Mar 2016 updated: Exambible Microsoft 70-648 actual exam 151-165

★ Pass on Your First TRY ★ 100% Money Back Guarantee ★ Realistic Practice Exam Questions

Free Instant Download NEW 70-648 Exam Dumps (PDF & VCE):
Available on: https://www.certleader.com/70-648-dumps.html


High quality of 70-648 answers materials and bible for Microsoft certification for IT examinee, Real Success Guaranteed with Updated 70-648 pdf dumps vce Materials. 100% PASS Today!

2016 Mar 70-648 Study Guide Questions:

Q151. Your network contains two offices named Office1 and Office2. The offices connect to each other by using a demand-dial connection. 

You add a new subnet in Office2. 

You need to ensure that a demand-dial connection starts when users attempt to connect to resources in the new Office2 subnet. 

What should you do from the Remote Routing and Access console? 

A. From the remote access server in Office2, right-click the demand-dial interface and click Connect. 

B. From the remote access server in Office1, right-click the demand-dial interface and click Connect. 

C. From the remote access server in Office1, right-click the demand-dial interface and click Update Routes. 

D. From the remote access server in Office2, right-click the demand-dial interface and click Update Routes. 

Answer: C


Q152. Your network contains a Network Policy Server (NPS) named Server1. 

You need to configure a network policy for a VLAN. 

Which RADIUS attributes should you add? 

A. ¡¤Login-LAT-Service ¡¤Login-LAT-Node ¡¤Login-LAT-Group ¡¤NAS-Identifier 

B. ¡¤Tunnel-Assignment-ID ¡¤Tunnel-Preference ¡¤Tunnel-Client-Auth-ID ¡¤NAS-Port-Id 

C. ¡¤Tunnel-Client-Endpt ¡¤Tunnel-Server-Endpt ¡¤NAS-Port-Type ¡¤Tunnel-Password 

D. ¡¤Tunnel-Medium-Type ¡¤Tunnel-Pvt-Group-ID ¡¤Tunnel-Type ¡¤Tunnel-Tag 

Answer: D


Q153. Your company has two domain controllers named DC1 and DC2. DC1 hosts all domain and forest operations master roles. DC1 fails. 

You need to rebuild DC1 by reinstalling the operating system. You also need to rollback all operations master roles to their original state. You perform a metadata cleanup and remove all references of DC1. 

Which three actions should you perform next? (To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.) 

A. Transfer operations master roles from DC1 to DC2. 

B. Transfer operations master roles from DC2 to DC1. 

C. Seize operations master roles from DC1 to DC2. 

D. Seize operations master roles from DC2 to DC1. 

E. Rebuild DC1 as a replica domain controller. 

F. Rebuild DC2 as a replica domain controller. 

Answer: BCE 


Q154. Your company has an Active Directory domain. You plan to install the Active Directory Certificate Services (ADCS) server role on a member server that runs Windows Server 2008 R2. 

You need to ensure that members of the Account Operators group are able to issue smartcard credentials. They should not be able to revoke certificates. 

Which three actions should you perform? (Each correct answer presents part of the solution. Choose three.) 

A. Install the AD CS server role and configure it as an Enterprise Root CA . 

B. Install the AD CS server role and configure it as a Standalone CA . 

C. Restrict enrollment agents for the Smartcard logon certificate to the Account Operator group. 

D. Restrict certificate managers for the Smartcard logon certificate to the Account Operator group. 

E. Create a Smartcard logon certificate. 

F. Create an Enrollment Agent certificate. 

Answer: ACE


Q155. Your network contains a Windows Server Update Services (WSUS) server named Server1. 

You need to configure all WSUS client computers to download approved updates directly from the Microsoft Update servers. The solution must ensure that all WSUS client computers report successful installation of updates to Server1. 

What should you do? 

A. From Active Directory, deploy a Group Policy object (GPO). 

B. From Server1, modify the Update Source and Proxy options. 

C. From Server1, modify the Update Files and Languages options. 

D. From the WSUS client computers, modify the local computer policy. 

Answer: C


70-648 exam

Renew 70-648 latest exam:

Q156. You manage a server that runs Windows Server 2008 R2. The D:\Payroll folder is corrupted. The most recent backup version is 10/29/2007-09:00. 

You need to restore all the files in the D:\Payroll folder back to the most recent backup version without affecting other folders on the server. 

What should you do on the server? 

A. Run the Recover d:\payroll command. 

B. Run the Wbadmin restore catalog -backuptarget:D: -version:10/29/2007-09:00 quiet command. 

C. Run the Wbadmin start recovery -backuptarget:D: -version:10/29/2007-09:00 overwrite Quiet command. 

D. Run the Wbadmin start recovery -version:10/29/2007-09:00 -itemType:File -items:d:\Payroll -overwrite -recursive quiet command. 

Answer: D


Q157. Your company has a single Active Directory domain. The company has a main office and a branch office. Both the offices have domain controllers that run Active Directory-integrated DNS zones. All client computers are configured to use the local domain controllers for DNS resolution. The domain controllers at the branch office location are configured as Read-Only Domain Controllers (RODC). 

You change the IP address of an existing server named SRV2 in the main office. You need the branch office DNS servers to reflect the change immediately. 

What should you do? 

