Exam 70-291 study material
Made available by Examsexpert.com
Free 70-291 Exam Preparation Questions
Exam 70-291: Implementing, Managing, and Maintaining a Microsoft Windows Server 2003 Network Infrastructure
For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
Question: 1 Your network consists of a single Active Directory domain named Hi-Tech.com.local. All servers run Windows Server 2003 Service Pack 2 (SP2). All internal computers are part of the domain. You deploy a stand-alone Web server in a perimeter network. Users on the Internet access the server by using the URL http://www.Hi-Tech.com.com. You need to ensure that internal users can connect to the Web server by using the URL http://Hi-Tech.comWeb. What should you add?
A. a host record for Hi-Tech.comWeb to the Hi-Tech.com.com DNS zone B. a host record for Hi-Tech.comWeb to the Hi-Tech.com.local DNS zone C. Hi-Tech.com.com as a DNS suffix on the network adapter for each computer D. Hi-Tech.com.com to the DNS search suffix list on the network adapter for each computer Answer: B Question: 2 Your network consists of a single Active Directory domain named Hi-Tech.com.com. All servers run Windows Server 2003 Service Pack2 (SP2). All client computers run Windows XP Professional Service Pack 3 (SP3). Yo have two DNS servers named DNS1.Hi-Tech.com.com and DNS2.Hi-Tech.com.com. All client computers are configured to use DNS1 as their preferred DNS server and DNS2 as an alternate DNS server. You need to verify that DNS1 is responding to name resolution queries from a client computer. What should you run from the client computer?
For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
A. Ipconfig.exe /displaydns B. Nbtstat.exe r C. Nslookup.exe - dns1.Hi-Tech.com.com D. Ping.exe dns1.Hi-Tech.com.com Answer: C Question: 3 You are the administrator of a Windows Server 2003 Service Pack 2 (SP2) computer named Server1. Server1 is an FTP server located in the company's internal network. Administrators report an increased amount of FTP traffic to Server1. You need to configure Server1 to achieve the following goals: Identify the media access control (MAC) address of any computer that is performing FTP transfers from Server1. Find out the exact FTP commands that were executed. Ensure that you do not disrupt the operation of Server1. What should you do? A. Configure a performance alert to write an event to the application event log whenever the number of established FTP connections exceeds 1. For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
B. Use a Network Monitor filter to capture IP traffic from any computer to Server1. C. Run the finger command on Server1 to identify the source of the FTP requests. D. Run the arp command on Server1 to identify the source of the FTP requests. Answer: B Question: You are the network administrator for your company. A Windows Server 2003 Service Pack 2 (SP2) computer named Router11 is used to connect the network to the Internet. You find out that some computers on the network are infected with a worm, which occasionally sends out traffic to various hosts on the Internet. This traffic always uses a certain source TCP port number. You need to identify which computers are infected with the worm. You need to configure a solution on Router11 that will perform the following two tasks: Detect and identify traffic that is sent by the worm. Immediately send a notification to a network administrator that the infected computer needs to be repaired. What should you do?
A. Configure a WMI event trigger. B. Configure a Network Monitor capture filter. C. Configure a Network Monitor trigger. D. Configure a System Monitor alert. Answer: C Question: 5 You work as the network administrator at Hi-Tech.com. The Hi-Tech.com network consists of a single Active Directory domain named Hi-Tech.com. All servers on the Hi-Tech.com network run Windows Server 2003 Service Pack 2 (SP2) and all client computers run Windows XP Professional. A new HiTech.com security policy requires that the network traffic to Web servers must be audited on a regular basis. Hi-Tech.com consists of a Web server named SERVER13, which is on Zkxl's intranet. On SERVER13, the Network Monitor Tools are installed. During routine maintenance, you discover that that the Network Monitor captured over 50,000 frames. You also notice that large amount of TCP connection requests came from the 131.107.0.1 IP address. What should you do to view the frames for network traffic that are captured between SERVER13 and the 131.107.0.1 IP address? You work as a security administrator for Microsoft. The basic network and some policies are as the following: What can you do to configure the remote DNS servers? To answer, the appropriate server configuration to the correct server or servers in the work area.
For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
A. Between the SERVER13 and the 131.107.0.1 IP address you should create an Address Capture filter for all network traffic that is captured. B. Between the SERVER13 and the 131.107.0.1 IP address you should create a Fin Frame Expression filter for network traffic captured. C. Create an Address Display filter for all network traffic captured between Zkxl1 and the 131.107.0.1 IP address. D. On SERVER13 you should create a Pattern Match capture trigger for the 131.107.0.1 IP address. Answer: C Question: 6 Your network consists of a single Active Directory domain. All servers run Windows Server 2003 Service Pack 2 (SP2). You have a DNS server named Server1 that hosts a primary zone for the domain. You have a DNS server named Server 2 that hosts a secondary zone for the domain. You discover that the resource records on Server2 are different from the resource records on Server1. You need to ensure that the resource records are the same on Server1 and Server2. What should you do?
