source Microsoft-Windows-Backup
Windows Server Backup writes detailed success and failure events to the Application event log under the Microsoft-Windows-Backup source, providing auditable backup status records.
Question 34: What happens when a DNS server cannot resolve a query and no forwarder is configured?
- The client retries indefinitely
- The DNS server uses root hints to contact authoritative servers on the Internet (Correct answer)
- The query is dropped silently
- An error is logged and no response is sent
Correct answer: The DNS server uses root hints to contact authoritative servers on the Internet
Without a forwarder, the DNS server falls back to iterative resolution using root hints to find authoritative name servers.
Question 35: An auditor needs to verify that only authorized administrators have rights to link GPOs to the domain root. Where are these delegation settings reviewed and documented?
- Group Policy Management Console > Domain > Delegation tab (Correct answer)
- Auditpol /get /subcategory:'Policy Change'
- Active Directory Users and Computers > Domain Properties > Security tab
- Secedit /export /cfg report.txt
Correct answer: Group Policy Management Console > Domain > Delegation tab
The Delegation tab on the domain object in GPMC shows which users and groups have permission to link GPOs, providing the auditor with the authorization documentation they require.
Question 36: What AD command-line tool is used to check replication status between domain controllers?
- adrepl /check
- ntdsutil /replication
- dcdiag /test:replications
- repadmin /replsummary (Correct answer)
Correct answer: repadmin /replsummary
repadmin /replsummary provides a summary of replication status across all DCs, showing failures and lag times.
Question 37: A penetration test reveals that an expired user account was used to authenticate to a file server three months after termination. Which AD control would have prevented this risk?
- Configuring a fine-grained password policy with a maximum password age
- Enabling automatic account expiration and monitoring via audit logs (Correct answer)
- Adding terminated user accounts to a Deny Logon GPO
- Moving terminated accounts to a disabled OU with restricted permissions
Correct answer: Enabling automatic account expiration and monitoring via audit logs
Setting the account expiration date at termination and monitoring audit events 4625/4768 ensures expired accounts cannot authenticate after the expiry date.
Question 38: At what minimum domain functional level must a domain operate to support Password Settings Objects (PSOs) for fine-grained password policies?
- Windows Server 2000 Native
- Windows Server 2012
- Windows Server 2003
- Windows Server 2008 (Correct answer)
Correct answer: Windows Server 2008
Fine-Grained Password Policies using PSOs require the domain functional level to be set to Windows Server 2008 or higher.
Question 39: Which type of trust shortens the authentication path between two domains in the same forest that are separated by multiple hops?
- External trust
- Realm trust
- Shortcut trust (Correct answer)
- Forest trust
Correct answer: Shortcut trust
A shortcut trust directly connects two domains within the same forest to speed up authentication that would otherwise traverse multiple parent-child domain links.
Question 40: Which PowerShell cmdlet is used to create a new group object in Active Directory?
- Add-ADGroup
- Set-ADGroup
- New-ADGroup (Correct answer)
- Create-ADGroup
Correct answer: New-ADGroup
New-ADGroup is the correct PowerShell cmdlet for creating Active Directory group objects, following the standard Verb-ADNoun naming convention.
Question 41: How should an MCTS 70-640 professional present complex information to non-experts?
- Translate into accessible language, use visuals, and check for understanding (Correct answer)
- Provide written reports only
- Use full technical terminology
- Skip complex topics entirely
Correct answer: Translate into accessible language, use visuals, and check for understanding
This is fundamental to MCTS 70-640 Exam practice. Translate into accessible language, use visuals, and check for understanding represents the professional standard for communication in the MCTS 70-640 certification framework.
Question 42: What is the primary competency framework for MCTS 70-640 Exam professionals?
- Employer-specific requirements only
- Self-assessed capabilities only
- Ad-hoc skill development
- Structured competency standards defined by the certifying body (Correct answer)
Correct answer: Structured competency standards defined by the certifying body
This is fundamental to MCTS 70-640 Exam practice. Structured competency standards defined by the certifying body represents the professional standard for professional standards in the MCTS 70-640 certification framework.
