Jason from United Kingdom -
Sep 28 2012, 10:53 PMReport Spam
Many thanks Anonimus and all of you guys ... for all your work.
It is still valid...
I have passed today with 876
sharon from Israel -
Sep 20 2012, 5:22 PMReport Spam
still valid get 841 today
ghoster from Thailand -
Sep 15 2012, 5:20 AMReport Spam
to Anonymous, I test today is passed 858 score
Thank you very much.
MPro from United States -
Sep 13 2012, 3:25 AMReport Spam
This dump is still valid. Took exam today, studied material from book, this dump and maxbox. Got 805!! This dump was 80% valid.Thanks guys!!
ThangMai from Vietnam -
Sep 11 2012, 3:11 AMReport Spam
I can exam change and correct the answers! Thanks you all people!!
Shmoel from Unknown -
Sep 09 2012, 6:59 PMReport Spam
I went a month ago and I failed the 635 and learned from Newton 329q.vce, Max Books and more 35 Andy's questions.
I went back two weeks ago: two first questions I learned from Anonymous 468q.vce and the rest of FixedAnswers 468q.vce and I knew them perfectly, four new questions and got 735.
Dump 70% good
You should not go to lower the number of questions to learn
And correct the answers
Islam Zidan from Egypt -
Sep 07 2012, 2:36 PMReport Spam
Your network contains two Active Directory forests named contoso.com and fabrikam.com. Each forest contains one domain. A two-way forest trust exists between the forests.
You plan to add users from fabrikam.com to groups in contoso.com.
You need to identify which group you must use to assign users in fabrikam.com access to the shared folders in contoso.com.
To which group should you add the users?
Group 3: Security Group - Global.
Group 5: Security Group - Universal.
Which One Is Right (Universal Or Global)?? can anyone verify !!
Majer from United States -
Aug 21 2012, 4:02 PMReport Spam
Am I thinking too much like microsoft. the question does not ask about changing group membership. the question is asking how to apply a solution.
yes, you would need to plan and create your security groups in advance.
Don from United States -
Aug 19 2012, 8:53 PMReport Spam
Plz explain:
F - Q18
Replicate new user
Current: A. Active directory sites and services
Should be: C. Repadmin
Astraor from Italy -
Aug 19 2012, 8:47 PMReport Spam
Exam J Q18 is A not C
the question is:
Your network contains two Active Directory forests named contoso.com and fabrikam.com. Each forest contains one domain. A two-way forest trust exists between the forests.
You plan to add users from fabrikam.com to groups in contoso.com.
You need to identify which group you must use to assign users in fabrikam.com access to the shared folders in contoso.com.
Planning is to assign user from fabrikam to a group present in contoso.
If you create global group in contoso, you can assign only user of same domain, in this case contoso, if you create a group Domain local in contoso, you can assign user from fabrikam .
majer from United States -
Aug 19 2012, 8:45 PMReport Spam
@ whiskey@cia.ca
According to this -
http://technet.microsoft.com/en-us/library/cc739505%28v=ws.10%29.aspx
Only CA administrators and certificate managers are assigned by using the Certification Authority snap-in. To change the permissions of a user or group, you must change the user's security permissions, group membership, or user rights.
My understanding is the only way to do this is by using users and computers or group policy to change the user or group membership.
Q39 from exam E. Te question is about offline joining of the server to the domain, but answet is about Windows 7 ;/
whiskey@cia.ca from Unknown -
Aug 19 2012, 8:28 PMReport Spam
exam K Q14
exam G Q37
Both questions
You need to ensure that all of the members of a group named Group1 can view the event log entries for Certificate Services.
My answer for both, (same question, different answers is CA Certification Authority)
that is where you configure permissions and roles for the CA.
refer to
http://www.kurtdillard.com/StudyGuides/70-640/6.html (1/3 deep into the article)
Figure 6: Configuring CA Permissions.
Can someone confirm if the logic is correct.
NowAnonymous from Sweden -
Aug 19 2012, 8:19 PMReport Spam
Ok guys. I have created a list of questions that need to be corrected. Please go over them and check if everything is in order.
If you want me to add corrections please use the same format. It makes it much easier for me to process.
Much thanks :)
EXAM G:
Q8: B. [Repadmin] http://technet.microsoft.com/en-us/library/cc835086(v=ws.10).aspx
EXAM I:
Q18: ???
------------------------------------------------------------
EXAM J:
Q18: C. [Group 3: Security Group - Global.]
Q24: A. [Active Directory Sites And Services console]
Q37: A. [Enable the Audit directory service access setting in the Default Domain Controllers Policy Group Policy Object.] http://technet.microsoft.com/en-us/library/cc731607(v=WS.10).aspx
------------------------------------------------------------
EXAM K:
Q11: D. [Enable loopback processing in merge mode.]
Majer from United States -
Aug 19 2012, 8:16 PMReport Spam
exam K Q10 - I would say it is D.
