Showing posts with label mcts cerfication. Show all posts
Showing posts with label mcts cerfication. Show all posts

Monday, January 2, 2012

70-294 Q & A / Study Guide

MCTS Training, MCITP Trainnig

Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com


QUESTION 1
You work as the IT Admin at Certkingdom.com. The Certkingdom.com network has a forest that operates at the
forest functional level of Windows Server 2003. The forest has a root domain named Certkingdom.com,
and two child domains named north.Certkingdom.com and south.Certkingdom.com. Each domain has a security
group named Research which holds the user accounts for that domain.
Two domain controllers are situated in each of these domains. One domain controller in each
domain hosts a copy of the global catalog.
The global catalog server in the Certkingdom.com domain holds the domain naming and the schema
master roles. The global catalog server in north.Certkingdom.com and south.Certkingdom.com holds the relative
ID (RID), infrastructure, and PDC emulator master roles.
A Certkingdom.com user named Ally Wagner, in the south.Certkingdom.com domain, was recently married. When
Ally Wagner got back, she asked you to change her surname in her user account. After changing
Ally Wagner’s user account to Ally Hamm, you notice that her user account is still incorrectly
specified as Ally Wagner in the Research group.
Which of the following master roles should you move to the domain controller that does not have
the Global Catalog in each domain?

A. The domain naming master role.
B. The infrastructure master role.
C. The RID master role.
D. The schema master role.
E. The PDC emulator master role.

Answer: B

Explanation: Problems like this can occur when the Infrastructure master role is on the same
domain controller as the Global Catalog. The infrastructure master updates the group-to-user
reference whenever group memberships change and replicates these changes across the domain.
The infrastructure master compares its data with that of a global catalog. Global catalogs receive
regular updates for objects in all domains through replication, so the global catalog data will
always be up to date. If the infrastructure master finds that its data is out of date, it requests the
updated data from a global catalog. The infrastructure master then replicates that updated data to
the other domain controllers in the domain.
Unless there is only one domain controller in the domain, the infrastructure master role should not
be assigned to the domain controller that is hosting the global catalog. If the infrastructure master
and global catalog are on the same domain controller, the infrastructure master will not function.
The infrastructure master will never find data that is out of date, so it will never replicate any
changes to the other domain controllers in the domain. Transferring the Infrastructure master role
to a different computer would resolve this problem. There is no reason to transfer any other master
roles.
Reference:
Michael Cross, Jeffery
A. Martin, Todd
A. Walls, Martin Grasdal, Debra Littlejohn Shinder & Dr.
Thomas W. Shinder, MCSE: Exam 70-294: Planning, Implementing, and Maintaining a Windows
Server 2003 Active Directory Infrastructure Study Guide & DVD Training System, Syngress
Publishing, Rockland, MA, 2003, pp. 505-509.


QUESTION 2
You work as the IT Network Admin at Certkingdom.com. The Certkingdom.com network has a forest with two child
domains named us.Certkingdom.com and uk.Certkingdom.com. All servers and domain controllers on the
Certkingdom.com network have Windows 2000 Server installed.
You have been given the task to uABCrade the domain controllers in uk.Certkingdom.com to Windows
Server 2003. You therefore need to take the appropriate steps that are required to prepare the
forest for the impending deployment.
Which of the following actions should you take?
Answer by selecting the appropriate steps from the column on the left and place it in the correct
order in the column on the left.



Answer:




QUESTION 3
You work as the IT Admin at Certkingdom.com. The Certkingdom.com network has a domain named Certkingdom.com.
Certkingdom.com has offices in London and Berlin, which are configured as separate sites.
A Backup of Certkingdom.com’s Ntds.dit file is performed outside of business hours, seven days a week.
The domain has an OU named Research that currently holds no Active Directory objects. During
the course of the business day an administrator in Berlin removes the Research OU, while an
administrator in London simultaneously places existing Active Directory objects in it. The London
administrator is later informed of the removal, and now realizes that the objects that were placed
into the Research OU are missing.
The CIO has subsequently instructed you to make sure that a Research OU and the missing
Active Directory objects are available to the London administrator. The CIO also informs you that
your solution should have no impact on network connectivity and resources. You have already
created a new OU, and named it Research.
Which of the following actions should you take NEXT?

A. You should transfer the objects from the LostAndFound container to the new Research OU
B. You should recreate the objects and then place the replicas in a Domain Group Policy that
should be linked to all OUs.
C. You should restore the objects to the new Research OU nonauthoritatively.
D. You should restore the objects to the new Research OU authoritatively.

Answer: A

Explanation: You moved the objects to an OU that had just been deleted. When you move
objects to an object that is no longer there, the objects get moved to the LostAndFound container.
This means that we haven’t lost the objects, so we can just re-create the Research OU and move
the users from the LostAndFound container to the new OU.
Reference:
Michael Cross, Jeffery
A. Martin, Todd
A. Walls, Martin Grasdal, Debra Littlejohn Shinder & Dr.
Thomas W. Shinder, MCSE: Exam 70-294: Planning, Implementing, and Maintaining a Windows
Server 2003 Active Directory Infrastructure Study Guide & DVD Training System, Syngress
Publishing, Rockland, MA, 2003, pp. 38-39, 99-101


QUESTION 4
You work as a IT Admin at Certkingdom.com. Certkingdom.com has its headquarters located in Dallas and branch
division in Miami. The Dallas and Miami division represent separate sites. The Dallas and Miami
divisions are linked to each other via a WAN link.
You have added a domain controller named ABC-SR01 to the Miami division and configured it as
a global catalog server. You have just completed configuring the site link between the Dallas and
Miami divisions.
The CIO at Certkingdom.com has instructed you to make sure that Miami workstations authenticate to the
network via ABC-SR01. The CIO also informs you that the replication of domain changes has to
happen instantaneously.
Which of the following actions should you take?

A. You should reduce the site link interval.
B. You should reduce the site link cost.
C. You should combine the Dallas and Miami sites into a single site
D. You should increase the site link cost.

Answer: A

Explanation:


QUESTION 1
You work as the IT Admin at Certkingdom.com. The Certkingdom.com network has a forest that operates at the
forest functional level of Windows Server 2003. The forest has a root domain named Certkingdom.com,
and two child domains named north.Certkingdom.com and south.Certkingdom.com. Each domain has a security
group named Research which holds the user accounts for that domain.
Two domain controllers are situated in each of these domains. One domain controller in each
domain hosts a copy of the global catalog.
The global catalog server in the Certkingdom.com domain holds the domain naming and the schema
master roles. The global catalog server in north.Certkingdom.com and south.Certkingdom.com holds the relative
ID (RID), infrastructure, and PDC emulator master roles.
A Certkingdom.com user named Ally Wagner, in the south.Certkingdom.com domain, was recently married. When
Ally Wagner got back, she asked you to change her surname in her user account. After changing
Ally Wagner’s user account to Ally Hamm, you notice that her user account is still incorrectly
specified as Ally Wagner in the Research group.
Which of the following master roles should you move to the domain controller that does not have
the Global Catalog in each domain?

A. The domain naming master role.
B. The infrastructure master role.
C. The RID master role.
D. The schema master role.
E. The PDC emulator master role.

Answer: B

Explanation: Problems like this can occur when the Infrastructure master role is on the same
domain controller as the Global Catalog. The infrastructure master updates the group-to-user
reference whenever group memberships change and replicates these changes across the domain.
The infrastructure master compares its data with that of a global catalog. Global catalogs receive
regular updates for objects in all domains through replication, so the global catalog data will
always be up to date. If the infrastructure master finds that its data is out of date, it requests the
updated data from a global catalog. The infrastructure master then replicates that updated data to
the other domain controllers in the domain.
Unless there is only one domain controller in the domain, the infrastructure master role should not
be assigned to the domain controller that is hosting the global catalog. If the infrastructure master
and global catalog are on the same domain controller, the infrastructure master will not function.
The infrastructure master will never find data that is out of date, so it will never replicate any
changes to the other domain controllers in the domain. Transferring the Infrastructure master role
to a different computer would resolve this problem. There is no reason to transfer any other master
roles.
Reference:
Michael Cross, Jeffery
A. Martin, Todd
A. Walls, Martin Grasdal, Debra Littlejohn Shinder & Dr.
Thomas W. Shinder, MCSE: Exam 70-294: Planning, Implementing, and Maintaining a Windows
Server 2003 Active Directory Infrastructure Study Guide & DVD Training System, Syngress
Publishing, Rockland, MA, 2003, pp. 505-509.


QUESTION 2
You work as the IT Network Admin at Certkingdom.com. The Certkingdom.com network has a forest with two child
domains named us.Certkingdom.com and uk.Certkingdom.com. All servers and domain controllers on the
Certkingdom.com network have Windows 2000 Server installed.
You have been given the task to uABCrade the domain controllers in uk.Certkingdom.com to Windows
Server 2003. You therefore need to take the appropriate steps that are required to prepare the
forest for the impending deployment.
Which of the following actions should you take?
Answer by selecting the appropriate steps from the column on the left and place it in the correct
order in the column on the left.



Answer:




QUESTION 3
You work as the IT Admin at Certkingdom.com. The Certkingdom.com network has a domain named Certkingdom.com.
Certkingdom.com has offices in London and Berlin, which are configured as separate sites.
A Backup of Certkingdom.com’s Ntds.dit file is performed outside of business hours, seven days a week.
The domain has an OU named Research that currently holds no Active Directory objects. During
the course of the business day an administrator in Berlin removes the Research OU, while an
administrator in London simultaneously places existing Active Directory objects in it. The London
administrator is later informed of the removal, and now realizes that the objects that were placed
into the Research OU are missing.
The CIO has subsequently instructed you to make sure that a Research OU and the missing
Active Directory objects are available to the London administrator. The CIO also informs you that
your solution should have no impact on network connectivity and resources. You have already
created a new OU, and named it Research.
Which of the following actions should you take NEXT?