For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
A. On Server2, select Reload in the DNS zone. B. On Server2, select Reload from Master in the DNS zone. C. On Server1, select Update Server Data File in the DNS zone. D. On Server1, deselect the Fail on load if bad zone data option. Answer: B Question: 7 Your company has a single Active Directory domain named Hi-Tech.com.com. All servers in the domain run Windows Server 2003 Service Pack 2 (SP2). You have two DNS servers named DNS1 and DNS2. DNS1 hosts an Active Directory-integrated zone for Hi-Tech.com.com. DNS2 hosts a standard secondary zone for Hi-Tech.com.com. You need to monitor the total number of zone transfer requests. What should you do? A. On DNS1 create a counter log. B. On DNS2 create a counter log. C. On DNS1 use Active Directory Replication Monitor. D. On DNS2 use Active Directory Replication Monitor. Answer: A Question: 8 Your network consists of a single Active Directory domain. You have a Web server named server1.HiTech.com.com that runs Windows Server 2003 Service Pack 2 (SP2). Users access a Web site on Server1 by using the URL http://server1.Hi-Tech.com.com. Users also access the Web site on Server1 by using the URL http://192.168.1.10. You need to configure DNS to enable users to access the Web site by using the URL http://www.Hi-Tech.com.com. The solution must prevent the need to manually update DNS if the IP address of Server1 changes. Which type of resource record should you create in DNS?
For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
A. alias (CNAME) B. host (A) C. host (AAAA) D. host information (HINFO) For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
Answer: A Question: 9 You are the network administrator for your company. The network consists of a single Active Directory domain. All servers run Windows Server 2003 Service Pack 2 (SP2). All client computers run Windows XP Professional. You need to implement a new software update infrastructure. You discover that security patches, critical updates, and service packs have never been installed on any client computer on the network. You install Windows Server Update Services (WSUS) on a Windows Server 2003 Service Pack 2 (SP2) computer named Server5. You synchronize and approve all of the current security patches, critical updates, and service packs. You need to ensure that all client computers receive all Microsoft security patches, critical updates, and service packs. Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.) You work as a security administrator for Microsoft.The basc network and some configures are as the following:
. A. Open the WSUS console. Select the option to automatically approve WSUS updates. B. Install the Automatic Updates client on all client computers. C. Modify the Microsoft Update settings of the Default Domain Controller organizational unit (OU) Group Policy object (GPO) to point client computers to http ://server5. D. Modify the Microsoft Update settings of the Default Domain Policy Group Policy object (GPO) to point client computers to http: //server5. E. Open the WSUS console. Create a target group and assign all client computers to the group. Answer: B, D Question: 10 You work as the network administrator at Hi-Tech.com. The Hi-Tech.com network consists of a single Active Directory domain named Hi-Tech.com. All servers on the Hi-Tech.com network run Windows Server 2003 Service Pack 2 (SP2) and all client computers run Windows XP Professional. You are setting up a sales booth at a large trade expo. Twelve Hi-Tech.com sales representatives with a portable computer each will be working in the booth. You create a LAN in the booth and connect all the sales representatives' portable computers to the LAN. You install as a server named SERVER01 that is For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
configured with a LAN connection and a dial-up connection to the Internet in the booth. You connect SERVER01 to the LAN. However, a user named Rory Allen complains that he cannot connect to the Internet. Rory Allen informs you that the other sales representatives at the expo are having the same problem. Rory Allen's portable computer is named CLIENT299. You log on to CLIENT299 and run the ipconfig /all command. You receive the output as shown in the exhibit. You need to provide the sales representatives that work in the booth with Internet access. What should you do?
A. Enable and configure Internet Connection Sharing (ICS) on SERVER01. B. Install the DHCP service on SERVER01 and configure the 12 sales representatives' client computers to receive their IP addresses from DHCP. C. Modify the Internet Explorer properties on the 12 sales representatives' client computers to specify 169.254 as the proxy server. D. Install the Connection Manager Administration Kit (CMAK) on SERVER01. Answer: A Question: 11 Your network consists of a single Active Directory domain. The domain contains an organizational unit (OU) named SecureServers. The SecureServers OU contains a computer account for a server named Server1. You link a Group Policy object (GPO) to the SecureServers OU. In the GPO, you assign an IPSec policy that requires encryption for all communications. You notice that all communications to Server1 are unencrypted. You need to ensure that all communications to Server1 are encrypted immediately. What should you do?
