← All MCTS 70-640 Flashcard Decks

Quality Control & Assurance Flashcards

7 cards from real MCTS 70-640 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Quality Control & Assurance flashcards as text
  1. A company requires that password changes in Active Directory meet complexity requirements. Which Group Policy setting enforces this rule?

    Answer: Password must meet complexity requirements

    'Password must meet complexity requirements' enforces rules such as mixed case, numbers, and special characters in passwords.

  2. During a security audit, you need to verify which users have not logged on in the past 90 days. Which tool can query Active Directory for inactive accounts?

    Answer: dsquery user -inactive 13

    dsquery user -inactive accepts a number of weeks and returns user accounts that have not logged on in that period.

  3. What is the default tombstone lifetime in Windows Server 2008 Active Directory, and why is it significant for quality assurance?

    Answer: 90 days; DCs offline longer may have inconsistent data

    The default tombstone lifetime in Windows Server 2008 is 180 days, but wait — for forests raised from earlier versions it is 60 days; the default for new Windows Server 2008 forests is 180 days. DCs offline longer can develop lingering objects.

  4. An administrator needs to test whether Group Policy is being applied immediately after a policy change. Which command forces an immediate refresh of Group Policy on a client?

    Answer: gpupdate /force

    gpupdate /force immediately reapplies all Group Policy settings regardless of whether they have changed.

  5. You are reviewing your Active Directory backup strategy. Which Windows Server 2008 feature allows you to perform a non-authoritative restore of AD DS?

    Answer: Windows Server Backup with Directory Services Restore Mode

    A non-authoritative restore is performed by booting into Directory Services Restore Mode (DSRM) and restoring from a Windows Server Backup system state backup.

  6. Which audit policy category should be enabled to track changes made to Active Directory objects such as user accounts and OUs?

    Answer: Audit directory service access

    Audit directory service access records access to Active Directory objects and is needed to track changes to AD objects.

  7. A security team wants to prevent brute-force attacks on domain accounts. Which Group Policy settings should they configure?

    Answer: Account lockout threshold and account lockout duration

    Account lockout threshold defines how many failed attempts lock an account, and account lockout duration defines how long the lockout lasts.