A. You should transfer the objects from the LostAndFound container to the new Research OU
B. You should recreate the objects and then place the replicas in a Domain Group Policy that
should be linked to all OUs.
C. You should restore the objects to the new Research OU nonauthoritatively.
D. You should restore the objects to the new Research OU authoritatively.

Answer: A

Explanation: You moved the objects to an OU that had just been deleted. When you move
objects to an object that is no longer there, the objects get moved to the LostAndFound container.
This means that we haven’t lost the objects, so we can just re-create the Research OU and move
the users from the LostAndFound container to the new OU.
Reference:
Michael Cross, Jeffery
A. Martin, Todd
A. Walls, Martin Grasdal, Debra Littlejohn Shinder & Dr.
Thomas W. Shinder, MCSE: Exam 70-294: Planning, Implementing, and Maintaining a Windows
Server 2003 Active Directory Infrastructure Study Guide & DVD Training System, Syngress
Publishing, Rockland, MA, 2003, pp. 38-39, 99-101


QUESTION 4
You work as a IT Admin at Certkingdom.com. Certkingdom.com has its headquarters located in Dallas and branch
division in Miami. The Dallas and Miami division represent separate sites. The Dallas and Miami
divisions are linked to each other via a WAN link.
You have added a domain controller named ABC-SR01 to the Miami division and configured it as
a global catalog server. You have just completed configuring the site link between the Dallas and
Miami divisions.
The CIO at Certkingdom.com has instructed you to make sure that Miami workstations authenticate to the
network via ABC-SR01. The CIO also informs you that the replication of domain changes has to
happen instantaneously.
Which of the following actions should you take?

A. You should reduce the site link interval.
B. You should reduce the site link cost.
C. You should combine the Dallas and Miami sites into a single site
D. You should increase the site link cost.

Answer: A

Explanation:


QUESTION 5
You work as the IT Admin at Certkingdom.com. The Certkingdom.com network has a domain named Certkingdom.com. All
servers on the Certkingdom.com network have Windows Server 2003 installed and all workstations have
Windows XP Professional installed.
Certkingdom.com is made up of four divisions named Sales, Marketing, Finance and Research. The
Certkingdom.com network has an organizational unit (OU) named after each division that holds the user
accounts of all employees working in that specific division.
You need to install a new application for all employees in the Marketing division. You start by
creating an installation package and a Group Policy object (GPO). You plan to make use of the
new GPO to deploy the package to the workstations in the Marketing division. You therefore
connect the GPO to the Marketing OU. However, the application does not install.
The CIO informs you that the application must be installed and that you should make sure that
marketing application is not installed on workstations in the other Certkingdom.com divisions.
How will you accomplish the task?

A. Advise the Marketing users to reboot their workstations.
B. Edit the GPO and assign the application to user accounts with Marketing OU membership.
C. Connect the GPO to the Certkingdom.com domain.
D. Connect the GPO to the OU that contains computer accounts and not the Marketing OU.

Answer: B

Explanation: It is likely that the application was assigned to the computer accounts, rather than
the user accounts.
Reference:
Jill Spealman, Kurt Hudson & Melissa Craft, MCSE Self-Paced Training Kit (Exam 70-294);
Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory
Infrastructure, Microsoft Press, Redmond, Washington, 2004, pp. 12-3 to 12-10, 12-13 to 12-28,
12-34 to 12-39

QUESTION 5
You work as the IT Admin at Certkingdom.com. The Certkingdom.com network has a domain named Certkingdom.com. All
servers on the Certkingdom.com network have Windows Server 2003 installed and all workstations have
Windows XP Professional installed.
Certkingdom.com is made up of four divisions named Sales, Marketing, Finance and Research. The
Certkingdom.com network has an organizational unit (OU) named after each division that holds the user
accounts of all employees working in that specific division.
You need to install a new application for all employees in the Marketing division. You start by
creating an installation package and a Group Policy object (GPO). You plan to make use of the
new GPO to deploy the package to the workstations in the Marketing division. You therefore
connect the GPO to the Marketing OU. However, the application does not install.
The CIO informs you that the application must be installed and that you should make sure that
marketing application is not installed on workstations in the other Certkingdom.com divisions.
How will you accomplish the task?

A. Advise the Marketing users to reboot their workstations.
B. Edit the GPO and assign the application to user accounts with Marketing OU membership.
C. Connect the GPO to the Certkingdom.com domain.
D. Connect the GPO to the OU that contains computer accounts and not the Marketing OU.

Answer: B

Explanation: It is likely that the application was assigned to the computer accounts, rather than
the user accounts.
Reference:
Jill Spealman, Kurt Hudson & Melissa Craft, MCSE Self-Paced Training Kit (Exam 70-294);
Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory
Infrastructure, Microsoft Press, Redmond, Washington, 2004, pp. 12-3 to 12-10, 12-13 to 12-28,
12-34 to 12-39

MCTS Training, MCITP Trainnig

Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com

Wednesday, October 12, 2011

Certkingdom 70-647 Exam Q & A

Best Microsoft MCTS Training – Microsoft MCITP Training at Certkingdom.com

QUESTION 1
You work as an enterprise administrator at Certkingdom.com. The Certkingdom.com network has a domain named
Certkingdom.com. All servers in the Certkingdom.com network run Windows Server 2008.
The Certkingdom.com network has a file server named ABC-SR07 that hosts a shared folder named
ABCDocs. Several Microsoft Word documents are stored in the ABCDocs share. You want to
enable document version history on these documents. You also want the documents in the
ABCDocs share to be accessed through a Web page.
Which of the following roles or services would you install on ABC-SR07 to achieve the desired
results cost effectively?

A. FTP Server role.
B. Application Server role.
C. Microsoft Windows SharePoint Services (WSS) 3.0.
D. File and Print Services role.
E. Microsoft Office SharePoint Server (MOSS) 2007.
F. SMTP Server role.

Answer: C

Explanation:
To achieve the desired results without requiring any additional cost, you need to use Microsoft
Windows SharePoint Services (WSS) 3.0.
Reference: Microsoft Windows SharePoint Services 3.0 and the Mobile Workplace
http://download.microsoft.com/download/b/b/6/bb6672dd-252c-4a21-89de-
78cfc8e0b69e/WSS%20Mobile%20Workplace.doc


QUESTION 2
You work as an enterprise administrator at Certkingdom.com. The Certkingdom.com network has a domain named
Certkingdom.com with a single site named Site
A. All servers in the Certkingdom.com network run Windows Server
2008.
You reorganize the Active Directory infrastructure to include a second site named SiteB with its
own domain controller.
How would you configured the firewall to allow replication between SiteA and SiteB?

A. Enable IPSec traffic to pass through the firewall.
B. Enable RPC traffic to pass through the firewall.
C. Enable SMTP traffic to pass through the firewall.
D. Enable NNTP traffic to pass through the firewall.
E. Enable FTP traffic to pass through the firewall.

Answer: B

Explanation:
You should permit RPC traffic through the firewall to enable the domain controllers to replicate
between the two sites because the Active Directory relies on remote procedure call (RPC) for
replication between domain controllers. You can open the firewall wide to permit RPC's native
dynamic behavior.
Reference: Active Directory Replication over Firewalls
http://technet.microsoft.com/en-us/library/bb727063.aspx


QUESTION 3
You work as an enterprise administrator at Certkingdom.com. The Certkingdom.com network has a domain named
Certkingdom.com. All servers in the Certkingdom.com network run Windows Server 2008.
Certkingdom.com runs a critical application that accesses data that is stored in a Microsoft SQL Server
2005 database server named ABC-DB02. Which of the following options would you choose to
ensure that the database is always available?

A. Two Windows Server 2008 servers running MS SQL Server 2005 Standard Edition in a
Network Load Balancing (NLB) cluster.
B. Two Windows Server 2008 servers running MS SQL Server 2005 Enterprise Edition in a
Network Load Balancing (NLB) cluster
C. Two Windows Server 2008 servers running MS SQL Server 2005 Standard Edition in a failover
cluster.
D. Two Windows Server 2008 servers running MS SQL Server 2005 Enterprise Edition in a
failover cluster.

Answer: D

Explanation:
To ensure the high availability of the data store, you need to use a Windows Server 2008 failover
cluster with shared storage.
Failover clustering can help you build redundancy into your network and eliminate single points of
failure.
Administrators have better control and can achieve better performance with storage than was
possible in previous releases. Failover clusters now support GUID partition table (GPT) disks that
can have capacities of larger than 2 terabytes, for increased disk size and robustness.
Administrators can now modify resource dependencies while resources are online, which means
they can make an additional disk available without interrupting access to the application that will
use it. And administrators can run tools in Maintenance Mode to check, fix, back up, or restore
disks more easily and with less disruption to the cluster
You should not use Network Load Balancing (NLB) because it only allows you to distribute TCP/IP
requests to multiple systems in order to optimize resource utilization, decrease computing time,
and ensure system availability.
Reference: High Availability
http://www.microsoft.com/windowsserver2008/en/us/high-availability.aspx


QUESTION 4
You work as an enterprise administrator at Certkingdom.com. The Certkingdom.com network has a domain named
Certkingdom.com. All servers in the Certkingdom.com network run Windows Server 2008. Certkingdom.com has its
headquarters in Chicago and sub-divisions in Boston, Atlanta, Miami and Dallas. All domain
controllers are currently installed in the Chicago.
You need to have new domain controllers installed in the Boston, Atlanta, Miami and Dallas subdivisions.
Certkingdom.com issues a security policy for the new domain controllers that states the
following:
• Unauthorized user must not be able to access the Active Directory database.
• Unauthorized user must not be able to boot a domain controller from an alternate boot disk.
Which of the following options would you choose to implement the security policy?