It is a selective trust so you have to give group 1 the allowed to authenticate permission to access the shared resource from the server's computer account.
exam K Q14 Group policy management can assign to those groups
exam G Q37 Users and computers can assign to those groups
Peter from Sweden -
Aug 19 2012, 7:45 PMReport Spam
damn can someone put most of the good questions in a updated separate dump? its a mess boys !
Astraor from Italy -
Aug 19 2012, 6:49 PMReport Spam
@whiskey@cia.ca you are right, in Active directory users and computers, attribute editor tab, I can see the account lockout.
about question:
exam K Q14
exam G Q37
can you help me?
whiskey@cia.ca from Canada -
Aug 19 2012, 5:34 PMReport Spam
About question K Q12 is identical of K Q44 but with different answer
You have an Active Directory domain named contoso.com.
You need to view the account lockout threshold and duration for the domain.
Which tool should you use?
Computer Management
Net Config
Active Directory Users and Computers
Gpresult
Net User
Active Directory Users and Computers
Group Policy Management Console (GPMC)
Computer Management
**computer mangement, net config, net user does not have the information.**
leaves, Active Directory Users and Computers
Group Policy Management Console (GPMC) to configure
Gpresult /h gives an HTML report
Active Directory Users and Computers >advanced feature option turned on,attribute editor tab.
(I don't have a server in front of me so I can not confirm that Active directory users and computers is the correct answer)
but my answer would be > Active Directory Users and Computers < for both.
Astraor from Italy -
Aug 19 2012, 5:06 PMReport Spam
exam K Q14
exam G Q37
someone have info?
Astraor from Italy -
Aug 19 2012, 4:13 PMReport Spam
@whiskey@cia.ca
About question K Q12 is identical of K Q44 but with different answer
Astraor from Italy -
Aug 19 2012, 4:05 PMReport Spam
@whiskey@cia.ca
@ssniyer
Thanks for help
whiskey@cia.ca from Canada -
Aug 19 2012, 3:51 PMReport Spam
@Astraor from Italy,
exam K Q10, I agree with answer (UPN is not the question being asked for the forest), when assigning permissions, they are assigned to the local resource. So talking about about changing computer >account< permissions is wrong. by process of elimination, leaves A: the permissions of the Group1 group
exam K Q29 Start of Authority 2 places where you delegate the person in charge.
b:From DNS Manager, open the properties of the Start of Authority (SOA) record ofcontoso.com, Specify admin1.contoso.com as the responsible person.
c:Open the %SystemrootSystem32DNSContoso.com.dns file by using Notepad and change all instances of "hostmaster@contoso.com" to "adminl@contoso.com"
The difference is the GUI properties is >person.domain.com<, the dns database file is >person@domain.com<
http://technet.microsoft.com/en-us/library/cc816941(v=ws.10).aspx#BKMK_winui
exam K Q12 A:Active Directory Users and Computers, Gpresult /h file.html also works
exam K Q37 b: dsmod http://technet.microsoft.com/en-us/library/cc732406(v=ws.10).aspx
Modifies attributes of one or more existing partitions in the directory.
exam K Q30
A: and D: explanation for D: http://technet.microsoft.com/en-us/library/cc778798(WS.10).aspx
J Q7 answer is correct, you need to activate DS changes auditing. needs to be activated at the command line, the subcategories is the giveaway in this question. if auditing DS changes, it needs to be applied against the default domain controller policy.
J Q37 DS auditing is done in 2 parts.
correct answer is A:Enable the Audit directory service access setting in the Default Domain Controllers Policy Group Policy Object.
turning on the GPO alone would not be a complete answer. You would then need to activate with the command line, auditpol.exe (for DS changes)
Youssef from Egypt -
Aug 19 2012, 3:41 PMReport Spam
@NowAnonymous
Are you planning to upload a fixed version of this?
ssniyer from India -
Aug 19 2012, 3:00 PMReport Spam
@Olaf - You are right. Answer is D.
@Astraor - Exam J, Q7 answer is D because none of the other answers are correct and answer D is the best course of action. I had reasoned the answer for Q37 earlier and I am pretty sure A is the right answer for Q37, that is, Audit Directory Access has to be enabled in Domain Controller Group Policy.
Astraor7 from Italy -
Aug 19 2012, 1:17 PMReport Spam
someone can get me clarification about 2 question
exam J Q7 and Q37
Olaf from Norway -
Aug 19 2012, 12:22 PMReport Spam
How Can this be B? Should be D?
Your company has an Active Directory domain. All servers run Windows Server 2008 R2. Your
company uses an Enterprise Root certification authority (CA) and an Enterprise Intermediate CA.
The Enterprise Intermediate CA certificate expires.
You need to deploy a new Enterprise Intermediate CA certificate to all computers in the domain.
What should you do?
A. Import the new certificate into the Intermediate Certification Store on the Enterprise Root CA
server,
B. Import the new certificate into the Intermediate Certification Store on the Enterprise
Intermediate CA server,
C. Import the new certificate into the Intermediate Certification Store in the Default Domain
Controllers group policy object,
D. Import the new certificate into the Intermediate Certification Store in the Default Domain group
policy object.
