显示标签为“70-294”的博文。显示所有博文
显示标签为“70-294”的博文。显示所有博文

2014年3月24日星期一

最新のMicrosoftのMB6-823 70-293 70-294 70-297 70-298試験の練習問題と解答を無料でダウンロード する

IT-Passports.comはMicrosoftのMB6-823 70-293 70-294 70-297 70-298認定試験に対して問題集を提供しておるサイトで、現場のMicrosoftのMB6-823 70-293 70-294 70-297 70-298試験問題と模擬試験問題集を含みます。ほかのホームページに弊社みたいな問題集を見れば、あとでみ続けて、弊社の商品を盗作することとよくわかります。ass4Testが提供した資料は最も全面的で、しかも更新の最も速いです。

IT-Passports.com のMicrosoftのMB6-823 70-293 70-294 70-297 70-298問題集は最も徹底的で、最も正確で、かつアップ·ツー·デートなものです。当面の市場であなたに初めて困難を乗り越える信心を差し上げられるユニークなソフトです。MicrosoftのMB6-823 70-293 70-294 70-297 70-298認証試験は世界でどの国でも承認されて、すべての国が分け隔てをしないの試験です。IT-Passports.com のMicrosoftのMB6-823 70-293 70-294 70-297 70-298認証証明書はあなたが自分の知識と技能を高めることに助けになれることだけでなく、さまざまな条件であなたのキャリアを助けることもできます。IT-Passports.com のMicrosoftのMB6-823 70-293 70-294 70-297 70-298問題集を利用することをお勧めいたします。

IT-Passports.comのMicrosoftのMB6-823 70-293 70-294 70-297 70-298認証試験について最新な研究を完成いたしました。無料な部分ダウンロードしてください。きっと君に失望させないと信じています。最新MicrosoftのMB6-823 70-293 70-294 70-297 70-298認定試験は真実の試験問題にもっとも近くて比較的に全面的でございます。

現在の社会の中で優秀なIT人材が揃て、競争も自ずからとても大きくなって、だから多くの方はITに関する試験に参加してIT業界での地位のために奮闘しています。MB6-823 70-293 70-294 70-297 70-298はMicrosoftの一つ重要な認証試験で多くのIT専門スタッフが認証される重要な試験です。

IT-Passports.comは我々が研究したトレーニング資料を無料に更新します。それはあなたがいつでも最新のMB6-823 70-293 70-294 70-297 70-298試験トレーニング資料をもらえるということです。MB6-823 70-293 70-294 70-297 70-298認定試験の目標が変更されば、IT-Passports.comが提供した勉強資料も変化に追従して内容を変えます。IT-Passports.com は各受験生のニーズを知っていて、あなたがMB6-823 70-293 70-294 70-297 70-298認定試験に受かることに有効なヘルプを差し上げます。あなたが首尾よく試験に合格するように、我々は最も有利な価格と最高のクオリティーを提供して差し上げます。

試験番号:MB6-823問題集
試験科目:Microsoft 「AX 2009 Project Series」
問題と解答:全89問

試験番号:70-293問題集
試験科目:Microsoft 「Planning and Maintaining a Microsoft Windows Server 2003 Network Infrastructure」
問題と解答:全290問

試験番号:70-294問題集
試験科目:Microsoft 「Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 AD Infrastructure」
問題と解答:全220問

試験番号:70-297問題集
試験科目:Microsoft 「Designing a Microsoft Windows Server 2003 Active Directory and Network Infrastructure」
問題と解答:全142問

試験番号:70-298問題集
試験科目:Microsoft 「Designing Security for a MS Windows Server 2003 Network」
問題と解答:全130問

