Free MCSE Braindumps .com provides the best resource to prepare for the actual certification exams like 070-290, 070-293, 070-210 and more.
Welcome to Free MCSE Braindumps.com
[Home] [Free MCSE dumps] [MCSE certification Deatils] [MCSE study guides] [MCSE Sample Tests] [Microsoft Books] [Certification News] [Submit Dumps] [Web Resources] [Links]
Pablo Software Solutions
70-294 Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure
1. You are the network administrator for Alecnet .com. You are implementing a new Windows Server
2003 network environment. You install one Active Directory forest root domain named cpandl.com. You
install the first domain controller named DC1. You configure DC1 as a DHCP server and as an Active
Directory-integrated DNS server with dynamic updates enabled. Later you install an additional domain
controller named DC2.
You cannot raise the functional level of the domain to Windows Server 2003. You discover that the
service locator (SRV) resource records of DC1 are not created in the cpandl.com zone on the DNS server.
You run the Dcdiag tool on DC1 and receive the output shown in the exhibit.

You need to make it possible to raise the functional level of the domain to Windows Server 2003.
What should you do?

A. Upgrade DC2 to a global catalog server.
B. Use the DHCP server locator utility to find out which DHCP servers are available in the cpandl.com zone.
C. Start the Net Logon service on DC1.
D. Restart the DNS Server service on DC1 to enable DNS clients to resolve host names by answering queries
and update requests.
Answer: C


2. You are the network administrator for Alecnet .com. The network consists of a single Active
Directory forest that contains five domains and 30 remote sites located in cities throughout the world.
There are a total of 40,000 users in the five domains. All remote sites are connected to the company
network by unreliable 56-Kbps WAN connections.
Each site contains at least one domain controller and one global catalog server. All domain controllers in
the forest run Windows Server 2003. The functional level of all the domains in the forest is Windows
2000 native.
You plan to deploy several Active Directory-enabled applications over the next six months. Each of these
applications will add attributes to the global catalog or modify existing attributes in the global catalog.
You need to make modifications to the Active Directory infrastructure in order to prepare for these
deployments. You plan to accomplish this task during off-peak hours. You need to ensure that you can
minimize any potential network disruption that would be caused by the deployment of these applications
in the future. You also need to ensure that the modifications do not disrupt user access to resources.
What should you do?

A. Decrease the tombstone lifetime attribute in the Active Directory Schema NIDS-Service object class.
B. Remove the global catalog role from the global catalog servers in each remote site.
C. Raise the functional level of the forest to Windows Server 2003.
D. Configure universal group membership caching in each remote site.
Answer: C

3. You are the network administrator for Acme. Acme consists of two subsidiaries namely Mimex and
Alecnet Ltd. The network contains two Active Directory forests. The functional level of each domain
is Windows 2000 native. All domain controllers run Windows 2000 Server. External relationships exist
between domains, as shown in the exhibit.
User accounts and resources are located in the child domains. All user principal names (UPNs) in each
forest comply with a standard company e-mail address.
Each domain controller functions as a DNS server. All DNS zones are Active Directory-integrated zones.
The Alecnet .com and mimex.com DNS zones have no root (".") zone. DNS servers in each forest root
DNS zone are configured with root hints to Internet root servers.
You upgrade each domain controller in both forests to Windows Server 2003. You raise the functional
level for each domain to Windows Server 2003. You plan to implement a smart-card authentication
strategy for the entire company.


You need to ensure that users are able to access resources in all domains in each forest and on the
Internet. You want to accomplish this task by using the minimum amount of administrative effort. You
also need to ensure that access to resources is not disrupted.
Which two courses of action should you take? (Each correct answer presents part of the solution. Choose
two)

A. Create a two-way external trust relationship between the two forest root domains.
Raise the functional level of the forest to Windows Server 2003.
B. Raise the functional level of the forest to Windows Server 2003.
Replace existing trust relationships with a two-way forest trust relationship between the two forest root
domains.
C. Create root hints between DNS servers in each child domain and DNS servers in the root domain for the
opposite forest.
D. Create conditional DNS forwarders between domain controllers in each root domain.
Answer: B, D


