This is a composition of 7 questions that may or may not be included on your exam.  I had a few of these myself.  These were added because the original 81 questions obviously are not enough.

1. You are the network administrator for the Beijing office of Westwood Bank. A branch office is located in Cairo. The DNS servers in both locations run Windows Server 2003.<p>The network uses two DNS namespaces internally. They are named publishing.contoso.com. The location of the primary name servers are shown in the following table.<p>
<b>Namespace	- Location of primary name server </b><br>
publishing.contoso.com	- Cairo office<br>
contoso.com	- Beijing Office<p>
The Beijing office contains some servers that are registered in the contoso.com zone and other that are registered in the publishing.contoso.com zone. All computers in the Beijing office are configured to use the local DNS server as their preferred DNS server. The two offices are connected only by using a VPN through the internet. Various network problems occasionally result in loss of connectivity between the two offices. 

Firewalls prevent the DNS server in the Beijing office to allow successful resolution of all queries from the Beijing office for names in the publishing.testking.com namespace, even when the VPN link between the Beijing and Cairo offices fails. 

What should you configure on the DNS server in the Beijing office?

A.In the contoso.com zone, create a delegated subdomain named publishing. Specify the DNS server in the Cairo office as a name server.

B.Create a secondary zone name publishing.contoso.com.  Specify the DNS server in the Cairo office as a master server.

C.Configure conditional forwarding for the publishing.contoso.com namespace. Specify the DNS server in the Cairo office as a target server.

D.Create a stub zone named publishing.contoso.com. Specify the DNS server in the Cairo office as a master server.

Answer:B

2. You are the network administrator for Contoso. The network consists of a single Active Directory domain named contoso.com. The domain contains two Windows Server 2003 domain controllers named Server1 and Server2. Server1 and Server2 have the DNS service installed.<p> Server1 is located in the main office in Toronto.  Server2 is located I a branch office in Mexico City. The branch office network contains an IP subnet with the network address 192.168.1.0/24. You plan to designate main office servers as the master servers for any future reverse lookup zone. The DNS servers are not configured to perform reverse lookups. <p> You need to create a reverse lookup record for a branch office client computer named computer1.contoso.com, which has IP address of 192.168.1.21.  What should you do?<p>
<b>Note:</b> On the exam it will say<i> "To answer, drag the action that you should perform first the Action 1 box. Continue dragging actions to the corresponding numbered boxes until you list all required actions in the correct order. You might not need to use all numbered boxes."</i> Here, just select the correct three answers.<p>

A.On Server1, create a primary reverse lookup zone named 1.168.192.in-addr.arps

B.On Server1, create a zone delegation for 0/24 that points to Server 2

C.Create a PTR record for 21 that has an FQDN of computer1.contoso.com.

D.On Server2, create a primary reverse lookup zone named 1.168.192.in-addr.arps

E.On Server2, create a zone delegation for 0/24 that points to Server 2

F.Create a CNAME record for 21 that has an FQDN of computer1.contoso.com

Answer: A,B,C 

I had this question myself.  Just remember these first three.  They will not be in order on the exam.  Drag them to their respective spots in the order above.

3. You are the network administrator for Contoso. The company registers the DNS domain name contoso.com. The contoso.com DNS domain will contain the host name records for three servers in the company that are accessible from the Internet. One of these servers functions as a Web server, one functions as an FTP server, and one functions as a mail server.

The primary name server for the contoso.com zone is a Windows Server 2003 computer named CONTOSOSRVA. CONTOSOSRVA is on a network segment that is accessible form the Internet.

The company also wants to use the DNS namespace contoso.com to register hosts from the internal network. The internal network is protected by a firewall that filters traffic from the Internet. The written company security policy states that host names on the internal network must not be resolved by queries from the Internet.

You install Windows Server 2003 on a computer named CONTOSOSRVB. CONTOSOSRVB will be used to allow computers on the internal network to resolve host names in the contoso.com namespace. All computers on the internal network will be configured to use CONTOSOSRVB as their DNS server. The company network is configured as shown it the exhibit.

You need to configure CONTOSOSRVA and CONTOSOSRVB so that all computers on the internal network can resolve the host names of <p>
<li>other computers on the internal network, and</li>
<li>the three servers that are accessible from the internet</li><p>
Which two actions should you perform? (Each correct answer presents part of the solution. Choose two)

A.Create a primary DNS zone named contoso.com on CONTOSSRVB.

B.Create a secondary DNS zone named contoso.com on CONTOSOSRVB.

C.Configure DNS forwarding from CONTOSOSRVB to CONTOSOSRVA.

D.Configure DNS forwarding from CONTOSOSRVA to CONTOSOSRVB.

