Free MCSE Braindumps .com provides the best resource to prepare for the actual certification exams like 070-290, 070-293, 070-210 and more.
Welcome to Free MCSE Braindumps.com
[Home] [Free MCSE dumps] [MCSE certification Deatils] [MCSE study guides] [MCSE Sample Tests] [Microsoft Books] [Certification News] [Submit Dumps] [Web Resources] [Links]
Pablo Software Solutions
70-217 Implementing and Administering a Microsoft Windows 2000 Directory Services Infrastructure


Comments: webmaster@freemcsebraindumps.com
Copyright 2000-2005, Free
MCSE Brain dumps .com
The material on this web site is not sponsored by, endorsed by or affiliated with
Microsoft or the MCSE certification or with any vendor such as Cisco, Oracle, Sun etc.
They own trademarks to their certifications. We use them to display information as a fair use
of the names.

QUESTION 1:
You are the administrator of Alecnet .sc om's Windows 2000 network. The network
contains two Active Directory sites:MunichandSingapore. The network also consists of two domains:
fabrikam.com and asia.fabrikam.com. The network is configured as shown in the exhibit.
Users from theSingaporeoffice often travel to theMunichoffice with their portable computers. When
these users log on to the network fromMunich, their computers display the text "Applying your personal
settings" for a long time.
You want to ensure that users fromSingaporedo not experience these delays when they log on to the
network fromMunich.
What should you do?
A. Associate theMunichsubnet with theSingaporesite.
B. Create a trust relationship so that fabrikam.com trusts asia.fabrikam.com.
C. Install a domain controller for asia.fabrikam.com in theMunichsubnet.
D. Use the Active Directory Sites and Services snap-in to move DC3 to theMunichsite.
Answer: C
Explanation: When the users fromSingaporelog on atMunichtheir personal settings are downloaded from
Singapore. Due to the slow WAN link, this procedure causes long delays. By adding a domain controller
for asia.fabrikam.com in theMunichsubnet, these logins could be processed locally atMunichand the
logon delays would disappear.
Incorrect Answers:
A:A site should be a well-connected TCP/IP network.Munichis only connected toSingaporewith a slow WAN
link and should therefore not be included in theSingaporesite.
B:Fabrikam.com and asia.fabrikam.com are in the same domain tree and there already exists a two-way implicit
trust between the domains by default since this is a Windows 2000 network. There would be no need to create
any explicit trusts between the domains.
D:DC3 is physically placed in theSingaporesubnet. To logically move it toMunichsite would not increase
performance, on the contrary it would most likely increase traffic on the WAN link and performance would
decrease. Computers should only be added to the site to which their subnet belongs.
QUESTION 2:
You are installing a new Windows 2000 Server computer on your existing Windows NT network. You
run DCPromo.exe to promote the server to a Domain Controller in a domain named domain.local. You
receive the following error message: "The domain name specified is already in use on the network".


There are no other Windows 2000 domains on your network.
What should you do?
A. Place an entry in your DNS server host table for the domain.local domain name.
B. Place an entry in your WINS database for the domain.local domain name.
C. Change the domain name to domain.com.
D. Change the down level domain name to domain1.
Answer: D
Explanation: The default NetBIOS domain name is DOMAIN.The Windows NT domain is using this
domain name therefore we need to change the NetBIOS domain name during the DCPromo process.
QUESTION 3:
You are the enterprise administrator of a Windows 2000 domain named fabrikam.com. The domain
contains three Domain Controllers named DCA, DCB, and DCC. DCA does not hold any operations
master roles. You backed up the System state data of DCA two weeks ago.
Without warning, the DCA hard disk fails. You decide to replace DCA with a new computer. You install
a new Windows 2000 computer.
What should you do next?
A. Add the server to the domain.
Do an authoritative restore of the original backup of the originalDCASystemStatedata that you made two weeks
ago.
B. Add the server to the domain.
Use Windows Backup to create a backup of theDCBSystemStatedata, and restore this backup on the new DCA.
C. Use the Active Directory installation wizard to make the new computer a replica in the domain.
D. Use the Ntdsutil utility to copy the Active Directory database from DCB to the new DCA.
Answer: C
Explanation: When a Domain Controller that has no Operation Master roles fails, it can be restored to a
new computer by using the Active Directory installation wizard to make the new computer a replica in
the domain. No further action is required, as the Domain Controller had no Operation Master roles.
Incorrect Answers:
A:The original Domain Controller had no Operation Master roles therefore we do not need to perform any
restore from the previous backup. We could simply set the Domain Controller to be a replica in the domain.
B:We cannot restore system state data to different computer.
D:It is not necessary to manually copy the Active Directory database from another Domain Controller to the
new computer, as this will occur automatically during the installation of Active Directory.