4. You are the network administrator for Acme Inc. Your network consists of a single Active Directory
forest that contains one domain named acme.com. The functional level of the forest is Windows Server
Acme, Inc. acquires a company named Alecnet . The Alecnet network consists of a single Active
Directory forest that contains a root domain named Alecnet .com and a child domain named
asia. Alecnet .com. The functional level of the forest is Windows 2000. The functional level of
the asia. Alecnet .com domain is Windows 2000 native.
A business decision by Alecnet requires that asia. Alecnet .com domain to be removed.
You need to move all user accounts from the asia. Alecnet .com domain to the acme.com domain by
using the Active Directory Migration Tool. You need to accomplish this task without changing the logon
rights and permissions for all other users. You need to ensure that users in asia. Alecnet .com can log on
to acme.com by using their current user names and passwords.
What should you do?

A. Create a two-way Windows Server 2003 external trust relationship between the acme.com domain and the
Alecnet .com domain.
B. Create a one-way Windows Server 2003 external trust relationship in which the acme.com domain trusts the
Alecnet .com domain.
C. Create a temporary two-way external trust relationship between the acme.com domain and the
asia. Alecnet .com domain.
D. Create a temporary one-way external trust relationship in which the asia. Alecnet .com domain trusts
the acme.com domain.
Answer: C

5. You are the network administrator of a company that consists of two subsidiaries named Alecnet and
Contoso, Ltd. The network consists of a single Active Directory forest that contains two domain trees, as
shown in the exhibit.

ome users are temporarily relocated from Hong Kong to New York. Their user accounts remain in the
asia.contoso.com domain, and they use their principal names (UPNs) to log on from the
namerica. Alecnet .com domain. The relocated users report that their authentication time is
extremely slow.
You need to improve their authentication time.
What should you do?


A. Create a universal security group in the asia.contoso.com domain and add the relocated users into the group.
Add the universal group to the domain local groups in the asia.contoso.com domain that have permission for the
object to which the users need access.
B. Create a universal security group in the namerica. Alecnet .com domain and add the relocated users into
the group.
Add the universal group to the domain local groups in the asia.contoso.com domain that have permission for the
objects to which the users need access.
C. Create a shortcut trust relationship in which the asia.contoso.com domain trusts the namerica. Alecnet
.com domain.
D. Create a shortcut trust relationship in which the namerica. Alecnet .com domain trusts the
asia.contoso.com domain.
Answer: D

6. You are the network administrator for
A. Datum Corporation. The company has a subsidiary named
Alecnet . The
A. Datum Corporation network consists of a single Active Directory forest. The forest
contains one domain named adatum.com. The functional level of the domain is Windows Server 2003.
The Alecnet network consists of a single Windows NT 4.0 domain named Alecnet .
A file server named Server1 is a member of the adatum.com domain. All users in both domains need to
save files on Server1 every day.
You need to allow users in the Alecnet domain to access files on Server1. You need to ensure that
the domain administrators of the Alecnet domain cannot grant users in the adatum.com domain
permissions on servers in the Alecnet domain.
What should you do?
A. Upgrade the Alecnet domain to Windows Server 2003 and make this domain the root domain of a
second tree in the existing forest.
B. Upgrade the Alecnet domain to Windows Server 2003 and make this domain the root domain of a
new forest. Create a two-way forest trust relationship.
C. Create a one-way external trust relationship in which the adatum.com domain trusts the Alecnet
domain. D. Create a one-way external trust relationship in which the Alecnet domain trusts the
adatum.com domain.
Answer: C

7. You are the network administrator for a company named Alecnet Holdings. The company consists
of two subsidiaries named Contoso, Ltd, and City Power & Light. The network contains two Active
Directory forests named contoso.com and cpand1.com. The functional level of each forest is Windows
Server 2003.
A two-way forest trust relationship exists between the forests.
You need to achieve the following goals:

1. Users in the contoso.com forest must be able to access all resources in the cpand1.com forest.
2. Users in the cpand1.com forest must be able to access only resources on a server named
HRApps.contoso.com.
You need to configure the forest trust relationship and the resources on HRApps.contoso.com to achieve
the goals.
Which three actions should you take? (Each correct answer presents part of the solution. Choose three)
A. On a domain controller in the contoso.com forest, configure the properties of the incoming forest trust
relationship to use selective authentication.
B. On a domain controller in the contoso.com forest, configure the properties of the incoming forest trust
relationship to use forest-wide authentication.
C. On a domain controller in the cpand1.com forest, configure the properties of the incoming forest trust
relationship to use selective authentication.
D. On a domain controller in the cpand1.com forest, configure the properties of the incoming forest trust
relationship to use forest-wide authentication.
E. Modify the discretionary access control list (DACLs) on HRApps.contoso.com to allow access to the Other
Organization security group.
F. Modify the discretionary access control lists (DACLs) on HRApps.contoso.com to deny access to This
Organization security group.
Answer: A, D, E

8. You are the network administrator for Alecnet .com. The company consists of two subsidiaries
named Alecnet ., and Fabrikam, Inc. The network consists of two Active Directory forests. All
servers run Windows Server 2003. The domain configuration is shown in the exhibit.
The North American department in the company is renamed to Northwind Traders. You rename the
NA. Alecnet .com domain to northwindtraders.com. You change the NetBIOS name for the domain
to northwindtraders. The northwindtraders.com domain is a second tree in the Alecnet .com forest.
After the domain is renamed, users in the northwindtraders.com domain report that they cannot access
any shared resourced in the fabrikam.com domain. In addition, users in the fabrikam.com domain report
that they cannot access shared resources in the norhwindtraders.com domain.
You need to re-enable the sharing of resources between the northwindtraders.com domain and the
fabrikam.com domain.
What should you do?

A. Change the NetBIOS name for the northwindtraders.com domain to NA.
B. Delete and re-create the two one-way trust relationships between the northwindtraders.com domain and the
fabrikam.com domain.
C. Configure conditional forwarding on the DNS server in the fabrikam.com domain to forward requests for the
northwindtraders.com domain to the DNS servers in the Alecnet .com domain.
D. Reset the computer account passwords on all of the domain controllers in the northwindtraders.com domain.
Answer: B

9. You are the network administrator at Acme Inc. The network consists of a single Active Directory forest
that contains a single domain named acme.com. The functional level of the forest is Windows Server
2003.
Acme purchase a company named Alecnet . The Alecnet network consists of one Windows NT 4.0
account domain and two Windows NT 4.0 resource domains, as shown in the exhibit.

All file resources are stored on file servers in the acme.com domain and in the Alecnet SOURCE1
domain.
You need to accomplish the following goals:

1. You need to minimize the number of trust relationships that must be maintained in the network
environment.
2. Users in each company must be able to access the file resources on the file servers in the other
company's domain.

Which two actions should you take? (Each correct answer presents part of the solution. Choose two)

A. Create a one-way external trust relationship in which the Alecnet SOURCE1 domain trusts the
acme.com domain.
B. Create a one-way external trust relationship in which the acme.com domain trusts the Alecnet SOURCE1
domain.
C. Create a one-way external trust relationship in which the acme.com domain trusts the
Alecnet ACCOUNT domain.
D. Create a one-way external trust relationship in which the Alecnet ACCOUNT domain trusts
the acme.com domain.
Answer: A, C

10. You are the network administrator for your company. The company consists of three subsidiaries named
Alecnet Ltd, Fabricam Inc and Adatum Corporation. The network consists of three Active Directory
forests that include external trust relationships, as shown in the exhibit.
The functional level of each forest is Windows 2000. The functional level of each domain is Windows 2000
native.
Alecnet requires users in each domain to be able to access resources in all domains across all forests
by using the minimum number of trust relationships.
You need to ensure that users don't have accounts in one of the other two forests. You need to accomplish
this goal by using the minimum amount of administrative effort. You upgrade every domain controller to
Windows Server 2003.
Which additional action or actions should you take? (Choose all that apply).