A. Modify the permissions of the ntds.dat file.
B. Configure a read-only domain controller (RODC) in the Boston, Atlanta, Miami and Dallas.
C. Disable replication of the Sysvol folder on the new domain controllers.
D. Configure Windows BitLocker Drive Encryption (BitLocker) on the new domain controllers.
E. Disable the Global Catalog role on the new domain controllers.
F. Configure EFS encryption on the new domain controllers.

Answer: D

Explanation:
To configure domain controller at each branch office to ensure that no unauthorized user should
be allowed to copy the Active Directory database from a branch office domain controller by starting
the server from an alternate startup disk, you need to use Windows BitLocker Drive Encryption
(BitLocker)
BitLocker allows you to encrypt all data stored on the Windows operating system volume and use
the security of using a Trusted Platform Module (TPM) that helps protect user data and to ensure
that a computer running Windows Vista or Server 2008 have not been tampered with while the
system was offline.
In addition, BitLocker offers the option to lock the normal startup process until the user supplies a
personal identification number (PIN) or inserts a removable USB device, such as a flash drive, that
contains a startup key. This process will ensure that users can only access all files on the servers
if they have the PIN. You cannot use an alternate startup disk to boot the server.
Reference: BitLocker Drive Encryption Technical Overview
http://technet2.microsoft.com/windowsserver2008/en/library/a2ba17e6-153b-4269-bc46-
6866df4b253c1033.mspx?mfr=true


QUESTION 5
You work as an enterprise administrator at Certkingdom.com. The Certkingdom.com network has a domain named
Certkingdom.com that runs at the domain functional level of Windows Server 2008.
Which of the following options can be used for tracking any modification to Active Directory
Objections?

A. Configure a Group Policy to run the Security Configuration Wizard on all computers in the ABC
network.
B. Configure the Default Domain Controllers Group Policy to audit Directory Services.
C. Configure the Default Domain Group Policy to audit Directory Services.
D. Enable auditing of the ntds.dat file in the Default Domain Group Policy.
E. Enable auditing of the ntds.dat file in the Default Domain Group Policy.

Answer: B

Explanation:
To implement an audit and compliance policy and ensure that all changes made to Active
Directory objects are recorded, you need to configure a Directory Services Auditing policy in the
Default Domain Controller Policy
In Windows Server 2008, you can enable Audit Directory Service Access policy to log events in
the Security event log whenever certain operations are performed on objects stored in Active
Directory.
Enabling the global audit policy, Audit directory service access, enables all directory service policy
subcategories. You can set this global audit policy in the Default Domain Controllers Group Policy
(under Security Settings\Local Policies\Audit Policy).
Reference: Windows Server 2008 Auditing AD DS Changes Step-by-Step Guide
http://technet2.microsoft.com/windowsserver2008/en/library/a9c25483-89e2-4202-881cea8e02b4b2a51033.
mspx?mfr=true


QUESTION 6
You work as an enterprise administrator at Certkingdom.com. The Certkingdom.com network has a domain named
Certkingdom.com. All servers in the Certkingdom.com network run Windows Server 2003.
You want to install a read-only domain controller (RODC) without uABCrading the existing domain
controllers Windows Server 2008.
What action should you take? (Each correct option will form a part of the answer. Select TWO.)

A. Raise the forest functional level to Windows 2000.
B. Raise the forest functional level to Windows 2003.
C. Raise the forest functional level to Windows 2008.
D. Raise the domain functional level to Windows Server 2000
E. Raise the domain functional level to Windows Server 2003
F. Raise the domain functional level to Windows Server 2008

Answer: B,E

Explanation:
To create an Active Directory forest and domain functional levels to support Read-only domain
controllers (RODC) and Windows Server 2003 domain controllers, you need to create both the
forest and domain functional levels of Windows Server 2003. This is because only when you use
both the forest and domain functional levels of Windows Server 2003, you will be able to support
Read-only domain controllers (RODC) and Windows Server 2003 domain controllers.
Reference: Appendix of Functional Level Features
http://technet2.microsoft.com/windowsserver2008/en/library/34678199-98f1-465f-9156-
c600f723b31f1033.mspx?mfr=true


QUESTION 7
You work as an enterprise administrator at Certkingdom.com. The Certkingdom.com network has a forest named
and Certkingdom.com that runs at the forest functional level of Windows Server 2003. Certkingdom.com has a
subsidiary company named TestLabs, Inc. The TestLabs, Inc. network has a forest named and
testlabs.com that runs at the forest functional level of Windows Server 2003. All domain controllers
on both the Certkingdom.com network and the TestLabs, Inc. network run Windows Server 2008.
Certkingdom.com users do not have access to network resources in TestLabs, Inc.
TestLabs, Inc. has a file server named TESTLABS-SR07. Certkingdom.com users must be able to access
shared folders on TESTLABS-SR07. However, Certkingdom.com users must not be able to access any
other network resources in TestLabs, Inc.
Which of the following options would you choose to accomplish this task? (Each correct option will
form a part of the answer. Select TWO.)

A. By raising the forest functional level of Certkingdom.com and testlabs.com to Windows Server 2008.
B. By raising the domain functional level of all domains in Certkingdom.com and testlabs.com to Windows
Server 2008.
C. By creating a forest trust between Certkingdom.com and testlabs.com.
D. By setting the Allowed to Authenticate for TESTLABS-SR07.
E. By setting the Allowed to Authenticate right on the computer object for the testlabs.com
infrastructure operations master object.

Answer: C,D

Explanation:
To ensure that the users in ABC-south.com are denied access to all the resources ABC-north.com
except the resources on ABC-SR07, you need to create a forest trust between ABC-south.com
and ABC-north.com so that resources can be shared between both the forests. You can however
set the trust authentication setting to selective authentication so that only selected authentication
is allowed.
Next you need to set the Allowed to Authenticate right on the computer object for ABC-SR07 so
that each user must be explicitly granted the Allowed to Authenticate permission to access
resources on ABC-SR07.
You should not set the Allowed to Authenticate right on the computer object for the ABC-north.com
infrastructure operations master object because Allowed to Authenticate right is set for the users in
a trusted Windows Server 2003 domain or forest to be able to access resources in a trusting
Windows Server 2003 domain or forest, where the trust authentication setting has been set to
selective authentication, each user must be explicitly granted the ‘Allowed to Authenticate’
permission on the security descriptor of the computer objects (resource computers) that reside in
the trusting domain or forest.
Reference: Grant the Allowed to Authenticate permission on computers in the trusting domain or
forest
http://technet2.microsoft.com/windowsserver/en/library/b4d96434-0fde-4370-bd29-
39e4b3cc7da81033.mspx?mfr=true


QUESTION 8
You work as an enterprise administrator at Certkingdom.com. The Certkingdom.com network has a domain named
Certkingdom.com. All servers in the Certkingdom.com network run Windows Server 2008. Certkingdom.com has its
headquarters in Chicago and branch offices in Boston. The Boston office is connected to the
Chicago by a WAN link. The Chicago office has a DNS Sever named ABC-SR04 that is configured
as a single DNS zone. The Boston office has two servers named ABC-SR07 and ABC-SR08.
ABC-SR08 hosts shared folders that are only accessed by Certkingdom.com users in the Boston office.
You work in the Chicago office while a network administrator named Rory Allen works in the
Boston office.
Certkingdom.com wants you to ensure that users at the Boston office can log on to the Certkingdom.com domain
and can connect to the shared folders on ABC-SR08 even when the WAN link is down. You must
allow Rory Allen to configure the servers in the Boston office without allowing him to modify the
Active Directory configuration.
Which actions should you take to accomplish this task? (Each correct option will form a part of the
answer. Choose THREE.)

A. By promoting ABC-SR07 to a domain controller.
B. By promoting ABC-SR07 to a read-only domain controller (RODC).
C. By installing USMT role on ABC-SR07.
D. By installing ADMT role on ABC-SR07.
E. By installing DNS role on ABC-SR07.
F. By adding Rory Allen to the Domain Admins group.
G. By creating an organizational unit (OU) for the Boston office.
H. By assigning administrative rights to Rory Allen.

Answer: B,E,H

Explanation:
To ensure that the users in the branch office are able to log on to the domain even if the WAN link
fails, you need to promote the member server to a read-only domain controller (RODC) because
the RODC works as a domain controller and allows log in to the domains except allowing
modifications and changes to the Active directory domain.
Delegating administrative rights to the local branch office administrator after promoting a member
server to a RODC will make sure that branch office administrator is not allowed to initiate any
changes to Active Directory but should be allowed to make configuration changes to the servers in
the branch office.
Configuring the DNS role to the member server, will ensure that the users are allowed to access
file shares on the local server in the absence of the WAN link. Without name resolution and the
other services that are provided by DNS servers, client access to remote host computers would be
prohibitively difficult. DNS servers need to be configured because in intranets computer users
rarely know the IP addresses of computers on their local area network (LAN).
Reference: DNS Server Role: Read-only domain controller support/ Who will be interested in this
server role?
http://technet2.microsoft.com/windowsserver2008/en/library/533a1cfc-5173-4248-914c-
433bd018f66d1033.mspx?mfr=true


QUESTION 9
You work as an enterprise administrator at Certkingdom.com. The Certkingdom.com network has a domain named
Certkingdom.com and a workgroup named ABCGROUP. All servers in the Certkingdom.com network run Windows
Server 2008 and all the client computers run Windows Vist
A. The Certkingdom.com network has
unmanaged network switches and has two servers named ABC-SR07 and ABC-SR08. ABC-SR07
is configured with the Active Directory Domain Services (AD DS), the Active Directory Certificate
Services (AD CS) and the Dynamic Host Configuration Protocol (DHCP) service while ABC-SR08
is configured with the Routing and Remote Access Service (RRAS), the Network Policy Service
(NPS) and Health Registration Authority (HRA).
You notice that the latest Microsoft updates have not been applied to all client computers that are
part of the ABCGROUP workgroup. You are concerned that Certkingdom.com users are accessing the
local area network (LAN) from these client computers.
You want to implement Network Access Protection (NAP) to secure the network by preventing
client computers that are not members of the Certkingdom.com network or do not have the latest Microsoft
updates from accessing any network servers that are members of the Certkingdom.com domain.
Which of the following option would you choose?