MicrosoftのMB6-823 70-293 70-294 70-297 70-298の認定試験は当面いろいろな認証試験で最も価値がある試験の一つです。最近の数十年間で、コンピュータ科学の教育は世界各地の数多くの注目を得られています。MicrosoftのMB6-823 70-293 70-294 70-297 70-298の認定試験はIT情報技術領域の欠くことができない一部ですから、IT領域の人々はこの試験認証に合格することを通じて自分自身の知識を増加して、他の分野で突破します。IT-Passports.comのMicrosoftのMB6-823 70-293 70-294 70-297 70-298認定試験の問題と解答はそういう人たちのニーズを答えるために研究した成果です。この試験に合格することがたやすいことではないですから、適切なショートカットを選択するのは成功することの必要です。IT-Passports.comはあなたの成功を助けるために存在しているのですから、IT-Passports.comを選ぶということは成功を選ぶのことと等しいです。IT-Passports.comが提供した問題と解答はIT領域のエリートたちが研究と実践を通じて開発されて、十年間過ぎのIT認証経験を持っています。

購入前にお試し,私たちの試験の質問と回答のいずれかの無料サンプルをダウンロード:http://www.it-passports.com/70-298.html

NO.1 You need to design a strategy to ensure that all servers are in compliance with the business
requirements for maintaining security patches. What should you do?
A. Log on to a domain controller and run the Resultant Set of Policy wizard in planning mode on the
domain.
B. Log on to each server and run Security Configuration and Analysis to analyze the security settings by
using a custom security template.
C. Create a logon script to run the secedit command to analyze all servers in the domain.
D. Run the Microsoft Baseline Security Analyzer (MBSA) on a server to scan for Windows vulnerabilities
on all servers in the domain.
Answer: D

Microsoft   70-298   70-298問題集

NO.2 You need to design a method to configure the servers in the development department to meet the
requirements of the chief information officer. What should you do?
A. Use error reporting on all servers in the development department to report errors for a custom
application.
B. Configure all servers in the development department so that they do not require the
CTRL+ALT+DELETE keys be pressed in order to log on interactively to the server.
C. Create a Group Policy object (GPO) and link it to the development department's Servers OU.
Configure the GPO with an interactive logon policy to display a message for users who attempt to log on.
D. Configure the screen saver on all servers in the development department to require a password.
Answer: C

Microsoft   70-298   70-298   70-298認定資格   70-298認定証

NO.3 You need to design a monitoring strategy to meet business requirements for data on servers in the
production department. What should you do?
A. Use Microsoft Baseline Security and Analyzer (MBSA) to scan for Windows vulnerabilities on all
servers in the production department.
B. Run Security and Configuration Analysis to analyze the security settings of all servers in the production
department.
C. Enable auditing for data on each server in the production department. Run System Monitor on all
servers in the production department to create a counter log that tracks activity for the Objects
performance object.
D. Create a Group Policy object (GPO) that enables auditing for object access and link it to the product
department's Servers OU. Enable auditing for data on each server in the production department.
Answer: D

Microsoft過去問   70-298   70-298   70-298認定証   70-298

NO.4 You need to design a strategy to log access to the company Web site. What should you do?
A. Enable logging on the company Web site and select the NCSA Common Log File Format. Store the log
files on a SQL Server computer.
B. Use System Monitor to create a counter log that captures network traffic to the Web server by using the
Web Service object. Store the log files on a SQL Server computer.
C. Run Network Monitor on the Web server. Create a capture filter for the SNA protocol and save the
results to a capture file. Store the capture file on a SQL Server computer.
D. Enable logging on the company Web site and select ODBC Logging. Configure the ODBC logging
options by using a nonadministrative SQL account.
Answer: D

Microsoft問題集   70-298   70-298参考書   70-298

NO.5 You need to design a method to protect traffic on the wireless networks. Your solution must meet the
requirements of the chief security officer. What should you do?
A. Configure the wireless access points in Denver and in Dallas to filter unauthorized Media Access
Control (MAC) addresses.
B. Configure the wireless network connection properties for all computers in Denver and in Dallas to use
the same
network name that the wireless access points use.
C. Create a Group Policy object (GPO) and link it to the Denver OU and to the Dallas OU. Create a
wireless network policy and configure it to use Windows to configure wireless network settings for the
Denver and the Dallas networks.
D. Create a Group Policy object (GPO) and link it to the Denver OU and to the Dallas OU. Create a
wireless network policy and enable data encryption and dynamic key assignment for the Denver and the
Dallas networks.
Answer: D