Astraor from Italy -
Aug 19 2012, 10:54 AMReport Spam
@NowAnonymous
you have missed the question 411 from pdf dump
Answer is H
NowAnonymous from United States -
Aug 19 2012, 10:10 AMReport Spam
@Anon from United States
Yes I'm still planning on updating the .vce but only between Monday[Tomorrow] and Wednesday as I want to wait for all the Questions to be corrected and discussed.
If someone else wants to correct them for me your more than welcome to do so and it will be much appreciated. I dont have allot of time on my hands and when I do have some time I study most of the time.
Thanks to everyone contributing with corrections and sources.
Take a look here: http://www.examcollection.com/microsoft/Microsoft.PrepKing.70-640.v2012-08-11.by.Marvin.369q.vce.file.html
If you have input please help.
Astraor from Italy -
Aug 19 2012, 8:20 AMReport Spam
exam K Q12
exam K Q37
exam K Q30
astraor from Italy -
Aug 19 2012, 7:52 AMReport Spam
Another question
exam K Q42
Astraor from Italy -
Aug 19 2012, 7:48 AMReport Spam
i hope this is last question
exam K Q49
Astraor from Italy -
Aug 19 2012, 7:43 AMReport Spam
exam K Q20 the right answer seems C not A
Astraor7 from Italy -
Aug 19 2012, 7:24 AMReport Spam
@ssniyer, @whiskey@cia.ca,
thanks for help :)
Seems that this dump have a lot of error...
I'have another doubt
exam K Q10
exam K Q29
@jose123 for question please post exam and question
whiskey@cia.ca from Canada -
Aug 19 2012, 5:25 AMReport Spam
@Astraor from Italy, for your question
exam F Q28,exam G Q8,exam J Q24,exam K Q8,exam K Q31
Correct answer for ALL is repadmin /syncall
http://technet.microsoft.com/en-us/library/cc835086(v=ws.10).aspx
jose123 from Colombia -
Aug 19 2012, 4:50 AMReport Spam
from test K, Q 37 say the answer B:Dsmod?..I think it's A: AD Sites and Services or D: Dsmgmt, what say you?
ssniyer from India -
Aug 19 2012, 4:49 AMReport Spam
@Anon: Exam I, Q18 - I think the 3rd option is given incorrectly and there should be an option that says - Restart DC. However, in your choices, option - Perform a restore of system state data to a time before the OU was deleted - should come first followed by - Run the NTDSUtil - to mark the restoration as Authoritative.
ssniyer from India -
Aug 19 2012, 4:34 AMReport Spam
@Astraor - I have gone through all the same/similar DNS questions pointed out. In all but one (Exam J, Q24), Repadmin is shown as one of the answer options. I would go with Repadmin in all the cases. Reason - One of the prime benefits of AD integrated zones is that no separate DNS replication topology is needed for DNS zone updates and zone replication happens along with AD replication. The best tool to force AD replication for DCs is Repadmin.
In the case where (Exam J, Q24) Repadmin is not an answer option, I will go with AD Sites and Services because it allows to force AD replication across connection objects.
Both DNSLint and nslookup are diagnostic tools. DNSLint is useful to make sure RRs are associated with the right services and nslookup for domain namespace resolution issues. There is no diagnostic need in this question.
Dnscmd is useful to administer/maintain a DNS server or zone using a command line tool. It is also the right tool to create Application Directory Partition. However, I don't see literature to suggest it as a good replication tool for AD integrated zones.
jose123 from Colombia -
Aug 19 2012, 4:21 AMReport Spam
Q: you need to ensure that only members of a group named Admin can create certificate templates. Which tool should you use to assing permissiones to admin1?
The answer is not B, is D: Active directory sites and services.
you think the same?
jose123 from Colombia -
Aug 19 2012, 3:49 AMReport Spam
Q: you need to specify a user named Admin1 as the person responsible for
managin the zone: the test say B and C. but I was looking and in both cases must write admin1.contoso.com without @, meaning that the answer is: A and B
jose123 from Colombia -
Aug 19 2012, 2:21 AMReport Spam
you need back up all of the GPOs, group police permissions and group police links for the domain. What should you do?
Answer in test is A: from group police management console..But in other test the answer is d: from windows powershell, run the backup-gpo cmdlt. This is correct for me.
Anon from United States -
Aug 19 2012, 2:17 AMReport Spam
@NowAnonymous
Are you still planning to upload a fixed version of this?
Anon from United States -
Aug 19 2012, 1:29 AMReport Spam
Exam I Q18
The answer to this does not seem right to me. It says you are in Directory Services Restore Mode (DSRM) so,
I think it should be:
1. Run the Ntdsutil utility
2. Perform a restore of system state data to a time before the OU was deleted
3. ???
and I would think you need to restart in normal mode but that is not a option.
ssniyer from India -
Aug 18 2012, 5:05 PMReport Spam
@Astraor - Thank you for pointing out this question. The answer to Exam J, Q37 is A - Enable the Audit Directory Service Access setting in the Default Domain Controllers Policy. Refer to Technet article - http://technet.microsoft.com/en-us/library/cc731607(v=WS.10).aspx - for details. I will get back to you on the DNS question tomorrow. Need to research it out.
ssniyer from India -
Aug 18 2012, 4:35 PMReport Spam
@Astraor - Q38 and Q48 - I think you are right. Q27 - I would stick to E. Answer D reloads the zone from the locally stored zone file. Selecting - Transfer new copy of zone from master - Transfers a full copy of the zone from the Master server, Server1 in this case.