For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
You work as a security administrator for Microsoft.The basc network and some configures are as the following:
For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
A. On Server1, run gpudate.exe. B. On Server1, run gpresult.exe. C. From the properties of the GPO, enable the Enforced option. D. From the properties on the SecureServers OU, enable the Block policy inheritance setting. Answer: A Question: 12 Your network consists of a single Active Directory domain. All servers run Windows Server 2003 Service Pack 2 (SP2). All client computers run Windows XP Professional Service Pack 3 (SP3). You install and configure Windows Server Update Services (WSUS) 3.0 on a server named Server1. You need to configure one client computer to check for software updates from Server1 every morning at 02:30. What should you do?
For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
A. On the client computer, run gpedit.msc and modify the Windows Update settings. B. On the client computer, open the Automatic Updates control panel applet and modify the Automatic Updates settings. C. On Server1, open the Update Services console and configure the Computers options. D. On Server1, open the Update Services console and configure the Synchronization Schedule options. Answer: A Question: 13 Your network consists of a single Active Directory domain. All servers run Windows Server 2003 Service Pack 2 (SP2). You need to provide a user named User1 the required permissions to reset passwords in the domain. What should you do? A. Install and run the Security Configuration Wizard (SCW). B. From the Authorization Manager snap-in, modify the authorization store type. C. From Active Directory Sites and Services, run the Delegation of Control Wizard. D. From Active Directory Users and Computers, run the Delegation of Control Wizard. Answer: D Question: 14 Your network contains a DNS server that has a reverse lookup zone for all of your network segments. You have a server named Server1 that runs Windows Server 2003 Service Pack 2 (SP2). An IP security policy is assigned to Server1. You verify IPSec traffic and see that the current security associations display only by IP address. You need to view the fully qualified domain names for all security associations. What should you do? You work as a security administrator for Microsoft.The basc network and some configures are as the
For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
following:
A. From the DNS console, add Server1 as a name server. B. From the DNS console, change dynamic updates to Secure only. C. From IP Security Monitor on Server1, enable DNS name resolution. D. From IP Security Monitor on Server1, create a new taskpad view. Answer: C Question: 15 You work as the network administrator at Hi-Tech.com. The Hi-Tech.com network consists of a single Active Directory domain named Hi-Tech.com. All servers on the Hi-Tech.com network run Windows Server 2003 Service Pack 2 (SP2) and all client computers run Windows XP Professional. The network consists of a Windows Server 2003 Service Pack 2 (SP2) Web server named SERVER10, which is connected to the Internet by means of a dedicated link. You have received instruction from the CIO to monitor the bandwidth utilization of SERVER10. The sample rate for the counter is set to 15 seconds, which is archived once each day. You now need to reconfigure the System Monitor log settings due to the fact that the System Monitor log is becoming too large for the available disk space. What should you do to reconfigure the System Monitor log settings to prevent the System Monitor log becoming too large for the available disk space?
For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
A. Keep SERVER10 on the current counter and set the sample rate to 5 seconds. B. Keep SERVER10 on the current counter and set the sample rate to 60 seconds. C. Change the counter of SERVER10 to Total Bytes and set the sample rate to 15 seconds. D. Change the counter of SERVER10 to Current Bandwidth and set the sample rate to 60 seconds. Answer: B Question: 16 You are the network administrator for your company. All servers run Windows Server 2003 Service Pack 2 (SP2). All client computers run Windows XP Professional. You install Windows Software Update Services (WSUS) on a computer named Server1. This WSUS installation must meet the following requirements: Use the least amount of disk space on Server1. All updates must be tested before being deployed to the client computers. You clear the Automatically Approve Updates for Installation checkbox. You open the WSUS console. You need to complete the installation and meet the requirements. Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.) You work as a security administrator for Microsoft.The basc network and some configures are as the following:
For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
A. Change the Advanced Synchronization Options dialog box so that updates are not stored locally. B. Change the Revisions to Updates setting so that new versions of previously approved updates are not automatically approved. C. Change the Revisions to Updates setting to automatically approve all updates. D. Remove the Critical Updates option from Updates Classifications. Answer: A, B Question: 17 You work as a domain administrator at Hi-Tech.com. The Hi-Tech.com network consists of a single Active Directory domain named Hi-Tech.com. All servers on the Hi-Tech.com network run either Windows Server 2003 Service Pack 2 (SP2) or Windows 2000 Server, and all client computers run Windows XP Professional. All the servers and client computers on the Hi-Tech.com network are connected to the Internet. The Hi-Tech.com security policy states that all data transmissions must be protected by Internet Protocol Security (IPSec.) Part of your job description includes that management of a Windows 2000 Server computer named SERVER29. You do however have a suspicion that certain IPSec policies are not being assigned to SERVER29 and the rest of the Windows 2000 Server computers. To verify your suspicions you need to view the name of the active IPSec policies in use by SERVER29. Which tool should you use to