Microsoft参考書   70-298   70-298認定証

NO.6 You need to design a method to deploy security configuration settings to servers. What should you
do?
A. Run the Resultant Set of Policy wizard with a Windows Management Instrumentation (WMI) filter on
each department's Server OU.
B. Log on to each server and use local policy to configure and manage the security settings.
C. Create a custom security template. Log on to a domain controller and run the secedit command to
import the security template.
D. Create a custom security template. Create a Group Policy object (GPO) and import the security
template. Link the GPO to each department's Server OU.
Answer: D

Microsoft   70-298過去問   70-298認定試験   70-298認定資格

NO.7 You need to design a method to log changes that are made to servers and domain controllers. You also
need to track when administrators modify local security account manager objects on servers. What should
you do?
A. Enable failure audit for privilege use and object access on all servers and domain controllers.
B. Enable success audit for policy change and account management on all servers and domain
controllers.
C. Enable success audit for process tracking and logon events on all servers and domain controllers.
D. Enable failure audit for system events and directory service access on all servers and domain
controllers.
Answer: B

Microsoft   70-298   70-298   70-298

NO.8 You need to design a method to monitor the security configuration of the IIS server to meet the
requirements in the written security policy. What should you do?
A. Log on to a domain controller and run the Resultant Set of Policy wizard in planning mode on the IIS
server computer account.
B. Run the Microsoft Baseline Security Analyzer (MBSA) on the IIS server and scan for vulnerabilities in
Windows and IIS checks.
C. Run Security Configuration and Analysis to analyze the IIS server's security settings by using a custom
security template.
D. On the IIS server, run the gpresult command from a command prompt and analyze the output.
Answer: B