A. Raise the functional level of each forest to Windows Server 2003
B. Create shortcut relationship between each child domain.
C. Replace existing external trust relationship with two-way forest trust relationships.
D. Create a two-way forest trust relationship between Alecnet .com and fabricam.com.
Answer: A, C, D

11. You are the network administrator for Alecnet .com. The network consists of a single Active
Directory domain with six sites. These sites are located in six different cities. The site configuration is
shown in the exhibit.


The site links are configured as shown in the following table.

Site link Replication Replication
name schedule frequency
SiteLink-1-2 24 hours per day 1 hour
SiteLink-16:
00 P.M. to 6:00
3-4 A.M. 1 hour
SiteLink-210:
00 P.M. to 6:00
5-6 A.M. 2 hours

All user accounts for the entire company are created by network administrators in Alecnet 1. The
number of employees in the office at Alecnet 3 is growing rapidly. Several accounts for new
employees are created for users in Alecnet 3 every day. The new employees report that they cannot log
on to the domain on the same day that their accounts are created. They can log on to the domain
successfully the next day.
You need to ensure that the employees can log on to the domain on the same day that their accounts are
created. You also need to ensure that the replication traffic between the Alecnet 1 and Alecnet 3
is compressed.
What should you do?

A. Move the Active Directory domain controller objects from Alecnet 3 to Alecnet
1. B. Add the Active Directory subnet object for Alecnet 3 to Alecnet 1.
C. Reconfigure SiteLink-1-2 to include Alecnet 1, Alecnet 2, and
Alecnet 3. Remove Alecnet 3 from SiteLink-1-3-4.
D. Remove Alecnet 1 from SiteLink-1-3-4.
Answer: C

12. You are the network administrator for Alecnet .com. The network consists of a single Active
Directory domain named Alecnet .com with five sites.
You configure the five Active Directory sites in accordance with the requirements of the company's site
configuration design. The network and site configuration is shown in the exhibit.
The site configuration design also requires you to configure site link bridges. The design requires the site
links connecting Alecnet 1, Alecnet 2, and Alecnet 3 to be transitive and all other site links to
be nontransitive.
You need to configure site link bridges to comply with the site configuration design.
Which action or actions should you take? (Choose all that apply)


A. Disable automatic site link bridging in the IP object properties.
B. Create new site links between each of the Active Directory sites.
C. Remove each of the sites from the default site link.
D. Create a new site link bridge.
Add the site links connecting Alecnet 1, Alecnet 2, and Alecnet 3 to the site link
bridge. E. Create a new link bridge.
Add the site links connecting Alecnet 3, Alecnet 4, and Alecnet 5 to the site link bridge.
Answer: A, C, D.

13. You are the network administrator for Alecnet , a company that has three offices. The offices are in
Boston, Chicago, and New York. All three offices are connected by leased lines as shown in the exhibit.
Alecnet is deploying a Windows Server 2003 forest. You create a single Active Directory domain
named Alecnet .com. You configure each office as a single site. You configure three domain controllers
in NYSite. You create a domain controller in each of the other sites. You create site links based on the
network topology. Each leased line is represented by a site link. Each site link connects only two sites.
The cost and the schedule for all site links is the same. The sites and site links are named as shown in the
following table.

Site link Linked
name Linked site

site

NYBoston NYSite BosSite

NYChi NYSite ChiSite

ChiBoston ChiSite BosSite
Users report that network requests between BosSite and ChiSite are taking much longer than they used
to take. You discover that replication traffic is using an unacceptably large percentage of the bandwidth
between BosSite and ChiSite
You need to reduce replication traffic over the ChiBoston site link.
What should you do?


