Exam Number/Code: 70-236
Exam Name: TS: Exchange Server 2007, Configuring

"TS: Exchange Server 2007, Configuring", also known as 70-236 exam, is a Microsoft certification.

You work as the network administrator at Certkiller .com. You are currently in the
process of developing an application that extends the Windows Server 2003 Active
Directory schema.
You create a new Active Directory forest in a test lab to test the new application.
The test forest contains two domain controllers named Certkiller -DC01 and
Certkiller -DC02, and the functional level of the forest have been set at Windows
Server 2003. You install the application on Certkiller -DC01, which is configured
as the schema master, and discover that it has created new schema classes with
incorrect names.
You uninstall the application and modify its code so that it will create the required
schema classes with correct names when it is installed.
You need to ensure that you continue to use the test environment without installing
a new forest.
What should you do?
A. You need to rename the schema classes that have incorrect names.
B. You should install the repaired application on Certkiller -DC02.
C. You need to delete the schema classes that have incorrect names.
D. You need to deactivate the schema classes that have incorrect names.
Answer: D
Explanation: The Active Directory schema is a set of definitions of object classes
and attributes, which are for the creation of new Active Directory objects. You can
add new classes and attributes to extend the schema. Once new attributes or classes
are added to the schema, they cannot be renamed, deleted or overwritten. When you
installed the original version of the application, it created new schema classes with
incorrect names. When you uninstall the application, these classes remained in the
schema. The next time you install the application, it will attempt to create new
classes with the same object IDs as the ones that were created by the previous
version of the application, but with different names. To be able to reuse the existing
object IDs, you deactivate the classes with incorrect names.
Incorrect Answers:
A, C: Once new attributes or classes are added to the schema, they cannot be renamed,
deleted or overwritten.
B: Installing the application on Certkiller -DC02 will not enable you to avoid this
You work as the network administrator at Certkiller .com. The Certkiller .com
network consists of a single Active Directory domain named Certkiller .com. All
servers on the Certkiller .com network run Windows Server 2003 and all client
computers run Windows XP Professional.
The Certkiller .com network contains numerous file servers that have been placed in
an OU named File Servers, which you have created for the purpose of managing file
servers. A GPO that is linked to the File Servers OU has the default security settings
specified for file servers.
You have recently deployed a new file server named
Certkiller -SR05. Shortly thereafter, users report that they are receiving unusual
errors when attempting to access certain resources on Certkiller -SR05. You
confirm that Certkiller -SR05 was deployed in the File Servers OU. After
troubleshooting further, you suspect that the default settings have been modified by
another network administrator.
You need to ensure that the default settings are reapplied as soon as possible.
What should you do?
A. You should restore all data, including system state data, from the latest backup.
B. You need to run the gpupdate /force command on Certkiller -SR05.
C. You should run the secedit command on Certkiller -SR05.
D. You have to move Certkiller -SR05 to a different OU, and then move it back to the
File Servers OU.
Answer: B
Explanation: Because the default security settings are applied through a GPO
linked to the OU that contains Certkiller -SR05, you can restore the security
settings by running the gpupdate /force command. The gpupdate command is used
to refresh Group Policy settings stored in the Active Directory, which includes
security settings. The /force option ignores all processing optimizations and
reapplies all settings.
Incorrect Answers:
A: Restoring from backups does not guarantee that the problem will be fixed, because
you do not know if the latest backup was made before the security settings were changed.
C: The secedit command is not used by Windows Server 2003 to reapply security
D: Moving a computer from one OU to another does not cause an immediate update.
You have recently been employed as a network administrator at Certkiller .com. The
Certkiller .com network consists of a single Active Directory domain named
Certkiller .com. All servers on the Certkiller .com network run Windows Server 2003.
Half the client computers run Windows 2000 Professional, and the rest run
Windows XP Professional. All client computers are included in an OU named Client
Computers, which has a GPO named Client Settings linked to it.
The former network administrator made the Domain Users group a member of the
local Power Users group on each client computer to allow users to run a custom
legacy application that does not comply with the Designed for Windows Logo
Program for Software. This configuration has produced various problems, like
users maguide unauthorized modifications to their computers. You notice that the
former network administrator also directly edited security policy settings on
numerous client computers.
Your first task is to rectify configuration changes and difficult-to-maintain security
configurations that were implemented by the former network administrator.
You need to ensure that the solution you choose does not negatively affect network
or domain performance.
What should you do? To answer, select the appropriate options and place it under
the correct node in the work area.
You need to apply the Setup security.inf security template to revert each client to the
default security. Microsoft specifies that Setup security.inf should never be applied
through Group Policy, because a large amount of data contained in the security template
can degrade performance.
You should import the Compatws.inf security template into the GPO linked to the Client
Computers OU, to have it applied to all client computers. Compatws.inf is designed to
remedy the compatability issues with legacy applications applications that require Power
Users membership by assigning necessary rights to standard users. The security template
will also remove all members from the Power Users group automatically.