Astraor from Italy -
Aug 18 2012, 4:22 PMReport Spam
@ssniyer thanks for reply.
on this dump there are some question apparently identical but with different reply
I'm little confused.
I know that the command DSlint is used for check replication but for replication when is used DNSCMD and when REPADMIN?
the question are:
exam F Q28
exam G Q8
exam J Q24
exam K Q8
exam K Q31
some reply seems wrong
ssniyer from India -
Aug 18 2012, 3:53 PMReport Spam
@Astraor - Q31: Answer is Repadmin (C). DNS is active directory integrated and all DNS are domain controllers. Therefore, DNS records are replicated along with AD replication. Repadmin can be used to force replication. I am pretty sure about this and I did see somebody else agree on this point.
Q14 is a little more tricky. Take a look at - http://technet.microsoft.com/en-us/library/cc732590 - note that Auditing is an Operating System feature and Auditor is an OS role. The question is about viewing event log entries for Certificate Services, which means auditing CS is already enabled. The Role and Activities table in the technet article says - By default the Local Administrator holds the System Audit user right. Therefore by making the Manager group member of the local Administrators group, they can be made to view the event log entries for the CS. This can be achieved through a GPO. Therefore, I would suggest Group Policy Management as the answer.
Astraor from Italy -
Aug 18 2012, 1:42 PMReport Spam
on previous post question from K exam is number 38 not 37
Sorry
Astraor from Italy -
Aug 18 2012, 1:34 PMReport Spam
question:
exam K Q27 correct reply seems D not E
exam K Q37 correct reply seems D not A
exam K Q48 correct reply seems B not C
Astraor from Italy -
Aug 18 2012, 1:12 PMReport Spam
Please check the question
Exam K, Q14
Exam K, Q31
Astraor from Italy -
Aug 18 2012, 12:18 PMReport Spam
Someone can tell me if reply from Exam J, Q37 are correct? Why?
Thanks in advance
SlayerX-767 from United States -
Aug 18 2012, 2:04 AMReport Spam
Took the exam today and passed 845. These questions were absolutely 100% valid. In fact, I could not have passed without this test. Awesome work, man!
whiskey@cia.ca from Canada -
Aug 18 2012, 2:00 AMReport Spam
Ignore previous post, Q18 correct, K,Q41 answer is wrong
Set-ADForest
Syntax:
To add values:
-UPNSuffixes @{Add=value1,value2,...}
To remove values:
-UPNSuffixes @{Remove=value3,value4,...}
To replace values:
-UPNSuffixes @{Replace=value1,value2,...}
To clear all values:
-UPNSuffixes $null
The GUI tool for UPN modifications is Active Directory Domains and Trusts.
Exam K, Q41
same scenario UPN to multiple domains in the same forest
correct answer is D:Set-ADForest
whiskey@cia.ca from Canada -
Aug 18 2012, 12:47 AMReport Spam
Exam K, Q18
forest wide UPN
UPN works at win2k level
correct answer is A: Active Directory Sites and Services
http://technet.microsoft.com/en-us/library/cc772007.aspx
Mitland from Italy -
Aug 17 2012, 11:02 PMReport Spam
@Mar
correct answer is group A because Domain Local Group Can have member from other trusted domain but is visible on one domain. Global group is visible on multiple domain but can have member only from the same domain
anon from United Kingdom -
Aug 17 2012, 10:14 PMReport Spam
I passed today with 900 using the ones from a month ago and just looked at the K and L sections of this one. Quite a lot were valid. I would google some of the questions in this one for the correct answers though.
Managof from Sweden -
Aug 17 2012, 9:40 PMReport Spam
can someone edit the dump and fix the bad answer with the good ones and up them in another topic please?
Q18 from J have wrong answer. Correct is Group 3 - Global security group, because you have 2 domains and Domain Local group could have only members from 1 domain.
whiskey@cia.ca from Unknown -
Aug 17 2012, 2:30 PMReport Spam
Exam L, Q5
Active Directory recycle Bin is activated by
D: Enable-ADOptionalFeature
http://technet.microsoft.com/en-us/library/dd379481(v=ws.10).aspx
whiskey@cia.ca from Unknown -
Aug 17 2012, 2:18 PMReport Spam
Exam L, Q13
hot spot answer is
Seattle > Servers > DC2 >> NTDS Settings <<
Majerr from United States -
Aug 17 2012, 2:03 PMReport Spam
Your network contains an Active Directory forest named contoso.com. The functional level of the forest is Windows Server 2008 R2
The DNS zone for contoso.com is Active Directory-integrated.
You deploy a read-only domain controller (RODC) named R0DC1. You install the DNS Server server role on R0DC1.