carry out your task? A. Netsh B. Ipseccmd C. Netdiag D. IP Security Monitor Answer: C Question: 18 You work as the network administrator at Hi-Tech.com. The Hi-Tech.com network consists of a single Active Directory domain named Hi-Tech.com that contains an organizational unit (OU) named IntranetServers OU. IntranetServers OU consists of 9 Windows Server 2003 Service Pack 2 (SP2) computers' computer accounts that operate as the intranet Web servers of the Hi-Tech.com network. A Group Policy object (GPO) named IntranetServerPolicy is used to set configuration settings on the Windows Server 2003 Service Pack 2 (SP2) computers in IntranetServers OU. IntranetServerPolicy is linked to IntranetServers OU and a global group named IntranetServerAdmins is a member of the Administrators local group on all intranet Web servers. You want to deploy a security scanning application on each intranet Web server that will update the HKEY_LOCAL_MACHINE\SYSTEM key in the registry of each computer on which the security scanning application is installed. The security scanning application will use a service account to make modifications to the HKEY_LOCAL_MACHINE\SYSTEM key in the registry of each computer. You create the necessary service account in the Hi-Tech.com domain. The written security policy of Hi-Tech.com stipulates that all service accounts must be assigned with only the minimum rights and permissions that they need to operate. You want to configure the intranet Web servers and ensure that their configuration is in compliance with the installation requirements of the security scanning application. You must also ensure
For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
that the rights and permissions assigned to the service account comply with the written security policy of Hi-Tech.com. You want to use the minimum amount of administrative effort to achieve your goal. What should you do to achieve your goal in these circumstances?
A. Add the service account used by the security scanning application to the IntranetServerAdmins global group. B. Specify the required permissions as registry security settings in the IntranetServerPolicy GPO. C. Run the regedit.exe command to add the necessary permissions to each intranet Web server's registry. D. Run the explorer.exe command to update the NTFS permissions on the Systemroot\System32\Config\System file. Assign the Allow - Change permission to the service account used by the security scanning application. E. Configure file system security settings in the IntranetServerPolicy GPO to update the NTFS permissions on the Systemroot\System32\Config\System file. Assign the Allow - Change permission to the service account used by the security scanning application. Answer: B Question: 19 You receive a report that Computerl is responding slowly to user requests. You 12-19 want a quick way to see which network traffic the server use Network Monitor. You want to see whether any general broadcast traffic is being sent to Computerl. Which counter should you enable? A. Nonunicasts/Interval B. Unicasts/Interval C. Bytes Sent/Interval D. Bytes Received/Interval
Answer: A
Question: 20 You are the network administrator for your company. The network consists of a single Active Directory domain. All servers run Windows Server 2003 Service Pack 2 (SP2). All client computers run Windows XP Professional. Two of the servers on the network contain highly confidential documents. The company's written security policy states that all network connections with these servers must be encrypted by using an IPSec policy. You place the two servers in an organizational unit (OU) named SecureServers. You configure a Group Policy object (GPO) that requires encryption for all connections. You assign the GPO to the SecureServers OU. You need to verify that users are connecting to the two servers by using encrypted connections. What should you do?
For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
A. Run the net view command. B. Run the gpresult command. C. Use the IP Security Monitor console. D. Use the IPSec Policy Management console. Answer: C Question: 21 You have two stand-alone servers named Server1 and Server2. Both servers run Windows Server 2003 Service Pack 2 (SP2). On Server1, you save the local security policy as a template. You need to import the template to Server2. What should you run on Server2? A. the Security Templates snap-in B. the Security Configuration Wizard C. the Microsoft Baseline Security Analyzer D. the Security Configuration and Analysis snap-in Answer: D Question: 22 You are a network administrator for A. Datum Corporation. The network consists of a single Active Directory domain named adatum.net. Users regularly browse the internal network and the Internet from their client computers. All Web and e-mail hosting for a separate DNS domain named adatum.com is outsourced to an ISP. All name resolution requests for adatum.com are resolved by the ISP. You have no administrative control over the DNS servers at the ISP. You cannot list the contents of adatum.com by using the nslookup command on the DNS servers at the ISP. A Windows Server 2003 Service Pack 2 (SP2) computer named Server1 is configured with a primary zone for adatum.net. All root hints have been removed from Server1. All client computers refer to this DNS server for name resolution. You need to configure DNS resolution to ensure that all client computers can locate and access resources in adatum.net, adatum.com, and the Internet. What should you do?
For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
A. Configure a secondary zone for adatum.com on Server1. B. Configure a primary zone for adatum.com on Server1. C. Configure conditional forwarding for adatum.com with the IP address of the DNS server at the ISP. D. Configure simple forwarding with the default settings with the IP address of the DNS server at the ISP. Answer: D Question: 23 You have a server that runs Windows Server 2003 Service Pack 2 (SP2) and Windows Server Update Services (WSUS) 3.0. You need to view the approved WSUS updates that have been superseded by newer updates. You want to achieve this goal by using the minimum amount of administrative effort. What should do you do?
