70-294 Exam
Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 AD
- Exam Number/Code : 70-294
- Exam Name : Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 AD
- Questions and Answers : 225 Q&As
- Update Time: 2014-03-27
-
Price:
$ 119.00$ 79.00 -
70-294 Hard Copy (PDF)
-
70-294 Test Engine
Free 70-294 Demo Download
Test4pass offers free demo for MCSE 2003 Security 70-294 exam (Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 AD). You can check out the interface, question quality and usability of our practice exams before you decide to buy it. We are the only one site can offer demo for almost all products.
Exam Description
It is well known that 70-294 exam test is the hot exam of Microsoft certification. Test4pass offer you all the Q&A of the 70-294 real test . It is the examination of the perfect combination and it will help you pass 70-294 exam at the first time!
Why choose Test4pass 70-294 braindumps
Quality and Value for the 70-294 Exam
100% Guarantee to Pass Your 70-294 Exam
Downloadable, Interactive 70-294 Testing engines
Verified Answers Researched by Industry Experts
Drag and Drop questions as experienced in the Actual Exams
Practice Test Questions accompanied by exhibits
Our Practice Test Questions are backed by our 100% MONEY BACK GUARANTEE.
Test4pass 70-294 Exam Features
Quality and Value for the 70-294 Exam
Test4pass Practice Exams for Microsoft 70-294 are written to the highest standards of technical accuracy, using only certified subject matter experts and published authors for development.
100% Guarantee to Pass Your 70-294 Exam
If you prepare for the exam using our Test4pass testing engine, we guarantee your success in the first attempt. If you do not pass the MCSE 2003 Security 70-294 exam (ProCurve Secure WAN) on your first attempt we will give you a FULL REFUND of your purchasing fee AND send you another same value product for free.
Microsoft 70-294 Downloadable, Printable Exams (in PDF format)
Our Exam 70-294 Preparation Material provides you everything you will need to take your 70-294 Exam. The 70-294 Exam details are researched and produced by Professional Certification Experts who are constantly using industry experience to produce precise, and logical. You may get questions from different web sites or books, but logic is the key. Our Product will help you not only pass in the first try, but also save your valuable time.
70-294 Downloadable, Interactive Testing engines
We are all well aware that a major problem in the IT industry is that there is a lack of quality study materials. Our Exam Preparation Material provides you everything you will need to take a certification examination. Like actual certification exams, our Practice Tests are in multiple-choice (MCQs) Our Microsoft 70-294 Exam will provide you with free 70-294 dumps questions with verified answers that reflect the actual exam. These questions and answers provide you with the experience of taking the actual test. High quality and Value for the 70-294 Exam:100% Guarantee to Pass Your MCSE 2003 Security exam and get your MCSE 2003 Security Certification.
Hot KeyWords On 70-294 test
We collect some hot keywords about this exam:
Test4pass , Pass 4 Sure , Test in Side ,Pass Guide ,Test King 70-294 exam | 70-294 pdf exam | 70-294 braindumps | 70-294 study guides | 70-294 trainning materials | 70-294 simulations | 70-294 testing engine | 70-294 vce | 70-294 torrent | 70-294 dumps | free download 70-294 | 70-294 practice exam | 70-294 preparation files | 70-294 questions | 70-294 answers.
How to pass your 70-294 exam
You can search on Search Engine and Find Best IT Certification site: Test4pass.com - Find the Method to succeed 70-294 test,The safer.easier way to get MCSE 2003 Security Certification MCSE 2003 Messaging Certification MCSE 2003 Certification MCSE Certification .
��
Exam : Microsoft 70-294
Title : Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 AD Infrastructure
1. You are a network administrator for your company. The relevant portion of your network configuration is shown in the work area.
Your company has offices in Toronto and New York. The Toronto office has 500 employees, and the New York office has 150 employees. Employees in both offices use an application that frequently reads configuration data in the global catalog.
You install Windows Server 2003 on all domain controllers. You create a single Windows Server 2003 Active Directory domain. The functional level of the forest is Windows Server 2003. You configure servers as shown in the following table.
Server name
Configuration
Server1
Domain controller, domain naming master, schema master
Server2
Domain controller, PDC emulator master, relative ID (RID) master, infrastructure master
Server3
Member server, file and print server
Server4
Member server, Web server
Server5
Domain controller
Server6
Member server, file and print server
You need to plan the placement of global catalog servers for your company. You need to ensure that the application performs well during times of peak activity. You need to ensure that the application continues to function in the event of multiple global catalog server failures.