You discover that R0DC1 does not have any DNS application directory partitions.
You need to ensure that R0DC1 has a copy of the DNS application directory partition of contoso.com.
What should you do? (Each correct answer presents a complete solution. Choose two.)
A. From DNS Manager, right-click RODC1 and click Create Default Application Directory Partitions.
B. Run ntdsutil.exe. From the Partition Management context, run the create nc command.
C. Run dnscmd.exe and specify the /createbuiltindirectorypartitions parameter.
D. Run ntdsutil.exe. From the Partition Management context, run the add nc replica command.
E. Run dnscmd.exe and specify the /enlistdirectorypartition parameter.
Exam K, must be wrong. C has to be the right answares.
A corporate network includes an Active Directory-integrated zone. All DNS servers that host the zone are domain controllers. You add multiple DNS records to the zone. You need to ensure that the new records are available on all DNS servers as soon as possible. Which tool should you use?
A. Ntdsutil
B. Dnscmd
C. Repadmin
D. Nslookup
answer: D
Exam L. About Site and DC 2 as a global catalog. It can not be smtp, its NTDS setting under DC2
NowAnonymous from Switzerland -
Aug 17 2012, 12:09 PMReport Spam
@anon from United Kingdom Your going to have to be more specific than that. The answers randomize on some of our clients. :) Use this format:
Exam L Question 13
A.**** is incorrect it must be D.****
Thanks
NowAnonymous from Switzerland -
Aug 17 2012, 12:04 PMReport Spam
@Mar My location is GMT+2. I will look into those questions tonight. If you see anything else just post them here and I will scan through them tonight. Thanks
We need all the help we can get. I'm still new to network administration, I only have 1 and 1/2 years experience from doing Microsoft courses and my A+ and Network+
@Everyone This dump is very valid and you will pass your test if you study it well. Some of the questions are incorrect but not enough of them to let you fail. You need to get more than 15 question incorrect to fail your test. Good Luck
anon from United Kingdom -
Aug 17 2012, 12:00 PMReport Spam
Test L Q13 is D
Youssef from Egypt -
Aug 17 2012, 11:37 AMReport Spam
All new questions in this dump are correct but i don't know the answers are right or wrong can anyone please reassures us. Thanks
Mar from Poland -
Aug 17 2012, 11:25 AMReport Spam
Q18 and Q 40 from K are very similar questions but answers are not the same... Can someone check this?
Mar from Poland -
Aug 17 2012, 11:16 AMReport Spam
Q11 from K should be loopback processing in merge mode
Mar from Poland -
Aug 17 2012, 10:56 AMReport Spam
I have a other order list of answers in this question about passwords but I see that You know what i want to say ;)
Please check if the Q48 krom K shouldn't be answer" Configure DC4 as a preferead bridgehed.." ? I think it's the correct because if you use prefered bridgehead nothing else replicates changes. Chech it if you can ;)
James from Netherlands -
Aug 17 2012, 10:13 AMReport Spam
@NowAnonymous from Unknown - can you do that today ?:P I am make this exam monday... It would be very helpful
NowAnonymous from Unknown -
Aug 17 2012, 10:11 AMReport Spam
@Astraor
Thanks I will go check on technet and do revision on those questions.
@Mar
Thanks for pointing that one out.
A. 1-2-3-4-5-a-b-c-e
D. 123456!@#$%^ Must be: E. %%PASS1234%%
F. !@#$1234ABCD
Q3 from exam L seem to be wrong...
The correct should be B,D,E not A because in A you use only 2 types of characters :)
Astraor from Italy -
Aug 17 2012, 8:57 AMReport Spam
also verify
exam K Q10
Astraor from Italy -
Aug 17 2012, 8:51 AMReport Spam
also verify the question:
exam K Q11
Astraor from Italy -
Aug 17 2012, 8:23 AMReport Spam
Can You verify the question :
exam L Q5
exam L Q13
the reply for those question seems wrong
Nico from Unknown -
Aug 17 2012, 8:05 AMReport Spam
Also from South Africa. Will be taking the exam next week Sat if studying goes as planned :P
Chad, please let us know if this dump is valid
Katlego from United States -
Aug 17 2012, 7:57 AMReport Spam
Hi Chad, i am also from South Africa, please keep me posted as well thanks :-)
0x000 from Egypt -
Aug 17 2012, 7:31 AMReport Spam
@ Anon
does it have the correct answers of new questions or like 461q dump
Chad from Unknown -
Aug 17 2012, 7:22 AMReport Spam
Hi
I am from south africa and taking the exam on thursday, I will keep everyone posted.
0x000 from Egypt -
Aug 17 2012, 7:18 AMReport Spam
good job Anonymous ,thank you
NowAnonymous from United States -
Aug 17 2012, 6:35 AMReport Spam
Hi everyone.
This dump is a combination of "InfiniteKewl " and the new questions from the latest "pass4sure.pdf" contributed by "Anonimo".
I added Exam K and L with a total of 65 new questions. I'm not sure but there might be a few repeated questions from previous exams and I apologise for this as I created the ".vce" ASAP after the ".pdf" was shared with us late at night.