A. TCP/IP
B. 802.1z
C. PPTP
D. DHCP
E. L2TP
F. IPsec

Answer: F

Explanation:
To ensure that only the computers that have the latest Microsoft updates installed should be able
to connect to servers in the domain and that only the computers that are joined to the domain
should be able to connect to servers in the domain, you need to use the IPSec NAP enforcement
method. IPsec domain and server isolation methods are used to prevent unmanaged computers
from accessing network resources. This method enforces health policies when a client computer
attempts to communicate with another computer using IPsec.
Reference: Protecting a Network from Unmanaged Clients / Solutions
http://www.microsoft.com/technet/security/midsizebusiness/topics/serversecurity/unmanagedclient
s.mspx
Reference: Network Access Protection (NAP) Deployment Planning / Choosing Enforcement
Methods
http://blogs.technet.com/nap/archive/2007/07/28/network-access-protection-deploymentplanning.
aspx


QUESTION 10
You work as an enterprise administrator at Certkingdom.com. The Certkingdom.com network has a domain named
Certkingdom.com. All servers in the Certkingdom.com network run Windows Server 2008. The Certkingdom.com network
has two web servers named ABC-SR07 and ABC-SR08. Certkingdom.com wants to hosts the company's
e-commerce Web site named sales.Certkingdom.com on the two web servers. You receive instructions
from the CEO to ensure that the Web site is available even when one of the Web servers is offline.
The CEO also wants the session state of the web site to be available should one of the web
servers be offline. Additionally, you must be able to support the Web site on up to six Web servers
with each Web server having a dedicated IP address.
What action should you take?

A. Configure a two-failover cluster on ABC-SR07 and ABC-SR08.
B. Configure multiple ports for the sales.Certkingdom.com web site.
C. Configure Network Load Balancing on ABC-SR07 and ABC-SR08.
D. Configure the sales.Certkingdom.com web site on each server with the site content on a network share.
E. Configure multiple host headers for the sales.Certkingdom.com website.
F. Configure multiple IP addresses for the sales.Certkingdom.com website.


Answer: C


Explanation:
To ensure that the users of the website would be able to access the Web site if a single server
fails. The website should be scalable to as many as seven Web servers and the web servers
should be able to store session-state information for all users. It should also provide support for
multiple dedicated IP addresses for each Web server.
The Network Load Balancing (NLB) feature in Windows Server 2008 enhances the availability and
scalability of Internet server applications such as those used on Web, FTP, firewall, proxy, virtual
private network (VPN), and other mission-critical servers. NLB provides high availability of a
website by detecting and recovering from a cluster host that fails or goes offline.
You should not use failover clustering in this scenario because failover clustering requires shared
storage which is not mentioned in this question.
Reference: Overview of Network Load Balancing
http://technet2.microsoft.com/windowsserver2008/en/library/11dfa41c-f49e-4ee5-8664-
8b81f6fb8af31033.mspx?mfr=true




Best Microsoft MCTS Training – Microsoft MCITP Training at Certkingdom.com

Saturday, September 17, 2011

Microsoft releases Windows Phone Mango to manufacturers

Microsoft has signed-off on the Release to Manufacturers build of the brand new Mango update for the Windows Phone operating system 70-640 Training.

That means the software giant has completed work on the OS and it’s now up to the manufacturers to implement it on forthcoming handsets.

The first Mango phones are set to arrive in the autumn, although the first handset to boast the update and an official timescale for release have yet to be revealed.



Best online Microsoft MCTS Training, Microsoft MCITP Training at Certkingdom.com


Preparing

Corporate Vice President of Windows Phone Engineering Terry Myserson explains: “This marks the point in the development process where we hand code to our handset and mobile operator partners to optimise Mango for their specific phone and network configurations.

“Here on the Windows Phone team, we now turn to preparing for the update process.

“The Mango update for current Windows Phone handsets will be ready this fall, and of course will come pre-installed on new Windows Phones.”

250 new features

The Windows Phone Mango update brings 250 new features to the operating system, including Internet Explorer 9 integration and app multi-tasking.

The upgrade was announced in May, so by the time the autumn comes around Mango will be around 6 months in the making. Get a move on, guys!

Thursday, September 15, 2011

Microsoft Excel world champion is British, of course

Analyse that raw data

A 15-year-old school girl from Cambridgeshire has been crowned world Microsoft Excel champion, beating 228,000 other spreadsheet-loving hopefuls to the prize.




Best online Microsoft MCTS Training, Microsoft MCITP Training at Certkingdom.com

Yes, such a thing as the Excel World Championship does exist and of course the winner is British, what with our love of order and all.

The contest takes place every year with regional heats providing ten finalists to take part in the Californian showdown.
Spreadsheet club

Rebecca Rickwood, who attends a specialist maths and computing school, performed timed tests using Excel 2007 without putting a foot wrong, earning her a score of 100 per cent.

"I heard my name read out in first place and I just couldn't believe it. I'm ecstatic," she said. "I just can't believe I won and now I'm world champion."

She was awarded the $5,000 prize money at a ceremony in San Diego; no doubt a glowing career in statistical analysis lies ahead.

From the BBC

Monday, September 5, 2011

Age bias in IT: The reality behind the rumors

Is high tech really that tough on older workers? Or are they simply not pulling their weight in an industry that never stops innovating?

Computerworld – Age bias: Some consider it IT’s dirty little secret, or even IT’s big open secretMicrosoft 70-640 Training .”

In the category of “computer and mathematical occupations,” the overall unemployment rate for people 55 and over jumped from 6% to 8.4% from 2009 to 2010, according to the data. For those 25 to 54 years old in that job category, the unemployment rate fell from 5.1% in 2009 to 4.5% in 2010.


Best Microsoft MCTS Certification, Microsoft MCITP Training
at certkingdom.com


Those figures are particularly striking when compared to the overall population, where 55-plus workers had lower unemployment rates (7%) than the 25-to-54-year olds (8.5%) in 2010.

That trend seems to be reflected in the level of anxiety among older IT workers who still have jobs. According to the latest Computerworld salary survey, the number of IT people feeling somewhat or very insecure rises steadily as they age.
Older workers feel less secure
Age 18-24 24-34 35-44 45-54 55+
Very secure or secure 69% 69.5% 59.3% 51.9% 55%
Somewhat secure 26.2% 23.8% 29.8% 34.3% 29.1%
Not very secure/not at all secure 4.8% 6.7% 10.9% 13.9% 15.9%
How secure high tech workers feel in their current position, by age (percentage of total respondents). Source: Computerworld 2011 Salary Survey of 4,852 high-tech workers employed full or part time.

As to the flat-lining of wages that’s rumored to sometimes happen in the second half of a high-tech career, Computerworld’s survey didn’t turn up evidence of age bias in actual salaries, but employees aged 55 and older were the most likely to report that they had generally “lost ground financially” in the past two years.

An academic study of IT salaries published in 2008 did show interesting disparities in IT salary by age in three specific industry segments — finance, IT and medical. Although the report is now out of date — it was based on data from 2001 — at least one of the original researchers believes its findings still hold true.

“The slow economic recovery and the stubborn high unemployment rate we have right now only make age discrimination even more pronounced,” says Jing Quan, an associate professor at Salisbury University in Salisbury, Md. “IT companies are more likely to value IT workers who have the most updated skill sets and can get the job done,” he says. “And those are more likely younger IT workers.”

Keep up or keep out

The hyper-accelerated pace of change in high technology makes it a particularly challenging field to keep up with. Put bluntly: “The special characteristics of the IT industry — highly competitive, fast-paced, short skill update cycle — do not favor older workers,” says Quan.

Julie McMullin, a professor at Canada’s University of Western Ontario, elaborates. “Perceptions of older, in this particular industry, have a lot to do with competing demands,” says McMullin, who leads an international project called Workforce Aging in the New Economy (WANE) that studies aging and workforce restructuring in the IT industry.

“If you’re an unencumbered worker” — that is, single with lots of time to work extra hours and attend training to update your skills — “then you’re ‘young,’” she says.

By those standards, Ronda Henning could pass for a spring chicken. In real-life years, she’s 53, but by her own estimate has logged enough extra hours and obtained enough degrees to give younger workers a run for their money.

A senior scientist specializing in security at Harris Corp., a communications and IT company based in Melbourne, Fla., Henning has earned several graduate degrees to supplement her undergraduate degree (a B.A. in English writing nonfiction and political science from the University of Pittsburgh). She holds an MBA from the Florida Institute of Technology and an M.S. in computer science from Johns Hopkins University, and she’s currently working toward a Ph.D. in information systems.