Microsoft   70-298   70-298問題集   70-298過去問   70-298

NO.9 Case 1, Lucerne Publishing
Overview
Lucerne Publishing is an industry leader in publishing technology textbooks, e-books, and magazines.
Physical Locations
The company has three offices, as shown in the Physical Locations and Connectivity exhibit.
The company's main office is in New York, and it has branch offices in Denver and Dallas. The company's
employees and departments are distributed as shown in the following table
Business Processes
The IT staff in the New York office uses client computers to remotely administer all Lucerne Publishing
servers and domain controllers. Employees use their company client computers to access archived
published books and archived accounting
information through an internal Web site that runs IIS 6.0.
Directory Services
The company's network consists of a single Active Directory domain named lucernepublishing.com. All
servers run Windows Server 2003, Enterprise Edition. Administration of Active Directory is centralized in
New York. Denver and Dallas user and computer accounts are located in their respective child OUs, as
shown in the Organizational Unit Hierarchy exhibit.
The NYAdmins, ProductionAdmins, EditorialAdmins, and DevelopmentAdmins global user groups have
full control of their respective organizational units (OUs). These global groups are located in their
respective OUs.
Network Infrastructure
All client computers run Windows XP Professional.
The domain contains a public key infrastructure (PKI). The company uses an internal subordinate
enterprise certification authority (CA) to issue certificates to users and computers. Each branch office has
a wireless network that supports desktop and portable client computers. The wireless network
infrastructure in each branch office contains an Internet Authentication Service (IAS) server and wireless
access points that support IEEE 802.1x, RADIUS, and Wired Equivalent Privacy (WEP).
Problem Statements
The following business problems must be considered: Members of the EditorialAdmins group and
unauthorized users as members to this group. Members of this group must be restricted to only
authorized users.
Editors connect to a shared folder named Edits on a member server named Server5. When they attempt
to encrypt data located in Edits, they receive an error message stating that they cannot encrypt data.
Editors need to encrypt data remotely on Server5.
Some users in the Dallas office changed the location of their My Documents folders to shared folders on
servers that do not back up their My Documents data. As a result, data was lost. The Dallas My
Documents folders need to be moved to a server that backs up user data. Users in the Dallas office must
be prevented from changing the location of their My Documents folder in the future.
Chief Information Officer
Security is Lucerne Publishing's primary concern. We must improve security on client computers, servers,
and domain controllers by implementing a secure password policy. For legal reasons, we need a logon
message that tells users that access to servers in the development department is restricted to only
authorized users.
System Administrator
Each department needs different security patches. We need to test security patches prior to deploying
them. After they are tested, the patches need to be deployed automatically to servers in each department.
As we deploy the patches, we need to limit the network bandwidth used to obtain security patches.
Chief Security Officer
We need to automatically track when administrators modify user rights on a server or on a domain
controller and when they modify local security account manager objects on servers.
We must implement the most secure method for authenticating Denver and Dallas users that access the
wireless networks.
We need to protect data as it is sent between the wireless client computers and the wireless access
points. Client computers need to automatically obtain wireless network access security settings.
Written Security Policy
The Lucerne Publishing written security policy includes the following requirements.
Passwords must contain at least seven characters and must not contain all or part of the user's account
name. Passwords must contain uppercase and lowercase letters and numbers. The minimum password
age must be 10 days, and the maximum password age must be 45 days.
Access to data on servers in the production department must be logged.
A standard set of security settings must be deployed to all servers in the development, editorial, and
production departments. These settings must be configured and managed from a central location.
Servers in the domain must be routinely examined for missing security patches and service packs and to
ascertain if any unnecessary services are running.
Services on domain controllers must be controlled from a central location. Which services start
automatically and which administrators have permission to stop and start services must be centrally
managed.
The IIS server must be routinely examined for missing IIS Security patches.
Users of the Web site and the files they download must be tracked. This data must be stored in a
Microsoft SQL Server database.
Vendors and consultants who use Windows 95 or Windows 98 client computers must have the Active
Directory Client Extensions software installed to be able to authenticate to domain controllers on the
company's network.
Questions
1. You need to design a certificate distribution method that meets the requirements of the chief security
officer.
Your solution must require the minimum amount of user effort. What should you do?
To answer, move the appropriate actions from the list of actions to the answer area, and arrange them in
the appropriate order.
Answer:

NO.10 You need to design a method to deploy security patches that meets the requirements of the systems
administrator. What should you do?
To answer, move the appropriate actions from the list of actions to the answer area, and arrange them in
the appropriate order. (Use only actions that apply. You might need to reuse actions.)
Answer:

2013年12月15日星期日

最新のMicrosoftの70-294試験の練習問題と解答を無料でダウンロード する

IT-Passports.comのシニア専門家チームはMicrosoftの70-294試験に対してトレーニング教材を研究できました。IT-Passports.comが提供した教材を勉強ツルとしてMicrosoftの70-294認定試験に合格するのはとても簡単です。IT-Passports.comも君の100%合格率を保証いたします。

Microsoftの70-294試験に受かるために一所懸命頑張って勉強していれば、あなたは間違っているのです。もちろん頑張って勉強するのは試験に合格することができますが、望ましい効果を達成できないかもしれません。現在はインターネットの時代で、試験に合格する ショートカットがたくさんあります。IT-Passports.comのMicrosoftの70-294試験トレーニング資料はとても良いトレーニング資料で、あなたが試験に合格することを保証します。この資料は値段が手頃だけでなく、あなたの時間を大量に節約できます。そうしたら、半分の労力で二倍の効果を得ることができます。

IT-Passports.comを選択したら、成功が遠くではありません。IT-Passports.comが提供するMicrosoftの70-294認証試験問題集が君の試験に合格させます。テストの時に有効なツルが必要でございます。

試験番号:70-294問題集
試験科目:Microsoft 「Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 AD Infrastructure」
問題と解答:全220問