Where should you place the global catalog server or servers?
To answer, select the appropriate computer or computers in the work area.
Answer:
2. You are the network administrator for your company. The network consists of a single Active Directory forest that contains multiple domains. The functional level of the forest is Windows Server 2003.
The forest includes two Active Directory sites named Site1 and Site2. Site1 contains two domain controllers that are global catalog servers named Server1 and Server2. Site2 contains two domain controllers that are not global catalog servers named Server3 and Server4. The two sites are connected by a WAN connection. Users in Site2 report that logon times are unacceptably long.
You need to improve logon times for the users in Site2 while minimizing replication traffic on the WAN connection.
How should you configure the network?
To answer, drag the appropriate configuration option or options to the correct location or locations in the work area.
Drag configuration hereConfiguration Options Global catalog server Universal group membership caching
Answer:
3. You are a network administrator for your company. The network consists of a single Active Directory forest that contains one domain. The company has its main office and one branch office in San Francisco.
The company has additional branch offices in Chicago, New York, and Toronto.
Administrators at the main office are responsible for managing all objects in the domain. Administrators at each branch office are responsible for managing user and computer objects for employees who work in the same branch office as the administrator. Administrators for the San Francisco branch office are also responsible for managing user and computer objects for employees who work in the main office. These users are managed as a single unit. You want administrators to be authorized to make changes only to the objects for which they are responsible.
You need to plan an organizational unit (OU) structure that allows the delegation of required permissions. You want to achieve this goal by using the minimum amount of administrative effort.
Which OU structure should you use?
A.
B.
C.
D.
Answer: A
4. You are the network administrator for your company. The network consists of a single Active Directory forest that contains one domain. The functional level of the forest is Windows 2000, and the functional level of the domain is Windows 2000 mixed. The domain contains four domain controllers named DC1, DC2, DC3, and DC4. There are two sites in the forest. DC1 and DC2 are in one site. DC3 and DC4 are in the other site. DC1 fails. You need to wait until the following week to restore DC1.
While connected to DC3, you perform a bulk import of user accounts and receive an error message stating that a number of the user accounts could not be created. You need to ensure that the user accounts can be created.
What should you do?
A. Seize the PDC emulator role to DC3.
B. Seize the relative ID (RID) master role to DC3.
C. Create a replication object to connect DC3 to DC2.
D. Raise the functional level of the domain and the functional level of the forest to Windows Server 2003.
Answer: B
5. You are the network administrator for Blue Yonder Airlines. The company has offices in Toronto, New York, and Chicago. The network connections are shown in the exhibit. (Click the Exhibit button.)
The network consists of two Active Directory domains. User objects for users in the Toronto office and the New York office are stored in the blueyonderairlines.com domain. User objects for users in the Chicago office are stored in the production.blueyonderairlines.com domain. Active Directory is configured as shown in the following table.
Location
Number of users
Number of domain controllers
Number of global catalog servers
Toronto
650
4
2
New York
15
1
0
Chicago
500
3
2
Users in the New York office frequently report that they cannot log on to the network, or that logging on takes a very long time. You notice increased global catalog queries to servers in the Toronto office during peak logon times.
You need to improve logon performance for users in the New York office without increasing WAN traffic that is due to replication.
What should you do?
A. Configure the domain controller in the New York office as a global catalog server.
B. Configure Active Directory to cache universal group memberships for the Toronto office.
C. Install an additional domain controller in the New York office.
D. Configure Active Directory to cache universal group memberships for the New York office.
Answer: D
6. You are the network administrator for your company. The network consists of a single Active Directory domain. The functional level of the domain is Windows Server 2003.
You configure two Active Directory sites named Site1 and Site2. Site1 contains all of the operations masters and two global catalog servers. Site2 contains a domain controller named Server1. You create a site link named SiteLink1 that includes Site1 and Site2.
You need to provide global catalog services locally in Site2.
Which Active Directory component should you configure?
To answer, select the appropriate component in the work area.
Answer:
7. You are a network administrator for a company that has a main office and five branch offices. The network consists of six Active Directory domains. All servers run Windows Server 200 Each office is configured as a single domain. Each office is also configured as an Active Directory site.
Your company uses an application server that queries user information from the global catalog. You install application servers in the main office and in three branch offices. The network is configured as shown in the exhibit. (Click the Exhibit button.)