Beyond that, Henning has taken care to invest in her career on her own time — publishing and presenting papers at conferences and identifying and pursuing new business initiatives within her organization. “Often that has to happen on your own time, in addition to your standard assignments,” she warns Microsoft Free MCTS Training and MCTS Online Training.

And then there’s the constant influx of the new, and the challenge of separating signal from noise. “I make a conscious effort to stay current, but these days, it’s very hard to absorb everything and figure out what’s truly important,” Henning acknowledges. “It can become a 24-hour-a-day job to try and do that.”

Thursday, September 1, 2011

70-640 Exam training kit

Microsoft 70-640 Training. 100% Instant Canyon Without Assay or Dumps, MCTS 70-640 MCITP, you will get anesthetized your assay in VUE/Prometric aural 3 canicule easily, and your Certification cachet can be arrested in Microsoft MCP website and your certificates will access from Microsoft to your home directly. so that you can get certified easily


Best Microsoft MCTS Certification, Microsoft MCITP Training
at certkingdom.com

1. Send us the enquiry email with your claimed advice (first name, endure name, tel no and country), again we will acknowledgment you with all simple action accomplish to canyon exams and Transaction Information.

2. Send us the transaction and you will get anesthetized aural 3 days.

3. Get Certified with Microsoft and you can abide the next test.

Generally, humans may baddest to buy a 70-640 braindumps to canyon the MCTS 70-640 Exam. Actually, There is no man affairs the absolute 70-640 depression of Microsoft 70-640 Exam, Microsoft is befitting afterlight the 70-640 Exam, so humans can’t canyon the 70-640 Assay easily, Microsoft 70-640 Braindumps is not torward for the absolute 70-640 exam. In absolute MCTS 70-640 Exam, Microsoft is not alone analysis the MC only, MCITP 70-640 Assay accommodate the lab catechism that is not accessible to accomplish for braindumps, but it is a lot of importain to canyon the exam, so we are not acclaim to acquirement the MCITP 70-640 dumps. Our casework advice the man who accept abundant experience(or 70-640 Training) but gluttonous the way to get Microsoft 70-640 Assay passed. Or any SME who is accommodating to get MCTS 70-640 or MCITP Certification to get any Microsoft artefact discount.

Upgrade exams for MCITP SA .You apperceive ,if you canyon assay 70-640 ,your MCSA on windows Server 2003 can be upgraded to MCTS credentials(MCTS :Windows Server 2008 Active Directory Agreement and Windows Server 2008 Network Infrastructure configuration).That is to say, advancement assay 70-648 is aggregate of MCTS 70-640 and 70-642 .So ,generally speaking ,70-648 is harder .After your casual 70-648 or accepting both of MCTS accreditation ,only if you canyon 70-646 ,you will get your MCITP :SA (Server Administrator on Windows Server 2008).

2. Yield MCTS bisect 2008 exams instead of the advancement paths. That is to say, you can yield any adjustment of 70-640 and 70-642 exams to get the aloft two MCTS credentials. In my opinion, this way is easier.

Which way would you prefer?
Personally, the easier avenue would be to just do Free MCTS Training and MCTS Online Training. 70-640 and 70-642 exams individually. Advancement exams are consistently harder! The advancement assay 70-648 is aggregate of 2 exams and far harder than the alone exams. Unless you accept abundant acquaintance on the technology Windows Server 2008, you¡®d bigger not yield 70-648 instead of free A+ exam questions.So for me it wouldn¡¯t accept fabricated a aberration if I did the exams alone from a amount of exams point of view.

Tuesday, August 30, 2011

VMware CEO: Cloud to end computer desktop era


VMware CEO Paul Maritz urged customers to make the move from virtualization to cloud infrastructure

VMware CEO Paul Maritz urged customers to think beyond the desktop computer. It is a dead metaphor, he insisted, one ill-suited for today's workforce 70-640 Training.

"PCs are not the only animal in the zoo anymore. Increasingly, users are holding other devices in their hands," he said, speaking at the kick-off of the VMworld 2011, being held this week in Las Vegas.




Best Microsoft MCTS Certification, Microsoft MCITP Training at certkingdom.com




See products shown at VMworld

Within five years, less than 20 percent of computing clients will be running Microsoft Windows, he predicted. The job of providing applications and data "can no longer belong to any one device, or any one operating system. So we have to float away from that aspect of the desktop," he said.

While VMware has made its mark by providing software for virtualizing servers, the company is rapidly building up a stack of software for organizations to use to run private and hybrid clouds, based around its vSphere software for managing virtual resources.

In his presentation before many of the conference's 19,000 attendees, Maritz said customers should move from virtualization to a full-fledged cloud infrastructure. Fifty percent of the world's infrastructure runs on virtualization, he noted. The cloud is the next logical step, he reasoned.

A cloud infrastructure will be necessary, he noted, to accommodate the needs of a more dynamic workforce. It will enable administrators to deliver applications and information to people, rather than devices.

Some organizations seem to be moving in this direction. Maritz said that there are now over 800,000 vSphere administrators, including 68,000 certified in handling the technology.

"I spent my whole life working on the PC," admitted Maritz, who is 56. The metaphor of the desktop came from Xerox Parc research lab in the 1970s, which at the time, was exploring "how to automate the life of the white collar worker, circa 1975," he said. This meant the researchers made computer based approximations of the tools of the office worker--file cabinets, typewriters, files, folder, inboxes and outboxes.

"We got a great a desktop environment," he said. "The problem is the people under the age of 35 don't sit behind desks, and they don't spend all of their time lovingly tending to documents. They will be dealing with streams of information that will be coming at them in much smaller chunks and much larger numbers. We're moving into a new post-document era, and we will need different solutions."

Maritz then explained how VMware's products can provide a foundation for this new type of operation. VMware's vFabric provides a set of tools for developers to build applications that can run natively in the cloud. CloudFoundry provides a Platform-as-a-Service (PaaS) that customers can use to run their own applications on external hardware Free MCTS Training and MCTS Online Training. VMware View VDI (Virtual Desktop Infrastructure) software allows users to access their data and applications across a wide range of clients. And the recently released VMware Horizon provides an enterprise portal for users to easily access new applications.

Saturday, August 27, 2011

Mobile device management

Managing mobile devices entails a level of complexity unheard of in the traditional enterprise world of Windows desktops. MDM software needs to control devices from multiple manufacturers, running different versions of as many as five operating systems, tied to carrier networks with their own particular constraints.

This makes mobile device management a tough battle, but one that IT execs need to take on because mobile device users can lose important company data, potentially increase personal and organizational liability, and compromise systems security at levels that will frighten even the most jaded of IT administrators.

We set up a comprehensive test that included eight mobile devices, four operating systems, two service providers and five mobile management vendors (see How We Did It).



Best online Microsoft MCTS Training, Microsoft MCITP Training at Certkingdom.com

Thursday, August 25, 2011

New book: I. M. Wright’s “Hard Code”: A Decade of Hard-Won Lessons from Microsoft, Second Edition


We’re very happen to announce that the second, newly expanded edition of I. M. Wright’s “Hard Code”: A Decade of Hard-Won Lessons from Microsoft, by Eric Brechner is available for purchase. (Print ISBN 9780735661707; Page Count 448).

Here is an excerpt from Chapter 5, “Software Quality—More Than a Dream”.




Best online Microsoft MCTS Training, Microsoft MCITP Training at Certkingdom.com

Chapter 5
Software Quality—More Than a Dream

image

Some people mock software development, saying if buildings were built like
software, the first woodpecker would destroy civilization. That’s quite funny, or
disturbing, but regardless it’s misguided. Early buildings lacked foundations. Early
cars broke down incessantly. Early TVs required constant fiddling to work properly.
Software is no different.


At first, Microsoft wrote software for early adopters, people comfortable replacing
PC boards. Back then, time to market won over quality, because early adopters
could work around issues, but they couldn’t slow the clock. Shipping fastest meant
coding quickly and then fixing just enough to make it work.


Now our market is consumers and the enterprise, who value quality over the
hassles of experimentation. The market change was gradual, so Microsoft’s initial
response was simply to fix more bugs. Soon bug fixing was taking longer than
coding, an incredibly slow process. The fastest way to ship high quality is to trap
errors early, coding it right the first time and minimizing rework. Microsoft has
been shifting to this quality upstream approach over the time I’ve been writing
these columns. The first major jolt that drove the company-wide change was a
series of Internet virus attacks in late 2001.


In this chapter, I. M. Wright preaches quality to the engineering masses. The first
column evaluates security issues. The second analyzes why quality is essential and
how you get it. The third column explains an engineering approach to software that
dramatically reduces defects. The fourth talks about design and code inspections.
The fifth describes metrics that can predict quality issues before customers experience them.
The sixth focuses on techniques to make software resilient. And
the chapter aptly finishes by emphasizing the five basics of software quality.
While all these columns provide an interesting perspective, the second one,
“Where’s the beef? Why we need quality” stands out as an important turning point.
When I wrote it few inside or outside Microsoft believed we were serious about
quality. Years later, many of the concepts are taken for granted. It took far more
than an opinion piece to drive that change, but it’s nice to call for action and have
people respond.
May 1, 2008: “Crash dummies: Resilience”

imageI heard a remark the other day that seemed stupid on the surface,
but when I really thought about it I realized it was completely idiotic
and irresponsible. The remark was that it’s better to crash and let
Watson report the error than it is to catch the exception and try to
correct it.



image

From a technical perspective, there is some sense to the strategy of allowing the crash to
complete and get reported. It’s like the logic behind asserts—the moment you realize you
are in a bad state, capture that state and abort. That way, when you are debugging later
you’ll be as close as possible to the cause of the problem. If you don’t abort immediately, it’s
often impossible to reconstruct the state and identify what went wrong. That’s why asserts
are good, right? So, crashing is sensible, right?

image

Oh please. Asserts and crashing are so 1990s. If you’re still thinking that way, you need to
shut off your Walkman and join the twenty-first century, unless you write software just for
yourself and your old-school buddies. These days, software isn’t expected to run only until its
programmer got tired. It’s expected to run and keep running. Period.