For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
A. View the WindowsUpdate.log file. B. Create a new log view in Event Viewer. C. From Update Services, view the WSUS Updates update view. D. From Update Services, run an Update Status Summary report. Answer: A, C Question: 24 You are the network administrator for Margies Travel. The network consists of a single Active Directory forest that contains two domains named europe.margiestravel.com and namerica.margiestravel.com.The network contains Windows Server 2003 Service Pack 2 (SP2) computers and Windows XP Professional computers. All client computers and 25 servers are dynamically assigned IP addresses by DHCP. All company computers are registered in either the europe.margiestravel.com DNS zone or the namerica.margiestravel.com DNS zone. All DNS servers contain copies of all zones. The written company network management policy states that computers cannot have duplicate host names. Client computers always connect to other computers by specifying only the name of the target computer. A fully qualified domain name (FQDN) is not required. You need to configure the client computers to ensure that all computer names can be resolved by using DNS without the domain name being specified. The configuration of client computers must be automated so that they do not need to be manually reconfigured if an additional domain is added to the forest.What should you do? A. Configure the Append these DNS suffixes option in the DNS client configuration of each client computer. B. Configure the 015 DNS Domain Name option on all DHCP scopes. C. Configure the Default Domain Policy Group Policy object (GPO) in each domain. Enable the DNS For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
Suffix Search List policy setting in the GPO. D. Configure the Default Domain Policy Group Policy object (GPO) in each domain. Enable the Primary DNS Suffix policy setting in the GPO. Answer: C Question: 25 Your network consists of a single Active Directory domain named Hi-Tech.com.com. You have a server named Server1 that runs Windows Server 2003 Service Pack 2 (SP2). You have two domain user accounts named Admin1 and User1. Admin1 is a member of the Administrators group on Server1. User1 is a member of the Domain Users group only. You log on to Server1 as User1. You need to run several administrative tools. You must minimize the number of times you are prompted to enter a username and password when starting the tools. You must achieve this goal without logging off from Server1. What should you do? You work as a security administrator for Microsoft.The basc network and some configures are as the following:
For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
A. Configure the secondary logon service to start by using the Admin1 account. B. Configure the Start menu shortcut for each administrative tool to run as Admin1. C. Create a Start menu shortcut for cmd.exe to run as Admin1, and then start the administrative tools from the command prompt. D. Configure the Start menu shortcut for each administrative tool, and assign the Admin1 account ownership of the shortcuts. Answer: C Question: 26 You have a server that runs Windows Server 2003 Service Pack 2 (SP2). You create a user account named Admin1. You need to allow Admin1 to restart services and to review the security log. You must minimize the rights assigned to Admin1. Which group should you add Admin1 to?
A. Power Users B. Administrators C. HelpServicesGroup For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
D. Remote Desktop Users Answer: B Question: 27 You work as the network administrator at Hi-Tech.com. The Hi-Tech.com network consists of a single Active Directory forest that contains a forest root domain named Hi-Tech.com. The IT department manages Hi-Tech.com. Hi-Tech.com's root domain contains three domain controllers named DC01, DC02, and DC03 that are running Windows Server 2003 Service Pack 2 (SP2) and have the DNS Service installed. The exhibit displays the configuration of the Hi-Tech.com zone. When you view the event logs of these domain controllers, you detect that there are frequent failures of Active Directory transactions that are caused by DNS lookup failures against the Hi-Tech.com zone. You then find that the data in the DNS zone on DC03 is out of date. Which of the following is a task that you should execute on DC03? A. Use the Replmon utility to look for Active Directory replication errors. B. Use Event Viewer to examine the DNS Server log for zone transfer errors. C. Enable debug logging and examine the log file for transfer packets. D. Use System Monitor to monitor the DNS\Zone Transfer Failure counter. Answer: A Question: 28 You have a server that runs Windows Server 2003 Service Pack 2 (SP2). You attempt to download a device driver. You receive an error message indicating that the Web site is blocked and scripting is disabled. You need to ensure that you can download the device driver while ensuring that access to scripts on other Web sites are restricted. What should you do?
For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
A. Run Cscript.exe //h:cscript. B. Disable Windows Internet Explorer Advanced Security. C. Enable TCP/IP filtering and allow TCP port 80 and 443. D. Add the device manufacturers Web site to the Trusted sites zone. For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
Answer: D Question: 29 You have two servers named Server1 and Server2 that run Windows Server 2003 Service Pack 2 (SP2). On Server1, you install an application that runs as a service named App1. App1 will savefiles to a file share on Server2. You perform the following actions: Create a domain account named App1Service. Set the password for App1Service. Create a file share on Server2. Grant App1Service the Allow - Change share permission. You need to ensure that App1 can save files to the share on Server2. What should you do?