Microsoftの70-294認定試験はIT職員が欠くことができない認証です。IT職員のキャリアと関連しますから。 Microsoftの70-294試験トレーニング資料は受験生の皆さんが必要とした勉強資料です。IT-Passports.comのトレーニング資料は受験生が一番ほしい唯一なトレーニング資料です。IT-Passports.comのMicrosoftの70-294試験トレーニング資料を手に入れたら、試験に合格することができるようになります。

IT-Passports.comのMicrosoftの70-294試験トレーニング資料は現在で一番人気があるダウンロードのフォーマットを提供します。PDFとソフトのフォーマットで、ダウンロードするのは易いです。IT-Passports.comが提供した製品がIT専門家は実際の経験を活かして作った最も良い製品で、あなたが自分の目標を達成するようにずっと一生懸命頑張っています。

購入前にお試し,私たちの試験の質問と回答のいずれかの無料サンプルをダウンロード:http://www.it-passports.com/70-294.html

NO.1 Your company has a single Active Directory directory service forest with multiple domains. The
Schema FSMO role is held by one of the domain controllers in the forest root domain. The Domain
Naming Master FSMO role is held by one of the domain controllers in a child domain. All domain
controllers have Windows Server 2003 installed.
You need to upgrade all domain controllers to Windows Server 2003 R2.
Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)
A. Run the adprep /forestprep command in the forest root domain.
B. Run the adprep /forestprep command in all the child domains.
C. Run the adprep /domainprep command in all the child domains only.
D. Run the adprep /domainprep command in all domains.
Answer: AD

Microsoft   70-294   70-294   70-294問題集   70-294

NO.2 Your company has a single Active Directory directory service forest with a forest root domain and a
child domain. The child domain is set to the default domain functional level.
You install a second domain controller in the child domain by promoting a server named SVR1.
You need to rename SVR1 to DC2, and you must ensure that there will be no interruption in the ability of
client computers to authenticate to DC2, except during reboot.
What should you do?
A. Raise the domain functional level of the child domain to Windows 2000 native. Use System Properties
on SVR1 to rename SVR1 to DC2.
B. Raise the domain functional level of the child domain to Windows Server 2003. Run the netdom
command to rename SVR1 to DC2.
C. Raise the domain functional level of the child domain to Windows 2000 native. Run the dcpromo
command on SVR1 to remove Active Directory directory service. Use System Properties to rename SVR1
to DC2. Run the dcpromo command to re-install Active Directory.
D. Raise the domain functional level of the child domain to Windows Server 2003. Create a DNS CNAME
record for DC2.contoso.com that points to SVR1.contoso.com.
Answer: B

Microsoft問題集   70-294   70-294   70-294   70-294

NO.3 Your company has a single Active Directory directory service forest with three domains.
You plan to modify the Active Directory schema.
You need to identify the schema master for the forest.
What should you do?
A. Run the regsvr32 schmmgmt.dll command. Use the Active Directory Domains and Trusts snap-in.
B. Run the regsvr32 schmmgmt.dll command. Use the Active Directory Users and Computers snap-in.
C. Use the Dsget command-line tool.
D. Use the Dsquery command-line tool.
Answer: D

Microsoft問題集   70-294認定証   70-294過去問

NO.4 Your company has a single Active Directory directory service forest with a forest root domain and a
child domain. The company has a main office and several branch offices. You are planning to remove the
child domain.
All of the domain controllers in the forest root domain are located in the main office, and all FSMO roles
are on separate domain controllers. The last domain controller in the child domain is named DC1 and is
located in a branch office.
You attempt to remove Active Directory from DC1, but you receive an error message stating that the
operation could not be completed.
You need to remove Active Directory from DC1.
What should you do?
A. Restore connectivity to the domain controller that holds the Domain Naming Master role.
B. Restore connectivity to the domain controller that holds the Schema Master role.
C. Restore connectivity to the domain controller that holds the Infrastructure Master role.
D. Restore connectivity to the domain controller that holds the PDC Emulator role.
Answer: A

Microsoft認証試験   70-294   70-294   70-294   70-294認証試験

NO.5 You have a single Active Directory directory service domain. Your company has a main office and
multiple branch offices. Each office has an Active Directory site. The company s network is not fully
routed.
You need to ensure complete replication between the Active Directory sites.
What should you do?
A. Configure site links, and disable site link bridging.
B. Configure site links to use the SMTP transport, and enable site link bridging.
C. Configure a preferred bridgehead server for each branch office site.
D. Configure a preferred bridgehead server for the main office site.
Answer: A

Microsoft認定試験   70-294   70-294   70-294認定試験   70-294

NO.6 Your Windows Server 2003 environment consists of a single Active Directory directory service forest
with multiple domains. The forest functional level is set to Windows 2000 Server. Your company has a
main office and four branch offices. Each office has two domain controllers. The domain controllers in the
main office are global catalog servers.
In the branch offices, searches for some printers in Active Directory are slow.
You need to improve the performance of Active Directory printer searches in the four branch offices.
What should you do?
A. Enable universal group membership caching in each branch office.
B. Increase the number of domain controllers in each branch office.
C. Add global catalog services to each branch office.
D. Upgrade the forest functional level to Windows Server 2003.
Answer: C

Microsoft   70-294   70-294   70-294

NO.7 Your company has a single Active Directory directory service forest with multiple domains. The
company has a main office with 1,000 users and a single branch office with 500 users. Each office is a
separate Active Directory site. The main office Active Directory site has two domain controllers with Global
Catalog services.
Company employees must be able to work in both offices.
You need to plan the placement and configuration of domain controllers.
What should you do?
A. Deploy two additional domain controllers in the main office Active Directory site.
B. Deploy global catalog servers in the branch office Active Directory site.
C. Enable change notification on the site link between the main office Active Directory site and the branch
office Active Directory site.
D. Disable change notification on the site link between the main office Active Directory site and the branch
office Active Directory site.
Answer: B

Microsoft   70-294   70-294認証試験   70-294

NO.8 Your company has a single Active Directory directory service domain. The company has five Active
Directory sites on the West coast and five Active Directory sites on the East coast. The West coast sites
and the East coast sites are in two separate hub-and-spoke configurations that are separated by a firewall.
All Active Directory replication between the West coast and East coast occurs between a single West
coast domain controller named WestDC1 and a single East coast domain controller named EastDC1.
You need to ensure that if WestDC1 fails, other West coast domain controllers continue to replicate with
each other, but not with East coast domain controllers.
What should you do?
A. Create site links between the West coast hub site and the West coast spoke sites.
B. Create a site link bridge between the West coast hub site and the East coast hub site.
C. Clear the Bridge all site links option and create a site link bridge for all the East coast sites.
D. Clear the Bridge all site links option and create a site link bridge for all the West coast sites.
Answer: D

Microsoft   70-294参考書   70-294認定資格   70-294   70-294

NO.9 You have a single Active Directory directory service domain. You are preparing to create a child
domain. Your user account is in a global security group named Server Administrators. The Server
Administrators group is in the local Administrators group on all servers.
You need to install Active Directory on a server named Server1 to create the new child domain.
What should you do?
A. Have your user account added to the Domain Admins group.
B. Have your user account added to the Schema Admins group.
C. Have your user account added to the Enterprise Admins group.
D. Have your user account added to the Incoming Forest Trust Builders group.
Answer: C

Microsoft   70-294認定証   70-294認定資格   70-294練習問題

NO.10 Your company has a single Active Directory directory service forest named contoso.com. A partner
organization has a forest named fabrikam.com. You create a forest trust relationship between
contoso.com and fabrikam.com.
You need to enable selective authentication between contoso.com and fabrikam.com.
Which tool should you use?
A. Netdom
B. Nltest
C. Dsacls
D. Ntdsutil
Answer: A

Microsoft練習問題   70-294   70-294問題集

NO.11 Your company has a single Active Directory directory service forest with a forest root domain and a
child domain.
The company has a high rate of employee turnover, and administrators create several hundred user
accounts per week.
A domain controller in the child domain fails. Within several hours of the failure, administrators are unable
to create new user accounts within the child domain.
You need to ensure that administrators can create user accounts in the child domain.
What should you do?
A. Seize the PDC Emulator role in the child domain.
B. Seize the RID Master role in the child domain.
C. Seize the Infrastructure Master role in the child domain.
D. Create a new domain controller in the child domain, and configure it as a global catalog server.
Answer: B

Microsoft   70-294認定資格   70-294   70-294認定試験   70-294認定資格   70-294

NO.12 You have a single Active Directory directory service domain. There is a branch office that connects to
the main office through a low-bandwidth WAN link.
The first domain controller is named DC1 and is located in the main office. The branch office has a single
server named Server1. Server1 runs Windows Server 2003.
You are preparing to install Active Directory on Server1. You back up the system state of DC1, and you
send the backup to the administrator at the branch office.
You need to make Server1 an additional domain controller in your domain, while minimizing the
bandwidth usage between the two offices.
What should you do?
A. Restore the system state data from DC1 to an alternate location on Server1. Run the dcpromo
command with the /adv parameter, and select the From these restored backup files option.
B. Restore the system state data from DC1 to the original location on Server1. Run the dcpromo
command with the /adv parameter, and select the From these restored backup files option.
C. Create a new Active Directory site. Create an unattended installation file with the
CriticalReplicationOnly parameter. Run the dcpromo command with the /answer parameter.
D. Create a new Active Directory site. Create an unattended installation file with the SiteName parameter
to place Server1 into the new site. Run the dcpromo command with the /answer parameter.
Answer: A

Microsoft   70-294   70-294

NO.13 Your company has a Windows Server 2003 environment with a single Active Directory directory service
forest. The forest has multiple domains and two sites named Site1 and Site2. Site1 has six domain
controllers. Two of the domain controllers are global catalog servers. Site2 has three domain controllers.
The WAN link between Site1 and Site2 is slow.
You are preparing the environment for an Active Directory application that requires universal group
membership to make authorization decisions. Application servers will be located in Site1 and Site2.
You need to prepare the Active Directory environment for the introduction of the Active Directory
application.
What should you do?
A. Increase the number of domain controllers in Site2 to four.
B. Enable universal group membership caching in Site1.
C. Add additional global catalog servers to Site1.
D. Configure at least one of the domain controllers in Site2 to be a global catalog server.
Answer: D

Microsoft認定証   70-294   70-294   70-294問題集

NO.14 Your company has a main office and a single branch office. The two offices are connected through a
WAN link. You have Active Directory directory service site objects for each office. Domain controllers are
associated with the appropriate site objects.
Users in the main office are currently authenticated by domain controllers in the branch office.
You need to ensure that users in the main office are authenticated by the domain controllers in the main
office.
What should you do?
A. Clear the Bridge all site links option.
B. Configure a preferred bridgehead server for the site for the main office.
C. Associate the subnets for the main office with the site for the main office.
D. Associate the subnets for the branch office with the site for the branch office.
Answer: C

Microsoft   70-294参考書   70-294   70-294参考書

NO.15 Your company has a single Active Directory directory service domain with three domain controllers.
You need to move domain-wide FSMO roles to a different domain controller.
Which tool should you use?
A. Active Directory Domains and Trusts snap-in
B. Active Directory Sites and Services snap-in
C. Active Directory Users and Computers snap-in
D. Active Directory Schema snap-in
Answer: C

Microsoft過去問   70-294練習問題   70-294   70-294過去問

NO.16 Your company s Windows Server 2003 environment consists of a single Active Directory directory
service forest. The forest has multiple domains and three sites named Site1, Site2, and Site3. Site1 is the
main office and has four domain controllers. Two of the domain controllers are global catalog servers.
Site2 is a branch office with two domain controllers. Site3 is a branch office with a slow and unreliable
WAN link and two domain controllers.
You need to improve user logon performance for users in Site2 and Site3.
Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)
A. Enable change notification between Site1 and Site2.
B. Enable change notification between Site1 and Site3.
C. Implement universal group membership caching in Site2.
D. Implement universal group membership caching in Site3.
Answer: CD

