โ† All MCTS 70-640 Flashcard Decks

MCTS 70 640: Active Directory, Configuring Flashcards

7 cards from real MCTS 70-640 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 MCTS 70 640: Active Directory, Configuring flashcards as text
  1. You are configuring a new AD DS forest. Which server holds the Schema Master FSMO role by default?

    Answer: The first DC installed in the forest root domain

    The Schema Master role is automatically assigned to the first domain controller installed in the forest root domain.

  2. A user reports they cannot log on from a branch office. The branch office has an RODC. The user's credentials are NOT in the Allowed RODC Password Replication Group. What happens when the user attempts to authenticate?

    Answer: The RODC forwards the authentication request to a writable DC over the WAN

    When a user's credentials are not cached on an RODC, the RODC proxies the authentication request to a writable DC; if the WAN is down, logon fails.

  3. Which DNS record type must be present for AD DS to function correctly, as it allows clients to locate domain controllers?

    Answer: SRV records

    Active Directory relies on SRV records in DNS for clients to discover domain controllers, Kerberos services, and other AD DS services.

  4. You want to ensure that when a user object is deleted from one domain controller, that deletion replicates to all other DCs before any other changes to the same object. Which AD DS concept governs this?

    Answer: Change notification with urgent replication

    Certain changes, such as account lockouts and password changes, trigger urgent replication via change notification to ensure rapid propagation.

  5. An administrator needs to extend the AD schema to support a custom application. Which group membership is required to perform schema extensions?

    Answer: Schema Admins

    Only members of the Schema Admins group have permission to modify the Active Directory schema.

  6. You run 'repadmin /showrepl' and notice lingering objects warnings between two domain controllers. Which command removes lingering objects from a DC?

    Answer: repadmin /removelingeringobjects

    The 'repadmin /removelingeringobjects' command identifies and removes objects that should not exist on a DC due to replication gaps.

  7. You need to configure a trust so that users in your AD DS forest can authenticate to resources in a partner company's Kerberos V5 realm running on UNIX. Which trust type should you create?

    Answer: Realm trust

    A realm trust connects an AD DS domain to a non-Windows Kerberos V5 realm, enabling cross-platform authentication.