For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
A. From the Services snap-in, configure the Log On settings. B. From the Services snap-in, configure the Recovery settings. C. From Local Security Policy, disable the Network access: Shares that can be accessed anonymously setting. D. From Local Security Policy, disable the Network access: Let Everyone permissions apply to anonymous users setting. Answer: A Question: 30 You work as the network administrator at Hi-Tech.com. The Hi-Tech.com network consists of a single Active Directory domain named Hi-Tech.com. All servers on the Hi-Tech.com network run Windows Server 2003 Service Pack 2 (SP2) and all client computers runWindows XP Professional. The HiTech.com network contains a Web server named SERVER24 that currently runs IIS 6.0 and hosts a secure intranet site. Users are required to connect to the intranet site by authenticating and using HTTPS but your current Web application can only be used connect to the Web site using HTTP thus HTTPS cannot be configure for the intranet site to require. What should you do to collect information about which users are connecting to the Web site by using HTTPS? A. The application log must be checked on the Web server. B. Network Monitor must be used to capture network traffic on the Web server. C. The log files must be reviewed and are created by IIS on the Web server. D. A performance log must be configured to capture all Web service counters. The performance log data must be reviewed.
For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
Answer: C Question: 31 You work as the network administrator at Hi-Tech.com. The Hi-Tech.com network consists of a single Active Directory domain named Hi-Tech.com. The Hi-Tech.com network contains 35 Windows Server 2003 Service Pack 2 (SP2) servers, 3,000 Windows XP Professional computers and 2000 Windows 2000 Professional computers. You have received instruction from the CIO to install and configure Software Update Services (SUS) on a Windows Server 2003 Service Pack 2 (SP2) server named SERVER24. What should you do to scan all computers in the domain to check if they have received all approved updates located on the SUS server?
For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
A. Install and run the mbsacli.exe command with the appropriate configuration switches on a server. B. Install and configure urlscan.exe on a server that runs IIS C. The Default Domain Policy must be edited and configured to enable the Configure Automatic Updates policy. D. On SERVER24, run the netsh.exe command to scan all computers in the domain from a command prompt. Answer: A Question: 32 Your network consists of a single Active Directory domain. The network contains a server that runs Windows Server 2003 Service Pack 2 (SP2). The server has an application that runs as a service. The application uses a domain service account to access other servers in the domain. Security policies require that users reset their passwords every 30 days. After the application runs for a month, the application fails. You need to ensure that the application starts and can access the remote servers. What should you do?
For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
A. In the Services snap-in, set the service to log on as the Local System account and start the service. B. In the Services snap-in, set the service to log on as the Local Administrator account and start the service. C. In Active Directory Users and Computers, reset the servers computer account. In the Services snapin, start the service. D. In Active Directory Users and Computers, set the Account Expires option to Never. In the Services snap-in, start the service. Answer: D Question: 33 Your network consists of a single Active Directory domain that has three Active Directory sites. Each site contains two Active Directory domain controllers. All domain controllers run Windows Server 2003 Service Pack 2 (SP2). All domain controllers have Windows Support Tools installed. You need to verify For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
the replication status of Active Directory. Which tool should you use? A. Active Directory Sites and Services B. Nltest.exe C. Network Monitor D. Replmon.exe Answer: A, D Question: 34 You are the network administrator for your company. The network consists of a single Active Directory domain. All servers run Windows Server 2003 Service Pack 2 (SP2). All client computers run either Windows 2000 Professional with Service Pack 4 or Windows XP Professional. You install Windows Server Update Services (WSUS) on a computer named Server2. You create a Group Policy object (GPO) that configures all client computers to receive software updates from Server2. One week later, you run Microsoft Baseline Security Analyzer (MBSA) on all client computers to find out whether all updates are being applied. You discover that all of the Windows 2000 Professional client computers receive updates, but the Windows XP Professional client computers do not receive updates. You verify that the GPO setting was applied on all Windows XP Professional computers. You need to ensure that the Windows XP Professional client computers receive their updates from Server2. What should you do? You work as a security administrator for Microsoft.The basc network and some configures are as the following:
A. Make all users of Windows XP Professional client computers members of the Administrators local group. B. On all Windows XP Professional client computers, install the latest service pack. C. On all Windows XP Professional client computers, use the gpupdate /force command. D. On all Windows XP Professional client computers, delete the NoAutoUpdate value under HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU. Answer: B Question: 35 You are the network administrator for your company. The network consists of a single Active Directory domain. All servers run Windows Server 2003 Service Pack 2 (SP2). All client computers run Windows XP Professional. You install and configure a single server to run Windows Server Update Services (WSUS). You configure the appropriate Group Policy settings to specify separate WSUS target groups for client and server computers. You need to ensure that computers automatically assign themselves to the correct computer group. What should you do?