QUESTION 4:
Your company's network consists of two divisions: Contoso Ltd, and Fabrikam Each division has
two domains. All domains are contained in the same forest.
Contoso Ltd. contains two domains: contoso.com andsales.contoso.com, Fabrikam contains two
domains: fabrikam.com andsales.fabrikam.com. Thesales.contoso.com domain and thesales
.fabrikam.com domain each contain an OU named Marketing.
Fabrikam, is changing its name to Litware, You need to create a user principle name (UPN) of
litware.com. Users in both Marketing OUs will use the UPN to be authenticated by Active Directory.
At which level in Active Directory should you create the UPN?
A. The Marketing OU insales.contoso.com and the Marketing OU insales.fabrikam.com.
B. The contoso.com domain tree and the fabrikam.com domain tree.
C. The root domain.
D. The forest.
Answer: B
Explanation: The UPN, which stands for User Principal Name, is "user friendly" and a UPN is composed
of a shorthand name for the user account and the DNS name of the tree where the user account object
resides. For example,user Firstname Lastname (substitutethe first and last names of an actual user) in
the microsoft.com tree might have a UPN of
FirstnameL@microsoft.com (using the full first name and
the first letter of the last name). Hence the UPN is made up of the complete domain name therefore
changes must be made at the top of the domain tree.
Reference:Users Can Log in Using User Name or User Principal Name (Q243280)
HOW TO: Add UPN Suffixes to aForest(Q243629)
Incorrect Answers:
A:The UPN is made up of the complete domain name therefore changes must be made at the top of the domain
tree and not at the OU level.
C:The root domain is the first domain created.It might not be the top of the Fabrikam tree. Therefore this is not
the best
Answer:
D:The UPN is made up of the complete domain name. It is therefore related to the domain tree and not the
forest.
QUESTION 5:
Your company's network consists of a single Windows 2000 domain named contoso.com. You are a
member of the Domain Admins group.
Contoso Ltd., wants to create a new division named Fabrikam The new division will consist of two
domains: fabrikam.com andsales.fabrikam.com. You need to create these two new domains. You need to
configure all three domains so that they can share resources by using the least amount of administrative
effort.