You monitor the WAN connections between the main office and each branch office and discover that the utilization increased from 70 percent to 90 percent. Users report slow response times when accessing information on the application server.
You need to place global catalog servers in offices where they will improve the response times for the application servers. You need to achieve this goal with a minimum amount of increase in WAN traffic.
In which office or offices should you place a new global catalog server or servers? (Choose all that apply.)
A. Bonn
B. Rome
C. New York
D. San Francisco
E. Chicago
Answer: D AND C AND B
8. You are the network administrator for Fabrikam, Inc. Your network consists of a single Active Directory forest that contains one domain named fabrikam.com. The functional level of the forest is Windows Server 2003.
Fabrikam, Inc., acquires a company named Contoso, Ltd. The Contoso, Ltd., network consists of a single Active Directory forest that contains a root domain named contoso.com and a child domain named usa.contoso.com. The functional level of the forest is Windows 2000. The functional level of the usa.contoso.com domain is Windows 2000 native.
A business decision by the company requires the usa.contoso.com domain to be removed.
You need to move all user accounts from the usa.contoso.com domain to the fabrikam.com domain by using the Active Directory Migration Tool. You need to accomplish this task without changing the logon rights and permissions for all other users. You need to ensure that users in usa.contoso.com can log on to fabrikam.com by using their current user names and passwords.
What should you do?
A. Create a two-way Windows Server 2003 external trust relationship between the fabrikam.com domain and the contoso.com domain.
B. Create a one-way Windows Server 2003 external trust relationship in which the fabrikam.com domain trusts the contoso.com domain.
C. Create a temporary two-way external trust relationship between the fabrikam.com domain and the usa.contoso.com domain.
D. Create a temporary one-way external trust relationship in which the usa.contoso.com domain trusts the fabrikam.com domain.
Answer: C
9. You are the network administrator for Contoso, Ltd. The network consists of a single Active Directory forest, as shown in the exhibit. (Click the Exhibit button.)
A domain controller named dc1.corp.contoso.com runs Windows 2000 Server. All other domain controllers run Windows Server 2003.
Contoso, Ltd., is engaged in a joint venture with Litware, Inc. The network at Litware, Inc., consists of a single Active Directory forest named litwareinc.com that contains one domain. The functional level of the litwareinc.com forest is Windows Server 2003.
You need to ensure that the users at Contoso, Ltd., can log on to the litwareinc.com forest. You upgrade dc1.corp.contoso.com to Windows Server 2003.
Which two additional courses of action should you take? (Each correct answer presents part of the solution. Choose two.)
A. Raise the functional level of the corp.contoso.com domain and the east.corp.contoso.com domain to Windows 2000 native. Raise the functional level of the contoso.com forest to Windows Server 2003.
B. Raise the functional level of the corp.contoso.com domain to Windows 2000 native. Raise the functional level of the east.corp.contoso.com domain to Windows Server 2003. Raise the functional level of the west.contoso.com domain to Windows Server 2003.
C. Create a one-way forest trust relationship in which the contoso.com forest trusts the litwareinc.com forest.
D. Create a one-way forest trust relationship in which the litwareinc.com forest trusts the contoso.com forest.
Answer: D AND A
10. You are a network administrator for your company. The network consists of a single Active Directory forest that contains one root domain and multiple child domains. The functional level of all child domains is Windows Server 2003. The functional level of the root domain is Windows 2000 native.
You configure a Windows Server 2003 computer named Server1 to be a domain controller for an existing child domain. Server1 is located at a new branch office, and you connect Server1 to a central data center by a persistent VPN connection over a DSL line. Server1 has a single replication connection with a bridgehead domain controller in the central data center.
You configure DNS on Server1 and create secondary forward lookup zones for each domain in the forest.
You need to minimize the amount of traffic over the VPN connection caused by logon activities.
What are two possible ways to achieve this goal? (Each correct answer presents a complete solution. Choose two.)
A. Configure the DNS zones to be Active Directory-integrated zones.
B. Configure Server1 to be the PDC emulator for the domain.
C. Configure Server1 to be a global catalog server.
D. Configure universal group membership caching on Server1.
Answer: C AND D
11. You are the network administrator for Alpine Ski House. The network consists of a single Active Directory forest that contains five domains. The functional level of the forest is Windows 2000. You have not configured any universal groups in the forest.
One domain is a child domain named child1.alpineskihouse.com that contains two domain controllers and 50 client computers. The functional level of the domain is Windows Server 2003.