A. In the WSUS console, configure Computer Options so that Use group policy or registry settings on computers is selected. B. In the WSUS console, configure Computer Options so that Use the Move Computers Task in Windows Server Update Services is selected. C. In the WSUS console, create the appropriate computer groups. D. Create organizational units (OUs) for each group.
For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
Answer: A, C Question: 36 You have a server named Server1 that runs Windows Server 2003 Service Pack 2 (SP2). Server1 is configured as a FTP server. You need to view all the FTP packets sent to Server1 for a period of one hour. What should you do? A. From System Monitor, add all counters for the Network object. B. From Network Monitor, create a new capture and then create a display filter. C. From the command prompt, run Ftp.exe d server1. Review the files in %systemdrive%\intepub\ftproot\. D. From Internet Information Services (IIS) Manager, enable and configure logging for the FTP site. Open the FTP log. Answer: B Question: 37 Your network consists of a single Active Directory domain. You have 10 file servers that run Windows Server 2003 Service Pack 2 (SP2). You need to monitor the bandwidth usage on all the file servers from a central location. What should you do?
A. Open the Shared Folders snap-in on one of the servers. Examine the Sessions folder. B. Install Simple TCP/IP Services on all file servers. From one of the servers, run Netcap.exe. C. Install Network Monitor Tools on all file servers. From one of the servers, create a new capture. D. Open the Performance Logs and Alerts snap-in on one of the servers and create a new counter log. Answer: D Question: 38 You have a server that runs Windows Server 2003 Service Pack 2 (SP2). You create a user account named Admin1. You need to allow Admin1 to restart the server and to manage shared folders. You must minimize the rights assigned to Admin1. Which group should you add Admin1 to? You work as a security administrator for Microsoft.The basc network and some configures are as the following:
For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
A. Power Users B. Administrators C. HelpServicesGroup D. Remote Desktop Users Answer: A Question: 39 You work as the network administrator at Hi-Tech.com. The Hi-Tech.com network consists of a single Active Directory domain named Hi-Tech.com. Hi-Tech.com has its headquarters in Chicago and a branch office in Dallas. The branch office in Dallas is connected to the corporate WAN by using a Windows Server 2003 Service Pack 2 (SP2) computer named SERVER20, which is configured as a dial-up router. SERVER20 has two network adapters, one which connects to the Ethernet LAN and the other network adapter is a broadband networking device. For future planning you need to expand the Dallas branch office employees by at least 30 percent. You need to confirm that the current network bandwidth of the broadband connection will be sufficient for the future expansion of the Dallas office. You want to use System Monitor on SERVER20 to find out the current utilization of the broadband network connection. What should you do? A. On SERVER20, monitor the Bytes Total/sec counter on the Network Interface Object. B. On SERVER20, monitor the Bytes Total/sec counter on the Server Object. C. On SERVER20, monitor the Server\\Packets/sec counter on the Server Object. D. On SERVER20, monitor the Current Bandwidth counter on the Network Interface Object. Answer: A Question: 40 You work as the network administrator at Hi-Tech.com. The Hi-Tech.com network consists of a single Active Directory domain named Hi-Tech.com. The Hi-Tech.com network contains a server named SERVER20. SERVER20 has a third party application installed on it. The application runs as a service named NetApp1, which fails from time to time. You need to configure the recovery options for NetApp1 so that if NetApp1 runs successfully for a day or more then fails, NetApp1 is immediately restarted upon failure. If NetApp1 does not run successfully for a day after the failure, you must ensure the entire server is immediately restarted. Which of the following should you perform? (Each correct answer presents part of the solution. Choose three)
For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
A. Configure the Reset fail count after value for NetApp1 to 1 day. B. Configure the Restart service after value for NetApp1 to 1,440 minutes. C. Configure the response to the first failure to be restart NetApp1. D. Configure the response to the first failure to be restart SERVER20. E. Configure the response to the second failure to be restart NetApp1. F. Configure the response to the second failure to be restart SERVER20. Answer: A, C, F Question: 41 You have a server that runs Windows Server 2003 Service Pack 2 (SP2). The server has Windows Server Update Services (WSUS) 3.0 installed. The server contains a single 30-GB volume named Volume1. Volume1 is 90 percent full. You install a new 136-GB hard disk in the server. You create a new 136-GB volume named Volume2. You need to increase the storage space available to WSUS. What should you do?