Struggle against reality


Hold on, an old-school developer, I’ll call him Axl Rose, wants to inject “reality” into the
discussion. “Look,” says Axl, “you can’t just wish bad machine states away, and you can’t fix
every bug no matter how late you party.” You’re right, Axl. While we need to design, test,
and code our products and services to be as error free as possible, there will always be bugs.
What we in the new century have realized is that for many issues it’s not the bugs that are
the problem—it’s how we respond to those bugs that matters.


Axl Rose responds to bugs by capturing data about them in hopes of identifying the cause.
Enlightened engineers respond to bugs by expecting them, logging them, and making their
software resilient to failure. Sure, we still want to fix the bugs we log because failures are
costly to performance and impact the customer experience. However, cars, TVs, and networking
fail all the time. They are just designed to be resilient to those failures so that crashes
are rare.

image
Perhaps be less assertive


“But asserts are still good, right? Everyone says so,” says Axl. No. Asserts as they are implemented
today are evil. They are evil. I mean it, evil. They cause programs to be fragile instead
of resilient. They perpetuate the mindset that you respond to failure by giving up instead of
rolling back and starting over.


We need to change how asserts act. Instead of aborting, asserts should log problems and
then trigger a recovery. I repeat—keep the asserts, but change how they act. You still want
asserts to detect failures early. What’s even more important is how you respond to those failures, including the ones that slip through Free MCTS TrainingMCTS Online Training .
If at first you don’t succeed

So, how do you respond appropriately to failure? Well, how do you? I mean, in real life, how
do you respond to failure? Do you give up and walk away? I doubt you made it through the
Microsoft interview process if that was your attitude.


When you experience failure, you start over and try again. Ideally, you take notes about what
went wrong and analyze them to improve, but usually that comes later. In the moment, you
simply dust yourself off and give it another go.


For web services, the approach is called the five Rs—retry, restart, reboot, reimage, and
replace. Let’s break them down:
■ Retry First off, you try the failed action again. Often something just goofed the first
time and will work the second time.
■ Restart If retrying doesn’t work, restarting often does. For services, this often means
rolling back and restarting a transaction or unloading a DLL, reloading it, and performing
the action again the way Internet Information Server (IIS) does.
■ Reboot If restarting doesn’t work, do what a user would do, and reboot the machine.
■ Reimage If rebooting doesn’t work, do what support would do, and reimage the
application or entire box.
■ Replace If reimaging doesn’t do the trick, it’s time to get a new device.
Welcome to the jungle



Much of our software doesn’t run as a service in a datacenter, and contrary to what Google
might have you believe, customers don’t want all software to depend on a service. For client
software, the five Rs might seem irrelevant to you. Ah, to be so naïve and dismissive.


The five Rs apply just as well to client and application software on a PC or a phone. The key
most engineers miss is defining the action, the scope of what gets retried or restarted.
On the web it’s easier to identify—the action is usually a transaction to a database or a GET
or POST to a page. For client and application software, you need to think more about what
action the user or subsystem is attempting.


Well-designed software will have custom error handling at the end of each action, just like
I talked about in my column “A tragedy of error handling” (which appears in Chapter 6).
Having custom error handling after actions makes applying the five Rs much simpler.
Unfortunately, lots of throwback engineers, like Axl Rose, use a Routine for Error Central
Handling (RECH) instead, as I described in the same column. If your code looks like Axl’s,
you’ve got some work to do to separate out the actions, but it’s worth it if a few actions harbor
most crashes and you aren’t able to fix the root cause.


Just like starting over


Let’s check out some examples of applying the five Rs to client and application software:
■ Retry PCs and devices are a bit more predictable than web services, so failed operations
will likely fail again. However, retrying works for issues that fail sporadically, like
network connectivity or data contention. So, when saving a file, rather than blocking
for what seems like an eternity and then failing, try blocking for a short timeout and
then trying again—a better result for the same time or less. Doing so asynchronously
unblocks the user entirely and is even better, but it might be tricky.
■ Restart What can you restart at the client level? How about device drivers, database
connections, OLE objects, DLL loads, network connections, worker threads, dialogs, services,
and resource handles. Of course, blindly restarting the components you depend
upon is silly. You have to consider the kind of failure, and you need to restart the full
action to ensure that you don’t confuse state. Yes, it’s not trivial. What kills me is that as
a sophisticated user, restarting components is exactly what I do to fix half the problems
I encounter. Why can’t the code do the same? Why is the code so inept? Wait for it, the
answer will come to you.
■ Reboot If restarting components doesn’t work or isn’t possible because of a serious
failure, you need to restart the client or application itself—a reboot. Most of the
Office applications do this automatically now. They even recover most of their state as a
bonus. There are some phone and game applications that purposely freeze the screen
and reboot the application or device in order to recover (works only for fast reboots).
■ Reimage If rebooting the application doesn’t work, what does product support
tell you to do? Reinstall the software. Yes, this is an extreme measure, but these days
installs and repairs are entirely programmable for most applications, often at a component
level. You’ll likely need to involve the user and might even have to check online for
a fix. But if you’re expecting the user to do it, then you should do it.
■ Replace This is where we lose. If our software fails to correct the problem, the customer
has few choices left. These days, with competitors aching

Monday, August 22, 2011

System Center Orchestrator 2012 - what's changing?


OIS 6.3 is repackaged and given a facelift but remains fundamentally the same.

By Kerrie Meyler and Pete Zerger. Now that System Center Orchestrator 2012 is available in beta, you may be wondering if it is worthwhile to continue creating policies with Opalis Integration Server (OIS) 6.3. Will you have to rewrite all your OIS policies for the next release?



Best online Microsoft MCTS Training, Microsoft MCITP Training at Certkingdom.com

This is a valid question, as Opalis Software's first release of OIS was not compatible with its previous OpalisRobot offering. However, Robot had a different code base than OIS. This is not the case going from OIS 6.3 to Orchestrator 2012, as the underlying engine is not changing, and Microsoft has announced that policies built in OIS (unless they use Legacy objects), along with their data, are usable in Orchestrator. Of course, some things ARE changing; here is a quick look:

New Operator Console. The OIS console is based on Java, requires numerous downloads, and has a fairly painful installation. With Orchestrator, Microsoft has rewritten the console in Silverlight, and it now ships with the core product and uses typical Microsoft installation technology.

New Web Service. The Java-based Opalis web service is replaced by an OData web service. Invoking runbooks through this web service doesn't seem to be documented yet.

Renaming. Here are some of the terminology changes with Orchestrator 2012:

Foundation objects become standard activities (and objects are now known as activities). These objects have updated, as have the icons for these objects.
Policies renamed to runbooks
Action server renamed to runbook server
Policy Testing Console becomes the Runbook Tester
Operator Console now the Orchestration Console

Changes in Foundation objects (now Standard activities).

Workflow Control category now called Runbook Control
Custom Start now Invoke Data
Publish Policy Data now Return Data
Trigger Policy now Invoke Runbooks
Notification Category - Send Page activity gone
System Category - Purge Event Log activity gone

WSDL gone. System Center Orchestrator 2012 uses a ReST-based Web Service so there is no WSDL. The web service supports OData, enabling easy management of the runtime environment.

Security. Updated cryptography and security model based on Microsoft best practices, allowing for centralized security management.

Operating environment for system components. Orchestrator must be installed on Windows 2008 R2 (SP1 is supported), and requires Microsoft SQL Server 2008 R2 for its database engine

No Oracle backend support. This should not be much of a surprise, given that Microsoft does not have a history of using Oracle for a database engine. System Center Opalis Integration Server 6.3 Unleashed warns that this was not anticipated to be a supported platform in the next release. And from what we've heard, the people who had to support it are happy it's gone!

Although there is no longer support for Legacy objects - and their use was not recommended even in OIS 6.3 - the engine is still 32-bit and has not been re-architected. Other than some terminology changes, improved installation experience, and new consoles, the product remains fundamentally the same. This means that your policies will continue to work after you export them out of the Opalis environment and into the Orchestrator environment (presuming there are no legacy objects in the policies).

At the moment, Operations Manager 2012 and Orchestrator SCO 2012 work together, although most of the System Center 2012 beta products do not, and will not until MS produces updated IPs for them.

Figure 1 shows the new Orchestrator console, Figure 2 displays the .Net Orchestration Console and Web Service in IIS Manager.

Saturday, August 20, 2011

Inspector Gadgets: Windows 7 Gadgets for Monitoring Your PC


It's been nearly two years since Windows 7 was released, and yet there are still some features that Windows 7 users may not be taking full advantage of -- such as desktop gadgets. Similar to the Mac's Dashboard Widgets, Windows desktop gadgets are mini-applications that reside on your desktop and can display live data, perform simple functions like search or password generation, or give you a sneak peek inside the inner workings of your PC.



Best online Microsoft MCTS Training, Microsoft MCITP Training at Certkingdom.com


Brand-specific gadgets

While the focus of this story is on gadgets that everyone can use to get some insight into how their system is working, I've also included two great gadgets that require specific hardware or software to work: the gadget that's included with Symantec's (SYMC) Norton Internet Security software and the Intel Core Series gadget for looking at certain Intel (INTC) processors.