A. Create an SMTP-based connection object from a domain controller in NYSite to a domain controller in
BosSite.
B. Increase the cost of the ChiBoston site link.
C. Create a site link bridge that includes the NYBoston and NYChi site links.
D. Increase the replication interval for the NYBoston site link.
Answer: B

14. You are the network administrator for Alecnet .com. Alecnet has three offices. The network consists
of a single Active Directory domain named Alecnet .com with three sites. Each office is configured as a
separate site.
Alecnet opens a new branch office in Montreal that has 10 users. This office does not contain a
domain controller.
The Montreal Office has WAN connections to two of the existing offices. A router is installed at each of
the four offices to route network traffic across the WAN connections. The network after the addition of
the Montreal Office is shown in the exhibit.
You need to ensure that when the users in the Montreal office log on the domain during normal
operations, they will be authenticated by a domain controller in Alecnet Site2.
What are two possible ways to achieve this goal? (Each correct answer presents a complete solution.
Choose two)


A. Create a new IP subnet object that includes the subnet used in the Montreal Office.
Link the new subnet object to the Alecnet Site2 site object.
B. Create a new IP subnet object that includes the subnet used in the Montreal Office.
Link the new subnet object to the Alecnet Site3 site object.
C. Create an additional site for the Montreal Office.
Configure a site link to Alecnet Site3 with a cost of
300. Configure a site link to Alecnet Site2 with a cost
of 200. D. Create an additional site for the Montreal
Office. Configure a site link to Alecnet Site2 with a
cost of 300. Configure a site link to Alecnet Site3 with
a cost of 200.
E. Assign IP addresses to the client computers in the Montreal Office that are on the same IP subnet as the
network at Site2.
Answer: A, C

QUESTION 15:

You are the network administrator for Alecnet .com. The network consists of a single Active
Directory domain named Alecnet .com with two sites. Each site contains two domain controllers.
One domain controller in each site is a global catalog server.
You add a domain controller to each site. Each new domain controller has a faster processor than the
existing domain controllers.
Alecnet requires Active Directory replication to flow through the servers that have the most powerful
CPUs in each site.
You need to configure the intersite replication to comply with Alecnet 's requirement for Active
Directory replication.
What should you do?


A. Configure the new domain controllers as global catalog servers.
B. Configure the new domain controller in each site as a preferred bridgehead server for the IP transport.
C. Configure the new domain controller in each site as a preferred bridgehead server for the SMTP transport.
D. Configure an additional IP site link between the two sites.
Assign a lower site link cost to this site link than the site link cost for the original site link.
Answer: B

16. You are the network administrator for Alecnet .com. The network consists of a single Active
Directory domain with three sites named Alecnet 1, Alecnet 2, and Alecnet 3. The sites and site
links are configured to use Alecnet 2 to connect Alecnet 1 and Alecnet 3. Each site contains
three Windows Server 2003 domain controllers. A domain controller in each site is configured as a
preferred bridgehead server. All user and group accounts are created in Alecnet 1.
Several new users start work in Alecnet 2. When they attempt to log on to the network, the logon fails.
You confirm that the user accounts are created and are visible in Alecnet 1 and Alecnet 2. You
discover that the preferred IP bridgehead server in Alecnet 2 failed. You repair the server and confirm
that replication is successful to Alecnet 2.
You need to ensure that the failure of a single domain controller in any site will not interfere with Active
Directory replication between sites.
What are two possible ways to achieve this goal? (Each correct answer presents a complete solution.
Choose two)

A. Configure an IP site link between Alecnet 1 and Alecnet 3.
B. Configure two domain controllers in each site as preferred IP bridgehead servers.
C. Configure two domain controllers in each site as preferred SMTP bridgehead servers.
D. Configure each site to have no preferred bridgehead servers.
E. Configure an SMTP site link between each of the sites.
Assign a cost of 200 to the SMTP site link.
Answer: B, D
Go Back to the Braindumps Page
Go Back to the Braindumps Page
Comments: webmaster@freemcsebraindumps.com
Copyright 2000-2005, Free
MCSE Brain dumps .com
The material on this web site is not sponsored by, endorsed by or affiliated with
Microsoft or the MCSE certification or with any vendor such as Cisco, Oracle, Sun etc.
They own trademarks to their certifications. We use them to display information as a fair use
of the names.