What should you do?
A. In the contoso.com domain tree, create a new child domain named fabrikam.com. Create a new child domain
for fabrikam.com namedsales.fabrikam.com
B. In the contoso.com domain tree, create a new child domain namedsales.fabrikam.com. Create a new parent
domain forsales.fabrikam.com named fabrikam.com
C. In the existing forest, create a new domain tree for fabrikam.com. Create a new child domain for
fabrikam.com namedsales.fabrikam.com
D. In a new forest, create a new domain tree for fabrikam.com. Create a new child domain for fabrikam.com
namedsales.fabrikam.com
Answer: C
Explanation: In this scenario we require a new tree so that the top-level domain can be called
fabrikam.com.Then we can create a child domain forsales.fabrikam.com.
Incorrect Answers:
A:In this scenario we require a new tree so that the top-level domain can be called fabrikam.com. We do not
require a new child domain. Furthermore, the new child domain name must be appended to the top-level
domain. Therefore we cannot create a new child domain named fabrikam.com.
B:In this scenario we require a new tree so that the top-level domain can be called fabrikam.com. We cannot
create a parent domain of an existing child domain. We can only create top-level domains.
D:In this scenario we require a new tree so that the top-level domain can be called fabrikam.com. This new tree
must be created in the same forest and not in a new forest.
QUESTION 6:
You are the enterprise administrator of a Windows 2000 domain. The domain has three Domain
Controllers named DC1, DC2, and DC3.
Because of changed hardware requirements, you want to replace the Domain Controller named DC1
with a newer computer named DC4. You want DC4 to be a Domain Controller in the domain. You no
longer want DC1 to function as a Domain Controller.
What should you do?
A. Install DC4 as a stand-alone server in a workgroup named WG. Restore aSystemStatedata backup of DC1 on
DC4. On DC1, Use the Active Directory Installation wizard to remove Active Directory from DC1.
B. Install DC4 as a stand-alone server in a workgroup named WG. Disconnect DC1 from the network. Rename
DC4 to DC1. On DC2, force replication of Active Directory to all its replication partners.
C. Install DC4 as a member server in the domain. On DC4, use the Active Directory installation wizard to
install
Active Directory on DC4. On DC1 use the Active Directory Installation wizard to remove Active Directory
from DC1.
D. Install DC4 as a member server in the domain. On DC1 use the Ntdsutil to copy the Active Directory files to
DC4. Use the Active Directory Installation wizard to remove Active Directory from DC1.


Answer: C
Explanation: To install a Domain Controller, we must first install the computer as member server.There
after we can run the Active Directory installation wizard to promote the server to a Domain Controller.
By running the Active Directory installation wizard on a Domain Controller we would be able to demote the
computer back to a member server.
Incorrect Answers:
A:The machine must be installed as a member server, not a stand-alone server, and then promoted to a Domain
Controller.
B:The machine must be installed as a member server, not a standalone server, and then promoted to a Domain
Controller.
D:You cannot promote DC4 to a Domain Controller by using Ntdsutil and copying the Active Directory files to
DC4. The Ntdsutil is used to physically move the DNS database. We must run the Active Directory installation
wizard on DC4 to promote it to a Domain Controller.
QUESTION 7:
Your company's network consists of two domains: contoso.com andsales.contoso.com. The contoso.com
domain contains three Domain Controllers and one member server. Thesales.contoso.com domain is a
new domain that contains one Domain Controller and one member server. You are a member of the
Domain Admins group insales.contoso.com.
You wantsales.contoso.com to contain two Domain Controllers. Which two actions can you take? (Each
correct answer presents a complete solution. Choose two)
A. Manually install a new server insales.contoso.com. During the installation process, install the server as a
Domain Controller.
B. Manually install a new member server insales.contoso.com. After it is installed, promote the server to a
Domain Controller.
C. Move the domain membership of the member server in contoso.com tosales.contoso.com by usingSystem
Propertiesin Control Panel.
D. Move the domain membership of the Domain Controller in contoso.com tosales.contoso.com by using
System Propertiesin Control Panel.
E. Run DCPromo.exe on the member server insales.contoso.com and provide credentials of a user in the
Domain
Admins group insales.contoso.com
F. Run DCPromo.exe on the member server in contoso.com and provide credentials of a user in the Domain
Admins group in contoso.com
Answer: B, E
Explanation:
B:To install a new Domain Controller we must first install a computer as a member server and then promote it