E.Manually add a host (A) record for each computer on the internal network to the contoso.com zone on CONTOSOSRVA.

F.Manually add a host (A) record for each Internet-accessible computer to the contoso.com zone on CONTOSRVB.

Answer: A, F


4.You are a network administrator for Contoso. You work in the Contosos branch office in Cape Town. The network in your office consists of 40 Windows XP Professional desktop computers and one Windows Server 2003 computer named Contoso3. Contoso3 connects to the Internet through a 512-Kbps leased line. The main office of the company is in Johannesburg.

Users of the desktop computers in the Cape Town office are developers who are developing a new software product. You want these users to place daily builds of the product in a shared folder on Contoso3. You want developers in the Johannesburg office to be able to download the daily builds from Contoso3 by using FTP.

You install IIS on Contoso3 and configure the FTP site so that it is available to the developers in the Johannesburg office. However, when you monitor inbound Internet connection attempts to Contoso3, you notice many attempted HTTP connections.

You want to secure Contoso3 so that it is not susceptible to malicious Internet users. Contoso3 must also connect to the Internet to use Windows Update and to download virus definition updates. You do not want to purchase additional hardware or software.

What should you do on Contoso3?

A.Enable Internet Connection Sharing (ICS).

B.Configure port filtering on the network adapter to allow only TCP port 80 and TCP port 21.

C.Enable Internet Connection Firewall (ICF) and create service setting in the Internet Connection Firewall settings that allows:<br>
<li>Internal and external TCP port 21 to Contoso3.</li>
<li>Internal and external TCP port 80 to Contoso3.</li><p>

D.Enable Internet Connection firewall (ICF) and select the FTP Server check box in the Services tab.  Enter Contoso3 as the server hosting the FTP services.  

Answer: A


5.You are a network administrator for Contoso. The network consists of a single Active Directory domain named Contoso.com.

The domain contains two Windows Server 2003 terminal servers that host applications that are used by company employees. An organization unit (OU) named TerminalServers contains only the  computer accounts for these two Terminal servers. A Group Policy object (GPO) named TSPolicy is linked to the TerminalServers OU, and you have been granted the right to modify the GPO. 

Users should use the terminal servers to run only authorized applications. A custom financial application suite is currently the only allowed application. The financial application suite is installed in the folder C:\Program files\MT Apps. The financial application suite contains many executable files.

Users must also be able to use Internet Explorer to access a browser-based application on the company intranet. The browser-based application makes extensive use of unsigned ActiveX components. 

The financial application suite and the browser-based application are frequently updated with patches or new versions. 

You need to configure the terminal servers to prevent users from running unauthorized applications. You plan to configure software restriction policies in the TSPolicy GPO. To reduce administrative overhead, you want to create a solution that can be implemented once, without requiring constant reconfiguration.

Which three actions should you perform to configure software restrictions policies? (Each correct answer presents part of the solution. Choose three)

A.Set the default security level to <b>Disallowed</b>.

B.Set the default security level to <b>Unrestricted</b>.
 
C.Create a new certificate rule.

D.Create a new hash rule.

E.Create a new Internet zone rule. 

F.Create a new path rule.

Answer: A, E, F

6.You are a network administrator for Contoso. The network consists of a single Active Directory domain named Contoso.com. The Internet Web site is hosted on a Windows Server 2003 computer named Contoso4, which is a member of a workgroup. All Client computers are members of the domain and are enabled for IPSec.

The network security administrator creates a new security policy for Contoso4. The policy states that only HTTP traffic is permitted, that HTTP traffic must be encrypted, and that all computers must be authenticated.

The new security policy is implemented. Domain users report that they are not able to connect tot Contoso4. You load the IP Security Monitor snap-in, and you view the details shown it the following window.

You need to ensure that all domain users can securely connect to Contoso4. What should you do?

A.Install a digital certificate on Contoso4.

B.Make Contoso4 a member of the domain.

C.Change the source and destination ports for outbound traffic.

D.Change the source and destination ports for inbound traffic.

Answer:B

I had this question as well.


7.You are the network administrator for Contoso. The company has a main office at Toronto and several branch offices in North America. You work in Toronto. 

The network contains Windows Server 2003 computers and Windows XP Professional Computers.

A user named Lisa works in a branch office. She reports that her client computers cannot connect to a remote VPN server. You suspect that her client computer did not receive a recent hot fix.

You need to verify which hot fixes are installed on Lisas computer. What should you do?

A.From a command prompt, run the update.exe command.

B.From a command prompt, run the wmic.qfe command.

C.View the History-synch.xml file.

D.View the History-apprive.xml file.

Answer: B

I had this question as well.