Drag & Drop and Hot Area questions are fully interactive and I corrected Question 8 from Exam G from B.repadmin to H.dnscmd. ref: http://technet.microsoft.com/en-us/library/cc778513(WS.10).aspx
Good Luck with your exam and please reply here on how it went as I'm also almost writing my exam.. :P
It is still valid...
I have passed today with 876
Thank you very much.
I went back two weeks ago: two first questions I learned from Anonymous 468q.vce and the rest of FixedAnswers 468q.vce and I knew them perfectly, four new questions and got 735.
Dump 70% good
You should not go to lower the number of questions to learn
And correct the answers
You plan to add users from fabrikam.com to groups in contoso.com.
You need to identify which group you must use to assign users in fabrikam.com access to the shared folders in contoso.com.
To which group should you add the users?
Group 3: Security Group - Global.
Group 5: Security Group - Universal.
Which One Is Right (Universal Or Global)?? can anyone verify !!
http://technet.microsoft.com/en-us/library/cc732590%28v=ws.10%29.aspx
see my response in the fixed thread.
Am I thinking too much like microsoft. the question does not ask about changing group membership. the question is asking how to apply a solution.
yes, you would need to plan and create your security groups in advance.
F - Q18
Replicate new user
Current: A. Active directory sites and services
Should be: C. Repadmin
the question is:
Your network contains two Active Directory forests named contoso.com and fabrikam.com. Each forest contains one domain. A two-way forest trust exists between the forests.
You plan to add users from fabrikam.com to groups in contoso.com.
You need to identify which group you must use to assign users in fabrikam.com access to the shared folders in contoso.com.
Planning is to assign user from fabrikam to a group present in contoso.
If you create global group in contoso, you can assign only user of same domain, in this case contoso, if you create a group Domain local in contoso, you can assign user from fabrikam .
According to this -
http://technet.microsoft.com/en-us/library/cc739505%28v=ws.10%29.aspx
Only CA administrators and certificate managers are assigned by using the Certification Authority snap-in. To change the permissions of a user or group, you must change the user's security permissions, group membership, or user rights.
My understanding is the only way to do this is by using users and computers or group policy to change the user or group membership.
exam G Q37
Both questions
You need to ensure that all of the members of a group named Group1 can view the event log entries for Certificate Services.
My answer for both, (same question, different answers is CA Certification Authority)
that is where you configure permissions and roles for the CA.
refer to
http://www.kurtdillard.com/StudyGuides/70-640/6.html (1/3 deep into the article)
Figure 6: Configuring CA Permissions.
Can someone confirm if the logic is correct.
If you want me to add corrections please use the same format. It makes it much easier for me to process.
Much thanks :)
EXAM G:
Q8: B. [Repadmin] http://technet.microsoft.com/en-us/library/cc835086(v=ws.10).aspx
EXAM I:
Q18: ???
------------------------------------------------------------
EXAM J:
Q18: C. [Group 3: Security Group - Global.]
Q24: A. [Active Directory Sites And Services console]
Q37: A. [Enable the Audit directory service access setting in the Default Domain Controllers Policy Group Policy Object.] http://technet.microsoft.com/en-us/library/cc731607(v=WS.10).aspx
------------------------------------------------------------
EXAM K:
Q11: D. [Enable loopback processing in merge mode.]
Q31: C. [Repadmin]
Q41: D. [Set-ADForest]
------------------------------------------------------------
EXAM L:
Q3: B,D,E [!@#$1234ABCD/1-2-3-4-5-a-b-c-e/%%PASS1234%%]
Q5: D. [Enable-ADOptionalFeature] http://technet.microsoft.com/en-us/library/dd379481(v=ws.10).aspx
Q13: Seattle > Servers > DC2 >> NTDS Settings << http://www.petri.co.il/configure_a_new_global_catalog.htm
------------------------------------------------------------
It is a selective trust so you have to give group 1 the allowed to authenticate permission to access the shared resource from the server's computer account.
http://technet.microsoft.com/en-us/library/cc732590%28v=ws.10%29.aspx
exam K Q14 Group policy management can assign to those groups
exam G Q37 Users and computers can assign to those groups
about question:
exam K Q14
exam G Q37
can you help me?
You have an Active Directory domain named contoso.com.
You need to view the account lockout threshold and duration for the domain.
Which tool should you use?
Computer Management
Net Config
Active Directory Users and Computers
Gpresult
Net User
Active Directory Users and Computers
Group Policy Management Console (GPMC)
Computer Management
**computer mangement, net config, net user does not have the information.**
leaves, Active Directory Users and Computers
Group Policy Management Console (GPMC) to configure
Gpresult /h gives an HTML report
Active Directory Users and Computers >advanced feature option turned on,attribute editor tab.
(I don't have a server in front of me so I can not confirm that Active directory users and computers is the correct answer)
but my answer would be > Active Directory Users and Computers < for both.
exam G Q37
someone have info?