to a Domain Controller.To promote a member server to a Domain Controller, we need to run the Active
Directory installation wizard.
We can do this by clicking Start, Run and typing DCPROMO and following the instructions in the wizard to
install Active Directory.
E:We can also promote an existing member server to a Domain Controller at any time by running the Active
Directory installation wizard.
Incorrect Answers:
A:Manually installing a new server as a Domain Controller during the server installation process was used on
Windows NT 4.0 Server to install a Domain Controller. This process has changed in Windows 2000. We thus
cannot install Windows 2000 as a Domain Controller during the installation process Instead we must first install
a computer as a member server and then promote to a Domain Controller.
C:We cannot change the domain membership of a Domain Controller by using the control panel.We can use the
System control panel on a Windows 2000 client to change its domain membership but not to create a Domain
Controller.
D:We cannot change the domain membership of a Domain Controller by using the control panel.To change the
domain membership of a Domain Controller, we would have to demote it to a member server first and then
re-promote it to a Domain Controller in the new domain.
F:To run DCPromo.exe on a member server, you need to be an administrator of that domain, not the parent
domain.
QUESTION 8:
You are the administrator of a Windows 2000 domain. Your current Domain Controller's hard disk
drive is failing. You install a new server as a Domain Controller to replace the failing Domain Controller.
You ran DCPromo.exe on the failing Domain Controller in your domain to remove Active Directory.
While you are running DCPromo.exe, the hard disk drive fails. The server will not reboot. However, the
objects for the failed server are still appearing in Active Directory. You are using the Ntdsutil utility to
remove the objects.
You want to remove the old server from Active Directory. What option should you use?
A. metadatacleanup.
B. semanticdatabase analysis.
C. securityaccount management.
D. domainmanagement.
E. authoritativerestore.
Answer: A
Explanation:
Ntdsutil is a command-line tool that provides directory service management. It maintains the Active
Directorystore,manages and controls Flexible Single Master Operations masters, and purges metadata
left behind by abandoned Domain Controllers (which are removed from the network without being
uninstalled).
Incorrect Answers:


B:Semantic database analysis is used to for diagnostic purposes, not to remove objects in Active Directory.
C:Security account management is the process of managing user and group accounts. It is not used to manage
Active Directory or to remove objects in Active Directory.
D:Domain management forms part of the job functions of a network administrator. It is not an operating system
tool that can be used to remove objects in Active Directory.
E:An authoritative restore refers to the restoration of Active Directory. It is used when the restored version of
Active Directory must be replicated to other servers despite its datestamp which would indicate that the restored
version of Active Directory is older than the current version of Active Directory that is in use on the network.
QUESTION 9:
Your company's network consists of two Windows 2000 domains: contoso.com andsales.contoso.com.
Each domain contains one domain controller and one member server. You are a member of the
EnterpriseAdmins group.
You want each domain to contain two domain controllers. Which two actions should you take? (Each
correct answer presents part of the solution. Choose two.)
A. Manually install a new server insales.contoso.com by using the Windows 2000 CD-ROM.During this
process, install the server as a domain controller.
B. Manually install a new server in contoso.com by using the Windows 2000 CD-ROM.During this process,
install the server as a domain controller.
C. Manually install a new member server insales.contoso.com by a network installation pointThen, promote the
server to a domain controller.
D. Manually install a new member server in contoso.com by a network installation pointPromote the server to a
domain controller by using an unattended setup file to script the promotion process.
E. Install a new member server insales.contoso.com by using Remote Installation Services (RIS).Then, promote
the server to a domain controller.
F. Install a new member server in contoso.com by using Remote Installation Services (RIS).Promote the server
to a domain controller by using an unattended setup file to script the promotion process
Answer: C, D
Explanation: First we must install the servers as member servers. Then we upgrade them to domain
controllers. There are two separate steps which cannot be merged into one single step.
Note:To upgrade a member server to domain controller either use dcpromo.exe or the Configure Your Server
utilities.
Incorrect Answers:
A, B:It is not possible to configure a domain controller during the installation process.
E, F:It is possible to install a member server with RIS (see Q308508). This would require SP3 and a fix to SP3.
No installation of Service Packs is discussed in the scenario.RIS might also seem an unnecessary complicated
procedure to install only two servers.Note:It is possible to use a script to promote a member to a domain
controller (see Q224390, Q223757).
Reference:
Unable to Create Windows 2000 Server Image on RIS Server (Q308508)