Question 43: A branch office manager requests to be notified when their site's domain controller goes offline. Which Windows feature enables proactive DC availability monitoring and notification?
- Active Directory-integrated DNS scavenging alerts
- DHCP failover notifications
- System Center Operations Manager (SCOM) or configuring Windows event forwarding with availability monitors (Correct answer)
- DFS replication conflict reporting
Correct answer: System Center Operations Manager (SCOM) or configuring Windows event forwarding with availability monitors
SCOM or Windows event forwarding with custom availability monitors provides automated alerting when a domain controller stops responding, enabling proactive communication with branch managers.
Question 44: Under Kerberos authentication standards in Windows Server 2008 AD DS, what is the maximum allowed clock skew between a client and a domain controller by default?
- 30 minutes
- 1 hour
- 10 minutes
- 5 minutes (Correct answer)
Correct answer: 5 minutes
Kerberos requires clocks within 5 minutes of each other by default; exceeding this skew causes authentication failures and is mitigated by AD's time synchronization hierarchy.
Question 45: Which DNS record type must be present for AD DS to function correctly, as it allows clients to locate domain controllers?
- A records only
- PTR records
- MX records
- SRV records (Correct answer)
Correct answer: SRV records
Active Directory relies on SRV records in DNS for clients to discover domain controllers, Kerberos services, and other AD DS services.
Question 46: What must occur before you can convert a Universal security group to a Global group?
- Remove all nested Universal groups
- Raise the domain functional level
- Convert it to a Distribution group first
- Remove all members from other domains (Correct answer)
Correct answer: Remove all members from other domains
Global groups can only contain members from their own domain, so any cross-domain members must be removed before converting a Universal group to Global.
Question 47: What does the DNS TTL value control?
- The maximum number of DNS queries per second
- How long a resolver caches a DNS record before requesting a fresh copy (Correct answer)
- How long a zone transfer takes
- The replication interval between AD-integrated DNS zones
Correct answer: How long a resolver caches a DNS record before requesting a fresh copy
TTL (Time to Live) specifies in seconds how long a DNS record can be cached by resolvers before they must query the authoritative server again.
Question 48: How should an MCTS 70-640 professional handle an outcome that differs from expectations?
- Blame external factors
- Ignore the discrepancy
- Repeat the same approach
- Analyze contributing factors, document findings, and adjust approach based on lessons learned (Correct answer)
Correct answer: Analyze contributing factors, document findings, and adjust approach based on lessons learned
This is fundamental to MCTS 70-640 Exam practice. Analyze contributing factors, document findings, and adjust approach based on lessons learned represents the professional standard for practical in the MCTS 70-640 certification framework.
Question 49: Which FSMO role is responsible for maintaining a consistent time source across all domain controllers in a domain?
- Schema Master
- RID Master
- Infrastructure Master
- PDC Emulator (Correct answer)
Correct answer: PDC Emulator
The PDC Emulator is the authoritative time source for its domain; all other DCs in the domain sync their clocks to the PDC Emulator to keep Kerberos working.
Question 50: After enabling AD Recycle Bin, an IT manager wants to communicate its capabilities to the helpdesk team. Which statement accurately describes the AD Recycle Bin's restoration capability?
- It only restores user objects, not groups or OUs
- Restored objects are placed in the Lost and Found container by default
- It requires a forest functional level of Windows Server 2003
- It restores deleted objects with all attributes intact, including group memberships, without requiring a restart or authoritative restore (Correct answer)
Correct answer: It restores deleted objects with all attributes intact, including group memberships, without requiring a restart or authoritative restore
The AD Recycle Bin, available at Windows Server 2008 R2 forest functional level, restores deleted objects with all linked attributes intact and does not require domain controller restarts.
Question 51: Which tool is commonly used for root cause analysis in MCTS 70-640 quality management?
