โ† All MCTS 70-640 Flashcard Decks

Professional Standards & Competencies Flashcards

7 cards from real MCTS 70-640 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Professional Standards & Competencies flashcards as text
  1. A technician is troubleshooting a Group Policy application failure. What is the recommended first diagnostic step according to Microsoft troubleshooting methodology?

    Answer: Run gpresult /h to generate an HTML report and identify which GPOs are applied or blocked

    gpresult /h provides a complete, readable summary of GPO application, filtering, and errors, making it the authoritative first diagnostic tool.

  2. The Active Directory Recycle Bin feature in Windows Server 2008 R2 requires what forest functional level to enable?

    Answer: Windows Server 2008 R2

    The AD Recycle Bin requires the forest functional level to be raised to Windows Server 2008 R2 or higher before it can be enabled.

  3. Under Kerberos authentication standards in Windows Server 2008 AD DS, what is the maximum allowed clock skew between a client and a domain controller by default?

    Answer: 5 minutes

    Kerberos requires clocks within 5 minutes of each other by default; exceeding this skew causes authentication failures and is mitigated by AD's time synchronization hierarchy.

  4. What professional standard should guide the configuration of DNS zones integrated with Active Directory to ensure security?

    Answer: Use AD-integrated DNS zones with dynamic updates set to Secure Only to prevent unauthorized record registration

    AD-integrated zones with Secure Only dynamic updates ensure only authenticated domain members can register or update DNS records, preventing DNS poisoning.

  5. Which domain controller hardening measure is recommended by Microsoft security baselines for Windows Server 2008 domain controllers?

    Answer: Apply the appropriate Security Compliance Manager baseline, disable unnecessary services, and restrict local logon to domain admins only

    Applying a security baseline, minimizing installed roles, and restricting interactive logon reduces the attack surface of domain controllers, which are crown-jewel assets.

  6. A company's compliance team requires proof that no unauthorized changes were made to AD group memberships in the last 90 days. What Windows Server 2008 capability best supports this?

    Answer: Enable Audit Directory Service Changes (DS Changes) subcategory and archive Security event logs for 90 days or more

    The DS Changes audit subcategory records old and new values for modified AD attributes, providing a complete changelog for group membership alterations.

  7. When planning the placement of global catalog servers in a multi-site Active Directory environment, what professional guideline applies?

    Answer: Place at least one global catalog server in each site to reduce WAN logon traffic and support universal group membership caching

    Placing a global catalog in each site prevents logon delays caused by cross-site GC queries for universal group membership during authentication.