70-648_A.v2012-03-15.by.Ackley

of 107
11 views
PDF
All materials on our website are shared by users. If you have any questions about copyright issues, please report us to resolve them. We are always happy to assist you.
Document Description
PrepKing Number: 70-648 Passing Score: 700 Time Limit: 120 min File Version: 8.0 PrepKing-70-648 Sections 1. 70-640 2. 70-642 Exam A QUESTION 1 Your network contains an Active Directory domain. The relevant servers in the domain are configured as shown in the following table: Server name Server1 Server2 Server3 Operating System Windows 2008 Windows 2008 R2 Windows 2008 R2 Server role Domain controller Enterprise root certification authority (CA) Network Device Enrollment Service (NDES) You n
Document Share
Document Tags
Document Transcript
  PrepKing Number: 70-648Passing Score: 700Time Limit: 120 minFile Version: 8.0 PrepKing-70-648Sections 1.70-6402.70-642  Exam AQUESTION 1 Your network contains an Active Directory domain. The relevant servers in the domain are configured as shownin the following table: Server nameOperating SystemServer role Server1Windows 2008Domain controllerServer2Windows 2008 R2Enterprise root certification authority (CA)Server3Windows 2008 R2Network Device Enrollment Service (NDES) You need to ensure that all device certificate requests use the MD5 hash algorithm. What should you do?A.On Server2, run the Certutil tool.B.On Server1, update the CEP Encryption certificate template.C.On Server1, update the Exchange Enrollment Agent (Offline Request) template.D.On Server3, set the value of the HKLM\Software\Microsoft\Cryptography\MSCEP\ HashAlgorithm \HashAlgorithm registry key. Answer: D Section: 70-640 Explanation/Reference:QUESTION 2 Your network contains an Active Directory domain. You have a server named Server1 that runs WindowsServer 2008 R2. Server1 is an enterprise root certification authority (CA). You have a client computer namedComputer1 that runs Windows 7. You enable automatic certificate enrollment for all client computers that runWindows 7. You need to verify that the Windows 7 client computers can automatically enroll for certificates. Which command should you run on Computer1?A.certreq.exe - retrieveB.certreq.exe - submitC.certutil.exe - getkeyD.certutil.exe - pulse Answer: D Section: 70-640 Explanation/Reference:QUESTION 3 Your network contains two Active Directory forests named contoso.com and adatum.com. The functional levelof both forests is Windows Server 2008 R2. Each forest contains one domain. Active Directory Certificate  Services (AD CS) is configured in the contoso.com forest to allow users from both forests to automatically enrolluser certificates. You need to ensure that all users in the adatum.com forest have a user certificate from the contoso.comcertification authority (CA). What should you configure in the adatum.com domain?A.From the Default Domain Controllers Policy, modify the Enterprise Trust settings.B.From the Default Domain Controllers Policy, modify the Trusted Publishers settings.C.From the Default Domain Policy, modify the Certificate Enrollment policy.D.From the Default Domain Policy, modify the Trusted Root Certification Authority settings. Answer: C Section: 70-640 Explanation/Reference:QUESTION 4 You have a server named Server1 that has the following Active Directory Certificate Services (AD CS) roleservices installed:Enterprise root certification authority (CA)Certificate Enrollment Web ServiceCertificate Enrollment Policy Web ServiceYou create a new certificate template. External users report that the new template is unavailable when theyrequest a new certificate. You verify that all other templates are available to the external users. You need to ensure that the external users can request certificates by using the new template. What should you do on Server1?A.Run iisreset.exe /restart.B.Run gpupdate.exe /force.C.Run certutil.exe - dspublish.D.Restart the Active Directory Certificate Services service. Answer: A Section: 70-640 Explanation/Reference:QUESTION 5 Your network contains an enterprise root certification authority (CA). You need to ensure that a certificate issued by the CA is valid. What should you do?A.Run syskey.exe and use the Update option.  B.Run sigverif.exe and use the Advanced option.C.Run certutil.exe and specify the -verify parameter.D.Run certreq.exe and specify the -retrieve parameter. Answer: C Section: 70-640 Explanation/Reference:QUESTION 6 You have an enterprise subordinate certification authority (CA). The CA issues smart card logon certificates.Users are required to log on to the domain by using a smart card. Your company's corporate security policystates that when an employee resigns, his ability to log on to the network must be immediately revoked. Anemployee resigns. You need to immediately prevent the employee from logging on to the domain. What should you do?A.Revoke the employee's smart card certificate.B.Disable the employee's Active Directory account.C.Publish a new delta certificate revocation list (CRL).D.Reset the password for the employee's Active Directory account. Answer: B Section: 70-640 Explanation/Reference:QUESTION 7 Your network contains a server that runs Windows Server 2008 R2. The server is configured as an enterpriseroot certification authority (CA).You have a Web site that uses x.509 certificates for authentication. The Web site is configured to use a many-to-one mapping.You revoke a certificate issued to an external partner. You need to prevent the external partner from accessing the Web site. What should you do?A.Run certutil.exe -crl.B.Run certutil.exe -delkey.C.From Active Directory Users and Computers, modify the membership of the IIS_IUSRS group.D.From Active Directory Users and Computers, modify the Contact object for the external partner. Answer: A Section: 70-640 Explanation/Reference:
Search Related
We Need Your Support
Thank you for visiting our website and your interest in our free products and services. We are nonprofit website to share and download documents. To the running of this website, we need your help to support us.

Thanks to everyone for your continued support.

No, Thanks
SAVE OUR EARTH

We need your sign to support Project to invent "SMART AND CONTROLLABLE REFLECTIVE BALLOONS" to cover the Sun and Save Our Earth.

More details...

Sign Now!

We are very appreciated for your Prompt Action!

x