- Customer surveys only
- Profit analysis
- Random sampling
- Fishbone (Ishikawa) diagram to identify contributing factors systematically (Correct answer)
Correct answer: Fishbone (Ishikawa) diagram to identify contributing factors systematically
This is fundamental to MCTS 70-640 Exam practice. Fishbone (Ishikawa) diagram to identify contributing factors systematically represents the professional standard for quality in the MCTS 70-640 certification framework.
Question 52: A risk scenario involves an insider threat where a help desk technician resets passwords for executives and uses the credentials. Which AD control provides a detective control for this behavior?
- Configure fine-grained password policies to require executives to change passwords immediately
- Enable Kerberos armoring (FAST) for executive accounts
- Audit account management events to log password reset actions with the initiator's identity (Correct answer)
- Use Protected Users group to prevent help desk from resetting executive passwords
Correct answer: Audit account management events to log password reset actions with the initiator's identity
Auditing account management events (event 4723/4724) records who reset a password, providing a detective control to identify insider abuse of password reset privileges.
Question 53: A branch office stakeholder wants to know how Bridgehead Servers are selected and whether they can influence the selection for communication reliability. Which statement is accurate?
- The KCC automatically selects bridgehead servers, but administrators can manually designate preferred bridgehead servers in Active Directory Sites and Services (Correct answer)
- Bridgehead servers are selected by the PDC Emulator using a priority algorithm
- Only RODCs can serve as bridgehead servers at branch offices
- Bridgehead servers are always manually designated by administrators
Correct answer: The KCC automatically selects bridgehead servers, but administrators can manually designate preferred bridgehead servers in Active Directory Sites and Services
While the KCC automatically elects bridgehead servers, administrators can manually designate preferred bridgehead servers in Active Directory Sites and Services to control inter-site replication reliability.
Question 54: An administrator wants to alert the network team automatically when AD replication fails between sites. Which Windows feature should be configured to send these notifications?
- SNMP traps via Windows SNMP Service
- Active Directory replication monitoring via SMTP notifications in Event Viewer subscriptions (Correct answer)
- DFS-N referral logging
- Windows Firewall alerts
Correct answer: Active Directory replication monitoring via SMTP notifications in Event Viewer subscriptions
Event Viewer subscriptions can be configured to collect replication failure events and forward them, enabling automated notification to the network team.
Question 55: Which service is responsible for downloading and applying Group Policy on domain members?
- Netlogon service
- Winlogon process
- Group Policy Client service (Correct answer)
- Task Scheduler
Correct answer: Group Policy Client service
The Group Policy Client service (gpsvc) handles the processing and application of Group Policy on Windows Vista/Server 2008 and later.
Question 56: What is the role of professional journals in MCTS 70-640 Exam practice?
- They are optional reading
- They are outdated by publication time
- They disseminate current research, best practices, and professional developments (Correct answer)
- They only benefit academics
Correct answer: They disseminate current research, best practices, and professional developments
This is fundamental to MCTS 70-640 Exam practice. They disseminate current research, best practices, and professional developments represents the professional standard for research in the MCTS 70-640 certification framework.
Question 57: How has digital technology transformed MCTS 70-640 Exam practice?
- It only affects large organizations
- It has enhanced data collection, analysis, communication, and operational efficiency (Correct answer)
- It has replaced all traditional methods
- It has had no impact
Correct answer: It has enhanced data collection, analysis, communication, and operational efficiency
This is fundamental to MCTS 70-640 Exam practice. It has enhanced data collection, analysis, communication, and operational efficiency represents the professional standard for technology in the MCTS 70-640 certification framework.
Question 58: What is the primary function of the 'Manager' attribute on an Active Directory user object?
- Sets the manager as the user's Group Policy owner
- Automatically grants the manager admin rights over the user
- Stores an informational reference enabling the Direct Reports list (Correct answer)
- Automatically adds the user to the manager's department group
Correct answer: Stores an informational reference enabling the Direct Reports list
The Manager attribute is informational, linking a user to their manager's AD account and enabling the Direct Reports view in tools like Outlook and the Address Book.