About question K Q12 is identical of K Q44 but with different answer
@ssniyer
Thanks for help
exam K Q10, I agree with answer (UPN is not the question being asked for the forest), when assigning permissions, they are assigned to the local resource. So talking about about changing computer >account< permissions is wrong. by process of elimination, leaves A: the permissions of the Group1 group
exam K Q29 Start of Authority 2 places where you delegate the person in charge.
b:From DNS Manager, open the properties of the Start of Authority (SOA) record ofcontoso.com, Specify admin1.contoso.com as the responsible person.
c:Open the %SystemrootSystem32DNSContoso.com.dns file by using Notepad and change all instances of "hostmaster@contoso.com" to "adminl@contoso.com"
The difference is the GUI properties is >person.domain.com<, the dns database file is >person@domain.com<
http://technet.microsoft.com/en-us/library/cc816941(v=ws.10).aspx#BKMK_winui
exam K Q12 A:Active Directory Users and Computers, Gpresult /h file.html also works
exam K Q37 b: dsmod http://technet.microsoft.com/en-us/library/cc732406(v=ws.10).aspx
Modifies attributes of one or more existing partitions in the directory.
exam K Q30
A: and D: explanation for D: http://technet.microsoft.com/en-us/library/cc778798(WS.10).aspx
J Q7 answer is correct, you need to activate DS changes auditing. needs to be activated at the command line, the subcategories is the giveaway in this question. if auditing DS changes, it needs to be applied against the default domain controller policy.
J Q37 DS auditing is done in 2 parts.
correct answer is A:Enable the Audit directory service access setting in the Default Domain Controllers Policy Group Policy Object.
turning on the GPO alone would not be a complete answer. You would then need to activate with the command line, auditpol.exe (for DS changes)
Are you planning to upload a fixed version of this?
@Astraor - Exam J, Q7 answer is D because none of the other answers are correct and answer D is the best course of action. I had reasoned the answer for Q37 earlier and I am pretty sure A is the right answer for Q37, that is, Audit Directory Access has to be enabled in Domain Controller Group Policy.
exam J Q7 and Q37
Your company has an Active Directory domain. All servers run Windows Server 2008 R2. Your
company uses an Enterprise Root certification authority (CA) and an Enterprise Intermediate CA.
The Enterprise Intermediate CA certificate expires.
You need to deploy a new Enterprise Intermediate CA certificate to all computers in the domain.
What should you do?
A. Import the new certificate into the Intermediate Certification Store on the Enterprise Root CA
server,
B. Import the new certificate into the Intermediate Certification Store on the Enterprise
Intermediate CA server,
C. Import the new certificate into the Intermediate Certification Store in the Default Domain
Controllers group policy object,
D. Import the new certificate into the Intermediate Certification Store in the Default Domain group
policy object.
you have missed the question 411 from pdf dump
Answer is H
Yes I'm still planning on updating the .vce but only between Monday[Tomorrow] and Wednesday as I want to wait for all the Questions to be corrected and discussed.
If someone else wants to correct them for me your more than welcome to do so and it will be much appreciated. I dont have allot of time on my hands and when I do have some time I study most of the time.
Thanks to everyone contributing with corrections and sources.
If you have input please help.
exam K Q37
exam K Q30
exam K Q42
exam K Q49
thanks for help :)
Seems that this dump have a lot of error...
I'have another doubt
exam K Q10
exam K Q29
@jose123 for question please post exam and question
exam F Q28,exam G Q8,exam J Q24,exam K Q8,exam K Q31
Correct answer for ALL is repadmin /syncall
http://technet.microsoft.com/en-us/library/cc835086(v=ws.10).aspx
In the case where (Exam J, Q24) Repadmin is not an answer option, I will go with AD Sites and Services because it allows to force AD replication across connection objects.
Both DNSLint and nslookup are diagnostic tools. DNSLint is useful to make sure RRs are associated with the right services and nslookup for domain namespace resolution issues. There is no diagnostic need in this question.
Dnscmd is useful to administer/maintain a DNS server or zone using a command line tool. It is also the right tool to create Application Directory Partition. However, I don't see literature to suggest it as a good replication tool for AD integrated zones.
The answer is not B, is D: Active directory sites and services.
you think the same?
managin the zone: the test say B and C. but I was looking and in both cases must write admin1.contoso.com without @, meaning that the answer is: A and B
Answer in test is A: from group police management console..But in other test the answer is d: from windows powershell, run the backup-gpo cmdlt. This is correct for me.
Are you still planning to upload a fixed version of this?
The answer to this does not seem right to me. It says you are in Directory Services Restore Mode (DSRM) so,
I think it should be:
1. Run the Ntdsutil utility
2. Perform a restore of system state data to a time before the OU was deleted
3. ???
and I would think you need to restart in normal mode but that is not a option.
on this dump there are some question apparently identical but with different reply
I'm little confused.
I know that the command DSlint is used for check replication but for replication when is used DNSCMD and when REPADMIN?
the question are:
exam F Q28
exam G Q8
exam J Q24
exam K Q8
exam K Q31
some reply seems wrong
Q14 is a little more tricky. Take a look at - http://technet.microsoft.com/en-us/library/cc732590 - note that Auditing is an Operating System feature and Auditor is an OS role. The question is about viewing event log entries for Certificate Services, which means auditing CS is already enabled. The Role and Activities table in the technet article says - By default the Local Administrator holds the System Audit user right. Therefore by making the Manager group member of the local Administrators group, they can be made to view the event log entries for the CS. This can be achieved through a GPO. Therefore, I would suggest Group Policy Management as the answer.
Sorry
exam K Q27 correct reply seems D not E
exam K Q37 correct reply seems D not A
exam K Q48 correct reply seems B not C
Exam K, Q14
Exam K, Q31
Thanks in advance
Exam K, Q18
forest wide UPN Q18 correct answer of B: Set-ADForest
Set-ADForest
Syntax:
To add values:
-UPNSuffixes @{Add=value1,value2,...}
To remove values:
-UPNSuffixes @{Remove=value3,value4,...}
To replace values:
-UPNSuffixes @{Replace=value1,value2,...}
To clear all values:
-UPNSuffixes $null
The GUI tool for UPN modifications is Active Directory Domains and Trusts.
http://technet.microsoft.com/en-us/library/cc772007.aspx
Exam K, Q41
same scenario UPN to multiple domains in the same forest
correct answer is D:Set-ADForest
forest wide UPN
UPN works at win2k level
correct answer is A: Active Directory Sites and Services
http://technet.microsoft.com/en-us/library/cc772007.aspx
correct answer is group A because Domain Local Group Can have member from other trusted domain but is visible on one domain. Global group is visible on multiple domain but can have member only from the same domain
cheerz
Active Directory recycle Bin is activated by
D: Enable-ADOptionalFeature
http://technet.microsoft.com/en-us/library/dd379481(v=ws.10).aspx
hot spot answer is
Seattle > Servers > DC2 >> NTDS Settings <<
http://www.petri.co.il/configure_a_new_global_catalog.htm
The DNS zone for contoso.com is Active Directory-integrated.
You deploy a read-only domain controller (RODC) named R0DC1. You install the DNS Server server role on R0DC1.
You discover that R0DC1 does not have any DNS application directory partitions.
You need to ensure that R0DC1 has a copy of the DNS application directory partition of contoso.com.
What should you do? (Each correct answer presents a complete solution. Choose two.)
A. From DNS Manager, right-click RODC1 and click Create Default Application Directory Partitions.
B. Run ntdsutil.exe. From the Partition Management context, run the create nc command.
C. Run dnscmd.exe and specify the /createbuiltindirectorypartitions parameter.
D. Run ntdsutil.exe. From the Partition Management context, run the add nc replica command.
E. Run dnscmd.exe and specify the /enlistdirectorypartition parameter.
Answer: A,D
I think the answer should be D, E
http://technet.microsoft.com/en-us/library/cc742490%28v=ws.10%29.aspx
A corporate network includes an Active Directory-integrated zone. All DNS servers that host the zone are domain controllers. You add multiple DNS records to the zone. You need to ensure that the new records are available on all DNS servers as soon as possible. Which tool should you use?
A. Ntdsutil
B. Dnscmd
C. Repadmin
D. Nslookup
answer: D
Exam L Question 13
A.**** is incorrect it must be D.****
Thanks
We need all the help we can get. I'm still new to network administration, I only have 1 and 1/2 years experience from doing Microsoft courses and my A+ and Network+
@Everyone This dump is very valid and you will pass your test if you study it well. Some of the questions are incorrect but not enough of them to let you fail. You need to get more than 15 question incorrect to fail your test. Good Luck
Please check if the Q48 krom K shouldn't be answer" Configure DC4 as a preferead bridgehed.." ? I think it's the correct because if you use prefered bridgehead nothing else replicates changes. Chech it if you can ;)
Thanks I will go check on technet and do revision on those questions.
@Mar
Thanks for pointing that one out.
A. 1-2-3-4-5-a-b-c-e
D. 123456!@#$%^ Must be: E. %%PASS1234%%
F. !@#$1234ABCD
Letters, numbers and special characters.
The correct should be B,D,E not A because in A you use only 2 types of characters :)
exam K Q10
exam K Q11
exam L Q5
exam L Q13
the reply for those question seems wrong
Chad, please let us know if this dump is valid
does it have the correct answers of new questions or like 461q dump
I am from south africa and taking the exam on thursday, I will keep everyone posted.
This dump is a combination of "InfiniteKewl " and the new questions from the latest "pass4sure.pdf" contributed by "Anonimo".
I added Exam K and L with a total of 65 new questions. I'm not sure but there might be a few repeated questions from previous exams and I apologise for this as I created the ".vce" ASAP after the ".pdf" was shared with us late at night.
Drag & Drop and Hot Area questions are fully interactive and I corrected Question 8 from Exam G from B.repadmin to H.dnscmd. ref: http://technet.microsoft.com/en-us/library/cc778513(WS.10).aspx
Good Luck with your exam and please reply here on how it went as I'm also almost writing my exam.. :P