The network includes an Active Directory site named Site1 that contains two domain controllers. Site1 represents a remote clinic, and the location changes every few months. All of the computers in child1.alpineskihouse.com are located in the remote clinic. The single WAN connection that connects the remote clinic to the main network is often saturated or unavailable. Site1 does not include any global catalog servers.
You create several new user accounts on the domain controllers located in Site1. You need to ensure that users in the remote clinic can always quickly and successfully log on to the domain.
What should you do?
A. Enable universal group membership caching in Site1.
B. Add the HKEY_LOCAL_MACHINESystemCurrentControlSetControlLsaIgnoreGCFailures key to the registry on both domain controllers in Site1.
C. Add the HKEY_LOCAL_MACHINESystemCurrentControlSetControlLsaIgnoreGCFailures key to the registry on all global catalog servers in the forest.
D. Raise the functional level of the forest to Windows Server 2003.
Answer: B
12. You are the network administrator for Contoso Pharmaceuticals. Your network consists of a single Active Directory forest that contains three domains. The forest root domain is named contoso.com. The domain contains two child domains named usa.contoso.com and europe.contoso.com. The functional level of the forest is Windows Server 2003.
Each domain contains two Windows Server 2003 domain controllers named DC1 and DC2. DC1 in the contoso.com domain performs the following two operations master roles: schema master and domain naming master. DC1 in each child domain performs the following three operations master roles: PDC emulator master, relative ID (RID) master, and infrastructure master. DC1 in each domain is also a global catalog server.
The user account for Nancy Buchanan in the europe.contoso.com domain is a member of the Medicine Students security group. Because of a name change, the domain administrator of europe.contoso.com changes the Last name field of Nancy's user account from Buchanan to Anderson.
The domain administrator of usa.contoso.com discovers that the user account for Nancy is still listed as Nancy Buchanan.
You need to ensure that the user account for Nancy Anderson is correctly listed in the Medicine Students group.
What should you do?
A. Transfer the PDC emulator master role from DC1 to DC2 in each domain.
B. Transfer the infrastructure master role from DC1 to DC2 in each domain.
C. Transfer the RID master role from DC1 to DC2 in each domain.
D. Transfer the schema master role from DC1 to DC2 in the contoso.com domain.
Answer: B
13. You are the network administrator for your company. The network consists of a single Active Directory domain. The functional level of the domain is Windows Server 2003. The domain contains three Active Directory sites named Site1, Site2, and Site3. The sites are connected by site links as shown in the work area.
SiteLink1 and SiteLink2 include redundant, high-speed WAN connections.
Each site has one subnet associated with it. The number of computers in each site and the operating system that the computers are running are indicated in the following table.
Operating system
Site1
Site2
Site3
Windows 98
50
30
550
Windows NT Workstation 4.0
50
20
550
Windows 2000 Professional
0
500
100
Windows XP Professional
100
0
0
Windows Server 2003
10
20
15
Site1 contains a Windows Server 2003 domain controller named Server1 that is the relative ID (RID) master for the domain. Site2 contains two Windows Server 2003 domain controllers named Server2 and Server3. Server2 is the infrastructure master for the domain. Site3 contains a Windows Server 2003 domain controller named Server4.
You need to decide where to place the PDC emulator role holder. You want to optimize the overall response time for users in all sites.
Where should you place the PDC emulator role?
To answer, select the appropriate domain controller or domain controllers in the work area.
Answer:
14. You are the network administrator for Adventure Works. The network consists of a single Active Directory forest that contains a forest root domain named adventure-works.com and a child domain named child1.adventure-works.com. The functional level of the forest is Windows Server 2003.
The company uses universal groups to prevent temporary employees from accessing confidential information on computers in the forest.
The child1.adventure-works.com domain contains a Windows 2000 Server computer named Server1. Server1 runs an application that makes frequent LDAP queries to the global catalog. Server1 is located on a subnet associated with an Active Directory site named Site2 that has no global catalog servers. Site2 is connected to another site by a WAN connection.
You need to enable the application on Server1 to run at high performance levels and to continue operating if a WAN connection fails. You also need to minimize traffic over the WAN connection.
What should you do?
A. Enable universal group membership caching in Site2.
B. Configure at least one global catalog server in Site2.
C. Add the HKEY_LOCAL_MACHINESystemCurrentControlSetControlLsaIgnoreGCFailures key to the registry on all domain controllers in Site2.
D. Remove Server1 from the child1.adventure-works.com domain and add it to a workgroup.
Answer: B