Question 59: A junior administrator accidentally deleted an OU containing 200 user accounts. No Recycle Bin is enabled. What is the correct recovery procedure?
- Use dsadd to recreate the OU and users manually
- Perform an authoritative restore from a system state backup using ntdsutil (Correct answer)
- Run repadmin /syncall to recover from another DC
- Run dcdiag /fix to restore deleted objects
Correct answer: Perform an authoritative restore from a system state backup using ntdsutil
An authoritative restore using ntdsutil marks the restored objects with a high USN so they replicate back to all other DCs, overwriting deletions.
Question 60: What is the default Group Policy refresh interval for computers (excluding domain controllers)?
- 60 minutes
- 90 minutes with a random offset of up to 30 minutes (Correct answer)
- Every startup only
- 30 minutes
Correct answer: 90 minutes with a random offset of up to 30 minutes
By default, computers refresh Group Policy every 90 minutes with a random 0–30 minute offset to prevent all machines from contacting DCs simultaneously.
Question 61: You are configuring Universal Group Membership Caching (UGMC) for a remote site that has no Global Catalog server. Where is UGMC configured?
- On each domain controller in the site via the registry
- In Active Directory Sites and Services on the NTDS Site Settings object (Correct answer)
- In Active Directory Users and Computers under the site container
- In the Default Domain Policy GPO
Correct answer: In Active Directory Sites and Services on the NTDS Site Settings object
UGMC is enabled on the NTDS Site Settings object for a site in Active Directory Sites and Services, applying to all DCs in that site.
Question 62: What tool is used to import and export data (LDIF files) into an AD LDS instance?
- dsmod.exe
- ntdsutil.exe
- ldifde.exe (Correct answer)
- csvde.exe
Correct answer: ldifde.exe
ldifde.exe imports and exports LDAP Data Interchange Format (LDIF) files, which is the standard method for populating AD LDS instances.
Question 63: What is the purpose of a stub zone in DNS?
- To replicate all DNS records to all domain controllers
- To cache all records from a primary zone
- To block external DNS queries
- To contain only NS, SOA, and A records for a zone to resolve names in that zone (Correct answer)
Correct answer: To contain only NS, SOA, and A records for a zone to resolve names in that zone
A stub zone holds only NS, SOA, and glue A records so the DNS server knows the authoritative servers for that zone.
Question 64: What is the recommended professional standard for validating that Group Policy is applying correctly after a new GPO deployment?
- Run gpresult /r or use GPMC's Group Policy Results and Modeling features to verify effective policy (Correct answer)
- Restart all domain controllers simultaneously
- Wait for user complaints to identify misconfigured policies
- Check the SYSVOL folder size only
Correct answer: Run gpresult /r or use GPMC's Group Policy Results and Modeling features to verify effective policy
gpresult and the GPMC's built-in reporting tools provide definitive evidence of which GPOs are applied and in what order, enabling rapid troubleshooting.
Question 65: Coho Winery's Active Directory schema needs to be extended for a new application. The administrator runs the extension tool and receives 'Access Denied'. What is the minimum group membership required?
- Schema Admins (Correct answer)
- Domain Admins in any domain
- Domain Admins in the forest root domain
- Enterprise Admins
Correct answer: Schema Admins
Schema Admins is the only group with permission to modify the Active Directory schema.
Question 66: When configuring DNS on a new Windows Server 2008 domain controller, which zone should be created to support AD DS?
- A secondary zone pointing to the PDC
- A reverse lookup zone only
- An MX-only zone
- A forward lookup zone for the AD domain (Correct answer)
Correct answer: A forward lookup zone for the AD domain
A forward lookup zone for the Active Directory domain name is essential so clients and DCs can resolve domain names to IP addresses and locate AD services.
TS: Windows Server 2008 Active Directory, Configuring (70-640)
The MCTS 70-640 exam validates skills in configuring Windows Server 2008 Active Directory, covering DNS integration, AD infrastructure, directory objects, additional server roles, and environment maintenance. It is part of the Microsoft Certified Technology Specialist (MCTS) track.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds