K Q10 has to be answer D.

It is even stated in your reference:
Answer D may sound tempting but it speak of permission of server1 computer account.

Open the properties of the computer to which trusted users should be allowed to authenticate.

You have to Add the group to the computer account and check it with allow to authenticate. A corporate netwok includes an AD DS forest that contains two domains. All servers run windows Serve2008R2. All DCs are configured as DNS servers. A standrad primary zone for is stored ona member server.You need to ensure that all domain controllers can resolve names from the zone. What should you do?

A) On one DC ,create a secondary zone.
B) On the member server create a secondary sever
C) On each domain controller , create a secondary zone.
D) On one domain controller create a conditional Forwader.Configure the conditional forwarder to replicate to all DNS servers in the domain.


2) A corporate network contains a Windows 2008R2 AD forest.You need to add a user principal name (UPN) suffix to the forest.which tool should you use?

a) AD module for Windows powershell
b) AD administrative centre console
c) AD Sites and Services Console
4) AD users and computer Console I've uploaded a new version, Venomous_v2.

Please use v2 as it has corrections for the following questions:
E02,11,12
F31
G37
K14,32

Many thanks to Luffy, 'confused', Camel73 and Wesley for their contributions! E11 and E12 will be corrected in Venomous_v2. The correct answers are:

E11
D. an organization claim

E12
D. Personal Information Exchange PKCS #12 (.pfx)

Ok, regarding K13. D is not correct and here's why:

Domain Name System Security Extensions (DNSSEC) is a suite of extensions that adds security to the DNS protocol by providing the ability for DNS servers to validate DNS responses. With DNSSEC, resource records are accompanied by digital signatures. These digital signatures are generated when DNSSEC is applied to a DNS zone using a process called zone signing. When a resolver issues a DNS query for resource record in a signed zone, a digital signature is returned with the response so that validation can be performed. If validation is successful, this proves that the data has not been modified or tampered with in any way.

So, DNSSEC is used to validate DNS responses, *NOT* to encrypt zone transfers.

This line says it all: "Active Directory replication traffic is encrypted; therefore zone replication traffic is encrypted automatically."
To achieve this we create a primary zone in the ForestDNSZone directory partition. This way it gets replicated to all domain controllers with a DNS role in the forest, including DC2, in encrypted form. Your network contains an Active Directory forest. The forest contains two domains named and The domain contains a domain controller named DC1. The domain contains a domain controller named DC2. DC1 and DC2 have the DNS Server server role installed.

You need to create a DNS zone that is available on DC1 and DC2. The solution must ensure that zone transfers are encrypted.

What should you do?

A. Create a primary zone on DC1 and store the zone in a zone file. On DC1 and DC2, configure inbound rules and outbound rules by using Windows Firewall with Advanced Security. Create a secondary zone on DC2 and select DC1 as the master.
B. Create a primary zone on DC1 and store the zone in a DC=ForestDNSZones, DC=Contoso, DC=com naming context.
C. Create a primary zone on DC2 and store the zone in a DC=DC=East, DC=Contoso/DC=com naming context. Create a secondary zone on DC1 and select DC2 as the master.
D. Create a primary zone on DC1 and store the zone in a zone file. Configure DNSSEC for the zone. Create a secondary zone on DC2 and select DC1 as the master.

Original answer was D. Fixed answer is B. DC1 and DC2 have the DNS Server server role installed. <br /> <br /> You need to create a DNS zone that is available on DC1 and DC2. The solution must ensure that zone transfers are encrypted.<br /> <br /> What should you do?<br /> <br /> A. Create a primary zone on DC1 and store the zone in a zone file. On DC1 and DC2, configure inbound rules and outbound rules by using Windows Firewall with Advanced Security. Create a secondary zone on DC2 and select DC1 as the master.<br /> B. Create a primary zone on DC1 and store the zone in a DC=ForestDNSZones, DC=Contoso, DC=com naming context. <br /> C. Create a primary zone on DC2 and store the zone in a DC=DC=East, DC=Contoso/DC=com naming context. Create a secondary zone on DC1 and select DC2 as the master.<br /> D. Create a primary zone on DC1 and store the zone in a zone file. Configure DNSSEC for the zone. Create a secondary zone on DC2 and select DC1 as the master.<br /> <br /> Original answer was D. Fixed answer is B. The answers in the dump are correct for K48 and L04. Have you checked the exhibits? They are different.. ;-)Sunday, January 27, 2013 10:32 AM UTgosha there again.. :)<br /> exam K q48<br /> exam L q4<br /> <br /> Configure DC1 as a preferred bridgehead server for IP transport.<br /> or<br /> Configure DC4 as a preferred bridgehead server for IP transport.<br /> <br /> exactly the same question different answer<br /> <br /> witch one is the right one?Sunday, January 27, 2013 10:25 AM UTVenomous<br /> I think because the 70-640 doesn't contain simulations. Regarding C31:
The question states:

"You selected the Normal option for the Event delivery optimization setting by using the HTTP protocol."

This means we do not have to run winrm quickconfig on the collector computer. Check the explanation and the Technet reference. The 70-642 Self Paced Kit doesn't take this into consideration.

Also, if you look at the exercises on page 536, the author lists the same steps as answers A, C and F:

* Configuring a Computer to Collect Events
- At a command prompt, run the following command to configure the Windows Event Collector service:
wecutil qc

* Configuring a Computer to Forward Events
- At a command prompt, run the following command to configure the Windows Remote Management service:
winrm quickconfig

- Run the following command at the command prompt to grant Dcrsv1 access to the event log. If your collecting computer has a different name or domain name, replace Dcsrv1 with the correct name and nwtraders.msft with the correct domain name.
net localgroup "Event Log Readers" Dcsrv1$@nwtraders.msft /add

[In the question we add the computer account to the Administrators group, but it has the same effect: access to the event log.]

Given the choice between the Self Paced Kits and Technet, I'd choose Technet every time. :-) Regarding G06:
I'm sorry, I can't explain it any clearer than I have done in the dump and here.

Check the explanation and the references again. The answer for G06 is D, nothing else. It's all in the word "first".

If you think it's something else, please provide a clear explanation why, not by just providing a link or saying "surely it must be C". Below are the PowerShell options that pertain to Fine Grained Password Policy and the link is a bit of information on the MS exam structure. Get-adFineGrainedPasswordPolicy: Get one or more AD fine-grained password policies.
New-adFineGrainedPasswordPolicy: Create a new AD fine-grained policy.
Remove-adFineGrainedPasswordPolicy: Remove an AD fine-grained password policy.
Set-adFineGrainedPasswordPolicy: Modify an AD fine-grained password policy.
Add-adFineGrainedPasswordPolicySubject: Apply a fine-grained password policy to one more users and groups.
Get-adFineGrainedPasswordPolicySubject: Get the users and groups to which a fine-grained policy is applied.
Remove-adFineGrainedPasswordPolicySubject: Remove one or more users from a fine-grained policy. Yes, we use Add-ADFineGrainedPasswordPolicySubject to assign an Active Directory fine grained password policy. But before we can do that we need to *have* an Active Directory fine grained password policy. We cannot assign something that is not there.

So, the *first* thing (remember, "What should you do first?") that needs to be done is to *create* an Active Directory fine grained password policy. Only after creating it can we apply it using Add-ADFineGrainedPasswordPolicySubject.