Norton Internet Security gadget

Symantec's Norton gadget is among the most colorful. When the software is up to date and Internet bad guys are kept at bay, there's a prominent green banner across the top of the gadget that says "Secure." You'll immediately know that something is amiss if, for instance, your version of the software is out of date, because the banner turns red and says "At Risk."

Below the banner are icons that lead to the four major elements of the security suite. You can see details about the system's current security status, discover what other members of your family have been doing online (the software keeps tabs on other computers on your network that share your Norton Internet Security license), check if your backups are up to date and find out if a website is safe before clicking to it.

There's no download link for the Norton gadget: The only way to get it is to buy Norton Internet Security (regularly $70; now on sale for $50).

Intel Core Series

By contrast, the Core Series gadget is available online and can tell you a lot about your system's processor -- but only if it's a recent Intel CPU.

The gadget wasn't written by Intel, but it does a great job of interrogating Intel processors. (AMD (AMD) has a similar system monitoring program, but it's a full Windows 7 application, not a gadget.)

Like System Control A1, the Core Series gadget monitors up to eight processing threads (rather than cores, as it says), but it's valuable information nonetheless. It adds a handy overall CPU Usage rating and a graph below. If you add the WinRing0 software, which Core Series can download for you, the gadget can display the chip's actual clock speed as well.

You can choose a color scheme for the gadget and tell it what to include in the graph along the bottom: individual threads, all the operating threads, core temperature, or temperature and threads together. You can't resize it, though, which is a problem because the graph is rather crowded.

Thursday, August 18, 2011

Exam 70-620: Configuring Vista Client

My exam was taken this morning - I was seriously unimpressed with the 70-620. It covers configuring Vista - or at least the new features, UAC, the Wireless connectivity, presentation settings etc etc.

If this is your very first Microsoft exam then its an easy introduction - if you have any significant history with Microsoft exams you will find it very easy - too easy.


Best online Microsoft MCTS Training, Microsoft MCITP Training at Certkingdom.com

The questions are about which menu option do you choose or which button do you click. Very little, if any, understanding of the underlying concepts is required to pass this exam.

I thought the NT exams were fairly easy. Things started to get more challenging with the Windows 2000 and Windows 2003 exams. This is a complete reversal.

I hope this isn't setting the standard for exams to come in the Windows 2008 wave of products.

Wednesday, August 17, 2011

Default Groups


Windows Server 2003 has four categories of default groups: groups in the Builtin folder, groups in the Users folder, special identity groups, and default local groups. All of the default groups are security groups and have been assigned common sets of rights and permissions that you might want to assign to the users and groups that you place into the default groups.



Best online Microsoft MCTS Training, Microsoft MCITP Training at Certkingdom.com


Groups in the Builtin Folder

Windows Server 2003 creates default security groups with a domain local scope in the Builtin folder in the Active Directory Users And Computers console. The groups in the Builtin folder are primarily used to assign default sets of permissions to users who have administrative responsibilities in the domain. Table 8-2 describes the default groups in the Builtin folder.

This group exists only on domain controllers. By default, the group has no members. By default, members can create, modify, and delete accounts for users, groups, and computers in all containers and OUs of Active Directory except the Builtin folder and the Domain Controllers OU. Members do not have permission to modify the Administrators and Domain Admins groups, nor do they have permission to modify the accounts for members of those groups.

Members have complete and unrestricted access to the computer or domain controller, including the right to change their own permissions. If the Administrator account resides on the first domain controller con-figured for the domain, the Administrator account is automatically added to the Domain Admins group and complete access to the domain is granted.

By default, this group has no members. Members can back up and restore all files on a computer, regardless of the permissions that pro¬tect those files. Members can also log on to the computer and shut it down.

Members have the same privileges as members of the Users group. Members can create incoming, one-way trusts to this forest.

Members have the same default rights as members of the Users group. Members can perform all tasks related to the client side of network configuration except for installing and removing drivers and services. Members cannot configure network server services such as the Domain Name System (DNS) and Dynamic Host Configuration Protocol (DHCP) server services.

Members have remote access to schedule logging of performance counters on this computer.

Members have remote access to monitor this computer.

Members have read access on all users and groups in the domain. This group is provided for backward compatibility for computers running Microsoft Windows NT 4 and earlier.

This group exists only on domain controllers. Members can manage printers and document queues.

Members can log on to a computer from a remote location.

This group supports directory replication functions and is used by the file replication service on domain controllers. By default, the group has no members. The only member should be a domain user account used to log on to the Replicator services of the domain controller. Do not add users to this group.

This group exists only on domain controllers. By default, the group has no members. Members can log on to a server interactively, create and delete network shares, start and stop services, back up and restore files, format the hard disk of the computer, and shut clown the computer.

Terminal Server License Servers

Members are prevented from making accidental or intentional system-wide changes. Members can run certified applications, use printers, shut down and start the computer, and use network shares for which they are assigned permissions. Members cannot share folders or install printers on the local computer. By default, the Domain Users group is a member.

Members have access to the computed tokenGroupsGlobalAndUniversal attribute on User objects.

Off the Record If you need to create a list of groups, you can use the Net Localgroup and Net Group commands. For example, you could open a command prompt and type net localgroup > C:\localgroups.txt to create a list of local groups in a file named C:\localgroups.txt. As another example of how the Net commands work, examine and run the batch file named Grouplistings.bat on the Supplemental CD-ROM in the \70-294\ Labs\Chapter08 folder.

Tuesday, August 16, 2011

Taking the 70-620 TS: Windows Vista, Configuring Exam

If you go for the MCSE or MCITP Enterprise, you will have to take an exam covering a client operating system. One exam, you can take the 70-620: Configuring Microsoft Windows Vista.
The objectives are broken down to the following main groups:


Best online Microsoft MCTS Training, Microsoft MCITP Training at Certkingdom.com

* Installing and Upgrading Windows Vista
* Configuring and Troubleshooting Post-Installation System Settings
* Configuring Windows Security Features
* Configuring Network Connectivity
* Configuring Applications Included with Windows Vista
* Maintaining and Optimizing Systems That Run Windows Vista
* Configuring and Troubleshooting Mobile Computing

As with an operating system, you should first start with how to install Windows Vista. Besides running the normal installation DVD, you also need to be familiar with how to install Windows Vista with answer files, Windows images, ImageX, and Sysprep. You will then need to know how to upgrade from older versions of Windows to Windows Vista and from one version of Windows Vista to another version of Windows Vista. You will also need to know how to migrate data files and settings from one computer running Windows to a new computer running Windows Vista using Windows Easy Transfer (WET) and User State Migration Tool V3.0.

One of the new enhancements to the Windows Interface is Windows Aero. Therefore, you need to know the requirements for Aero to work including the color depth, the refresh rate, theme, color scheme and frame transparency.

With Windows Vista, Microsoft has enhanced some tools while introducing entirely new set of tools. For the exam, you will need to know accessibility tools and parental control. Of course, since the wide adoption of IPv6 is right around the corner, you will need to know how to configure IPv4 and IPv6. In addition, since wireless technology has become commonplace, you will need to know how to setup wireless connections.

Over the last few years, there has been a big push for security with Microsoft operating system and applications. As with any modern Windows operating system, you will need to know how to configure file system security. This will be done with NTFS permissions, Share permissions, EFS and BitLocker. BitLocker is a new technology that can encrypt an entire drive, which will protect if a computer such as a laptop is stolen. Be sure to know when it is best to use EFS for encryption and when it is best to use BitLocker. Also know the system requirements for BitLocker.

If you have used Windows Vista, you have seen and experienced User Account Control (UAC). So you will need to know how User Account Control protects your computer and you will need to know how to react to User Account Control prompts and if necessary, you will need to know how to disable UAC. Other tools that help protect your computer are Windows Defender and Windows Firewall. Therefore, you will need to know how to configure those tools.

Besides the new updated interface, Windows Vista also included Internet Explorer (IE) 7.0. Therefore, you will need to know how to configure IE. In addition, you will need to know how to configure Windows Media Player and Media Player Center including understanding regions and Codecs.

As a user, you will need to use standard applications include Wordpad, Notepad, Mail, Calendar, Fax and Scan and Meeting Space. You also need to now how to configure Windows Sidebar and its gadgets.

Lastly, you need to know the tools that are made for mobile computers. That would be including configuring Power management (power plans and hibernate, hybrid and sleep mode), Sync center, offline folders and Windows SideShow. Lastly, you need to be familiar with how to configure Tablet PCs and how to configure Flicks.

If you want to prepare for this exam, I would highly recommend the Exam Cram book 70-620 TS: Windows Vista, Configuring by Patrick Regan (Que Publishing), which will cover each of these topics and give you plenty of practice questions.

Monday, August 15, 2011

70-680 Exam Questions&Answers-Part 2






Best online Microsoft MCTS Training, Microsoft MCITP Training at Certkingdom.com


Exam : Microsoft 70-680

Title : TS: Windows 7, Configuring

13. You have a computer named Computer1 that runs Windows Vista and a computer named Computer2 that runs Windows 7.

You plan to migrate all profiles and user files from Computer1 to Computer2.

You need to identify how much space is required to complete the migration.

What should you do?

A. On Computer1 run Loadstate c:\store /nocompress

B. On Computer1 run Scanstate c:\store /nocompress /p

C. On Computer2 run Loadstate \\computer1\store /nocompress

D. On Computer2 run Scanstate \\computer1\store /nocompress /p

Answer: B



14. You have a computer that runs Windows Vista. The computer contains a custom application.

You need to export the user state and the settings of the custom application.

What should you do?

A. Run Loadstate.exe and specify the /config parameter.

B. Run Scanstate.exe and specify the /genconfig parameter.

C. Modify the miguser.xml file. Run Loadstate.exe and specify the /ui parameter.

D. Modify the migapp.xml file. Run Scanstate.exe and specify the /i parameter.

Answer: D



15. You have a reference computer that runs Windows 7.

You plan to deploy an image of the computer.