Microsoft   70-294練習問題   70-294過去問   70-294練習問題

NO.17 Your company has an Active Directory directory service forest with a forest root domain and a child
domain. You have two Active Directory sites named Site1 and Site2. The two sites represent physical
locations that are connected by a WAN link.
All domain controllers are located in Site2. All users log on to the child domain. Several users in Site1 use
computers that run Windows NT 4.0 operating systems.
You configure a new domain controller for each domain, and you place the new domain controllers in
Site1.
You need to ensure that all users in Site1 can change their passwords in the event of a WAN link failure.
What should you do?
A. Transfer the root domain PDC Emulator role to a domain controller in Site1.
B. Transfer the child domain PDC Emulator role to a domain controller in Site1.
C. Transfer the root domain Infrastructure Master role to a domain controller in Site1.
D. Transfer the child domain Infrastructure Master role to a domain controller in Site1.
Answer: B

Microsoft   70-294   70-294認定試験   70-294

NO.18 Your company has a single Active Directory directory service forest with four domains. The domains
are named contoso.com, corp.contoso.com, fabrikam.com, and corp.fabrikam.com.
Users in the corp.contoso.com domain frequently access resources that are located in the
corp.fabrikam.com domain.
You need to improve user logon times from the corp.contoso.com domain to the corp.fabrikam.com
domain.
What should you do?
A. Enable universal group caching in sites where corp.contoso.com domain controllers are located.
B. Enable universal group caching in sites where corp.fabrikam.com domain controllers are located.
C. Create a shortcut trust from the corp.fabrikam.com domain to the corp.contoso.com domain.
D. Create a shortcut trust from the corp.contoso.com domain to the corp.fabrikam.com domain.
Answer: C

Microsoft練習問題   70-294問題集   70-294   70-294

NO.19 Your company has a single Active Directory directory service forest named contoso.com. A partner
organization has a forest named fabrikam.com. Both forests are set to the Windows 2000 forest functional
level. Domains named contoso.com and fabrikam.com are set to Windows 2000 Native Mode.
You plan to create a forest trust relationship between contoso.com and fabrikam.com.
You need to be able to configure selective authentication for the trust relationship.
What should you do?
A. Raise the forest functional level on contoso.com and fabrikam.com to Windows Server 2003.
B. Raise the domain functional level on contoso.com and fabrikam.com to Windows Server 2003.
C. Raise the domain functional level and the forest functional level on contoso.com to Windows Server
2003.
D. Raise the domain functional level and the forest functional level on fabrikam.com to Windows Server
2003.
Answer: A

Microsoft認定資格   70-294認定資格   70-294過去問   70-294   70-294問題集

NO.20 You have a single Active Directory directory service domain. Your domain controllers are configured as
shown in the following table.
Domain
controller
Site FSMO role or roles
Global catalog
server
DC1 Site1
Schema Master
Domain Naming Master
Yes
DC2 Site2 ? Yes
DC3 Site3 Infrastructure Master Yes
DC4 Site4 PDC Emulator No
File and print services are on servers in Site1. Microsoft Exchange Server is installed on servers in Site2.
The HR and user provisioning applications will be placed on servers in Site3.
You are planning placement of the RID Master FSMO role.
You need to ensure proper functionality of these applications within their sites during an extended WAN
outage.
On which domain controller should you place the RID Master role?
A. DC1
B. DC2
C. DC3
D. DC4
Answer: C

Microsoft   70-294   70-294認証試験   70-294問題集

IT認定試験の中でどんな試験を受けても、IT-Passports.comの70-294試験参考資料はあなたに大きなヘルプを与えることができます。それは IT-Passports.comの70-294問題集には実際の試験に出題される可能性がある問題をすべて含んでいて、しかもあなたをよりよく問題を理解させるように詳しい解析を与えますから。真剣にIT-Passports.comのMicrosoft 70-294問題集を勉強する限り、受験したい試験に楽に合格することができるということです。