How to Automate Windows 2000 Setup and Domain Controller Setup (Q224390)
Unattended Promotion and Demotion of Windows 2000 Domain Controllers (Q223757)
QUESTION 10:
You are the administrator of Alecnet s The network consists of a single domain. The company's
main office is located inSouth Africaand branch offices are located inAsiaandEurope. The offices are
connected by dedicated 256-Kbps lines. To minimize logon authentication traffic across the slow links,
you create an Active Directory site for each company office and configure site links between the sites.
Users in branch offices report that it takes a long time to log on to the domain. You monitor the network
and discover that all authentication traffic is still being sent to the domain controllers inSouth Africa.
You need to improve network performance. What should you do?
A. Schedule replication to occur more frequently between the sites.
B. Schedule replication to occur less frequently between the sites.
C. Create a subnet for each physical location, associate the subnets with theSouth Africasite, and move the
domain controller objects to theSouth Africasite.
D. Create a subnet for each physical location, associate each subnet with its site, and move each domain
controller object to its site.
Answer: D.
Explanation: You have created the sites and configured site links, but you haven't configured the sites.To
configure the site you need to create a subnet object for each physical location and associate each subnet
with its site.Then move each domain controller object to its site.
This will configure active directory so that authentication requests get sent to the 'local' domain
controller rather than going across the WAN links.
Incorrect Answers:
A:No replication will occur between the sites, because all domain controllers in the same (default) site.The
domain controller objects need to be moved to their respective sites.
B:No replication will occur between the sites, because all domain controllers in the same (default) site.The
domain controller objects need to be moved to their respective sites.
C:We don't want all the subnets to be in one site.They should be in their respective sites.
QUESTION 11:
You are the network administrator for Alecnet .s T he network consists of an Active Directory domain
named Alecnet .sc om. The domain includes Windows 2000 Server Computer, Windows 2000
Professional client and Windows NT 4.0 workstation client computers. All domain controllers run
Windows 2000
Server.
Alecnet hs a s a main office and a branch office. The branch office is connected to the main office
with a slow wan link. All of the Win NT 4.0 workstation client computers are located in the branch
office.
The following table shows the configuration of three Windows 2000 domain controllers.


Users in the branch office report that logon times are slow. You create a new Active Directory site named
Branch1site to coincide with the branch office. You rename the default site to main site to coincide with
the main office.
You need to move the domain controllers in to the correct sites and configure the appropriate domain as
global catalog servers to ensure the following criteria:
DNS queries do not go across theWanlink.
Users account can be created on the domain controllers in the main office even if theWanlink fails.
Users in each branch office can successfully log on to the domain even if theWanlinks fails.
What should you do?
Drag the appropriate domain controllers to the appropriate site. Drag the appropriate global catalog
answer to the appropriate domain controller global catalog configuration.
Answer:


Explanation:
At the main site, I would placeAlecnet Bs and Alecnet Cs there. With a global catalog server by
Alecnet Cs . An
infrastructure master role should never be placed on a global catalog server.
I would place Alecnet As in the Branch1 site. The question states that all of the WIN NT client computers
are located in the branch office. Therefore a PDC emulator is needed.The PDC emulator acts like a primary
domain controller to downlevel servers and clients. I would also place one global catalog server at the Branch
site.
The question states that you do not want DNS queries to go across WAN links.
This solution reinforces that. There will be one AD DNS configuration at each site.
QUESTION 12:
You are the network administrator for Alecnet ,s a company that has three offices. The offices are in
Boston,Chicago, andNew York. All three offices are connected by leased lines as shown in the exhibit.
Alecnet iss deploying a Windows Server 2000 forest. You create a single Active Directory domain.
You configure each office as a single site. You configure three domain controllers in NYSite. You create
a domain controller in each of the other sites. You create site links based on the network topology. Each
leased line is represented by a site link. Each site link connects only two sites. The cost and the schedule
for all site links is the same. The sites and site links are named as shown in the following table.
Site link name Linked site Linked site
NYBoston NYSite BosSite
NYChi NYSite ChiSite
ChiBoston ChiSite BosSite


