70-640,全稱Windows Server 2008 Active Directory. Configuring,考題由205題增加到209題,考試版本不變。
考試目標:
妳了解微軟最新的操作系統Windows Server 2008嗎?面對龐大的企業網絡,如何劃分子網、如何進行IP地址分配?DHCP動態分配IP地址幫助我們提高工作效率,妳知道如何提高DHCP的可用性嗎?DNS是如何實現名稱到IP地址的解析?擔心中病毒的計算機接入企業網絡時,如何避免網絡安全隱患?如何配置重要服務器的安全策略?通過培訓妳將豁然開朗,原來工作可以如此輕松!
適用對象:
Windows網絡系統管理員,系統工程師
1. Your network contains an Active Directory domain.
You have a server named Server1 that runs Windows Server 2008 R2. Server1 is an enterprise root certification authority (CA). You have a client computer named Computer1 that runs Windows 7. You enable automatic certificate enrollment for all client computers that run Windows 7. You need to verify that the Windows 7 client computers can automatically enroll for certificates.
Which command should you run on Computer1?
A. certreq.exe retrieve
B. certreq.exe submit
C. certutil.exe getkey
D. certutil.exe pulse
Answer: D
2. Your network contains two Active Directory forests named contoso.com and adatum.com. The functional level of both forests is Windows Server 2008 R2. Each forest contains one domain. Active Directory Certificate Services (AD CS) is configured in the contoso.com forest to allow users from both forests to automatically enroll user certificates. You need to ensure that all users in the adatum.com forest have a user certificate from the contoso.com
certification authority (CA). What should you configure in the adatum.com domain?
A. From the Default Domain Controllers Policy, modify the Enterprise Trust settings.
B. From the Default Domain Controllers Policy, modify the Trusted Publishers settings.
C. From the Default Domain Policy, modify the Certificate Enrollment policy.
D. From the Default Domain Policy, modify the Trusted Root Certification Authority settings.
Answer: C