A. Run the dnscmd /ZoneUpdateFromDs command on the branch office servers. 

B. Run the dnscmd /ZoneUpdateFromDs command on a domain controller in the main office. 

C. Change the domain controllers at the branch offices from RODCs to standard domain controllers. 

D. Decrease the Minimum (default) TTL option to 15 minutes on the Start of Authority (SOA) record for the zone. 

Answer: A


Q158. All consultants belong to a global group named TempWorkers. You place three file servers in a new organizational unit named SecureServers. The three file servers contain confidential data located in shared folders. 

You need to record any failed attempts made by the consultants to access the confidential data. 

Which two actions should you perform? (Each correct answer presents part of the solution. 

Choose two.) 

A. Create and link a new GPO to the SecureServers organizational unit. Configure the Audit privilege use Failure audit policy setting. 

B. Create and link a new GPO to the SecureServers organizational unit. Configure the Audit object access Failure audit policy setting. 

C. Create and link a new GPO to the SecureServers organizational unit. Configure the Deny access to this computer from the network user rights setting for the TempWorkers global group. 

D. On each shared folder on the three file servers, add the three servers to the Auditing tab. Configure the Failed Full control setting in the Auditing Entry dialog box. 

E. On each shared folder on the three file servers, add the TempWorkers global group to the Auditing tab. Configure the Failed Full control setting in the Auditing Entry dialog box. 

Answer: BE


Q159. Your network contains a server that runs Windows Server 2008 R2. You create a User Defined Data Collector Set (DCS) named Set1. 

You need to ensure that the reports generated for Set1 are stored for at least one year. 

What should you do? 

A. From the properties of Set1, modify the Task settings. 

B. From the properties of Set1, modify the Shedule settings. 

C. From Data Manager for Set1 modify the Actions settings. 

D. From Data Manager for Set1, modify the Data Manager settings. 

Answer: C


Q160. Your network contains an Active Directory forest. The forest contains two domain controllers. The domain controllers are configured as shown in the following table. 

Server name Server configuration 

Global catalog server DC1 Schema master Domain naming master 

Primary domain controller (PDC) emulator DC2 RID master Infrastructure master 

All client computers run Windows 7. 

You need to ensure that all client computers in the domain keep the same time as an external time server. 

What should you do? 

A. From DC1, run the time command. 

B. From DC2, run the time command. 

C. From DC1, run the w32tm.exe command. 

D. From DC2, run the w32tm.exe command. 

Answer: D


70-648 simulations

Exact 70-648 download:

Q161. Your company has an Active Directory forest. The company has three locations. Each location has an organizational unit and a child organizational unit named Sales. The Sales organizational unit contains all users and computers of the sales department. The company plans to deploy a Microsoft Office 2007 application on all computers within the three Sales organizational units. 

You need to ensure that the Office 2007 application is installed only on the computers in the Sales organizational units. 

What should you do? 

A. Create a Group Policy Object (GPO) named SalesAPP GPO. Configure the GPO to assign the application to the computer account. Link the SalesAPP GPO to the domain. 

B. Create a Group Policy Object (GPO) named SalesAPP GPO. Configure the GPO to assign the application to the user account. Link the SalesAPP GPO to the Sales organizational unit in each location. 

C. Create a Group Policy Object (GPO) named SalesAPP GPO. Configure the GPO to publish the application to the user account. Link the SalesAPP GPO to the Sales organizational unit in each location. 

D. Create a Group Policy Object (GPO) named SalesAPP GPO. Configure the GPO to assign the application to the computer account. Link the SalesAPP GPO to the Sales organizational unit in each location. 

Answer: D


Q162. Your company has an Active Directory forest. The company has branch offices in three locations. Each location has an organizational unit. 

You need to ensure that the branch office administrators are able to create and apply GPOs only to their respective organizational units. 

Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.) 

A. Add the user accounts of the branch office administrators to the Group Policy Creator Owners Group. 

B. Modify the Managed By tab in each organizational unit to add the branch office administrators to their respective organizational units. 

C. Run the Delegation of Control Wizard and delegate the right to link GPOs for the domain to the branch office administrators. 

D. Run the Delegation of Control Wizard and delegate the right to link GPOs for their branch organizational units to the branch office administrators. 

Answer: AD


Q163. You need to receive an e-mail message whenever a domain user account is locked out. 

Which tool should you use? 

A. Active Directory Administrative Center 

B. Event Viewer 

C. Resource Monitor 

D. Security Configuration Wizard 

Answer: B


Q164. Your company has an Active Directory domain named contoso.com. The company network has two DNS servers named DNS1 and DNS2. 

The DNS servers are configured as shown in the following table: 


You need to enable Internet name resolution for all client computers. 

What should you do? 

A. Create a copy of the.(root) zone on DNS1. 

B. Update the list of root hints servers on DNS2. 

C. Update the Cache.dns file on DNS2. Configure conditional forwarding on DNS1. 

D. Delete the.(root) zone from DNS2. Configure conditional forwarding on DNS2. 

Answer: D


Q165. Your network contains two DHCP servers named Server1 and Server2. On Server1, you create a scope named Scope1. 

You need to ensure that DHCP clients receive IP addresses from the address range in Scope1 if 

Server1 is unavailable. The solution must prevent both servers from assigning duplicate IP addresses. 

What should you do from the DHCP console? 

A. On Server1, create a superscope. 

B. On Server1, select Scope1, and then run the Split-Scope wizard. 

C. On Server2, create a scope, and then reconcile each scope. 

D. On Server2, create a scope, and then enable Network Access Protection. 

Answer: B