You create an answer file named answer.xml.

You need to ensure that the installation applies the answer file after you deploy the image.

Which command should you run before you capture the image?

A. Imagex.exe /append answer.xml /check

B. Imagex.exe /mount answer.xml /verify

C. Sysprep.exe /reboot /audit /unattend:answer.xml

D. Sysprep.exe /generalize /oobe /unattend:answer.xml

Answer: D



16. You plan to deploy Windows 7 to 100 computers on your corporate network.

You install Windows 7 on a computer.

You and need to prepare the computer to be imaged.

What should you do before you create the image of the computer?

A. At the command prompt, run the Dism command.

B. At the command prompt, run the Sysprep command.

C. Start the computer from the Windows Preinstallation Environment (Windows PE) and then run the Imagex command.

D. Start the computer from the Windows Preinstallation Environment (Windows PE) and then run the Wpeutil command.

Answer: B



17. You have a computer that runs Windows 7.

You need to configure the computer to meet the following requirements:

Generate a new security ID (SID) when the computer starts.

Ensure that the Welcome screen appears when the computer starts.

What should you do?

A. Run Sysprep.exe /oobe /generalize.

B. Run Sysprep.exe /audit /generalize.

C. Run Msconfig.exe and select Selective startup.

D. Run Msconfig.exe and select Diagnostic startup.

Answer: A



18. You have a reference computer that runs Windows 7.

You plan to create an image of the computer and then deploy the image to 100 computers.

You need to prepare the reference computer for imaging.

What should you do before you create the image?

A. Run Package Manager.

B. Run the System Preparation tool.

C. Install the User State Migration Tool.

D. Install Windows Automated Installation Kit.

Answer: B



19. You start a computer by using Windows Preinstallation Environment (Windows PE).

You need to dynamically load a network adapter device driver in Windows PE.

What should you do?

A. Run Peimg.exe and specify the device driver path.

B. Run Drvload.exe and specify the device driver path.

C. Run Winpeshl.exe and specify a custom Winpeshl.ini file.

D. Run Wpeutil.exe and specify the InitializeNetwork command.

Answer: B



20. You plan to install Windows 7 by using a Windows 7 DVD.

You need to perform an automated installation of Windows 7.

What should you do?

A. Create an answer file named oobe.xml. Copy the file to a network share.

B. Create an answer file named winnt.sif. Place the file on a removable drive.

C. Create an answer file named sysprep.inf. Copy the file to a network share.

D. Create an answer file named autounattend.xml. Place the file on a removable drive.

Answer: D



21. You have a Virtual Hard Disk (VHD) and a computer that runs Windows 7. The VHD has Windows 7 installed.

You need to start the computer from the VHD.

What should you do?

A. From Diskpart.exe, run Select vdisk.

B. From Disk Management, modify the active partition.

C. Run Bootcfg.exe and specify the /default parameter.

D. Run Bcdedit.exe and modify the Windows Boot Manager settings.

Answer: D



22. You have a new computer that does not have an operating system installed.

You have a virtual hard disk (VHD) that contains an installation of Windows 7.

You start the computer from the Windows Preinstallation Environment (Windows PE). You create a partition on the computer and copy the VHD to the partition.

You need to configure the computer to start from the VHD.

Which tools should you use?

A. Diskpart.exe and Bcdboot.exe

B. Imagex.exe and Bcdedit.exe

C. Scanstate.exe and Loadstate.exe

D. Wpeutil.exe and Dism.exe

Answer: A



23. Your have a computer that runs Windows 7.

You need to confirm that all device drivers installed on the computer are digitally signed.

What should you do?

A. At a command prompt, run Verify.

B. At a command prompt, run Sigverif.exe.

C. From Device Manager, click Scan for hardware changes.

D. From Device Manager, select the Devices by connection view.

Answer: B



24. You have a computer that runs Windows 7.

Multiple users log on to the computer.

You need to deny one user access to removable devices on the computer. All other users must have access to the removable drives.

What should you do?

A. From the local Group Policy, modify an application control policy.

B. From Control Panel, modify the BitLocker Drive Encryption settings.

C. From Device Manager, modify the settings of all removable devices.

D. From the local Group Policy, modify a removable storage access policy.

Answer: D



25. You have a computer that runs Windows 7.

You need to modify the file extensions that are associated to Internet Explorer.

What should you do?

A. From Internet Explorer, click Tools and then click Manage Add-ons.

B. From Control Panel, open Default Programs and then click Set Associations.

C. From the local Group Policy, expand Computer Configuration and then click Software Settings.

D. From Window Explorer, right-click %programfiles%\Internet Explorer\iexplore.exe and then click Properties.

Answer: B



26. Your network contains 100 computers that run Windows XP.

You need to identify which applications installed on all of the computers can run on Windows 7.

You must achieve this goal by using the minimum amount of administrative effort.

What should you install?

A. Microsoft Application Compatibility Toolkit (ACT)

B. Microsoft Assessment and Planning (MAP) Toolkit

C. Microsoft Deployment Toolkit (MDT)

D. Windows Automated Installation Kit (AIK)

Answer: A



27. You have a stand-alone computer named Computer1 that runs Windows 7. Several users share Computer1.

You need to prevent all users who are members of a group named Group1 from running Windows Media Player. All other users must be allowed to run Windows Media Player. You must achieve this goal by using the least amount of administrative effort.

What should you do?

A. From Software Restriction Policies, create a path rule.

B. From Software Restriction Policies, create a hash rule.

C. From Application Control Policies, create the default rules.

D. From Application Control Policies, create an executable rule.

Answer: D



28. You have a computer that runs Windows 7.

Your company has three custom applications named app1.exe, app2.exe, and app3.exe. The applications have been digitally signed by the company.

You need to create a policy that allows only applications that have been digitally-signed by the company to run.

What should you create?

A. an AppLocker executable rule

B. an AppLocker Windows Installer rule

C. a software restriction policy and a certificate rule

D. a software restriction policy and a hash rule

Answer: A

29. You have a computer that runs Windows 7.

You need to prevent Internet Explorer from saving any data during a browsing session.

What should you do?

A. Disable the BranchCache service.

B. Modify the InPrivate Blocking list.

C. Open an InPrivate Browsing session.

D. Modify the security settings for the Internet zone.

Answer: C



30. Your company has an Active Directory domain. All computers are members of the domain.

Your network contains an internal Web site that uses Integrated Windows Authentication.

From a computer that runs Windows 7, you attempt to connect to the Web site and are prompted for authentication.

You verify that your user account has permission to access the Web site.

You need to ensure that you are automatically authenticated when you connect to the Web site.

What should you do?

A. Create a complex password for your user account.

B. Open Credential Manager and modify your credentials.

C. Add the URL of the Web site to the Trusted sites zone.

D. Add the URL of the Web site to the Local intranet zone.

Answer: D

31. Your network consists of a single IPv4 subnet. The subnet contains 20 computers that run Windows 7.

You add a new computer named Computer1 to the subnet.

You discover that Computer1 has an IP address of 169.254.34.12.

You cannot connect to other computers on the network. Other computers on the network can connect to each other.

You need to ensure that you can connect to all computers on the network.

What should you do?

A. Turn off Windows Firewall.

B. Run Ipconfig.exe /renew.

C. Configure a static TCP/IP address.

D. Run Netsh.exe interface ipv4 install.

Answer: C



32. You have a computer that runs Windows 7.

The IPv6 address of the computer is configured automatically.

You need to identify the IPV6 address of the computer.

What should you do?

A. At the command prompt, run Netstat.

B. At the command prompt run Net config.

C. From the network connection status, click Details.

D. From network connection properties, select Internet Protocol Version 6 (TCP/IPv6) and click Properties.

Answer: C



33. Your network consists of an Active Directory domain named contoso.com. You have a computer named computer1.contoso.com.

Your network is configured to use only IPv6.

You need to request that a DNS record be created to enable users to connect to your computer by using the name dev.contoso.com.

Which type of record should you request?

A. A

B. AAAA

C. HINFO

D. NAPTR

Answer: B



34. Your network contains a wireless access point. You have a computer that runs Windows 7. The computer connects to the wireless access point.

You disable Service Set Identifier (SSID) broadcasts on the wireless access point.

You discover that you are now unable to connect to the wireless access point from the Windows 7 computer.

You need to ensure that the computer can connect to the wireless access point.

What should you do?

A. From Credential Manager, modify the generic credentials.

B. From Credential Manager, modify the Windows credentials.

C. From Network and Sharing Center, turn on Network discovery.

D. From Network and Sharing Center, modify the wireless network connection setting.

Answer: D



35. You have a wireless access point that is configured to use Advanced Encryption Standard (AES) security. A pre-shared key is not configured on the wireless access point.

You need to connect a computer that runs Windows 7 to the wireless access point.

Which security setting should you select for the wireless connection?

A. 802.1x

B. WPA-Personal

C. WPA2-Enterprise

D. WPA2-Personal

Answer: C



36. You have a computer named Computer1 that runs Windows 7.

You need to ensure that Computer1 can connect to File Transfer Protocol (FTP) servers only while it is connected to a private network.

What should you do?

A. From Windows Firewall with Advanced Security, create a new rule.

B. From the local Group Policy, modify the application control policies.

C. From Windows Firewall, modify the Allowed Programs and Features list.

D. From Network and Sharing Center, modify the Advanced Sharing settings.

Answer: A

MCITP Training - MCITP Certificaion - MCTS Exams Training - CCNA Exams - and more at CertKingdom.com