For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
A. Use wsusutil.exe to copy the updates to Volume2. Manually delete the folder that contains the updates on Volume1. B. Use ntbackup.exe to backup the updates on Volume1. Restore the updates to Volume2. Manually delete the folder that contains the updates on Volume1. C. From the Update Services console, configure the server to download Express Installation files. D. Modify the HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Update Services\Server\Setup\ContentDir registry setting. Restart the Update Services service. Answer: A Question: 42 You are the administrator of an Active Directory domain. All servers run Windows Server 2003 Service Pack 2 (SP2). You configure a server named Server3 as the DNS server for the domain. The company recently started using a new ISP. Since the change to the new ISP occurred, users report that they
For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
cannot access Internet Web sites by using their fully qualified domain names (FQDNs). You manually configure a test computer to use the DNS server address of the new ISP. The test computer can successfully access Internet Web sites by using their FQDNs. You need to ensure that network users can access Internet Web sites by using their FQDNs, while ensuring that user access to internal resources is not disrupted. What are two possible ways to achieve this goal? (Each correct answer presents a complete solution. Choose two.) A. Create a root zone on Server3. B. Configure Server3 to use the default root hints. C. Configure a forwarder on Server3 to the new ISP's DNS server. D. Configure all computers on your network to use the new ISP's DNS server. Answer: A, D Question: 43 Your network contains a Web server named Server1 that runs Windows Server 2003 Service Pack 2 (SP2). Server1 has one Web site. You configure Server1 to use a Web server certificate. Users report that they can access the Web site by using http://server1 and https://server1. You need to ensure that all traffic to, and from, Server1 is encrypted. What should you do?
A. In IIS Manager, enable the Require secure channel (SSL) option. B. In IIS Manager, enable the Digest authentication for Windows domain servers option. C. In Local Security Policy, enable Domain Member: Require strong (Windows 2000 or later) session key. D. In Local Security Policy, enable Domain Member: Digitally encrypt or sign secure channel data (always). Answer: A Question: 44 Your network consists of a single Active Directory domain. All servers run Windows Server 2003 Service Pack 2 (SP2). All client computers run Windows XP Professional Service Pack 3 (SP3). You have a server named Server1 that has Windows Server Update Services (WSUS) 3.0 installed. You need to ensure that all WSUS clients download approved updates directly from the Windows Update site. What should you do?
For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
A. From the Default Domain Policy, configure the Background Intelligence Transfer Service settings. B. From the Default Domain Policy, configure the Windows Update settings. C. From the Update Services console, create a new automatic approvals rule. D. From the Update Services console, configure the Update Files and Languages settings. Answer: D Question: 45 You work as the network administrator at Hi-Tech.com. The Hi-Tech.com network consists of a single Active Directory domain Hi-Tech.com. All servers on the Hi-Tech.com network run Windows Server For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
2003 Service Pack 2 (SP2) and all client computers run Windows XP Professional. You have received instruction to add a file server named SERVER14 to the Hi-Tech.com network. A new Hi-Tech.com security policy requires that all incoming and outgoing network traffic should be examined. To meet the requirements of the new network policy, you need to capture all the incoming and outgoing network traffic from SERVER14. To capture the traffic on SERVER14, you used another server named SERVER12 which is on the same segment as SERVER14. After installing the Network Monitor tools on SERVER12, you notice that it only captures its own incoming and outgoing traffic. What should you do to capture all incoming and outgoing traffic from SERVER14? A. On SERVER14 you should set up the Network Monitor driver and run the Network Monitor on SERVER12 to capture network traffic. B. On SERVER12 you should create a capture filter in the Network Monitor to capture all the protocols. After this you should run Network Monitor to capture network traffic. C. On SERVER14 you should set up the Network Monitor tool and run Network Monitor to capture network traffic D. On SERVER12 you should increased the capture buffer in the Network Monitor from 1 MB to 20 MB in size, and run the Network Monitor to capture network traffic. Answer: C Question: 46 You work as the network administrator at Hi-Tech.com. The Hi-Tech.com network consists of a single Active Directory domain named Hi-Tech.com. All servers on the Hi-Tech.com network run Windows Server 2003 Service Pack 2 (SP2) and all client computers run Windows XP Professional. The Hi-Tech.com network contains a domain controller named DC01. A Hi-Tech.com employee named Andy Reid works in the Research and Development department. One morning Andy Reid complains that he experiences intermittent delays when he logs on to DC01. An administrator named Mia Hamm informs you that replication attempts between DC01 and other domain controllers are sometimes delayed. You have received instruction to identify the cause of the intermittent connection delays to DC01, and determine if the problem is hardware related. Which of the following should you do first?
A. You should perform a network diagnostic test on DC01, by running the netdiag / verbose command. B. You should view the Active Directory replication status on DC01 by using the replmon command. C. Use Network Monitor to view the network traffic packet contents between DC01and all other computers. D. You should set up a System Monitor counter to track the queue lengths on the network adapter on DC01. Answer: D
For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html
For complete Exam 70-291 Training kits and Self-Paced Study Material Visit: http://www.Examsexpert.com/70-291.html
www.Examsexpert.com
For Latest 70-291 Exam Questions and study guides- visit- http://www.Examsexpert.com/70-291.html