Users report that network requests between BosSite and ChiSite are taking much longer than they used
to take. You discover that replication traffic is using an unacceptably large percentage of the bandwidth
between BosSite and ChiSite
You need to reduce replication traffic over the ChiBoston site link.
What should you do?
A. Create an SMTP-based connection object from a domain controller in NYSite to a domain controller in
BosSite.
B. Increase the cost of the ChiBoston site link.
C. Create a site link bridge that includes the NYBoston and NYChi site links.
D. Increase the replication interval for the NYBoston site link.
Answer: B
QUESTION 13:
You are the administrator of Alecnet .sc om's Windows 2000 network. The company has two offices
that are connected by a WAN link. Each office is configured as an Active Directory site. Both company
offices share an Active Directory application. During business hours, the application generates large
amounts of changes in Active Directory.
You need to reduce the amount of WAN bandwidth used by these changes during business hours. What
should you do?
A. Configure the intrasite replication topology generation to occur less frequently during business hours.
B. Enable slow link detection in the Default Domain Group Policy Object (GPO)
C. Enable slow link detection in the Default Domain Controllers Group Policy Object (GPO)
D. Configure intersite replication to occur less frequently during business hours.
Answer: D
Explanation: A site is comprised of one or more Internet Protocol (IP) subnets that are tied together by
high-speed and reliable connections. We can configure the replication schedule over site links.
Replication between sites is called intersite replication. Furthermore, by reducing the replication
frequency during business, we will reduce the competition for resources and network bandwidth.
Incorrect Answers:
A:Intrasite refers to replication within a site. This type of replication does not make use of the WAN
connection. Configuring replication within a site to occur less frequently will thus not reduce network traffic
across the WAN and so will not affect WAN bandwidth.Instead, we should configure intersite replication to
reduce the bandwidth being used by the WAN link.
B:Slow link detection is a mechanism used by Active Directory to determine the application of group policy.
This mechanism is not used to reduce the network traffic by reducing the frequency of replication.


C:Slow link detection is a mechanism used by Active Directory to determine the application of group policy.
This mechanism is not used to reduce the network traffic by reducing the frequency of replication.
QUESTION 14:
The Link betweenSydneyandTokyostops functioning. New users inTokyoreport that they cannot log on to
the domain. However, an administrator inTokyosuccessfully log on to the domain by using a Domain
Admin account. You need to ensure that new users can log on to the domain when the link between
SydneyandTokyois not functioning. Which role or roles should you assign to each domain controller?
Drag the appropriate roles to the correct servers in the work area. Use only roles that apply.ROLE
PDC EmulatorRID Master BlankInfrastructure MasterSchema MasterGlobal Catalog ServerPreferred
bridgehead Server
Sydney:
Tokyo:
Answer: Note!Unable to find required settings to fully answer the question.Answer provided in later
versions.
QUESTION 15:
You are the administrator of Alecnet .sc om's Windows 2000 network. The network consists of
four domains and five Active Directory sites. The network is configured as shown in the Exhibit.
Most company employees use portable computers. These employees report that they can browse the Web
from their own offices but not when they travel to other company offices.
You want to use Group Policy to maintain consistent Internet settings for company employees. What
should you do?


A. Create a low security zone for each domain.
B. Create a low security zone for each site.
C. Configure each domain to maintain its own Microsoft Internet Explorer proxy settings.
D. Configure each site to maintain its own Microsoft Internet Explorer proxy settings.
Answer: D
Explanation: A likely cause of the problem is different proxy server settings in each site. Each site has a
different name and IP address for the local Proxy server. We should therefore configure each site with its
own Microsoft Internet Explorer proxy settings.
Incorrect Answers
A, B:The browser problem is not to lack of configuration of the low security zone.
C:This proposed solution would very well in the in the Alecnet .sc om, newyork. Alecnet .sc om, and
in the arizona. Alecnet .sc om domains. However, in the marketing. Alecnet .sc om domain
theFloridaand theAlabamasite
would have different Microsoft Explorer proxy settings since their proxy servers have different names and IP
addresses.
QUESTION 16:
You are a member of theEnterpriseAdmins group inAlecnet 'ss Windows 2000 network. The
network consists of a single Active Directory site. The site contains one subnet, which has an IP address
range of
10.5.0.0 and a subnet mask of 255.255.255.0.
The company opens a new branch office and adds 300 client computers to the network. Users report that
network performance is slow.
You use a high-performance router to separate the network into two segments. Then, you add a domain
controller Alecnet Bs to the new segment named Segment CK2 . The network is now configured as
shown in the exhibit.
Users no longer report problems with network performance. However, they now report that changes in
Active Directory between the two segments take a long time to replicate.
You want directory replication between the two segments to take place every five minutes. What should
you do?
A. Create a new site and associate it with a new subnet that has an IP address range of 10.5.1.0 and a subnet


mask of 255.255.255.0.
B. Associate the existing site with a new subnet that has an IP address range of 10.5.1.0 and a subnet mask of
255.255.255.0.
C. Change the subnet mask for Segment CK1 from 255.255.255.0 to 255.255.254.0
D. Configure the router to pass broadcast packets between both segments.
Answer: B
Explanation: The second domain controller Alecnet Bs belongs to the default site. The replication
between Alecnet As and Alecnet Bs is therefore considered to be inter-site replication which only
occurs every 180 minutes by default. This is the reason for the slow changes in the Active Directory. To
enable intra-site replication we add the new subnet of Segment CK2 to the existing site. All changes in the
Active Directory would then be replicated between the Domain Controllers within 5 minutes of the
change.
Note:When a domain controller writes a change to its local copy of the Active Directory, a timer is started that
determines when the domain controller's intra-site replication partners should be notified of the change. By
default, this interval is 300 seconds (5 minutes).
Reference:
Microsoft Knowledge Base Article - Q232264,Replication Schedule for Intra-Site Replication Partners
Incorrect Answers
A:.If we create a second site we would only achieve inter-site replication. Inter-site replication should only
occur over slow WAN links, not in a LAN: Furthermore, the default replication interval for inter-site replication
is 180 minutes. However, the scenario requires a solution with scheduled replication every 5 minutes.
C:The subnet mask for segment is correct. There is no need to change it.
D:Routing broadcasts would decrease network performance. One of the advantages with routers is that they
stop broadcasts. Furthermore, replication does not take place through broadcasts.
QUESTION 17:
You are a member of theEnterpriseAdmins group in Alecnet .sc om's Windows 2000 network. The
network consists of a single Windows 2000 domain. The network is configured as shown in the exhibit:
For security reasons, you configure the routers so that Subnet 1 and Subnet 4 cannot directly
communicate. After configuring the routers, you notice directory replication errors on DC1 and DC4.
You need to resolve the errors. What should you do?
A. Configure DC2 and DC3 as global catalog servers.


B. Create a site link bridge that includes SiteAlecnet as n d Site Remote
C. Configure DC2 and DC3 as bridgehead servers.
D. Create one site link bridge for Site Alecnet asn d one sitelink bridgefor Site Remote.
Answer: C
Explanation: Bridgehead servers are the contact point for exchange of directory information between
sites. By selecting DC and DC3 as bridgehead servers all Active Directory replication traffic between the
Alecnet si t e and the Remote site will go between subnet 2 and subnet 3. There will be no directory
replication between Subnet 1 and subnet 4.
Reference:Windows Help, Using preferred bridgehead servers
Incorrect Answers
A:Global catalog servers would decrease replication traffic. However, replication traffic between subnet 1 and
subnet 4 would still be possible.
B, D:By creating a site link, you provide Active Directory with information about what connections are
available, which ones are preferred, and how much bandwidth is available. This is not useful in this scenario
however.
QUESTION 18:
You are the administrator of Alecnet s The network consists of a single domain. The company's
main office is located inSouth Africaand branch offices are located inAsiaandEurope. The offices are
connected by dedicated 256-Kbps lines. To minimize logon authentication traffic across the slow links,
you create an Active Directory site for each company office and configure site links between the sites.
Users in branch offices report that it takes a long time to log on to the domain. You monitor the network
and discover that all authentication traffic is still being sent to the domain controllers inSouth Africa.
You need to improve network performance. What should you do?
A. Schedule replication to occur more frequently between the sites.
B. Schedule replication to occur less frequently between the sites.
C. Create a subnet for each physical location, associate the subnets with theSouth Africasite, and move the
domain controller objects to theSouth Africasite.
D. Create a subnet for each physical location, associate each subnet with its site, and move each domain
controller object to its site.
Answer: D
Explanation: In this scenario no subnets have been associated with any sites. No objects have been added
to the subnets. Windows 2000 AD is therefore unable to distinguish between local and remote sources.
This results in slow performance.
The subnet of each location must be associated with the local site. The domain controllers must also be moved
to the appropriate local site:


Incorrect Answers
A, B:We must configure the sites, not the replication schedule.
C:If we associate all subnets with theSouth Africasite then Windows 2000 AD would view the entire network
as a single site. It would be impossible to distinguish between local and remote sources.
QUESTION 19:
You are the administrator of Alecnet .sc om's network. The company contains three office buildings.
You need to deploy Windows 2000 throughout the network.
Because of budget constraints, you can purchase only two domain controllers for implementation. You
deploy one Windows 2000 domain controller in Building 2 and one Windows 2000 domain controller in
Building 3. The network is configured as shown in the exhibit.
You create an Active Directory subnet for each building. You want to minimize WAN utilization and
ensure that all client computers have access to Windows 2000 directory services.
How should you arrange the Active Directory sites and subnets?
A. Create one site to contain all three buildings.Associate three subnets with the site.
B. Create one site for each building.Associate the subnet for each building with the site.
C. Create one site to contain Building 1 and Building 2, and associate the subnets for Building 1 and Building 2
with the site.Create one site for Building 3, and associate the subnet for Building 3 with the site.
D. Create one site to contain Building 2 and Building 3, and associate the subnets for Building 2 and Building 3
with the site.Create one site for Building 1, and associate the subnet for Building 1 with the site.
Answer: C
Explanation:
The subnets with domain controllers, Building 2 and Building 3, should have separate sites. The subnet of
Building 1 could very well be included in the same site as Building 2, since Building 1 doesn't have any
domain controllers.
Note:Sites are created to control Active Directory replication between Domain Controllers. Remote locations
with Domain Controllers should have separate sites.


Reference:Windows 2000 Server Documentation, When to establish separate sites
Incorrect Answers:
A:One site should be configured for each subnet containing a Domain controller.
B:It is not necessary to create a separate site for Building 1 since it doesn't include any domain controllers.
There is no replication traffic between Building 1 and the rest of the network.
D:We should create separate sites for Building 2 and Building 3.

QUESTION 20:
locations inNorth Americaand three locations inEurope. Your network includes six sites as shown in the
exhibit.
TheEngland,France, andItalysites are in the eur.blueskyairlines.com domain. The NorthWestUS,
CentralUS, and NorthEastUS sites are in the na.blueskyairlines.com domain. The root of the forest is
blueskyairlines.com.
The connection between the NorthEastUS site and theEnglandsite is unreliable. You want to configure
replication between the NorthEastUS site and theEnglandsite.
What should you do?
A. Create an SMTP site link between the NorthEastUS site and theEnglandsite.
B. Create an IP site link between the NorthEastUS site and theEnglandsite.
C. Create an SMTP site link bridge between the NorthEastUS site and theEnglandsite.
D. Create an IP site like bridge between the NorthEastUS site and theEnglandsite.
Answer: A
Explanation: Simple Mail Transfer Protocol (SMTP)is an Internet standard host-to-host mail transport
protocol that and operates over TCP port 25. When the network connection is interrupted, SMTP queues
network packets and attempts to send the packets later. SMTP is the best protocol to use across
unreliable network links.
Incorrect Answers:
B:IP site links should only be used on reliable connections, as it does not queue up network packets that were
not deliverable. Instead these packets are lost and thus replication will not be successful.
C: transport protocol: the site links are "bridget" . This means that all site links within the
links are "bridged". This means that all site links within the bridge can route replication traffic only within the
bridge. We thus do not require a site link bridge.
D: transport protocol: the site links are "bridget" . This means that all site links within the
links are "bridged". This means that all site links within the bridge can route replication traffic only within the
bridge. We thus do not require a site link bridge.
Go Back to the Braindumps Page
Go Back to the Braindumps Page